1 issue left for the package maintainer to handle:
CVE-2022-40897:
(needs triaging)
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
debian/patches: 13 patches to forward upstream
low
Among the 13 debian patches
available in version 68.1.2-1 of the package,
we noticed the following issues:
13 patches
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.