Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Comments

feat(kubeflow-pipelines-visualization-server): pending upstream fix GHSA-h95x-26f3-88hr#8661

Merged
philroche merged 1 commit intowolfi-dev:mainfrom
philroche:feature/cve-GHSA-h95x-26f3-88hr-kubeflow-pipelines-visualization-server
Oct 14, 2024
Merged

feat(kubeflow-pipelines-visualization-server): pending upstream fix GHSA-h95x-26f3-88hr#8661
philroche merged 1 commit intowolfi-dev:mainfrom
philroche:feature/cve-GHSA-h95x-26f3-88hr-kubeflow-pipelines-visualization-server

Conversation

@philroche
Copy link
Member

Marking as pending upstream fix:

There is not currently a fixed version of the js2py package. So, the upstream project must migrate away from using js2py or wait for js2py to release a fixed version (and upgrade to it). Upstream PR @ PiotrDabkowski/Js2Py#323 which is yet to be merged.

This follows on from the same advisory filed for apache-beam-python-3.11-sdk @ https://github.com/chainguard-dev/enterprise-advisories/pull/5130

Signed-off-by: philroche phil.roche@chainguard.dev

…HSA-h95x-26f3-88hr

Marking as pending upstream fix:

> There is not currently a fixed version of the js2py package. So, the upstream project must migrate away from using js2py or wait for js2py to release a fixed version (and upgrade to it). Upstream PR @ PiotrDabkowski/Js2Py#323 which is yet to be merged.

This follows on from the same advisory filed for apache-beam-python-3.11-sdk @ chainguard-dev/enterprise-advisories#5130

Signed-off-by: philroche <phil.roche@chainguard.dev>
@philroche philroche marked this pull request as ready for review October 14, 2024 15:21
@philroche philroche added this pull request to the merge queue Oct 14, 2024
Merged via the queue into wolfi-dev:main with commit da3609c Oct 14, 2024
@philroche philroche deleted the feature/cve-GHSA-h95x-26f3-88hr-kubeflow-pipelines-visualization-server branch October 14, 2024 19:04
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants