Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Sep 27, 2024

@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. labels Sep 27, 2024
@Dentrax
Copy link
Member

Dentrax commented Sep 29, 2024

Including the following didn't mitigate the CVEs:

poetry add "urllib3==1.26.19"
poetry add "setuptools==70.0.0"

reflex.yaml Outdated
poetry add "certifi==2024.07.04"
poetry add "idna==3.7"
poetry add "urllib3==1.26.19"
poetry add "setuptools==70.0.0"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like this didn't take affect:

└── 📄 /usr/lib/python3.12/site-packages/virtualenv/seed/wheels/embed/setuptools-68.0.0-py3-none-any.whl
        📦 setuptools 68.0.0 (python)
            High CVE-2024-6345 GHSA-cx63-2mw6-8hw5 fixed in 70.0.0

Though I don't see anywhere else we're using this as a runtime dependency in any other packages or images. If the version bump isn't working here we should remove it - we can still merge the package update

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, reverted my previous commit.

@Dentrax Dentrax force-pushed the wolfictl-10091c39-87f7-4d2c-acdd-86f99acf49ec branch from 1d88f68 to 51016da Compare September 30, 2024 11:23
@octo-sts
Copy link
Contributor Author

octo-sts bot commented Oct 1, 2024

superseded by #29762

@octo-sts octo-sts bot closed this Oct 1, 2024
@octo-sts octo-sts bot deleted the wolfictl-10091c39-87f7-4d2c-acdd-86f99acf49ec branch October 2, 2024 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated pr bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. manual/review-needed request-version-update request for a newer version of a package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants