-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Fix some of vulnerability issue relative python packages #14269
Conversation
Pillow: [CVE-2021-27921] Wheel: [CVE-2022-40898] Setuptools: [CVE-2022-40897] lxml: [CVE-2022-2309]
/azp run Azure.sonic-buildimage |
Azure Pipelines successfully started running 1 pipeline(s). |
Fix Setuptools: [CVE-2022-40897] later, since it has impact on the libyang build. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
@xumia PR conflicts with 202211 branch |
…onic-net#14269) Why I did it Fix some of vulnerability issue relative python packages sonic-net#14269 Pillow: [CVE-2021-27921] Wheel: [CVE-2022-40898] lxml: [CVE-2022-2309] How I did it
…onic-net#14269) Why I did it Fix some of vulnerability issue relative python packages sonic-net#14269 Pillow: [CVE-2021-27921] Wheel: [CVE-2022-40898] lxml: [CVE-2022-2309] How I did it
…14269) (#14353) Why I did it Fix some of vulnerability issue relative python packages #14269 Pillow: [CVE-2021-27921] Wheel: [CVE-2022-40898] lxml: [CVE-2022-2309] How I did it
For 202211: #14352 |
…14269) (#14352) Why I did it Fix some of vulnerability issue relative python packages #14269 Pillow: [CVE-2021-27921] Wheel: [CVE-2022-40898] lxml: [CVE-2022-2309] How I did it How to verify it
@xumia FYI Some utils like safety also report about CVE in
This old version is used in mgmt-framework. |
probably need also to upgrade sonic-buildimage/build_debian.sh Line 533 in 53ae6a0
|
@k-v1 , yes, we should fix the missing ones, I will send another PR to fix it. |
Why I did it
Fix some of vulnerability issue relative python packages #14269
Pillow: [CVE-2021-27921]
Wheel: [CVE-2022-40898]
lxml: [CVE-2022-2309]
How I did it
How to verify it
Which release branch to backport (provide reason below if selected)
Description for the changelog
Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU.
Link to config_db schema for YANG module changes
A picture of a cute animal (not mandatory but encouraged)