Skip to content

Commit bf0a298

Browse files
[anaconda] Update jupyter_server package due to GHSA-r726-vmfq-j9j3 (devcontainers#754)
* Bump `jupyter_server` package version * Add test * Update manifest
1 parent c8a3cdc commit bf0a298

File tree

3 files changed

+6
-2
lines changed

3 files changed

+6
-2
lines changed

src/anaconda/.devcontainer/Dockerfile

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,9 @@ RUN python3 -m pip install --upgrade \
3333
# https://github.com/advisories/GHSA-qppv-j76h-2rpx
3434
tornado==6.3.3 \
3535
# https://github.com/advisories/GHSA-282v-666c-3fvg
36-
transformers==4.30.0
36+
transformers==4.30.0 \
37+
# https://github.com/advisories/GHSA-r726-vmfq-j9j3
38+
jupyter_server==2.7.2
3739

3840
# Reset and copy updated files with updated privs to keep image size down
3941
FROM mcr.microsoft.com/devcontainers/base:1-bullseye

src/anaconda/manifest.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,8 @@
3939
"Werkzeug",
4040
"requests",
4141
"tornado",
42-
"transformers"
42+
"transformers",
43+
"jupyter_server"
4344
],
4445
"other": {
4546
"git": {},

src/anaconda/test-project/test.sh

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,7 @@ checkPythonPackageVersion "torch" "1.13.1"
4545
checkPythonPackageVersion "transformers" "4.30.0"
4646
checkPythonPackageVersion "mpmath" "1.3.0"
4747
checkPythonPackageVersion "aiohttp" "3.8.5"
48+
checkPythonPackageVersion "jupyter_server" "2.7.2"
4849

4950
# The `tornado` package doesn't have the `__version__` attribute so we can use the `version` attribute.
5051
tornado_version=$(python -c "import tornado; print(tornado.version)")

0 commit comments

Comments
 (0)