From 259f957ced884c92002bd6de183c523f6113db62 Mon Sep 17 00:00:00 2001 From: Justin Lecher Date: Mon, 20 May 2024 09:54:55 +0100 Subject: [PATCH 1/3] feat: upgrade to latest miniforge --- .../share/python-build/miniforge3-24.3.0-0 | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 plugins/python-build/share/python-build/miniforge3-24.3.0-0 diff --git a/plugins/python-build/share/python-build/miniforge3-24.3.0-0 b/plugins/python-build/share/python-build/miniforge3-24.3.0-0 new file mode 100644 index 0000000000..5c9973355d --- /dev/null +++ b/plugins/python-build/share/python-build/miniforge3-24.3.0-0 @@ -0,0 +1,13 @@ +case "$(anaconda_architecture 2>/dev/null || true)" in +"Linux-x86_64" ) + install_script "Miniforge3-24.3.0-0-Linux-x86_64.sh" "https://github.com/conda-forge/miniforge/releases/download/24.3.0-0/Miniforge3-24.3.0-0-Linux-x86_64.sh#0be3654cc3b9c43d3aeeeca5efe6d2f31e9f7711702f3818529b367b3db677fb" "miniconda" verify_py310 + ;; +* ) + { echo + colorize 1 "ERROR" + echo ": The binary distribution of Miniforge is not available for $(anaconda_architecture 2>/dev/null || true)." + echo + } >&2 + exit 1 + ;; +esac From dd5515603db7aec81ed00318b4433588a502fe6f Mon Sep 17 00:00:00 2001 From: Justin Lecher Date: Mon, 20 May 2024 10:12:29 +0100 Subject: [PATCH 2/3] fix: checksum --- plugins/python-build/share/python-build/miniforge3-24.3.0-0 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugins/python-build/share/python-build/miniforge3-24.3.0-0 b/plugins/python-build/share/python-build/miniforge3-24.3.0-0 index 5c9973355d..dd83c74228 100644 --- a/plugins/python-build/share/python-build/miniforge3-24.3.0-0 +++ b/plugins/python-build/share/python-build/miniforge3-24.3.0-0 @@ -1,6 +1,6 @@ case "$(anaconda_architecture 2>/dev/null || true)" in "Linux-x86_64" ) - install_script "Miniforge3-24.3.0-0-Linux-x86_64.sh" "https://github.com/conda-forge/miniforge/releases/download/24.3.0-0/Miniforge3-24.3.0-0-Linux-x86_64.sh#0be3654cc3b9c43d3aeeeca5efe6d2f31e9f7711702f3818529b367b3db677fb" "miniconda" verify_py310 + install_script "Miniforge3-24.3.0-0-Linux-x86_64.sh" "https://github.com/conda-forge/miniforge/releases/download/24.3.0-0/Miniforge3-24.3.0-0-Linux-x86_64.sh#23367676b610de826f50f7ddc91139a816d4b59bd4c69cc9b6082d9b2e7fe8a3" "miniconda" verify_py310 ;; * ) { echo From 35e44cab804a000aaa50537323f7f0bb240dfe6a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 23 May 2024 06:38:13 +0000 Subject: [PATCH 3/3] fix: plugins/python-build/scripts/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 --- plugins/python-build/scripts/requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/plugins/python-build/scripts/requirements.txt b/plugins/python-build/scripts/requirements.txt index a8fdb314a1..348c9566cb 100644 --- a/plugins/python-build/scripts/requirements.txt +++ b/plugins/python-build/scripts/requirements.txt @@ -1 +1,2 @@ requests-html +requests>=2.32.0 # not directly required, pinned by Snyk to avoid a vulnerability