Skip to content

Commit

Permalink
⬆️ 🔒️ Upgrades vulnerable libraries (ITISFoundation#4742)
Browse files Browse the repository at this point in the history
  • Loading branch information
pcrespov authored Sep 13, 2023
1 parent e888d90 commit ab5fa9a
Show file tree
Hide file tree
Showing 47 changed files with 353 additions and 74 deletions.
4 changes: 3 additions & 1 deletion api/tests/requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,9 @@ attrs==23.1.0
# jsonschema
# referencing
certifi==2023.7.22
# via requests
# via
# -c ../../requirements/constraints.txt
# requests
charset-normalizer==3.2.0
# via
# aiohttp
Expand Down
2 changes: 2 additions & 0 deletions packages/dask-task-models-library/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,8 @@ markupsafe==2.1.3
# via jinja2
msgpack==1.0.5
# via distributed
orjson==3.9.7
# via -r requirements/../../../packages/models-library/requirements/_base.in
packaging==23.1
# via
# dask
Expand Down
4 changes: 3 additions & 1 deletion packages/postgres-database/requirements/_migration.txt
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,9 @@ alembic==1.11.2
# -c requirements/_base.txt
# -r requirements/_migration.in
certifi==2023.7.22
# via requests
# via
# -c requirements/../../../requirements/constraints.txt
# requests
charset-normalizer==3.2.0
# via requests
click==8.1.6
Expand Down
7 changes: 6 additions & 1 deletion packages/service-integration/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,10 @@ attrs==23.1.0
# jsonschema
# referencing
certifi==2023.7.22
# via requests
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../requirements/constraints.txt
# requests
charset-normalizer==3.2.0
# via requests
click==8.1.6
Expand Down Expand Up @@ -44,6 +47,8 @@ markdown-it-py==3.0.0
# via rich
mdurl==0.1.2
# via markdown-it-py
orjson==3.9.7
# via -r requirements/../../../packages/models-library/requirements/_base.in
packaging==23.1
# via
# docker
Expand Down
8 changes: 7 additions & 1 deletion packages/service-library/requirements/_aiohttp.txt
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,11 @@ attrs==23.1.0
# jsonschema
# referencing
certifi==2023.7.22
# via requests
# via
# -c requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/./../../../requirements/constraints.txt
# requests
charset-normalizer==3.2.0
# via
# aiohttp
Expand Down Expand Up @@ -95,6 +99,8 @@ openapi-schema-validator==0.6.0
# openapi-spec-validator
openapi-spec-validator==0.6.0
# via openapi-core
orjson==3.9.7
# via -r requirements/./../../../packages/models-library/requirements/_base.in
parse==1.19.1
# via openapi-core
pathable==0.4.3
Expand Down
2 changes: 2 additions & 0 deletions packages/service-library/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,8 @@ multidict==6.0.4
# via
# aiohttp
# yarl
orjson==3.9.7
# via -r requirements/../../../packages/models-library/requirements/_base.in
pamqp==3.2.1
# via aiormq
pydantic==1.10.12
Expand Down
5 changes: 5 additions & 0 deletions packages/service-library/requirements/_fastapi.txt
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@ attrs==23.1.0
# referencing
certifi==2023.7.22
# via
# -c requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/./../../../requirements/constraints.txt
# httpcore
# httpx
click==8.1.6
Expand Down Expand Up @@ -61,6 +64,8 @@ markdown-it-py==3.0.0
# via rich
mdurl==0.1.2
# via markdown-it-py
orjson==3.9.7
# via -r requirements/./../../../packages/models-library/requirements/_base.in
pydantic==1.10.12
# via
# -c requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
Expand Down
1 change: 1 addition & 0 deletions packages/service-library/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ attrs==23.1.0
# referencing
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# -c requirements/_aiohttp.txt
# -c requirements/_fastapi.txt
# requests
Expand Down
4 changes: 4 additions & 0 deletions packages/simcore-sdk/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,10 @@ multidict==6.0.4
# via
# aiohttp
# yarl
orjson==3.9.7
# via
# -r requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/_base.in
packaging==23.1
# via -r requirements/_base.in
pamqp==3.2.1
Expand Down
1 change: 1 addition & 0 deletions packages/simcore-sdk/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,7 @@ botocore==1.24.21
# s3transfer
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# minio
# requests
cffi==1.15.1
Expand Down
3 changes: 2 additions & 1 deletion requirements/constraints.txt
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,8 @@
# Vulnerabilities -----------------------------------------------------------------------------------------
#
aiohttp>=3.7.4 # https://github.com/advisories/GHSA-v6wp-4m6f-gcjg
cryptography>=39.0.1 # https://github.com/advisories/GHSA-x4qr-2fvf-3mr5 Mar.2023
certifi>=2023.7.22 # https://github.com/advisories/GHSA-xqr8-7jwr-rhp7
cryptography>=41.0.2 # https://github.com/advisories/GHSA-cf7p-gm2m-833m
httpx>=0.23.0 # https://github.com/advisories/GHSA-h8pj-cxx2-jfg2 / CVE-2021-41945
jinja2>=2.11.3 # https://github.com/advisories/GHSA-g3rq-g295-4j3m
mako>=1.2.2 # https://github.com/advisories/GHSA-v973-fxgf-6xhp
Expand Down
6 changes: 6 additions & 0 deletions services/agent/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,10 @@ multidict==6.0.2
# via
# aiohttp
# yarl
orjson==3.9.7
# via
# -r requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/_base.in
packaging==23.1
# via -r requirements/_base.in
pamqp==3.2.1
Expand Down Expand Up @@ -150,6 +154,8 @@ starlette==0.27.0
# fastapi
tenacity==8.1.0
# via -r requirements/../../../packages/service-library/requirements/_base.in
toolz==0.12.0
# via -r requirements/../../../packages/service-library/requirements/_base.in
tqdm==4.64.1
# via -r requirements/../../../packages/service-library/requirements/_base.in
typer==0.6.1
