基础信息
项目名称:aws/sagemaker-python-sdk
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1720815800441700352/1720815800496226304
此报告由Murphysec提供
漏洞列表
| 漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
|---|---|---|---|---|
| pylint 存在拒绝服务漏洞 | 拒绝服务 | MPS-2022-15071 | 中危 |
缺陷组件
| 组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
|---|---|---|---|---|
| pylint | 2.6.2 | 2.7.0 | 间接依赖 | 可选修复 |
许可证风险
| 许可证类型 | 相关组件 | 许可证风险 |
|---|---|---|
| 自定义许可证 | 8 | 低 |
| Apache-2.0 | 10 | 低 |
| MIT | 13 | 低 |
| BSD-2-Clause | 1 | 低 |
| LGPL-2.1-or-later | 2 | 低 |
| BSD-3-Clause | 3 | 低 |
| GPL-3.0 | 1 | 中 |
| GPL-2.0-or-later | 1 | 低 |
| MPL-2.0 | 1 | 低 |
SBOM清单
| 组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
|---|---|---|---|
| docutils | 0.15.2 | 间接依赖 | pip |
| transformers | 4.28.1 | 间接依赖 | pip |
| requests | 2.31.0 | 间接依赖 | pip |
| nd | 间接依赖 | pip | |
| flake8-future-import | 0.4.6 | 间接依赖 | pip |
| doc8 | 0.10.1 | 间接依赖 | pip |
| transforms | 间接依赖 | pip | |
| datasets | 2.12.0 | 间接依赖 | pip |
| contextlib2 | 21.6.0 | 间接依赖 | pip |
| jinja2 | 3.1 | 间接依赖 | pip |
| StandardScaler | 间接依赖 | pip | |
| Pygments | 2.15.0 | 间接依赖 | pip |
| astroid | 2.4.2 | 间接依赖 | pip |
| tox | 3.24.5 | 间接依赖 | pip |
| packaging | 20.9 | 间接依赖 | pip |
| pytest | 6.2.5 | 间接依赖 | pip |
| flake8 | 4.0.1 | 间接依赖 | pip |
| pyenchant | 3.2.2 | 间接依赖 | pip |
| schema | 0.7.5 | 间接依赖 | pip |
| pydocstyle | 6.1.1 | 间接依赖 | pip |
| mypy | 0.942 | 间接依赖 | pip |
| twine | 3.8.0 | 间接依赖 | pip |
| pandas | 1.3.4 | 间接依赖 | pip |
| sphinx | 3.1.2 | 间接依赖 | pip |
| apache-airflow-providers-amazon | 7.2.1 | 间接依赖 | pip |
| sphinx-rtd-theme | 0.5.0 | 间接依赖 | pip |
| pytest-cov | 3.0.0 | 间接依赖 | pip |
| Jinja2 | 3.0.3 | 间接依赖 | pip |
| TFAutoModelForSequenceClassification | 间接依赖 | pip | |
| PyYAML | 6.0 | 间接依赖 | pip |
| black | 22.3.0 | 间接依赖 | pip |
| stopit | 1.1.2 | 间接依赖 | pip |
| pyspark | 3.3.1 | 间接依赖 | pip |
| apache-airflow | 2.7.2 | 间接依赖 | pip |
| pytest-timeout | 2.1.0 | 间接依赖 | pip |
| sagemaker_rl | 间接依赖 | pip | |
| pytest-xdist | 2.4.0 | 间接依赖 | pip |
| AutoTokenizer | 间接依赖 | pip | |
| smdebug | 间接依赖 | pip | |
| LabelEncoder | 间接依赖 | pip | |
| cloudpickle | 2.2.1 | 间接依赖 | pip |
| pylint | 2.6.2 | 间接依赖 | pip |
| pytest-rerunfailures | 10.2 | 间接依赖 | pip |
| sagemaker-experiments | 0.1.35 | 间接依赖 | pip |
| fabric | 2.6.0 | 间接依赖 | pip |
| scikit-learn | 1.3.0 | 间接依赖 | pip |
| datasets | 间接依赖 | pip | |
| scipy | 1.10.1 | 间接依赖 | pip |
| awslogs | 0.14.0 | 间接依赖 | pip |
| scoring_logic | 间接依赖 | pip | |
| OneHotEncoder | 间接依赖 | pip | |
| mock | 4.0.3 | 间接依赖 | pip |
| rl_coach | 间接依赖 | pip | |
| gluon | 间接依赖 | pip | |
| pyvis | 0.2.1 | 间接依赖 | pip |
| fake-requirement-for-unit-tests | 1.0.0 | 间接依赖 | pip |