Fedora Account System
Red Hat Associate
Red Hat Customer
pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1. https://github.com/mitmproxy/pdoc/pull/703 https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62 https://sansec.io/research/polyfill-supply-chain-attack
Created python-munkres tracking bugs for this issue: Affects: epel-all [bug 2294735] Affects: fedora-all [bug 2294736]
May I know what is the relation of this pdoc project to python-munkres? And Does Fedora uses pdoc or do we have pdoc packaged in Fedora?
Upstream is not aware of an issue regarding CVE-2024-38526 -> https://github.com/bmc/munkres/issues