Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
Update patches
- Enable patch for GHSA-5cpq-8wj7-hf2v;
- Rework patch for GHSA-45c4-8wx5-qw6w to install package from conda repo.
  • Loading branch information
alexander-smolyakov committed Sep 11, 2023
commit 6b22ef9887574dde8f39fd455352a50a23d1d99e
10 changes: 5 additions & 5 deletions src/anaconda/.devcontainer/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,13 @@ RUN . /etc/os-release && if [ "${VERSION_CODENAME}" != "bullseye" ]; then exit 1
RUN conda install \
# https://github.com/advisories/GHSA-5cpq-8wj7-hf2v
pyopenssl=23.2.0 \
# cryptography=41.0.2 # Disabled temporarily due to issue with conda \
cryptography=41.0.2 \
# https://github.com/advisories/GHSA-j8r2-6x86-q33q
requests=2.31.0 \
# https://github.com/advisories/GHSA-f865-m6cq-j9vx
mpmath==1.3.0
mpmath=1.3.0 \
# https://github.com/advisories/GHSA-45c4-8wx5-qw6w
aiohttp=3.8.5

RUN python3 -m pip install --upgrade \
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21797
Expand All @@ -30,9 +32,7 @@ RUN python3 -m pip install --upgrade \
# https://github.com/advisories/GHSA-qppv-j76h-2rpx
tornado==6.3.3 \
# https://github.com/advisories/GHSA-282v-666c-3fvg
transformers==4.30.0 \
# https://github.com/advisories/GHSA-45c4-8wx5-qw6w
aiohttp==3.8.5
transformers==4.30.0

# Reset and copy updated files with updated privs to keep image size down
FROM mcr.microsoft.com/devcontainers/base:1-bullseye
Expand Down