Skip to content

Commit 4735279

Browse files
[Anaconda]-Werkzeug-GHSA-2g68-c3qc-8985 patch for security vuln (devcontainers#1062)
Co-authored-by: Samruddhi Khandale <skhandale@microsoft.com>
1 parent 9fd57ac commit 4735279

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

src/anaconda/.devcontainer/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ RUN python3 -m pip install --upgrade \
2020
mistune==3.0.1 \
2121
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34141
2222
numpy==1.25.2 \
23-
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25577
24-
werkzeug==2.3.6 \
23+
# https://github.com/advisories/GHSA-2g68-c3qc-8985
24+
werkzeug==3.0.3 \
2525
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32862
2626
nbconvert==7.7.3 \
2727
# https://github.com/advisories/GHSA-qppv-j76h-2rpx

src/anaconda/test-project/test.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ checkPythonPackageVersion "setuptools" "65.5.1"
3737
checkPythonPackageVersion "future" "0.18.3"
3838
checkPythonPackageVersion "wheel" "0.38.1"
3939
checkPythonPackageVersion "nbconvert" "6.5.1"
40-
checkPythonPackageVersion "werkzeug" "2.2.3"
40+
checkPythonPackageVersion "werkzeug" "3.0.3"
4141
checkPythonPackageVersion "certifi" "2022.12.07"
4242
checkPythonPackageVersion "requests" "2.31.0"
4343
checkPythonPackageVersion "cryptography" "42.0.4"

0 commit comments

Comments
 (0)