PyPi: Scipp

CVE-2022-29238

Transitive

Safety vulnerability ID: 50232

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jun 14, 2022 Updated at Jun 21, 2024
Scan your Python projects for vulnerabilities →

Advisory

Scipp 0.15.0 updates its dependency 'notebook' to v6.4.12 to include a security fix.

Affected package

scipp

Latest version: 24.6.0

Multi-dimensional data arrays with labeled dimensions

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Raise ValueError if variance is 0 in curve_fit by jl-wynen in https://github.com/scipp/scipp/pull/2620
* Replace the widget-based table viewer with a simpler pure-HTML table by nvaytet in https://github.com/scipp/scipp/pull/2613
* Bump pypa/cibuildwheel from 2.5.0 to 2.6.0 by dependabot in https://github.com/scipp/scipp/pull/2614
* Update requirements via pip-compile-multi by SimonHeybrock in https://github.com/scipp/scipp/pull/2622
* Add nbstripout pre-commit hook and strip pycharm metadata by jl-wynen in https://github.com/scipp/scipp/pull/2623
* Add compact string formatter for Variables by g5t in https://github.com/scipp/scipp/pull/2556
* Update conan to avoid vulnerably pyjwt by SimonHeybrock in https://github.com/scipp/scipp/pull/2629
* To xarray by nvaytet in https://github.com/scipp/scipp/pull/2624
* Fix Variable.bins.concat(dim) by SimonHeybrock in https://github.com/scipp/scipp/pull/2638
* Fix hypothesis test flakyness and search critical param regions better by SimonHeybrock in https://github.com/scipp/scipp/pull/2637
* Keep target coords regardless of keep_* options by jl-wynen in https://github.com/scipp/scipp/pull/2642
* Minor update of "Data Structures" docs page by SimonHeybrock in https://github.com/scipp/scipp/pull/2643
* Fix linspace optimization by SimonHeybrock in https://github.com/scipp/scipp/pull/2644
* Fixes for copying binned structured data by SimonHeybrock in https://github.com/scipp/scipp/pull/2650
* Update notebook (security) by SimonHeybrock in https://github.com/scipp/scipp/pull/2651
* Change `flatten` to drop bin edges on mismatch, instead of raising by SimonHeybrock in https://github.com/scipp/scipp/pull/2652
* Bump pypa/cibuildwheel from 2.6.0 to 2.7.0 by dependabot in https://github.com/scipp/scipp/pull/2654
* Use specifc multi-threading threshold for reduction operations with binned data by SimonHeybrock in https://github.com/scipp/scipp/pull/2653
* New binning, grouping, and histogramming API by SimonHeybrock in https://github.com/scipp/scipp/pull/2633
* Fix slice by condition dim/shape checks by SimonHeybrock in https://github.com/scipp/scipp/pull/2657
* Add missing test for slice by condition by SimonHeybrock in https://github.com/scipp/scipp/pull/2659
* Pin versions in ci buildconfig environments by nvaytet in https://github.com/scipp/scipp/pull/2664
* Add possibility to switch to experimental plotting backend by nvaytet in https://github.com/scipp/scipp/pull/2645
* Bump JamesIves/github-pages-deploy-action from 4.3.3 to 4.3.4 by dependabot in https://github.com/scipp/scipp/pull/2663
* Optimization for auto-grouping by SimonHeybrock in https://github.com/scipp/scipp/pull/2658
* Support buffer types other than DataArray in HTML repr of scalar binned variable by SimonHeybrock in https://github.com/scipp/scipp/pull/2669
* Support variables in `hist`, `nanhist`, and `bin`. by SimonHeybrock in https://github.com/scipp/scipp/pull/2678
* ADR for removal of plotting resampling behavior by SimonHeybrock in https://github.com/scipp/scipp/pull/2661
* Keyword-arg API for `transform_coords` by SimonHeybrock in https://github.com/scipp/scipp/pull/2670
* Fix reduction operations of 0-D binned variables by SimonHeybrock in https://github.com/scipp/scipp/pull/2685
* Fix serious bug in `bin` by SimonHeybrock in https://github.com/scipp/scipp/pull/2680
* is_bins *does* support DataArray by SimonHeybrock in https://github.com/scipp/scipp/pull/2686
* Fix exception in `bin` with edges along dim other than input dim by SimonHeybrock in https://github.com/scipp/scipp/pull/2684
* Generalize `lookup` by SimonHeybrock in https://github.com/scipp/scipp/pull/2681
* Bump pypa/cibuildwheel from 2.7.0 to 2.8.0 by dependabot in https://github.com/scipp/scipp/pull/2690
* Support kwargs in rename_dims by jl-wynen in https://github.com/scipp/scipp/pull/2689
* Remove ancient tutorials by SimonHeybrock in https://github.com/scipp/scipp/pull/2693
* Support `__bool__` where sensible by SimonHeybrock in https://github.com/scipp/scipp/pull/2695
* [experimental plotting] Fix legend warning in 1d plot when legend labels are empty by nvaytet in https://github.com/scipp/scipp/pull/2698
* [experimental plotting] Fix pick callback for toggling norm on mesh when pick event does not originate from cbar by nvaytet in https://github.com/scipp/scipp/pull/2700
* [experimental plotting] Add better error message when trying to plot 3D data by nvaytet in https://github.com/scipp/scipp/pull/2699
* Fix usage of nbstripout by jl-wynen in https://github.com/scipp/scipp/pull/2701
* Update solar flares tutorial to new binning API by jl-wynen in https://github.com/scipp/scipp/pull/2697
* Update binned-data tutorial with new API by SimonHeybrock in https://github.com/scipp/scipp/pull/2694
* New docs by SimonHeybrock in https://github.com/scipp/scipp/pull/2702
* Compact string format by jl-wynen in https://github.com/scipp/scipp/pull/2625
* Fix error in new plotting when zooming in and returning to 'Home' with datetime axis by nvaytet in https://github.com/scipp/scipp/pull/2673
* Update "What's New" notebook and prepare for 0.15 by SimonHeybrock in https://github.com/scipp/scipp/pull/2704


**Full Changelog**: https://github.com/scipp/scipp/compare/0.14.0...0.15.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 4.3

CVSS v3 Details

MEDIUM 4.3
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
LOW
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
LOW
Integrity Impact (I)
NONE
Availability Availability (A)
NONE

CVSS v2 Details

MEDIUM 4.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
SINGLE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
NONE
Availability Impact (A)
NONE