Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Anaconda] Address vulnerabilities GHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j #900

Closed
wants to merge 9 commits into from
Closed

[Anaconda] Address vulnerabilities GHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j #900

wants to merge 9 commits into from

Conversation

gauravsaini04
Copy link
Contributor

@gauravsaini04 gauravsaini04 commented Dec 25, 2023

Address vulnerabilities as mentioned in issue #90 in Anaconda Dev container.

  1. Cryptography package GHSA-jfhm-5ghh-2f97
  2. Imagecodecs package GHSA-94vc-p8w7-5p49
  3. Transformers package GHSA-v68g-wm8c-6x7j

Updated to the required versions in Dockerfile and test.sh files. Was able to run tests successfully.

gauravsaini04 and others added 9 commits December 11, 2023 15:43
* [Anaconda] Update aiohttp due to GHSA-gfw2-4jvh-wgfg:aiohttp

* [anaconda] Address GHSA-q3qx-c6g2-7pw2 vulnerability

* Update Dockerfile
) (#893)

* Updated pyarrow package to fix GHSA-5wvp-7f3h-6wmm

* Updated pyarrow package to fix GHSA-5wvp-7f3h-6wmm

* [Anaconda] Address GHSA-q3qx-c6g2-7pw2 vulnerability (#889)

* [Anaconda] Update aiohttp due to GHSA-gfw2-4jvh-wgfg:aiohttp

* [anaconda] Address GHSA-q3qx-c6g2-7pw2 vulnerability

* Update Dockerfile

* Updated pyarrow package to fix GHSA-5wvp-7f3h-6wmm

* Updated pyarrow package to fix GHSA-5wvp-7f3h-6wmm

* removed package-lock.json as its not require

---------

Co-authored-by: gauravsaini04 <147703805+gauravsaini04@users.noreply.github.com>
* Replace deprecated Ruby extension

* Remove the extension since the feature is already installing it

* Update devcontainer.json
@gauravsaini04 gauravsaini04 requested a review from a team as a code owner December 25, 2023 11:36
@gauravsaini04 gauravsaini04 changed the title [Anaconda] Address GHSA_jfhm5ghh 2f97 ghsa 94vc p8w7 5p49 ghsa v68g wm8c 6x7j [Anaconda] Address GHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j Dec 25, 2023
@gauravsaini04 gauravsaini04 changed the title [Anaconda] Address GHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j [Anaconda] Address vulnerabilitiesGHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j Dec 25, 2023
@gauravsaini04 gauravsaini04 changed the title [Anaconda] Address vulnerabilitiesGHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j [Anaconda] Address vulnerabilities GHSA_jfhm_ghh_2f97; GHSA_94vc_p8w7_5p49; GHSA_v68g_wm8c_6x7j Dec 25, 2023
@gauravsaini04
Copy link
Contributor Author

Wrongly raised pull request.
Needed only one vulnerability remedial per pull request.
Thus, closing this PR.

@gauravsaini04 gauravsaini04 deleted the anaconda__GHSA-jfhm-5ghh-2f97__GHSA-94vc-p8w7-5p49__GHSA-v68g-wm8c-6x7j branch December 26, 2023 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants