You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Warning
Review the following alerts detected in dependencies.
According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
Action
Severity
Alert (click "▶" to expand/collapse)
Warn
Telemetry collection: pypi dagster
Note: This module implements a background telemetry uploader that reads local Dagster log files and POSTs compressed contents to a remote telemetry endpoint, then deletes uploaded files. It does not contain obvious obfuscated or stealthy backdoor code, but it does perform potentially sensitive data exfiltration (logs -> remote server) and uses insecure defaults (plain HTTP, compression/header mismatch). There are correctness/robustness bugs (content-encoding mismatch, a typo in exception handling) that may hide failures. If you do not trust the receiving endpoint or if logs may contain sensitive data, treat this as a moderate supply-chain/privacy risk and either disable telemetry via DAGSTER_DISABLE_TELEMETRY or review/modify the uploader to use HTTPS, authentication/allowlist, and safer file handling.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore pypi/dagster@1.13.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Telemetry collection: pypi dagster
Note: This module implements a background telemetry uploader that reads local Dagster log files and POSTs compressed contents to a remote telemetry endpoint, then deletes uploaded files. It does not contain obvious obfuscated or stealthy backdoor code, but it does perform potentially sensitive data exfiltration (logs -> remote server) and uses insecure defaults (plain HTTP, compression/header mismatch). There are correctness/robustness bugs (content-encoding mismatch, a typo in exception handling) that may hide failures. If you do not trust the receiving endpoint or if logs may contain sensitive data, treat this as a moderate supply-chain/privacy risk and either disable telemetry via DAGSTER_DISABLE_TELEMETRY or review/modify the uploader to use HTTPS, authentication/allowlist, and safer file handling.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore pypi/dagster@1.13.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.