Vulnerabilities in Python Dependencies #5939
Unanswered
phillipjohnson
asked this question in
Q&A
Replies: 1 comment
-
Thank you for bringing this up. The plan at the moment is to update the CI so it works properly again (probably move to GitHub Actions from CircleCI in the process) and then update all or most of the dependencies to make sure we are in a good posture security wise and in general. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I am pulling this over from the discourse thread since there was recent interest in it again.
Issue Summary
The Docker image for Redash 10 (i.e.
redash/redash:10.1.0.b50633 (debian 10.11)
) includes several Python libraries that have high and critical CVEs.PyYAML
5.1.2 -> 5.4httplib2
0.14.0 -> 0.19.0pyarrow
0.13.0 -> 0.15.0pycrypto
2.6.1 -> No known fix, suggested to usepycryptodome
sqlparse
0.3.0 -> 0.4.2urllib3
1.24.3 -> 1.26.5What is the recommended remediation? Has Redash been tested against any of these newer versions?
List of vulnerabilities:
Technical details:
Beta Was this translation helpful? Give feedback.
All reactions