TavernKeeper Scan Report

mekineer-com/OpenAlma

Commit ab04dfd Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 28 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory PYSEC-2026-3038 applies

Minor caution · medium confidence

A library used by the launcher has a known security issue. If you install fresh, you will likely get the fixed version. If you reuse an old environment, you might keep a vulnerable version. Since the launcher only runs on your own computer, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3038 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint in a requirements file for a local-only launcher service. The greater-than-or-equal constraint allows installing patched versions on fresh environments, but also permits vulnerable versions to remain in pre-existing virtual environments without triggering an upgrade. The launcher binds to localhost only, limiting attack surface to the local machine.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-3038
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1471 applies

Minor caution · medium confidence

A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Because the launcher runs only on your computer, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1471 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint overlaps the advisory's affected version range, but fresh installs resolve to the latest available version which is likely patched. The service runs on localhost only, reducing exposure to remote attack.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1471
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-59g5-xgcq-4qw3 applies

Minor caution · medium confidence

A library used by the launcher has a serious known security issue. However, because the launcher only runs on your own computer and fresh installs should get the fixed version, the practical risk is low. The main concern is if you reuse an old installation.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-59g5-xgcq-4qw3 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. While the scanner severity is high, the greater-than-or-equal constraint means fresh installs will resolve to the latest version, which is likely patched. The launcher service binds to localhost, so remote exploitation is not feasible without local access. The primary concern is a stale virtual environment retaining a vulnerable version, but the project setup instructions direct users to create a fresh venv.

Impact: low · Exploitability: unlikely

Developer action: Pin the affected dependency to a specific patched version to ensure vulnerable versions are never retained in stale environments.

Scanner
osv-scanner 2.4.0
Rule
GHSA-59g5-xgcq-4qw3
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-h75v-3vvj-5mfj applies

Minor caution · medium confidence

A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Since the launcher runs only on your computer, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h75v-3vvj-5mfj to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint allows both vulnerable and patched versions. Fresh installs resolve to the latest version, but stale environments may retain a vulnerable version. The service is localhost-only, limiting exposure.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h75v-3vvj-5mfj
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-gmj6-6f8f-6699 applies

Minor caution · medium confidence

A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Because the launcher runs only on your computer, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-gmj6-6f8f-6699 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint overlaps the affected version range but also permits patched versions. The launcher runs on localhost, reducing the attack surface to local users only.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
GHSA-gmj6-6f8f-6699
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-vffw-93wf-4j4q applies

Minor caution · medium confidence

A library used by the launcher has a minor known security issue. Fresh installs should get the fixed version, and the launcher only runs on your computer, so the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-vffw-93wf-4j4q to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The low scanner severity and localhost-only deployment further reduce practical risk. Fresh installs resolve to the latest version which is likely patched.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
GHSA-vffw-93wf-4j4q
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-3040 applies

Minor caution · medium confidence

A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Since the launcher runs only on your computer, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3040 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint allows both vulnerable and patched versions. The service is localhost-only, limiting exposure to local users. Fresh installs resolve to the latest version.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-3040
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1475 applies

Minor caution · medium confidence

A library used by the launcher has a known security issue. Fresh installs should get the fixed version, but old environments could keep a vulnerable one. Because the launcher runs only on your computer, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1475 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a lower-bound-only version constraint. The constraint overlaps the affected version range but also permits patched versions. The launcher binds to localhost, so remote exploitation is not feasible without local access.

Impact: low · Exploitability: unlikely

Developer action: Pin affected dependencies to specific patched versions or use compatible-release constraints instead of open-ended lower bounds.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1475
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1852 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1852 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1852
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1851 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1851 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1851
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-3037 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3037 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-3037
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-5rvq-cxj2-64vf applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5rvq-cxj2-64vf to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known high-severity advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5rvq-cxj2-64vf
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1473 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1473 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1473
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-cpwx-vrp4-4pq7 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-cpwx-vrp4-4pq7 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
GHSA-cpwx-vrp4-4pq7
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-3036 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3036 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-3036
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-3041 applies

Minor caution · medium confidence

The project uses a dependency that has a known security issue, but because it asks for the latest version, it might automatically get the fixed version. Since this tool runs locally on your machine, the risk is low. It is best practice to specify exact safe versions.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3041 to a dependency declared by this repository.

Contextual assessment: The requirements file declares an open-ended version constraint for a dependency with a known advisory. Because the constraint allows installing the latest available version, users may receive a patched release. The launcher is a local-first utility, limiting exposure to external attackers. The lack of strict version pinning creates a risk that a vulnerable version could be resolved in certain environments.

