Package | Installed | Affected | Info |
---|---|---|---|
websockets | 8.1 | >=8.0,<9.1 |
show Websockets before 9.1 has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. |
websockets | 8.1 | <10.0 |
show Websockets 10.0 includes a fix for a DoS vulnerability. https://github.com/aaugustin/websockets/commit/0a935b8ec16f4430ffe638cdbfbe45f6f9d7f684 |
https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/python-3-shield.svg
[![Python 3](https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/python-3-shield.svg)](https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/)
.. image:: https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/python-3-shield.svg :target: https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/ :alt: Python 3
<a href="https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/"><img src="https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/
{<img src="https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/]
https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg
[![Updates](https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg)](https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/)
.. image:: https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg :target: https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/ :alt: Updates
<a href="https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/"><img src="https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg(Updates)!:https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/
{<img src="https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/alpacahq/alpaca-trade-api-python/]