Skip to content

Conversation

@alexander-smolyakov
Copy link
Contributor

Dev container name:

  • miniconda

Description:

This PR addresses the GHSA-j8r2-6x86-q33q vulnerability. The vulnerability comes from the continuumio/miniconda3 image and is related to the requests package.

Changelog:

  • Updated Dockerfile to install the latest requests package version;
  • Added test to verify requests minimum version (Minimum package version set to 2.31.0 which fixes GHSA-j8r2-6x86-q33q).

Checklist:

  • Checked that applied changes work as expected

@alexander-smolyakov alexander-smolyakov requested a review from a team as a code owner July 27, 2023 14:10
@samruddhikhandale samruddhikhandale merged commit c3eb552 into devcontainers:main Jul 27, 2023
@alexander-smolyakov alexander-smolyakov deleted the miniconda_GHSA-j8r2-6x86-q33q_bump-requests-version branch July 27, 2023 15:54
@samruddhikhandale samruddhikhandale mentioned this pull request Jul 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants