Skip to content

Conversation

@alexander-smolyakov
Copy link
Contributor

Devcontainer name:

  • anaconda

Description:

This PR reworks the patch for the GHSA-v845-jxx5-vc9f vulnerability to install the urllib3 package from the Conda default channel instead of PIP. Currently, version 1.26.18 is only available in the Conda default channel.

Changelog:

  • Reworked patch for GHSA-v845-jxx5-vc9f to install a patched version of the urllib3 package via the conda install command;

  • Updated test to verify urllib3 minimum version (Minimum package version set to 1.26.17 which fixes GHSA-v845-jxx5-vc9f);

Checklist:

  • Checked that applied changes work as expected

@alexander-smolyakov alexander-smolyakov requested a review from a team as a code owner October 27, 2023 09:39
@samruddhikhandale samruddhikhandale merged commit 72a1b6a into devcontainers:main Oct 30, 2023
@alexander-smolyakov alexander-smolyakov deleted the anaconda_rework_patch_GHSA-v845-jxx5-vc9f branch October 31, 2023 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants