<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NetApp OnTap Python Library uses old version of marshmallow in ONTAP Rest API Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Rest-API-Discussions/NetApp-OnTap-Python-Library-uses-old-version-of-marshmallow/m-p/152186#M22</link>
    <description>&lt;P&gt;&lt;SPAN&gt;When installing the netapp-ontap package via pip, it shows a dependency of&amp;nbsp;marshmallow&amp;lt;=3.0.0rc7,&amp;gt;=3.0.0rc5. These version of marshmallow are vulnerable to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;CVE-2018-17175 and thus not allowed within my organization. Why does the library force such an old version (current version is 3.2.2)? Can the OnTap library be updated to support the new version?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 12:09:12 GMT</pubDate>
    <dc:creator>jsharpe</dc:creator>
    <dc:date>2025-06-04T12:09:12Z</dc:date>
    <item>
      <title>NetApp OnTap Python Library uses old version of marshmallow</title>
      <link>https://community.netapp.com/t5/ONTAP-Rest-API-Discussions/NetApp-OnTap-Python-Library-uses-old-version-of-marshmallow/m-p/152186#M22</link>
      <description>&lt;P&gt;&lt;SPAN&gt;When installing the netapp-ontap package via pip, it shows a dependency of&amp;nbsp;marshmallow&amp;lt;=3.0.0rc7,&amp;gt;=3.0.0rc5. These version of marshmallow are vulnerable to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;CVE-2018-17175 and thus not allowed within my organization. Why does the library force such an old version (current version is 3.2.2)? Can the OnTap library be updated to support the new version?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:09:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Rest-API-Discussions/NetApp-OnTap-Python-Library-uses-old-version-of-marshmallow/m-p/152186#M22</guid>
      <dc:creator>jsharpe</dc:creator>
      <dc:date>2025-06-04T12:09:12Z</dc:date>
    </item>
  </channel>
</rss>