Impact: low · Exploitability: unlikely

Developer action: Pin the dependency to a specific patched version to ensure a secure and predictable baseline.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-3041
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-pp6c-gr5w-3c5g applies

Minor caution · medium confidence

A library used by this local launcher tool has a known security issue in older versions. The version requirements allow older, vulnerable versions to be installed, though in practice a fresh install usually gets the fixed version. Since the tool runs only on your own machine, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-pp6c-gr5w-3c5g to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency declared with a lower-bound-only version constraint in a requirements file for a local launcher web UI. The constraint permits installation of versions known to contain a vulnerability, likely in a transitive web-framework dependency handling multipart form data. However, the launcher binds to localhost, fresh pip installs typically resolve to the latest patched version, and the practical impact is limited to local denial of service of a management tool. The advisory severity reflects the upstream library risk, not the deployment context here.

Impact: low · Exploitability: plausible

Developer action: Pin the affected dependency to a minimum version that excludes known-vulnerable releases, or add a lock file to ensure reproducible, patched installs.

Scanner
osv-scanner 2.4.0
Rule
GHSA-pp6c-gr5w-3c5g
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-v9pg-7xvm-68hf applies

Minor caution · medium confidence

A minor known issue exists in an older version of a templating library used by this local tool. The risk is very low because the tool runs on your machine and fresh installs usually get the fixed version.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v9pg-7xvm-68hf to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a dependency declared with a broad lower-bound constraint. The likely affected package is a templating library used for rendering the launcher web UI. The vulnerability in the affected version range is low severity and the service is local-only, limiting both reachability and impact. Fresh installs would typically receive a patched version under the current constraint.

Impact: low · Exploitability: unlikely

Developer action: Raise the minimum version constraint for the affected dependency to exclude the vulnerable version range.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v9pg-7xvm-68hf
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-mj87-hwqh-73pj applies

Minor caution · medium confidence

A library that handles web form submissions has a known issue where specially crafted input could slow down or crash the tool. Since the tool runs only on your own machine, the risk is low, and fresh installs usually get the fixed version.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mj87-hwqh-73pj to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency with a lower-bound-only constraint. The advisory likely concerns a multipart form-data parsing library susceptible to regular-expression denial of service. The launcher may accept form submissions for settings configuration, providing a potential entry point. However, the service is localhost-bound, limiting the attacker to local users, and the impact is denial of service of a management utility. Fresh installs typically resolve to a patched version.

Impact: low · Exploitability: plausible

Developer action: Raise the minimum version of the affected form-handling dependency to exclude known-vulnerable versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mj87-hwqh-73pj
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-wp53-j4wj-2cfg applies

Minor caution · medium confidence

Another high-severity issue was found in a web framework library used by this local tool. The issue could allow someone to crash the tool with crafted requests, but since it runs only on your machine, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wp53-j4wj-2cfg to a dependency declared by this repository.

Contextual assessment: A second high-severity advisory was matched against a dependency declared with a broad lower-bound constraint, likely affecting a transitive web-framework component handling request parsing. The vulnerability could allow denial of service through crafted requests. The launcher is localhost-bound, constraining exploitability to local users, and the impact is limited to disrupting a management tool. Fresh pip installs would typically receive a patched transitive version.

Impact: low · Exploitability: plausible

Developer action: Pin the direct dependency to a version that transitively requires a patched version of the affected component, or add a lock file.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wp53-j4wj-2cfg
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-h5c8-rqwp-cp95 applies

Minor caution · medium confidence

A moderate known issue exists in an older version of a library used by this local tool. The risk is low because the tool runs on your machine and fresh installs usually get the fixed version.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h5c8-rqwp-cp95 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency with a lower-bound-only version constraint. The affected package is likely a templating or web-framework component. The vulnerability severity is moderate and the service is local-only, reducing both reachability and impact. Fresh installs would generally receive a patched version under the current constraint.

Impact: low · Exploitability: unlikely

Developer action: Raise the minimum version constraint for the affected dependency to exclude the vulnerable version range.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h5c8-rqwp-cp95
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-q2x7-8rv6-6q7h applies

Minor caution · medium confidence

A moderate known issue was found in a library used by this local tool. Since the tool runs only on your machine, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q2x7-8rv6-6q7h to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency declared with a broad lower-bound constraint. The affected package may be a form-handling or web-framework library. The vulnerability is moderate in severity and the localhost-only deployment limits practical exploitability and impact. Fresh installs typically resolve to patched versions.

Impact: low · Exploitability: unlikely

Developer action: Raise the minimum version constraint for the affected dependency to exclude known-vulnerable versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q2x7-8rv6-6q7h
File role
documentation
Source
launcher/requirements.txt

Dependency advisory GHSA-6jv3-5f52-599m applies

Minor caution · medium confidence

A minor known issue exists in an older version of a library used by this local tool. The risk is very low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6jv3-5f52-599m to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a dependency with a lower-bound-only constraint. The affected package is likely a templating or configuration library. The vulnerability is low severity and the service is local-only, making practical exploitation unlikely and impact minimal. Fresh installs would typically receive a patched version.

Impact: low · Exploitability: unlikely

Developer action: Raise the minimum version constraint for the affected dependency to exclude the vulnerable version range.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6jv3-5f52-599m
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-3039 applies

Minor caution · medium confidence

A moderate known issue was found in a Python library used by this local tool. Since the tool runs only on your machine, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-3039 to a dependency declared by this repository.

Contextual assessment: A medium-severity Python ecosystem advisory was matched against a dependency declared with a broad lower-bound constraint. The affected package and specific vulnerability details were not provided, but the localhost-only deployment of the launcher limits practical exploitability and impact. Fresh installs would typically resolve to a patched version under the current constraint.

Impact: low · Exploitability: unlikely

Developer action: Raise the minimum version constraint for the affected dependency to exclude known-vulnerable versions, or add a lock file for reproducible installs.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-3039
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1474 applies

Minor caution · medium confidence

The dependency list uses open-ended version numbers, so anyone installing today would almost certainly get a version with the security fix already applied. The scanner flagged a known issue but did not provide enough detail to confirm which package or whether it actually affects this project. The risk is low because the software runs locally and the latest versions are used by default.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1474 to a dependency declared by this repository.

Contextual assessment: This advisory was matched against one of the five dependencies declared with lower-bound-only version constraints. Because all constraints use the greater-than-or-equal operator without an upper bound, a fresh install resolves to the latest published version, which is typically already patched for a medium-severity advisory. The advisory package details were not supplied, so the specific vulnerable code path, whether it is reachable in this launcher, and whether attacker-controlled input reaches it cannot be confirmed. Concrete harm is limited because this requirements file supports a local launcher web UI on loopback, narrowing the attack surface.

Impact: low · Exploitability: unlikely

Developer action: Pin each dependency to a known-patched version range rather than relying solely on open-ended lower bounds, so installs are reproducible and guaranteed patched.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1474
File role
documentation
Source
launcher/requirements.txt

Dependency advisory PYSEC-2026-1472 applies

Minor caution · medium confidence

Same situation as the other flagged dependency: open-ended version requirements mean users get the latest, likely-patched version. The scanner did not include enough detail to confirm which package is affected or whether the issue actually matters for this local tool. Risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory PYSEC-2026-1472 to a dependency declared by this repository.

Contextual assessment: This second advisory was matched against the same requirements file. As with the first candidate, all dependencies use lower-bound-only constraints, meaning pip resolves to the newest release, which generally includes fixes for medium-severity issues. Without the specific advisory text identifying the affected package, the fix version, and the vulnerability type, runtime reachability and attacker-control analysis cannot be completed. The launcher is a local tool bound to loopback, reducing exposure to external attackers.

Impact: low · Exploitability: unlikely

Developer action: Add upper or exact version pins for each dependency to a confirmed-patched release so that installs are deterministic and protected against regressions.

Scanner
osv-scanner 2.4.0
Rule
PYSEC-2026-1472
File role
documentation
Source
launcher/requirements.txt
Expected scanner matches (0)

None.

Related contextual observations

All dependencies use open-ended lower-bound version constraints

low risk · high confidence

The launcher lists its library requirements with very loose version rules. If you install fresh, you get the latest safe versions. If you reuse an old setup, you might keep versions with known security problems. Since the launcher only runs on your own computer, the overall risk is low, but tightening the version rules would make things safer.

Technical assessment

Every dependency in this requirements file uses a greater-than-or-equal constraint with no upper bound. This means pip will install the latest available version on fresh installs, which is typically patched. However, in pre-existing virtual environments, pip will not upgrade a package that already satisfies the constraint, so vulnerable versions can persist indefinitely. Eight advisories were matched across the five declared dependencies, indicating multiple packages have known issues in version ranges that overlap these constraints. The launcher service runs on localhost only, which significantly limits the attack surface for most of these advisories.

Impact: low · Exploitability: unlikely

Developer action: Replace all open-ended lower-bound constraints with pinned versions or compatible-release ranges that exclude known-vulnerable versions. Consider adding a lockfile or regular dependency scanning to catch new advisories.

Sources:

All dependencies use lower-bound-only version constraints without a lock file

low risk · medium confidence

The tool lists its library requirements with loose version rules that say any version at or above a minimum is acceptable. This means older, buggy versions could sometimes be installed. Using exact version pins or a lock file would prevent this.

Technical assessment

The requirements file specifies five direct dependencies using only greater-than-or-equal constraints and no lock file is present. This allows pip to install any version at or above the minimum, including versions with known vulnerabilities. While fresh installs typically resolve to the latest patched versions, cached environments or dependency resolution edge cases could result in vulnerable versions being installed. Adding a lock file or tightening minimum version constraints would ensure patched versions are always selected.

Impact: low · Exploitability: unlikely

Developer action: Add a lock file or tighten all minimum version constraints to exclude known-vulnerable version ranges across all five declared dependencies.

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity