[go: nahoru, domu]

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-40897 in Python runtime #352

Open
1 of 6 tasks
jenshonkan84 opened this issue Oct 12, 2023 · 4 comments
Open
1 of 6 tasks

CVE-2022-40897 in Python runtime #352

jenshonkan84 opened this issue Oct 12, 2023 · 4 comments
Assignees
Labels
kind/bug Something isn't working

Comments

@jenshonkan84
Copy link

Describe the bug
I have just started to test out buildpacks. When I build my little python API I can see that the Container Security Scanner finds a CVE marked as HIGH CVE-2022-40897.

Would be great if someone could fix that. :)

Additional context
How are you using GCP buildpacks?

  • pack and the gcr.io/buildpacks/builder
  • Cloud Functions
  • Cloud Run
  • Cloud Build
  • App Engine Standard
  • App Engine Flex

Did this used to work?
(Yes/No)
Was this working before? When did you start noticing these errors?

What language is your project primarily written in?
Python

Steps To Reproduce
Steps to reproduce the behavior:

  1. gcloud builds submit --pack builder=gcr.io/buildpacks/builder:latest,image=<image_name>

Screenshot:
image

@jenshonkan84 jenshonkan84 added the kind/bug Something isn't working label Oct 12, 2023
@paul-feng-github
Copy link
Collaborator
paul-feng-github commented Oct 12, 2023

@jenshonkan84 We are working on upgrading setuptools version for python311. I'll let you know when it is ready.

@paul-feng-github paul-feng-github self-assigned this Oct 12, 2023
@paul-feng-github
Copy link
Collaborator
paul-feng-github commented Oct 13, 2023

@jenshonkan84 All python311 runtimes have been updated. CVE-2022-40897 is fixed.

@jenshonkan84
Copy link
Author

Thx! I can confirm it is fixed. But... Now it looks like there is a Critical CVE instead.

image

Sorry if I am pushing this. But I just want to make you aware of it. This is related to Go...

@paul-feng-github
Copy link
Collaborator

What go version were you using? Could you please provide more details?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants