What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory PYSEC-2026-3038 applies
Minor caution · medium confidence
A library used by the launcher has a known security issue. If you install fresh, you will likely get the fixed version. If you reuse an old environment, you might keep a vulnerable version. Since the launcher only runs on your own computer, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3038 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint in a requirements file for a local-only launcher service. The greater-than-or-equal constraint allows installing patched versions on fresh environments, but also permits vulnerable versions to remain in pre-existing virtual environments without triggering an upgrade. The launcher binds to localhost only, limiting attack surface to the local machine.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-3038
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1471 applies
Minor caution · medium confidence
A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Because the launcher runs only on your computer, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1471 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint overlaps the advisory's affected version range, but fresh installs resolve to the latest available version which is likely patched. The service runs on localhost only, reducing exposure to remote attack.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1471
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-59g5-xgcq-4qw3 applies
Minor caution · medium confidence
A library used by the launcher has a serious known security issue. However, because the launcher only runs on your own computer and fresh installs should get the fixed version, the practical risk is low. The main concern is if you reuse an old installation.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-59g5-xgcq-4qw3 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. While the scanner severity is high, the greater-than-or-equal constraint means fresh installs will resolve to the latest version, which is likely patched. The launcher service binds to localhost, so remote exploitation is not feasible without local access. The primary concern is a stale virtual environment retaining a vulnerable version, but the project setup instructions direct users to create a fresh venv.
Impact: low · Exploitability: unlikely
Developer action: Pin the affected dependency to a specific patched version to ensure vulnerable versions are never retained in stale environments.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-59g5-xgcq-4qw3
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-h75v-3vvj-5mfj applies
Minor caution · medium confidence
A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Since the launcher runs only on your computer, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h75v-3vvj-5mfj to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint allows both vulnerable and patched versions. Fresh installs resolve to the latest version, but stale environments may retain a vulnerable version. The service is localhost-only, limiting exposure.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h75v-3vvj-5mfj
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-gmj6-6f8f-6699 applies
Minor caution · medium confidence
A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Because the launcher runs only on your computer, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-gmj6-6f8f-6699 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint overlaps the affected version range but also permits patched versions. The launcher runs on localhost, reducing the attack surface to local users only.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-gmj6-6f8f-6699
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-vffw-93wf-4j4q applies
Minor caution · medium confidence
A library used by the launcher has a minor known security issue. Fresh installs should get the fixed version, and the launcher only runs on your computer, so the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-vffw-93wf-4j4q to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The low scanner severity and localhost-only deployment further reduce practical risk. Fresh installs resolve to the latest version which is likely patched.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-vffw-93wf-4j4q
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-3040 applies
Minor caution · medium confidence
A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Since the launcher runs only on your computer, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3040 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint allows both vulnerable and patched versions. The service is localhost-only, limiting exposure to local users. Fresh installs resolve to the latest version.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-3040
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1475 applies
Minor caution · medium confidence
A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Because the launcher runs only on your computer, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1475 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint overlaps the affected version range but also permits patched versions. The launcher binds to localhost, so remote exploitation is not feasible without local access.
Impact: low · Exploitability: unlikely
Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1475
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1852 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1852 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1852
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1851 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1851 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1851
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-3037 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3037 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-3037
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-5rvq-cxj2-64vf applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5rvq-cxj2-64vf to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known high-severity advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5rvq-cxj2-64vf
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1473 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1473 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1473
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-cpwx-vrp4-4pq7 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-cpwx-vrp4-4pq7 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-cpwx-vrp4-4pq7
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-3036 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3036 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-3036
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-3041 applies
Minor caution · medium confidence
The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3041 to a dependency declared by this repository.
Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.
Impact: low · Exploitability: unlikely
Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-3041
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-pp6c-gr5w-3c5g applies
Minor caution · medium confidence
A library used by this local launcher tool has a known security issue in older versions. The version requirements allow older, vulnerable versions to be installed, though in practice a fresh install usually gets the fixed version. Since the tool runs only on your own machine, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-pp6c-gr5w-3c5g to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency declared with a lower-bound-only version constraint in a requirements file for a local launcher web UI. The constraint permits installation of versions known to contain a vulnerability, likely in a transitive web-framework dependency handling multipart form data. However, the launcher binds to localhost, fresh pip installs typically resolve to the latest patched version, and the practical impact is limited to local denial of service of a management tool. The advisory severity reflects the upstream library risk, not the deployment context here.
Impact: low · Exploitability: plausible
Developer action: Pin the affected dependency to a minimum version that excludes known-vulnerable releases, or add a lock file to ensure reproducible, patched installs.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-pp6c-gr5w-3c5g
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-v9pg-7xvm-68hf applies
Minor caution · medium confidence
A minor known issue exists in an older version of a templating library used by this local tool. The risk is very low because the tool runs on your machine and fresh installs usually get the fixed version.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v9pg-7xvm-68hf to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency declared with a broad lower-bound constraint. The likely affected package is a templating library used for rendering the launcher web UI. The vulnerability in the affected version range is low severity and the service is local-only, limiting both reachability and impact. Fresh installs would typically receive a patched version under the current constraint.
Impact: low · Exploitability: unlikely
Developer action: Raise the minimum version constraint for the affected dependency to exclude the vulnerable version range.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v9pg-7xvm-68hf
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-mj87-hwqh-73pj applies
Minor caution · medium confidence
A library that handles web form submissions has a known issue where specially crafted input could slow down or crash the tool. Since the tool runs only on your own machine, the risk is low, and fresh installs usually get the fixed version.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mj87-hwqh-73pj to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency with a lower-bound-only constraint. The advisory likely concerns a multipart form-data parsing library susceptible to regular-expression denial of service. The launcher may accept form submissions for settings configuration, providing a potential entry point. However, the service is localhost-bound, limiting the attacker to local users, and the impact is denial of service of a management utility. Fresh installs typically resolve to a patched version.
Impact: low · Exploitability: plausible
Developer action: Raise the minimum version of the affected form-handling dependency to exclude known-vulnerable versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mj87-hwqh-73pj
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-wp53-j4wj-2cfg applies
Minor caution · medium confidence
Another high-severity issue was found in a web framework library used by this local tool. The issue could allow someone to crash the tool with crafted requests, but since it runs only on your machine, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wp53-j4wj-2cfg to a dependency declared by this repository.
Contextual assessment: A second high-severity advisory was matched against a dependency declared with a broad lower-bound constraint, likely affecting a transitive web-framework component handling request parsing. The vulnerability could allow denial of service through crafted requests. The launcher is localhost-bound, constraining exploitability to local users, and the impact is limited to disrupting a management tool. Fresh pip installs would typically receive a patched transitive version.
Impact: low · Exploitability: plausible
Developer action: Pin the direct dependency to a version that transitively requires a patched version of the affected component, or add a lock file.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wp53-j4wj-2cfg
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-h5c8-rqwp-cp95 applies
Minor caution · medium confidence
A moderate known issue exists in an older version of a library used by this local tool. The risk is low because the tool runs on your machine and fresh installs usually get the fixed version.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h5c8-rqwp-cp95 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency with a lower-bound-only version constraint. The affected package is likely a templating or web-framework component. The vulnerability severity is moderate and the service is local-only, reducing both reachability and impact. Fresh installs would generally receive a patched version under the current constraint.
Impact: low · Exploitability: unlikely
Developer action: Raise the minimum version constraint for the affected dependency to exclude the vulnerable version range.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h5c8-rqwp-cp95
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-q2x7-8rv6-6q7h applies
Minor caution · medium confidence
A moderate known issue was found in a library used by this local tool. Since the tool runs only on your machine, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q2x7-8rv6-6q7h to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency declared with a broad lower-bound constraint. The affected package may be a form-handling or web-framework library. The vulnerability is moderate in severity and the localhost-only deployment limits practical exploitability and impact. Fresh installs typically resolve to patched versions.
Impact: low · Exploitability: unlikely
Developer action: Raise the minimum version constraint for the affected dependency to exclude known-vulnerable versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q2x7-8rv6-6q7h
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory GHSA-6jv3-5f52-599m applies
Minor caution · medium confidence
A minor known issue exists in an older version of a library used by this local tool. The risk is very low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6jv3-5f52-599m to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency with a lower-bound-only constraint. The affected package is likely a templating or configuration library. The vulnerability is low severity and the service is local-only, making practical exploitation unlikely and impact minimal. Fresh installs would typically receive a patched version.
Impact: low · Exploitability: unlikely
Developer action: Raise the minimum version constraint for the affected dependency to exclude the vulnerable version range.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6jv3-5f52-599m
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-3039 applies
Minor caution · medium confidence
A moderate known issue was found in a Python library used by this local tool. Since the tool runs only on your machine, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3039 to a dependency declared by this repository.
Contextual assessment: A medium-severity Python ecosystem advisory was matched against a dependency declared with a broad lower-bound constraint. The affected package and specific vulnerability details were not provided, but the localhost-only deployment of the launcher limits practical exploitability and impact. Fresh installs would typically resolve to a patched version under the current constraint.
Impact: low · Exploitability: unlikely
Developer action: Raise the minimum version constraint for the affected dependency to exclude known-vulnerable versions, or add a lock file for reproducible installs.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-3039
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1474 applies
Minor caution · medium confidence
The dependency list uses open-ended version numbers, so anyone installing today would almost certainly get a version with the security fix already applied. The scanner flagged a known issue but did not provide enough detail to confirm which package or whether it actually affects this project. The risk is low because the software runs locally and the latest versions are used by default.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1474 to a dependency declared by this repository.
Contextual assessment: This advisory was matched against one of the five dependencies declared with lower-bound-only version constraints. Because all constraints use the greater-than-or-equal operator without an upper bound, a fresh install resolves to the latest published version, which is typically already patched for a medium-severity advisory. The advisory package details were not supplied, so the specific vulnerable code path, whether it is reachable in this launcher, and whether attacker-controlled input reaches it cannot be confirmed. Concrete harm is limited because this requirements file supports a local launcher web UI on loopback, narrowing the attack surface.
Impact: low · Exploitability: unlikely
Developer action: Pin each dependency to a known-patched version range rather than relying solely on open-ended lower bounds, so installs are reproducible and guaranteed patched.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1474
- File role
- documentation
- Source
- launcher/requirements.txt
Dependency advisory PYSEC-2026-1472 applies
Minor caution · medium confidence
Same situation as the other flagged dependency: open-ended version requirements mean users get the latest, likely-patched version. The scanner did not include enough detail to confirm which package is affected or whether the issue actually matters for this local tool. Risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1472 to a dependency declared by this repository.
Contextual assessment: This second advisory was matched against the same requirements file. As with the first candidate, all dependencies use lower-bound-only constraints, meaning pip resolves to the newest release, which generally includes fixes for medium-severity issues. Without the specific advisory text identifying the affected package, the fix version, and the vulnerability type, runtime reachability and attacker-control analysis cannot be completed. The launcher is a local tool bound to loopback, reducing exposure to external attackers.
Impact: low · Exploitability: unlikely
Developer action: Add upper or exact version pins for each dependency to a confirmed-patched release so that installs are deterministic and protected against regressions.
- Scanner
- osv-scanner 2.4.0
- Rule
- PYSEC-2026-1472
- File role
- documentation
- Source
- launcher/requirements.txt
Expected scanner matches (0)
None.