[rhoai-2.25] fix(cve): CVE-2026-32274 - black#2128
Conversation
- Update black from 25.12.0 to 26.3.1 - Addresses arbitrary file writes from unsanitized user input in cache file name - Added override-dependencies entry for black>=26.3.1 in all affected pyproject.toml - Updated pylock.toml with new version hashes for all 7 affected workbench images - Affected images: datascience, trustyai, tensorflow, rocm/tensorflow, rocm/pytorch, pytorch, pytorch+llmcompressor - CVSS 8.7 (High) Resolves: RHOAIENG-53183, RHOAIENG-53184, RHOAIENG-53185, RHOAIENG-53186, RHOAIENG-53187, RHOAIENG-53188, RHOAIENG-53189 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
@crackcodecamp — This PR is from a fork. Recommended: Push your branch to the main repo for full CI: Then open a new PR from that branch. No push access? A maintainer will cherry-pick and test your changes. See CONTRIBUTING.md for details. |
📝 WalkthroughWalkthroughThis PR upgrades the Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related PRs
Suggested labels
Suggested reviewers
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/build-konflux |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: jiridanek The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
3653dea
into
red-hat-data-services:rhoai-2.25
Resolves: RHOAIENG-53183, RHOAIENG-53184, RHOAIENG-53185, RHOAIENG-53186, RHOAIENG-53187, RHOAIENG-53188, RHOAIENG-53189
Summary by CodeRabbit