Expand Down
1 change: 1 addition & 0 deletions services/agent/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ botocore==1.24.21
# s3transfer
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# httpcore
# httpx
# requests
Expand Down
43 changes: 24 additions & 19 deletions services/api-server/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -6,24 +6,7 @@
#
aio-pika==9.1.2
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./_base.in
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../requirements/constraints.txt
# -c requirements/../../../requirements/constraints.txt
# -r requirements/../../../packages/service-library/requirements/_base.in
# -r requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/_base.in
aiocache==0.12.1
Expand Down Expand Up @@ -104,8 +87,25 @@ attrs==21.4.0
# via
# aiohttp
# jsonschema
certifi==2023.5.7
certifi==2023.7.22
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/simcore-sdk/requirements/../../../requirements/constraints.txt
# -c requirements/../../../requirements/constraints.txt
# httpcore
# httpx
cffi==1.15.1
Expand All @@ -116,7 +116,7 @@ click==8.1.3
# via
# typer
# uvicorn
cryptography==41.0.1
cryptography==41.0.3
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
Expand Down Expand Up @@ -274,6 +274,11 @@ multidict==6.0.4
# yarl
orjson==3.9.1
# via
# -r requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/simcore-sdk/requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/_base.in
# fastapi
packaging==23.1
Expand Down
5 changes: 3 additions & 2 deletions services/api-server/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -57,8 +57,9 @@ botocore==1.31.26
# s3transfer
botocore-stubs==1.31.23
# via boto3-stubs
certifi==2023.5.7
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# -c requirements/_base.txt
# httpcore
# httpx
Expand All @@ -83,7 +84,7 @@ click==8.1.3
# flask
coverage==7.3.0
# via pytest-cov
cryptography==41.0.1
cryptography==41.0.3
# via
# -c requirements/../../../requirements/constraints.txt
# -c requirements/_base.txt
Expand Down
20 changes: 19 additions & 1 deletion services/autoscaling/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -72,8 +72,17 @@ botocore==1.27.59
# s3transfer
botocore-stubs==1.29.78
# via types-aiobotocore
certifi==2022.12.7
certifi==2023.7.22
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../requirements/constraints.txt
# httpcore
# httpx
charset-normalizer==3.0.1
Expand Down Expand Up @@ -144,6 +153,11 @@ multidict==6.0.4
# via
# aiohttp
# yarl
orjson==3.9.7
# via
# -r requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/_base.in
packaging==23.0
# via -r requirements/_base.in
pamqp==3.2.1
Expand Down Expand Up @@ -238,6 +252,10 @@ tenacity==8.2.1
# via
# -c requirements/../../../packages/service-library/requirements/./_base.in
# -r requirements/../../../packages/service-library/requirements/_base.in
toolz==0.12.0
# via
# -c requirements/../../../packages/service-library/requirements/./_base.in
# -r requirements/../../../packages/service-library/requirements/_base.in
tqdm==4.64.1
# via
# -c requirements/../../../packages/service-library/requirements/./_base.in
Expand Down
3 changes: 2 additions & 1 deletion services/autoscaling/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -38,8 +38,9 @@ botocore==1.27.59
# boto3
# moto
# s3transfer
certifi==2022.12.7
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# -c requirements/_base.txt
# httpcore
# httpx
Expand Down
22 changes: 20 additions & 2 deletions services/catalog/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -70,8 +70,18 @@ attrs==21.4.0
# via
# aiohttp
# jsonschema
certifi==2022.12.7
certifi==2023.7.22
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../requirements/constraints.txt
# httpcore
# httpx
charset-normalizer==2.0.12
Expand Down Expand Up @@ -183,7 +193,11 @@ multidict==6.0.2
# aiohttp
# yarl
orjson==3.7.2
# via fastapi
# via
# -r requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/_base.in
# -r requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/_base.in
# fastapi
packaging==23.1
# via -r requirements/_base.in
pamqp==3.2.1
Expand Down Expand Up @@ -306,6 +320,10 @@ tenacity==8.0.1
# -c requirements/../../../packages/service-library/requirements/./_base.in
# -r requirements/../../../packages/service-library/requirements/_base.in
# -r requirements/_base.in
toolz==0.12.0
# via
# -c requirements/../../../packages/service-library/requirements/./_base.in
# -r requirements/../../../packages/service-library/requirements/_base.in
tqdm==4.64.0
# via
# -c requirements/../../../packages/service-library/requirements/./_base.in
Expand Down
3 changes: 2 additions & 1 deletion services/catalog/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -31,8 +31,9 @@ attrs==21.4.0
# aiohttp
# jsonschema
# pytest-docker
certifi==2022.12.7
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# -c requirements/_base.txt
# httpcore
# httpx
Expand Down
9 changes: 9 additions & 0 deletions services/clusters-keeper/requirements/_base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,15 @@ botocore-stubs==1.31.36
# via types-aiobotocore
certifi==2023.7.22
# via
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/models-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
# -c requirements/../../../requirements/constraints.txt
# httpcore
# httpx
charset-normalizer==3.2.0
Expand Down
1 change: 1 addition & 0 deletions services/clusters-keeper/requirements/_test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ botocore==1.31.17
# s3transfer
certifi==2023.7.22
# via
# -c requirements/../../../requirements/constraints.txt
# -c requirements/_base.txt
# httpcore
# httpx
Expand Down
Loading

0 comments on commit ab5fa9a

Please sign in to comment.