Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[miniconda] Rework patch for GHSA-v845-jxx5-vc9f #822

Merged
merged 2 commits into from
Oct 27, 2023
Merged

[miniconda] Rework patch for GHSA-v845-jxx5-vc9f #822

merged 2 commits into from
Oct 27, 2023

Conversation

alexander-smolyakov
Copy link
Contributor

Devcontainer name:

  • miniconda

Description:

This PR reworks the patch for the GHSA-v845-jxx5-vc9f vulnerability to install the urllib3 package from the Conda default channel instead of PIP. Currently, version 1.26.18 is only available in the Conda default channel.

Changelog:

  • Reworked patch for GHSA-v845-jxx5-vc9f to install a patched version of the urllib3 package via the conda install command;

  • Updated test to verify urllib3 minimum version (Minimum package version set to 1.26.17 which fixes GHSA-v845-jxx5-vc9f);

Checklist:

  • Checked that applied changes work as expected

@alexander-smolyakov alexander-smolyakov requested a review from a team as a code owner October 27, 2023 10:11
@samruddhikhandale samruddhikhandale merged commit 1d4608c into devcontainers:main Oct 27, 2023
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants