Show HN: A curated list of insecure Python packages
github.com
github.com
https://www.owasp.org/index.php/OWASP_Dependency_Check
I can make a connection between you and Jeremy Long (head of the project) if you'd like. He's also on twitter as @ctxt
Unless insucure is a Python package I do not know about.
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.
It's a bit dirty, but was the right tool for the job. If you are working on a larger project, I'd probably use some template language like mustache to render the elements.
A side note anyone using Django should keep up to date. If you see the list of versions and the related packages which have known vulnerabilities you will realize keeping up to date is critical.
Edit: Switched to S3 to load the data.