Commit 75d0c10
authored
chore(cves) Fixes for latest CVEs (#7003)
* [alibi-detect-server] Fixing SNYK-PYTHON-URLLIB3-14192442 CVE
* Skip few job in CI to save resources
* Upgrade urrlib3 in alibi-explain-server component
* Remove spacy tests to eliminate the CVE-2024-6345 vulnerability in setuptools dependency
* Pin urllib3 in mlflowserver to get rid of CVE-2025-66471
* pin urllib3 for `tfserving_proxy`
* Print deps tree to debug
* Fix broken workflow after adding another `if`
* Pin setuptools again to check deps tree
* Try to manually add snyk ignore
* Fix `--policy-path` arg
* Try `--exclude-base-image-vulns` arg as well
* Add pip freeze for server images
* Make .snyk `ignore` section more specific
* Enable all jobs in the python security tests
* Upgrade tornado minor version in alibi-explain, alibi-detect
* pin setuptools to exact version in tfserving_proxy1 parent c521b3d commit 75d0c10
File tree
9 files changed
+54
-38
lines changed- .github/workflows
- components
- alibi-detect-server
- alibi-explain-server
- python
- servers
- mlflowserver/mlflowserver
- tfserving_proxy
9 files changed
+54
-38
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
148 | 148 | | |
149 | 149 | | |
150 | 150 | | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
151 | 156 | | |
152 | 157 | | |
153 | 158 | | |
| |||
166 | 171 | | |
167 | 172 | | |
168 | 173 | | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
169 | 180 | | |
170 | 181 | | |
171 | 182 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| 55 | + | |
| 56 | + | |
55 | 57 | | |
56 | 58 | | |
57 | 59 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
| 43 | + | |
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | 5 | | |
5 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
| 7 | + | |
0 commit comments