-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade Jupyter-server-proxy #46
Comments
2i2c patched QGIS and deployed already. https://github.com/2i2c-org/infrastructure/blob/7753be4874c32efad56112528091e0a979621603/config/clusters/nasa-veda/common.values.yaml#L194 |
Our last procedure to upgrade the pangeo-notebook image was: Checklist:
|
Best I can tell Rocker being tagged to 4.3 is also recent and likely patched https://hub.docker.com/r/rocker/binder/tags |
PR to 2i2c infra repo to update the |
I've confirmed in both VEDA and GHG hubs the new image is deployed - had to login and check the TODO: make it easier to tell what container image is being run, maybe there's an easy command but it's not obvious. |
@wildintellect there will be an environment variable called |
A fix has been released for a vulnerability in Jupyter-server-proxy, 2i2c has mitigations in place, however it's best practices that we update to non-vulnerable versions of packages.
jupyter-server-proxy >= 4.1.1 or 3.2.3
https://github.com/jupyterhub/jupyter-server-proxy/pull/465/filesUpgrade pattern should follow #41
Tasks
The text was updated successfully, but these errors were encountered: