-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump pyyaml from 5.3.1 to 5.4.1 #6511
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As part of this PR, can you please also pin the PyYAML version in:
- src/sonic-ctrmgrd/setup.py
- src/sonic-py-common/setup.py
And determine if we still need to explicitly install it in dockers/docker-snmp/Dockerfile.j2?
Both are good now. Even the dependency is not available in the build environment, the downloaded latest version is good. If they need any specific version, they need to pin it. In reply to: 572984163 [](ancestors = 572984163) |
Retest baseimage please |
c57931e
to
a3ecf52
Compare
a3ecf52
to
42bfa91
Compare
RCE resolved in new version yaml/pyyaml#420
RCE resolved in new version yaml/pyyaml#420
- Why I did it
RCE resolved in new version yaml/pyyaml#420
- How I did it
- How to verify it
- Which release branch to backport (provide reason below if selected)
- Description for the changelog
- A picture of a cute animal (not mandatory but encouraged)