Skip to content

fix: Vulnerability fix for starkbank-ecdsa 2.2.0 dependency - #1085

Merged
tiwarishubham635 merged 4 commits into
sendgrid:mainfrom
ranjanprasad1996:update_ecdsa_library
May 9, 2025
Merged

fix: Vulnerability fix for starkbank-ecdsa 2.2.0 dependency#1085
tiwarishubham635 merged 4 commits into
sendgrid:mainfrom
ranjanprasad1996:update_ecdsa_library

Conversation

@ranjanprasad1996

Copy link
Copy Markdown
Contributor

Fixes

As part of the quay.io vulnerability report, it is reported that the sendgrid-python==6.11.0 package has a vulnerability (GHSA-9wx7-jrvc-28mm) reported for dependency starkbank-ecdsa==2.2.0 which is the latest version available from 2022 (The starbank repository no longer seems to be maintained).

This PR solves replaces the outdated starbank-ecdsa library (https://github.com/starkbank/ecdsa-python) with an actively mainained library ecdsa (https://github.com/tlsfuzzer/python-ecdsa).

Checklist

  • I acknowledge that all my contributions will be made under the project's license
  • I have made a material change to the repo (functionality, testing, spelling, grammar)
  • I have read the Contribution Guidelines and my PR follows them
  • I have titled the PR appropriately
  • I have updated my branch with the main branch
  • I have added tests that prove my fix is effective or that my feature works
  • I have added the necessary documentation about the functionality in the appropriate .md file
  • I have added inline documentation to the code I modified
@ranjanprasad1996 ranjanprasad1996 changed the title fix: Vulnerability fix for starkbank-ecdsa 2.2.0 depeendency Aug 22, 2024
@kurtqq

kurtqq commented May 9, 2025

Copy link
Copy Markdown

@tiwarishubham635 should this be merged?

@tiwarishubham635

Copy link
Copy Markdown
Contributor

I see some tests are failing

@ranjanprasad1996

Copy link
Copy Markdown
Contributor Author

@tiwarishubham635 Have fixed the tests. Could you please retrigger the builds?

@tiwarishubham635 tiwarishubham635 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@tiwarishubham635
tiwarishubham635 merged commit 6eb4375 into sendgrid:main May 9, 2025
@ranjanprasad1996

ranjanprasad1996 commented May 9, 2025

Copy link
Copy Markdown
Contributor Author

@tiwarishubham635 When will this patch be released? Thanks

@tiwarishubham635

Copy link
Copy Markdown
Contributor

We will be releasing today. Thanks!

from ellipticcurve.publicKey import PublicKey
from ellipticcurve.signature import Signature

from .eventwebhook_header import EventWebhookHeader

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removing EventWebhookHeader breaks eventwebhook_example.py

@tiwarishubham635

Copy link
Copy Markdown
Contributor

I think we can export the EventWebhookHeader from eventwebhook init.py to fix this

@dacevedo12

Copy link
Copy Markdown
Contributor

tlsfuzzer/python-ecdsa@e276368

perhaps it wasn't a safe choice, not a good look on Twilio's SCA security posture.

are there plans to prioritize migrating to https://cryptography.io/en/latest/?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

5 participants