Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Latest vulnerability fixes #127

Merged
merged 5 commits into from
Apr 9, 2024
Merged

Commits on Apr 5, 2024

  1. Latest vulnerability fixes - ip

    1. Package ip had vulnerabilities.
    Upgrading node-alpine docker image to latest available version.
    
    This node image does not contain the ip package at all.
    Additionally, the latest ip version 2.0.1 might not contain the remediation as yet.
    Mahadik, Mukul Chandrakant authored and Mahadik, Mukul Chandrakant committed Apr 5, 2024
    Configuration menu
    Copy the full SHA
    7391c53 View commit details
    Browse the repository at this point in the history
  2. Updating pillow version

    Pillow version upgraded in viz_scripts/docker/environment36.dashboard.additions.yml.
    Mahadik, Mukul Chandrakant authored and Mahadik, Mukul Chandrakant committed Apr 5, 2024
    Configuration menu
    Copy the full SHA
    8ff17fe View commit details
    Browse the repository at this point in the history
  3. Whitespace fix

    MukuFlash03 authored Apr 5, 2024
    Configuration menu
    Copy the full SHA
    fe4e3a0 View commit details
    Browse the repository at this point in the history

Commits on Apr 8, 2024

  1. Updated Docker image tag

    Bumped up latest server image used build from as base docker image.
    Mahadik, Mukul Chandrakant authored and Mahadik, Mukul Chandrakant committed Apr 8, 2024
    Configuration menu
    Copy the full SHA
    9a9cf4c View commit details
    Browse the repository at this point in the history

Commits on Apr 9, 2024

  1. Reverted addition of pillow package

    Initially, AWS mentioned it as a SUPPRESSED status vulnerability with HIGH severity. Hence I added it.
    
    However, we don't really use pillow in public-dash viz_scripts and now can observe that the pillow vulnerability status has been changed to CLOSED.
    Mahadik, Mukul Chandrakant authored and Mahadik, Mukul Chandrakant committed Apr 9, 2024
    Configuration menu
    Copy the full SHA
    7ad5173 View commit details
    Browse the repository at this point in the history