Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Resolves the following CVEs:
I observed that the
glib2-devel
depends on and installs python 3.6. This was also installing rpm packages for the pip and setuptools versions reported above. Removing the relevant rpm packages did not resolve the CVEs, and I verified that the image build worked fine withoutglib2-devel
.I also removed the version pin for the
requests
package on the base layer. It's important to note that the Splunk product may install its own version(s) of requests depending on the build, however this will not affect the version we install via pip.