-
Notifications
You must be signed in to change notification settings - Fork 764
[universal] Conda: patch Python due to CVE-2023-32681 and GHSA-5cpq-8wj7-hf2v #627
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
samruddhikhandale
merged 26 commits into
devcontainers:main
from
alexander-smolyakov:users/alexander-smolyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
Aug 2, 2023
Merged
[universal] Conda: patch Python due to CVE-2023-32681 and GHSA-5cpq-8wj7-hf2v #627
samruddhikhandale
merged 26 commits into
devcontainers:main
from
alexander-smolyakov:users/alexander-smolyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
Aug 2, 2023
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…wj7-hf2v - Reorganize features installation queue; - Introduce patch-conda feature;
src/universal/.devcontainer/local-features/patch-conda/devcontainer-feature.json
Outdated
Show resolved
Hide resolved
src/universal/.devcontainer/local-features/patch-conda/install.sh
Outdated
Show resolved
Hide resolved
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
This reverts commit 046b94c.
samruddhikhandale
requested changes
Jun 20, 2023
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left one comment, can you also help resolve the merge conflicts? thanks!
src/universal/.devcontainer/local-features/patch-conda/devcontainer-feature.json
Show resolved
Hide resolved
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
src/universal/.devcontainer/local-features/patch-conda/install.sh
Outdated
Show resolved
Hide resolved
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
|
There was an error handling pipeline event c9650c9f-36bc-49b6-9c6f-b01bfaa947a7. |
This reverts commit a74d406.
…q-8wj7-hf2v_bump-cryptography-version
…q-8wj7-hf2v_bump-cryptography-version
…q-8wj7-hf2v_bump-cryptography-version
samruddhikhandale
approved these changes
Aug 2, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Dev container name:
Issue description:
This PR aims to address CVE-2023-32681 and GHSA-5cpq-8wj7-hf2v security vulnerabilities. These vulnerabilities come from Python distribution which ships with Conda.
Fix description:
In the
universaldevcontainer, we have three instances of Python distribution:flowchart TD CF[conda feature] --> CFP[Python 3.10.4] PF[python feature] --> PFP1[Python 3.10.8] PF --> PFP2[Python 3.9.16] CFP --"/opt/conda/bin/python3"--> U[universal devconatiner] PFP1 --"/usr/local/python/3.10.8/bin/python (set to current)"--> U[universal devconatiner] PFP2 --"/usr/local/python/3.9.16/bin/python"--> U[universal devconatiner]Originally fixes were applied during the
setup-userfeature installation and the feature installation queue looks the following:This approach resulted in the Anaconda Python distribution containing vulnerable packages in
site-packagesfolders, and this triggered our security checks. Additionally, when running theconda listcommand, it's listed vulnerable packages.The
pipdoesn't provide the ability to remove packages from the specificsite-packagesfolder. When we try to remove any packages for related Python distribution duringsetup-userinstallation, we face the following situation:The
piptrying to remove the package from the/home/codespace/.local/lib/python3.10/site-packages/folder when we need to remove the package fromopt/conda/lib/python3.10/site-packages. In order to remove packageopt/conda/lib/python3.10/site-packages, we should run the/opt/conda/bin/python3 -m pip uninstall requestscommand twice because we installed additional Python distribution via thepythonfeature:The other side effect of this approach is that it affects Python distribution coming from the
pythonfeature:To avoid such a situation, we have to reorganize the features installation queue to install the
condafeature and apply all patches to it before thepythonfeature installation.Fix results:
Before fix:
opt/conda/lib/python3.10/site-packages
conda list
With fix:
opt/conda/lib/python3.10/site-packages
conda list
Changelog:
cryptography,pyopensslto address GHSA-5cpq-8wj7-hf2v;Checklist: