Skip to content

Conversation

@dervoeti
Copy link
Member

Description

Setuptools was pinned to version 66.1.1 in #307. That package contains a vulnerability (CVE-2024-6345). I bumped the dependency to the latest version, building and running Superset in my test cluster worked fine. I only tested with Superset 4.0.2, as that is currently the only version we plan to ship with SDP 24.11.

@dervoeti dervoeti changed the title chore: update setuptools chore(superset): update setuptools Oct 21, 2024
@lfrancke
Copy link
Member

Does setuptools end up in the final image? (Doesn't change the fact that we should upgrade)

@dervoeti
Copy link
Member Author

It does, you can see the dependency tree here for example: https://secobserve.stackable.tech/#/observations/1514479/show

I have not validated or analyzed it further though. I don't know too much about Python, but I also thought that setuptools was not a runtime dependency.

@lfrancke
Copy link
Member

I also don't know enough about Python but to me that's unexpected. But what do I know :)
I'm happy to approve this but you requested Sigi...I'll approve it anyway. Up to you to wait or not.

@dervoeti dervoeti added this pull request to the merge queue Oct 21, 2024
Merged via the queue into main with commit afe481b Oct 21, 2024
2 checks passed
@dervoeti dervoeti deleted the chore/update-setuptools branch October 21, 2024 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants