VYPR

Conda Smithy

by Conda Forge

Source repositories

CVEs (3)

  • CVE-2025-49843LowJun 17, 2025
    risk 0.11cvss epss 0.01

    conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_headers function in the conda-smithy repository creates files with permissions exceeding 0o600, allowing…

  • CVE-2025-49824LowJun 17, 2025
    risk 0.04cvss epss 0.00

    conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_encrypt_binstar_token implementation in the conda-smithy package has been identified as vulnerable to an…

  • CVE-2026-46699Jun 18, 2026
    risk 0.00cvss epss

    conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.61.0, a vulnerability in the conda-forge automated webservices allowed unintended write access to feedstock repositories…