-
Notifications
You must be signed in to change notification settings - Fork 14.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update superset 3.1.0/3.1.1 dependency "setuptools 58.1.0" #26991
Comments
If I'm not mistaken, we're on >=65.5.1 now. |
CC @john-bodley to fact-check this for me... we can re-open if I'm mistaken. |
Hi again @rusackas I am not sure that in the 3.1.0 docker image is the updated setuptools? image => apache/superset:3.1.0 I still think this here is something to update (?) - but at least I cannot tell it to you for sure EDIT
|
Hi @rusackas also superset 3.1.1 has setuptools 58.1.0 inside ... I think we should reopen this ticket or? |
Fair enough! Re-opening, pending further investigation/confirmation. |
I made some tests with blank python docker images, it seems somehow to be an issue with python 3.9 (?) // use a default installation in python 3.9-slim
// use latest version in python 3.9-slim
// use latest version in python 3.10-slim
Because setuptool in default installation in 3.9-slim without version is python-version in superset ("buster") - might it be that there is some problem with a "default" package configuration depending the python version..? would also match with this: https://docs.python.org/3.9/whatsnew/changelog.html I found here a installation (don't know if this is the relevant position) here is no version set - so it MIGHT be installing the default old version inside the docker image? |
Thanks for the additional diagnostics @nigzak! If this seems to center on the flavor of Python involved, I wonder if @john-bodley or @mistercrunch might have ideas of how to address it. |
We're still a bit stuck with #26944, let me try to revive it. I could also just bump that |
Here -> #27405 |
I'll go ahead and close it. We typically close issues when there's no further developer action to take on |
Bug description
The docker inspector marks the image of superset 3.1.0 with a finding of setuptools 58.1.0
https://scout.docker.com/vulnerabilities/id/CVE-2022-40897?s=github&n=setuptools&t=pypi&vr=%3C65.5.1&utm_source=desktop&utm_medium=ExternalLink
CVSS = 7.5
fixed with 65.5.1
=> update to 65.5.1 (or newer) should be done
How to reproduce the bug
download superset 3.1.0 image
open docker scout
Screenshots/recordings
Superset version
3.1.0
3.1.1
master on 2024-03-05
Python version
3.9
Node version
16
Browser
Chrome
Additional context
V3.0.3 is also affected
Checklist
The text was updated successfully, but these errors were encountered: