Skip to content

[Snyk] Fix for 3 vulnerabilities#37

Closed
rapmd73 wants to merge 687 commits intomainfrom
snyk-fix-7a1244a77f3e836579e0590753df4d89
Closed

[Snyk] Fix for 3 vulnerabilities#37
rapmd73 wants to merge 687 commits intomainfrom
snyk-fix-7a1244a77f3e836579e0590753df4d89

Conversation

@rapmd73
Copy link
Copy Markdown
Owner

@rapmd73 rapmd73 commented Jun 20, 2025

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the pip dependencies of this project.

Snyk changed the following file(s):

  • requirements.txt
⚠️ Warning
ccxt 4.4.90 requires aiohttp, which is not installed.

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Use After Free
🦉 Open Redirect

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.margin
	modified:   Base/Library/JRRccxt.py
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
	new file:   Base/Library/apiKucoin.py
	modified:   Extras/ListMarkets
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
	modified:   Extras/Balances
Changes to be committed:
	modified:   Extras/Balances
Changes to be committed:
	modified:   Base/Library/apiKucoin.py
	new file:   Extras/CodeProofs/Kucoin/KucoiDocs.txt
	new file:   Extras/CodeProofs/Kucoin/testKucoinAPI
Changes to be committed:
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
Changes to be committed:
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
Changes to be committed:
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
Changes to be committed:
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
Changes to be committed:
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
Changes to be committed:
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
	new file:   Extras/Examples/orderbookMomentum
More examples included.

Changes to be committed:
	modified:   Base/Library/JRRccxt.py
	modified:   Base/Library/apiKucoin.py
	modified:   Extras/CodeProofs/Kucoin/testKucoinAPI
	new file:   Extras/Examples/OandaTradingBot/LauncherOB
	new file:   Extras/Examples/OandaTradingBot/oandaBot
	modified:   Extras/Examples/orderbookMomentum
…f simultaneous API calls

and maintain order or them all.

Changes to be committed:
	modified:   Base/Library/JackrabbitRelay.py
Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitLocker
…h the Sandbox

element in the config file

Memory leak testing in Locker.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/Library/JRRoanda.py
More work on margins

Balances and ListMarkets now work properly with margin accounts.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/Library/JRRccxt.py
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
… as well.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRccxt.py
	modified:   Base/OANDA-PlaceOrder
	modified:   Base/Orphan.ccxt
	modified:   Base/Orphan.oanda
Changes to be committed:
	modified:   Base/Orphan.ccxt
Changes to be committed:
	modified:   Base/JackrabbitLocker
…This is an unbound grid

bot.

Changes to be committed:
	new file:   Extras/Examples/OandaTradingBot/oandaBot.short
	renamed:    Extras/Examples/OandaTradingBot/oandaBot -> Extras/Examples/OandaTradingBot/oandaBot.long
	new file:   Extras/Examples/OandaTradingBot/LauncherOB.long
	new file:   Extras/Examples/OandaTradingBot/LauncherOB.short
	deleted:    Extras/Examples/OandaTradingBot/LauncherOB
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
Changes to be committed:
	modified:   Base/Library/JRRccxt.py
…edger entries.

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.future
	modified:   Base/CCXT-PlaceOrder.margin
	modified:   Base/CCXT-PlaceOrder.spot
Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Extras/Examples/OandaTradingBot/oandaBot.long
	modified:   Extras/Examples/OandaTradingBot/oandaBot.short
… as swap, not future

Adjust "MarketType" in config files to "Swap" and "Market" in orders to "Swap".

**IMPORTANT**: be sure to run UpdatePlaceOrder with ALL of your exchanges listed.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JackrabbitRelay.py
	modified:   UpdatePlaceOrder
rapmd73 and others added 28 commits September 16, 2024 13:44
Oanda ReduceBy bug fixed...

"Not enough balance" issues addressed.

Changes to be committed:
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/Library/JRRfix.py
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JRRoanda.py
	modified:   Base/Library/OliverTwist-ccxt.py
	modified:   Base/Library/OliverTwist-mimic.py
	modified:   Base/Library/OliverTwist-oanda.py
	modified:   Extras/OliverTwist/OliverTwistEquity
	modified:   Extras/OliverTwist/OliverTwistTrades
	modified:   Extras/OliverTwist/otcWatch
…ng together...

Changes to be committed:
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/Library/OliverTwist-ccxt.py
	modified:   Base/Library/OliverTwist-mimic.py
	modified:   Base/Library/OliverTwist-oanda.py
Changes to be committed:
	modified:   Base/Library/OliverTwist-ccxt.py
	modified:   Base/Library/OliverTwist-mimic.py
	modified:   Base/Library/OliverTwist-oanda.py
Changes to be committed:
	modified:   Extras/OliverTwist/OliverTwistEquity
	modified:   Extras/OliverTwist/OliverTwistTrades
Changes to be committed:
	modified:   Base/JackrabbitOliverTwist
Changes to be committed:
	modified:   Base/JackrabbitOliverTwist
Changes to be committed:
	modified:   Extras/OliverTwist/OliverTwistEquity
…passing string.

Changes to be committed:
	modified:   Base/Library/OliverTwist-oanda.py
Visual improvements in OliverTwist charting.

Changes to be committed:
	modified:   Base/Library/OliverTwist-oanda.py
	modified:   Extras/OliverTwist/OliverTwistEquity
	modified:   Extras/OliverTwist/OliverTwistTrades
Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JRRoanda.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
… kludgy, but

works for now.

Changes to be committed:
	modified:   Extras/OliverTwist/OliverTwistTrades
Version update.

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.spot
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRccxt.py
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Extras/CodeProofs/findMinCost
Version update.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JRRsupport.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Extras/CodeProofs/readOHLCV
	new file:   Extras/OliverTwist/ot2gb
… with

a negative balance.

Bug fix in OliverTwistEquity where the file name was not correct for
certain charts.

Code tuning in OliverTwist. Diagnostics added.

Version update.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/LauncherOliverTwist
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/Library/OliverTwist-oanda.py
	modified:   Extras/OliverTwist/OliverTwistEquity
Version update.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/Library/OliverTwist-oanda.py
Changes to be committed:
	modified:   Base/Library/OliverTwist-oanda.py
Changes to be committed:
	modified:   Base/Library/OliverTwist-oanda.py
strictly related to Oanda and OliverTwist if tracking the presence of
existing orders. I think I finally killed it once and for all.

Version update.

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/Library/OliverTwist-oanda.py
**Virtual environment now REQUIRED!** Please be sure to read the wiki on setting up
the new virtual environment.

All scripts now use the new virtual environment.

Bug fixes and performance improvements to Locker (distrubuted lock manager).

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   StartJackrabbit
	modified:   UpdatePlaceOrder
	modified:   install
…* with ALL of

your exchanges/brokers.

Version update.

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.future
	modified:   Base/CCXT-PlaceOrder.margin
	modified:   Base/CCXT-PlaceOrder.spot
	modified:   Base/CCXT-PlaceOrder.swap
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/OANDA-PlaceOrder
Fixed bug in ticker spread rounding.

Fixed typos.

Version update.

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.future
	modified:   Base/CCXT-PlaceOrder.margin
	modified:   Base/CCXT-PlaceOrder.swap
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRccxt.py
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Extras/CodeProofs/readTicker
…Extremely

small price levels)

File testing bug fix in WalletReset for Mimic

Changes to be committed:
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/MIMIC-PlaceOrder
	modified:   Extras/Mimic/WalletReset
Changes to be committed:
	modified:   install
Be sure to run **./UpdatePlaceOrder** with your exchanges. While the bugs may be
small, there is an overall improvement is removing them.

Version update.

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.future
	modified:   Base/CCXT-PlaceOrder.margin
	modified:   Base/CCXT-PlaceOrder.spot
	modified:   Base/CCXT-PlaceOrder.swap
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JRRsupport.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/Library/OliverTwist-ccxt.py
	modified:   Base/Library/OliverTwist-mimic.py
	modified:   Base/Library/OliverTwist-oanda.py
	modified:   Base/MIMIC-PlaceOrder
	modified:   Base/OANDA-PlaceOrder
	modified:   Base/PROXY-PlaceOrder
	modified:   CODE_OF_CONDUCT.md
	modified:   Extras/CodeProofs/MaxAsset
You will need to update youe exchanges with ./UpdateplaceOrder.

Version updated.

Changes to be committed:
	modified:   Base/CCXT-PlaceOrder.future
	modified:   Base/CCXT-PlaceOrder.margin
	modified:   Base/CCXT-PlaceOrder.spot
	modified:   Base/CCXT-PlaceOrder.swap
	modified:   Base/JackrabbitLocker
	modified:   Base/JackrabbitOliverTwist
	modified:   Base/JackrabbitRelay
	modified:   Base/Library/JRRmimic.py
	modified:   Base/Library/JRRsupport.py
	modified:   Base/Library/JackrabbitProxy.py
	modified:   Base/Library/JackrabbitRelay.py
	modified:   Base/MIMIC-PlaceOrder
	modified:   Base/OANDA-PlaceOrder
	modified:   Base/PROXY-PlaceOrder
Changes to be committed:
	modified:   Base/JackrabbitOliverTwist
	modified:   requirements.txt
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants