-
Notifications
You must be signed in to change notification settings - Fork 277
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
py3-setuptools/74.1.0 package update #27422
Conversation
octo-sts
bot
commented
Sep 2, 2024
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package py3-setuptools: Click to expand/collapsePackage py3-setuptools: Package py3.10-setuptools: Click to expand/collapsePackage py3.10-setuptools: Package py3.11-setuptools: Click to expand/collapsePackage py3.11-setuptools: Package py3.12-setuptools: Click to expand/collapsePackage py3.12-setuptools: Package py3-supported-setuptools: Click to expand/collapsePackage py3-supported-setuptools: bincapz found differences: Click to expand/collapseDeleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | evasion/single_line_imports | imports built-in and executes more code on the same line | import platform; |
-MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
-LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/path/file/url | file url | file:///home |
-LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | evasion/single_line_imports | imports built-in and executes more code on the same line | import platform; |
-MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
-LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
-MEDIUM | process/name/get | get the current process name | process_name |
-MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | evasion/single_line_imports | imports built-in and executes more code on the same line | import platform; |
-MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
-LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | core-metadata-download-url download_url |
-MEDIUM | process/name/get | get the current process name | process_name |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
-LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/shell_command | execute a shell command | system |
-LOW | fd/read | reads from a file handle | self.read() |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | core-metadata-download-url download_url |
-MEDIUM | process/name/get | get the current process name | process_name |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | core-metadata-download-url download_url |
-MEDIUM | process/name/get | get the current process name | process_name |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
-LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
-MEDIUM | process/name/get | get the current process name | process_name |
-MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/path/file/url | file url | file:///home |
-LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/shell_command | execute a shell command | system |
-LOW | fd/read | reads from a file handle | self.read() |
Deleted: py3.11-setuptools/var/lib/db/sbom/py3.11-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/9997350b1c1cdbe8d029e68dcab9 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Deleted: py3-setuptools/var/lib/db/sbom/py3-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/0d14239bda53c228c100b28039b5 |
Deleted: py3.12-setuptools/var/lib/db/sbom/py3.12-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/4a4a6562ace6e61be494cc391440 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
-MEDIUM | process/name/get | get the current process name | process_name |
-MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Deleted: py3.10-setuptools/var/lib/db/sbom/py3.10-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/927a426a8feefa4516173d59c0c3 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
-MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
-LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/shell_command | execute a shell command | system |
-LOW | fd/read | reads from a file handle | self.read() |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/path/file/url | file url | file:///home |
-LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools-74.1.0.post20240902.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/path/file/url | file url | file:///home |
+LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/compat/py312.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/cpython#77102 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools-74.1.0.post20240902.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/path/file/url | file url | file:///home |
+LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.12-setuptools/var/lib/db/sbom/py3.12-setuptools-74.1.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/250ec4b16c7720051beb3a95c02b |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools-74.1.0.post20240902.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/path/file/url | file url | file:///home |
+LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/msvc.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/compat/py312.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/cpython#77102 |
Added: py3.10-setuptools/var/lib/db/sbom/py3.10-setuptools-74.1.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/05af251379fcc167ffdf84f2d806 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/compat/py312.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/cpython#77102 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/msvc.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 |
Added: py3.11-setuptools/var/lib/db/sbom/py3.11-setuptools-74.1.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/5089f47b4a1bfb01269cb2b4d1c2 |
Added: py3-setuptools/var/lib/db/sbom/py3-setuptools-74.1.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/f1319c41241a4838774cd3d6628e |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/msvc.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 |