Safety vulnerability ID: 65481
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Maestrowf version 1.1.10 upgrades its cryptography package from version 37.0.1 to 38.0.3 as a measure to tackle the security vulnerability CVE-2022-3786.
https://github.com/LLNL/maestrowf/pull/410/commits/6768a29c2951d2e531dc1c7d0839a92f84bb4df0
Latest version: 1.1.10
A tool to easily orchestrate general computational workflows both locally and on supercomputers.
* Sync up read the docs config with dev environments using poetry (https://github.com/LLNL/maestrowf/pull/399)
* Print usage on command line when no args are provided (https://github.com/LLNL/maestrowf/pull/404)
* Add sacct fallback to slurm adapter to improve robustness of job tracking (https://github.com/LLNL/maestrowf/pull/405)
* Update Flurm Job State mappings for flux versions >= 0.26 (https://github.com/LLNL/maestrowf/pull/407)
* Bump certifi from 2021.10.8 to 2022.12.7 to address security issue (https://github.com/LLNL/maestrowf/pull/409)
* Bump cryptography from 37.0.1 to 38.0.3 to address security issue (https://github.com/LLNL/maestrowf/pull/410)
* Add missing shbang in unscheduled scripts from lsf adapter (https://github.com/LLNL/maestrowf/pull/411)
* Update poetry lockfile to address dependabot flagged security issues (https://github.com/LLNL/maestrowf/pull/412)
* Fix for Dockerfile smell DL3006 (https://github.com/LLNL/maestrowf/pull/418)
* Port Maestro documentation to mkdocs and expand coverage of features and tutorials (https://github.com/LLNL/maestrowf/pull/403)
* Update version info to be driven from pyproject.toml exclusively, and hook up to command line (https://github.com/LLNL/maestrowf/pull/419)
* Pin mermaid to < 10.x due to api change (https://github.com/LLNL/maestrowf/pull/422)
* Bump lock file certifi from 2022.12.7 to 2023.7.22 to address security issue (https://github.com/LLNL/maestrowf/pull/426)
* Refactor flux adapter to avoid using pickle to talk to flux brokers installed in external environments (https://github.com/LLNL/maestrowf/pull/415)
Also adds flux integration tests to exercise against real flux brokers
* Add pager functionality to status command (https://github.com/LLNL/maestrowf/pull/420)
* Patch broken flux job cancellation (https://github.com/LLNL/maestrowf/pull/428)
* Insulate slurm adapters from user customization of squeue and sacct output formats (https://github.com/LLNL/maestrowf/pull/431)
Also adds live unit and integration tests for slurm adapter
---------
Co-authored-by: Francesco Di Natale <frank.dinatale1988gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]users.noreply.github.com>
Co-authored-by: Bruno P. Kinoshita <kinowusers.noreply.github.com>
Co-authored-by: Charles Doutriaux <doutriaux1llnl.gov>
Co-authored-by: Giovanni Rosa <grosa23yahoo.com>
Co-authored-by: Brian Gunnarson <49216024+bgunnar5users.noreply.github.com>
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application