Skip to content

Commit

Permalink
[anaconda] Update patches for GHSA-5cpq-8wj7-hf2v and `GHSA-45c4-8w…
Browse files Browse the repository at this point in the history
…x5-qw6w` (#739)

* Update patches

- Enable patch for GHSA-5cpq-8wj7-hf2v;
- Rework patch for GHSA-45c4-8wx5-qw6w to install package from conda repo.

* Enable tests

* Update tests

- Remove comments
  • Loading branch information
alexander-smolyakov committed Sep 11, 2023
1 parent 99accaf commit daabdeb
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 7 deletions.
10 changes: 5 additions & 5 deletions src/anaconda/.devcontainer/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,13 @@ RUN . /etc/os-release && if [ "${VERSION_CODENAME}" != "bullseye" ]; then exit 1
RUN conda install \
# https://github.com/advisories/GHSA-5cpq-8wj7-hf2v
pyopenssl=23.2.0 \
# cryptography=41.0.2 # Disabled temporarily due to issue with conda \
cryptography=41.0.2 \
# https://github.com/advisories/GHSA-j8r2-6x86-q33q
requests=2.31.0 \
# https://github.com/advisories/GHSA-f865-m6cq-j9vx
mpmath==1.3.0
mpmath=1.3.0 \
# https://github.com/advisories/GHSA-45c4-8wx5-qw6w
aiohttp=3.8.5

RUN python3 -m pip install --upgrade \
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21797
Expand All @@ -30,9 +32,7 @@ RUN python3 -m pip install --upgrade \
# https://github.com/advisories/GHSA-qppv-j76h-2rpx
tornado==6.3.3 \
# https://github.com/advisories/GHSA-282v-666c-3fvg
transformers==4.30.0 \
# https://github.com/advisories/GHSA-45c4-8wx5-qw6w
aiohttp==3.8.5
transformers==4.30.0

# Reset and copy updated files with updated privs to keep image size down
FROM mcr.microsoft.com/devcontainers/base:1-bullseye
Expand Down
4 changes: 2 additions & 2 deletions src/anaconda/test-project/test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ checkPythonPackageVersion "nbconvert" "6.5.1"
checkPythonPackageVersion "werkzeug" "2.2.3"
checkPythonPackageVersion "certifi" "2022.12.07"
checkPythonPackageVersion "requests" "2.31.0"
# checkPythonPackageVersion "cryptography" "41.0.2" # Disabled temporarily due to issue with conda
checkPythonPackageVersion "cryptography" "41.0.2"
checkPythonPackageVersion "torch" "1.13.1"
checkPythonPackageVersion "transformers" "4.30.0"
checkPythonPackageVersion "mpmath" "1.3.0"
Expand All @@ -51,7 +51,7 @@ tornado_version=$(python -c "import tornado; print(tornado.version)")
check-version-ge "tornado-requirement" "${tornado_version}" "6.3.3"

checkCondaPackageVersion "pyopenssl" "23.2.0"
# checkCondaPackageVersion "cryptography" "41.0.2" # Disabled temporarily due to issue with conda
checkCondaPackageVersion "cryptography" "41.0.2"
checkCondaPackageVersion "requests" "2.31.0"
checkCondaPackageVersion "pygments" "2.15.1"
checkCondaPackageVersion "mpmath" "1.3.0"
Expand Down

0 comments on commit daabdeb

Please sign in to comment.