-
Notifications
You must be signed in to change notification settings - Fork 487
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[universal] Conda: patch Python due to CVE-2023-32681 and GHSA-5cpq-8wj7-hf2v #627
Merged
samruddhikhandale
merged 26 commits into
devcontainers:main
from
alexander-smolyakov:users/alexander-smolyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
Aug 2, 2023
Merged
[universal] Conda: patch Python due to CVE-2023-32681 and GHSA-5cpq-8wj7-hf2v #627
samruddhikhandale
merged 26 commits into
devcontainers:main
from
alexander-smolyakov:users/alexander-smolyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
Aug 2, 2023
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…wj7-hf2v - Reorganize features installation queue; - Introduce patch-conda feature;
src/universal/.devcontainer/local-features/patch-conda/devcontainer-feature.json
Outdated
Show resolved
Hide resolved
src/universal/.devcontainer/local-features/patch-conda/install.sh
Outdated
Show resolved
Hide resolved
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
This reverts commit 046b94c.
samruddhikhandale
requested changes
Jun 20, 2023
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left one comment, can you also help resolve the merge conflicts? thanks!
src/universal/.devcontainer/local-features/patch-conda/devcontainer-feature.json
Show resolved
Hide resolved
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
src/universal/.devcontainer/local-features/patch-conda/install.sh
Outdated
Show resolved
Hide resolved
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
…lyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
There was an error handling pipeline event c9650c9f-36bc-49b6-9c6f-b01bfaa947a7. |
This reverts commit a74d406.
…q-8wj7-hf2v_bump-cryptography-version
…q-8wj7-hf2v_bump-cryptography-version
…q-8wj7-hf2v_bump-cryptography-version
samruddhikhandale
approved these changes
Aug 2, 2023
alexander-smolyakov
deleted the
users/alexander-smolyakov/universal_GHSA-5cpq-8wj7-hf2v_bump-cryptography-version
branch
August 2, 2023 16:02
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Dev container name:
Issue description:
This PR aims to address CVE-2023-32681 and GHSA-5cpq-8wj7-hf2v security vulnerabilities. These vulnerabilities come from Python distribution which ships with Conda.
Fix description:
In the
universal
devcontainer, we have three instances of Python distribution:Originally fixes were applied during the
setup-user
feature installation and the feature installation queue looks the following:This approach resulted in the Anaconda Python distribution containing vulnerable packages in
site-packages
folders, and this triggered our security checks. Additionally, when running theconda list
command, it's listed vulnerable packages.The
pip
doesn't provide the ability to remove packages from the specificsite-packages
folder. When we try to remove any packages for related Python distribution duringsetup-user
installation, we face the following situation:The
pip
trying to remove the package from the/home/codespace/.local/lib/python3.10/site-packages/
folder when we need to remove the package fromopt/conda/lib/python3.10/site-packages
. In order to remove packageopt/conda/lib/python3.10/site-packages
, we should run the/opt/conda/bin/python3 -m pip uninstall requests
command twice because we installed additional Python distribution via thepython
feature:The other side effect of this approach is that it affects Python distribution coming from the
python
feature:To avoid such a situation, we have to reorganize the features installation queue to install the
conda
feature and apply all patches to it before thepython
feature installation.Fix results:
Before fix:
opt/conda/lib/python3.10/site-packages
conda list
With fix:
opt/conda/lib/python3.10/site-packages
conda list
Changelog:
cryptography
,pyopenssl
to address GHSA-5cpq-8wj7-hf2v;Checklist: