From: Zach Pearson <zjp@cgl.ucsf.edu>
Date: Wednesday, May 27, 2026 at 2:30 PM
To: Kirshner, Dan <kirshner1@llnl.gov>
Cc: chimerax-users@cgl.ucsf.edu <chimerax-users@cgl.ucsf.edu>
Subject: Re: [chimerax-users] Security scan complaining about ChimeraX Python component
Hi Dan,
I have updated that dependency for current release candidates. You should be able to download a new version of ChimeraX and the security alert should go away.
— Zach
> On 26 May 2026, at 12:08, Kirshner, Dan via ChimeraX-users <chimerax-users@cgl.ucsf.edu> wrote:
>
>
> Hello:
>
> Sorry, we’ve got an annoying security scan. Here’s its complaint:
>
> Path : /Applications/ChimeraX-1.12-rc2026.05.23.app/Contents/Library/Frameworks/Python.framework/Versions/3.11/lib/python3.11/site-packages/aiohttp-3.13.1.dist-info
> Installed version : 3.13.1
> Fixed version : 3.13.4
> Potential Vulnerability : Component
>
>
> Is there some way for me to update the Python that ChimeraX uses?
>
> Thanks very much,
>
> —Dan
> _______________________________________________
> ChimeraX-users mailing list -- chimerax-users@cgl.ucsf.edu
> To unsubscribe send an email to chimerax-users-leave@cgl.ucsf.edu
> Archives:
https://urldefense.us/v3/__https://mail.cgl.ucsf.edu/mailman/archives/list/chimerax-users@cgl.ucsf.edu/__;!!G2kpM7uM-TzIFchu!wL5duYl-CoaQgDbVhfk2072fM_AAcQ-8rmbhWCNyWwxNPit6YN4jWbW8C3EZHujK8ykmyb0Shs2Chub6kA$