Skip to content

Conversation

alexander-smolyakov
Copy link
Contributor

Devcontainer name:

  • universal

Description:

This PR addresses the GHSA-v8gr-m533-ghj9 vulnerability. The vulnerability comes from the conda distribution and is related to the cryptography package.

Changelog:

  • Updated patch-conda feature to install the latest cryptography package version;

  • Updated test to verify cryptography minimum version (Minimum package version set to 41.0.4 which fixes GHSA-v8gr-m533-ghj9);

  • Removed check for the minimum version of "wheel" since the package is no longer present in the PIP list;

Checklist:

  • Checked that applied changes work as expected

@alexander-smolyakov alexander-smolyakov requested a review from a team as a code owner October 6, 2023 15:53
Copy link
Member

@samruddhikhandale samruddhikhandale left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks ✨

@samruddhikhandale samruddhikhandale merged commit c4baad4 into devcontainers:main Oct 6, 2023
@samruddhikhandale samruddhikhandale mentioned this pull request Oct 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants