Skip to content

Commit bf889df

Browse files
[anaconda]-security vulnerability for GHSA-8qvm-5x2c-j2w7: protobuf and GHSA-9356-575x-2w9m: transformers (devcontainers#1554)
* [anaconda]-security vulnerability for GHSA-8qvm-5x2c-j2w7: protobuf and GHSA-9356-575x-2w9m: transformers * made changes
1 parent 7e1df86 commit bf889df

File tree

4 files changed

+7
-7
lines changed

4 files changed

+7
-7
lines changed

src/anaconda/.devcontainer/apply_security_patches.sh

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
# vulnerabilities:
44
# werkzeug - [GHSA-f9vj-2wh5-fj8j]
55

6-
vulnerable_packages=( "mistune=3.0.1" "aiohttp=3.10.11" "cryptography=44.0.1" "h11=0.16.0" "jinja2=3.1.6" "jupyter_core=5.8.1" "protobuf=4.25.8" "requests=2.32.4" "setuptools=78.1.1" "transformers=4.52.1" "urllib3=2.5.0" "Werkzeug=3.0.6" "jupyter-lsp=2.2.2" "scrapy=2.11.2" \
6+
vulnerable_packages=( "mistune=3.0.1" "aiohttp=3.10.11" "cryptography=44.0.1" "h11=0.16.0" "jinja2=3.1.6" "jupyter_core=5.8.1" "protobuf=5.29.5" "requests=2.32.4" "setuptools=78.1.1" "transformers=4.53.0" "urllib3=2.5.0" "Werkzeug=3.0.6" "jupyter-lsp=2.2.2" "scrapy=2.11.2" \
77
"zipp=3.19.1" "tornado=6.4.2")
88

99
# Define the number of rows (based on the length of vulnerable_packages)
@@ -26,7 +26,7 @@ done
2626

2727
# Add an array for packages that should always pin to the provided version,
2828
# even if higher version is available in conda channel
29-
pin_to_required_version=("jupyter_core" "cryptography" )
29+
pin_to_required_version=("jupyter_core" "cryptography")
3030
# Function to check if a package is in the pin_to_required_version array
3131
function is_pin_to_required_version() {
3232
local pkg="$1"

src/anaconda/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,8 +29,8 @@ Refer to [this guide](https://containers.dev/guide/dockerfile) for more details.
2929
You can decide how often you want updates by referencing a [semantic version](https://semver.org/) of each image. For example:
3030

3131
- `mcr.microsoft.com/devcontainers/anaconda:1-3`
32-
- `mcr.microsoft.com/devcontainers/anaconda:1.0-3`
33-
- `mcr.microsoft.com/devcontainers/anaconda:1.0.0-3`
32+
- `mcr.microsoft.com/devcontainers/anaconda:1.3-3`
33+
- `mcr.microsoft.com/devcontainers/anaconda:1.3.0-3`
3434

3535
See [history](history) for information on the contents of each version and [here for a complete list of available tags](https://mcr.microsoft.com/v2/devcontainers/anaconda/tags/list).
3636

src/anaconda/manifest.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"version": "1.2.9",
2+
"version": "1.3.0",
33
"build": {
44
"latest": true,
55
"rootDistro": "debian",

src/anaconda/test-project/test.sh

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,8 +41,8 @@ checkPythonPackageVersion "certifi" "2022.12.07"
4141
checkPythonPackageVersion "cryptography" "44.0.1"
4242
checkPythonPackageVersion "h11" "0.16.0"
4343
checkPythonPackageVersion "jupyter_core" "5.8.1"
44-
checkPythonPackageVersion "protobuf" "4.25.8"
45-
checkPythonPackageVersion "transformers" "4.52.1"
44+
checkPythonPackageVersion "protobuf" "5.29.5"
45+
checkPythonPackageVersion "transformers" "4.53.0"
4646
checkPythonPackageVersion "mpmath" "1.3.0"
4747
checkPythonPackageVersion "aiohttp" "3.10.2"
4848
checkPythonPackageVersion "tornado" "6.4.2"

0 commit comments

Comments
 (0)