Skip to content

Supply Chain license comment#3

Open
stuartcmehrens wants to merge 1 commit intomasterfrom
add-dependency-certifi
Open

Supply Chain license comment#3
stuartcmehrens wants to merge 1 commit intomasterfrom
add-dependency-certifi

Conversation

@stuartcmehrens
Copy link

No description provided.

Comment on lines +3 to +4
"certifi": {
"version": "==2023.7.22"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Legal Risk:
certifi 2023.7.22 was released under the MPL-2.0 license, a license currently prohibited by your organization. Merging is blocked until this is resolved

Recommendation:
Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant