You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Your PR has commits that are missing the Signed-off-by trailer. This is likely due to the pre-commit hook not being configured on your local machine. The usual fix for this issue is to run pre-commit install --install-hooks --overwrite -t commit-msg -t pre-commit, however for more detailed help in setting up the pre-commit hooks, follow the instructions at https://github.com/uktrade/github-standards/blob/main/README.md#usage
Your PR has commits that are missing the Signed-off-by trailer. This is likely due to the pre-commit hook not being configured on your local machine. The usual fix for this issue is to run pre-commit install --install-hooks --overwrite -t commit-msg -t pre-commit, however for more detailed help in setting up the pre-commit hooks, follow the instructions at https://github.com/uktrade/github-standards/blob/main/README.md#usage
Critical: apache-airflow 2.6.3
Component with known vulnerability
Critical: django 1.5.10
Django Potential account hijack via password reset form
High: flask 2.2.4
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
View all
ℹ️ Info
No other issues found (see more)
🛠️ No new code quality issues
🛡️ No new code vulnerabilities
🧱 No new Infrastructure as Code (IaC) issues
🔑 No new secrets detected
Useful? React with 👍 / 👎
This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 81c2a9a | Docs | Give us feedback!
The reason will be displayed to describe this comment to others. Learn more.
🔴 High: Library Vulnerability
torch@2.7.1
View all suggested fixes
Suggested change
torch==2.7.1
torch==2.13.0
Suggested change
torch==2.7.1
torch==2.12.1
Component with known vulnerability
Helpful? 👍/👎
sumau
changed the title
DO NOT MERGE: Test adding requirements.in with known vulnerabilities
DO NOT MERGE: Test adding requirements.txt with known vulnerabilities
Jul 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test Datadog and GitHub Dependency review picks up vulnerabilities when adding requirements.txt with known vulnerabilities