Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security updates for setuptools, requests, urllib, zipp, twitcher #622

Merged
merged 5 commits into from
Jul 23, 2024

Conversation

@fmigneault fmigneault self-assigned this Jul 23, 2024
@github-actions github-actions bot added doc Documentation improvements or building problem tests Test execution or additional use cases ci Something related to code tests, deployment and packaging labels Jul 23, 2024
@fmigneault fmigneault changed the title security updates for setuptools, requests, urllib, zipp security updates for setuptools, requests, urllib, zipp, twitcher Jul 23, 2024
@fmigneault fmigneault merged commit 465faba into master Jul 23, 2024
19 checks passed
@fmigneault fmigneault deleted the security-updates branch July 23, 2024 21:04
fmigneault added a commit to bird-house/birdhouse-deploy that referenced this pull request Sep 11, 2024
## Overview
Security updates.

## Changes

**Non-breaking changes**
- Magpie/Twitcher: update Python packages and base Docker image to address security vulnerabilities 

  - [Magpie 4.1.1](https://github.com/Ouranosinc/Magpie/blob/master/CHANGES.rst#411-2024-07-23)     (relates to [Ouranosinc/Magpie#622](Ouranosinc/Magpie#622)).
  - [Twitcher 0.10.0](https://github.com/bird-house/twitcher/blob/master/CHANGES.rst#0100-2024-07-22)     (relates to [bird-house/twitcher#136](bird-house/twitcher#136)).

**Breaking changes**
- n/a

## Related Issue / Discussion

PRs that are an agglomeration of vulnerability fixes flagged by Snyk.

- Ouranosinc/Magpie#622
- bird-house/twitcher#136

## Additional Information

- The change from Magpie 3.x to 4.x is caused by the drop of Python 3.5 to 3.7, and the addition of 3.12 some time ago. Major version was used only to highlight this change in case older versions were still employed by some instances. From a technical aspect in birdhouse-deploy, Magpie with Python 3.11 was already in use for a while (see https://github.com/Ouranosinc/Magpie/blob/3.38.0/Dockerfile#L1). Only minor package dependency differences are actually expected.

## CI Operations

birdhouse_daccs_configs_branch: master
birdhouse_skip_ci: false
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci Something related to code tests, deployment and packaging doc Documentation improvements or building problem tests Test execution or additional use cases
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant