Skip to content

Conversation

@alexander-smolyakov
Copy link
Contributor

Devcontainer name:

  • anaconda

Description:

This PR patches the following vulnerabilities:

These vulnerabilities come from the continuumio/anaconda3 image.

Changelog:

Tests:

  • Added test to verify Pillow minimum version (Minimum package version set to 10.0.1 which fixes GHSA-j7hp-h8jx-5ppr);
  • Added test to verify urllib3 minimum version (Minimum package version set to 1.26.17 which fixes GHSA-v845-jxx5-vc9f);

Checklist:

  • Checked that applied changes work as expected

@alexander-smolyakov alexander-smolyakov requested a review from a team as a code owner October 10, 2023 07:42
Copy link
Member

@samruddhikhandale samruddhikhandale left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you! 🚢

@samruddhikhandale samruddhikhandale merged commit e881310 into devcontainers:main Oct 10, 2023
@alexander-smolyakov alexander-smolyakov deleted the anaconda_address_GHSA-j7hp-h8jx-5ppr_GHSA-v845-jxx5-vc9f branch October 11, 2023 11:49
@samruddhikhandale samruddhikhandale mentioned this pull request Oct 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants