Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove version restriction from Pillow in TVM codebase #10238

Open
areusch opened this issue Feb 14, 2022 · 2 comments
Open

Remove version restriction from Pillow in TVM codebase #10238

areusch opened this issue Feb 14, 2022 · 2 comments
Assignees
Labels
actionable has an immediately do-able work plan and a detailed description type:dependency-security Security problems in dependencies of TVM

Comments

@areusch
Copy link
Contributor

areusch commented Feb 14, 2022

@kparzysz-quic states: There are 3 security vulnerabilities in Pillow < 9.0.0. They are all considered critical.

CVE-2022-22815 2
CVE-2022-22816
CVE-2022-22817
apps/microtvm/ethosu/requirements.txt lists Pillow==8.3.2.

@areusch : note this was originally listed in the docs install script as a hard version limit, but it's since gone. i suspect the task here is to just remove it from the various places in the codebase which mention it.

https://github.com/apache/tvm/search?q=Pillow

@areusch areusch added the type:dependency-security Security problems in dependencies of TVM label Feb 14, 2022
@manupak
Copy link
Contributor

manupak commented Feb 14, 2022

cc : @grant-arm

@leandron
Copy link
Contributor

Me and @grant-arm did some investigation in this and we found out that the fixed/safe versions of Pillow don't release for Python 3.6 anymore.

So this is one more reason for us to update our Docker images and CI, because this will certainly be trend that libraries stop releasing Python 3.6.

@denise-k denise-k added this to Q1 2022 in Apache TVM CI & Testing Feb 16, 2022
@leandron leandron self-assigned this Apr 4, 2022
@hpanda-naut hpanda-naut moved this from Q1 2022 to Q2 2022 in Apache TVM CI & Testing Apr 14, 2022
@hpanda-naut hpanda-naut moved this from Q2 2022 to Q1 2022 in Apache TVM CI & Testing Apr 14, 2022
@areusch areusch added the needs-triage PRs or issues that need to be investigated by maintainers to find the right assignees to address it label Oct 19, 2022
@driazati driazati added actionable has an immediately do-able work plan and a detailed description and removed needs-triage PRs or issues that need to be investigated by maintainers to find the right assignees to address it labels Oct 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
actionable has an immediately do-able work plan and a detailed description type:dependency-security Security problems in dependencies of TVM
Projects
Development

No branches or pull requests

4 participants