Skip to content

Commit fb1686c

Browse files
committed
FTRS-2976 Fixed Cve in rd main and auth
1 parent e6a1964 commit fb1686c

File tree

4 files changed

+20
-12
lines changed

4 files changed

+20
-12
lines changed
Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,13 @@
11
awscli==1.35.7
22
jsonschema==4.21.1
33
pytest==8.3.3
4-
protobuf==6.31.1
4+
protobuf==6.33.5
55
pyyaml==6.0.1
66
requests==2.32.4
77
numpy==2.1.2
88
boto3==1.35.41
9+
urllib3==2.6.3
10+
pyasn1==0.6.2
11+
certifi
12+
charset-normalizer
13+
idna

build/docker/authoriser-lambda/Dockerfile

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -24,11 +24,10 @@ RUN rm -f /etc/dnf/vars/releasever && \
2424
RUN dnf -y update glib2-2.82.2-769.amzn2023 && \
2525
dnf clean all
2626

27-
# Fix Python package CVEs - completely remove all versions and clean install
28-
RUN pip3 uninstall -y urllib3 pyasn1 requests || true
29-
RUN rm -rf /var/lang/lib/python*/site-packages/urllib3* /var/lang/lib/python*/site-packages/pyasn1* || true
30-
RUN rm -rf ${LAMBDA_TASK_ROOT}/urllib3* ${LAMBDA_TASK_ROOT}/pyasn1* ${LAMBDA_TASK_ROOT}/requests* || true
31-
RUN pip3 install urllib3==2.6.3 pyasn1==0.6.2 requests==2.32.4 certifi charset-normalizer idna --target "${LAMBDA_TASK_ROOT}" --no-cache-dir
27+
# Fix Python package CVEs - completely remove all versions and clean install from requirements.txt
28+
RUN pip3 uninstall -y urllib3 pyasn1 requests protobuf || true
29+
RUN rm -rf /var/lang/lib/python*/site-packages/urllib3* /var/lang/lib/python*/site-packages/pyasn1* /var/lang/lib/python*/site-packages/protobuf* || true
30+
RUN rm -rf ${LAMBDA_TASK_ROOT}/urllib3* ${LAMBDA_TASK_ROOT}/pyasn1* ${LAMBDA_TASK_ROOT}/requests* ${LAMBDA_TASK_ROOT}/protobuf* || true
3231

3332
# Fix CVE-2025-61726 - Update AWS Lambda RIE to version with Go stdlib 1.25.6
3433
RUN curl -Lo /usr/local/bin/aws-lambda-rie https://github.com/aws/aws-lambda-runtime-interface-emulator/releases/latest/download/aws-lambda-rie && \

build/docker/roaddistance-lambda/Dockerfile

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,10 @@ RUN rm -f /etc/dnf/vars/releasever && \
2626
RUN dnf -y update glib2-2.82.2-769.amzn2023 && \
2727
dnf clean all
2828

29-
# Fix Python package CVEs - completely remove all versions and clean install
30-
RUN pip3 uninstall -y urllib3 pyasn1 requests || true
31-
RUN rm -rf /var/lang/lib/python*/site-packages/urllib3* /var/lang/lib/python*/site-packages/pyasn1* || true
32-
RUN rm -rf ${LAMBDA_TASK_ROOT}/urllib3* ${LAMBDA_TASK_ROOT}/pyasn1* ${LAMBDA_TASK_ROOT}/requests* || true
33-
RUN pip3 install urllib3==2.6.3 pyasn1==0.6.2 requests==2.32.4 certifi charset-normalizer idna --target "${LAMBDA_TASK_ROOT}" --no-cache-dir
29+
# Fix Python package CVEs - completely remove all versions and clean install from requirements.txt
30+
RUN pip3 uninstall -y urllib3 pyasn1 requests protobuf || true
31+
RUN rm -rf /var/lang/lib/python*/site-packages/urllib3* /var/lang/lib/python*/site-packages/pyasn1* /var/lang/lib/python*/site-packages/protobuf* || true
32+
RUN rm -rf ${LAMBDA_TASK_ROOT}/urllib3* ${LAMBDA_TASK_ROOT}/pyasn1* ${LAMBDA_TASK_ROOT}/requests* ${LAMBDA_TASK_ROOT}/protobuf* || true
3433

3534
# Fix CVE-2025-61726 - Update AWS Lambda RIE to version with Go stdlib 1.25.6
3635
RUN curl -Lo /usr/local/bin/aws-lambda-rie https://github.com/aws/aws-lambda-runtime-interface-emulator/releases/latest/download/aws-lambda-rie && \
Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,14 @@
11
awscli==1.35.7
22
jsonschema==4.23.0
33
pytest==8.3.3
4-
protobuf==6.31.1
4+
protobuf==6.33.5
55
pyyaml==6.0.2
66
requests==2.32.3
77
numpy==2.1.2
88
boto3==1.35.41
99
coverage==7.6.3
10+
urllib3==2.6.3
11+
pyasn1==0.6.2
12+
certifi
13+
charset-normalizer
14+
idna

0 commit comments

Comments
 (0)