Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SAASMLOPS-1335 Upgrade gunicorn package to remove vulnerability #17

Merged
merged 2 commits into from
May 29, 2024

Conversation

brijesh-vora-sp
Copy link

What this PR does / why we need it:

Upgrade gunicorn package due to which there is vulnerability.

gunicorn 21.2.0 | CVE-2024-1135 | HIGH

Which issue(s) this PR fixes:

Fixes

@brijesh-vora-sp brijesh-vora-sp changed the title SAASMLOPS-1335 Upgrade unicorn package to remove vulnerability SAASMLOPS-1335 Upgrade gunicorn package to remove vulnerability May 28, 2024
@dawid-laszuk-sp
Copy link

@brijesh-vora-sp any chance you checked whether this is working correctly? Could you please provide a link to airflow DAG that uses this image?

@brijesh-vora-sp
Copy link
Author

Ah, good point. Let me run that.

@brijesh-vora-sp
Copy link
Author

brijesh-vora-sp commented May 29, 2024

The vulnerability scan report: https://cloudbees-core.ops-dev-use1.cloud.sailpoint.com/deploy/job/image-scan-cve/3095/console
HIGH CVE-2018-20225 is labeled as false positive.

11:49:48  + python /app/cs_imagescan.py --repo 406205545357.dkr.ecr.us-east-1.amazonaws.com/sailpoint/feast-bytewax --skip-push --tag SAASMLOPS-1335 -c us-2
11:49:48  INFO    Downloading Image Scan Report
11:49:59  INFO    Searching for vulnerabilities in scan report...
11:49:59  WARNING HIGH     CVE-2018-20225   Vulnerability detected affecting pip 24.0
11:49:59  INFO    Searching for leaked secrets in scan report...
11:49:59  INFO    Searching for malware in scan report...
11:49:59  INFO    Searching for misconfigurations in scan report...
11:49:59  WARNING Alert: Misconfiguration found
11:49:59  ERROR   Exiting: Vulnerability score threshold exceeded: '500' out of '500'

Copy link

@dawid-laszuk-sp dawid-laszuk-sp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Excellent!

@brijesh-vora-sp brijesh-vora-sp merged commit 037b803 into release May 29, 2024
13 of 14 checks passed
nick-amaya-sp pushed a commit that referenced this pull request Jul 23, 2024
* SAASMLOPS-1335 Upgrade unicorn package to remove vulnerability

* SAASMLOPS-1335 Add the gunicorn to sailpoint dockerfile
nick-amaya-sp pushed a commit that referenced this pull request Jul 23, 2024
* SAASMLOPS-1335 Upgrade unicorn package to remove vulnerability

* SAASMLOPS-1335 Add the gunicorn to sailpoint dockerfile
nick-amaya-sp pushed a commit that referenced this pull request Jul 23, 2024
* SAASMLOPS-1335 Upgrade unicorn package to remove vulnerability

* SAASMLOPS-1335 Add the gunicorn to sailpoint dockerfile
nick-amaya-sp pushed a commit that referenced this pull request Jul 24, 2024
* SAASMLOPS-1335 Upgrade unicorn package to remove vulnerability

* SAASMLOPS-1335 Add the gunicorn to sailpoint dockerfile
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants