-
Notifications
You must be signed in to change notification settings - Fork 614
Planned fix for security vulnerability for setuptools-65.5.0 lib #809
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,68 @@ | ||
| #!/bin/bash | ||
|
|
||
| set -e | ||
|
|
||
| # Optional: Import test library | ||
| source dev-container-features-test-lib | ||
|
|
||
| #check "setuptools version 65.5.0 not installed" bash -c "ls -lrt /usr/local/py-utils/shared/lib/python3.11/site-packages/setuptools-65.5.0.dist-info" | ||
| #checkPythonPackageVersion "setuptools" "65.5.1" | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can you add this check?
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Done. |
||
|
|
||
| # Check that tools can execute - make sure something didn't get messed up in this scenario | ||
| check "autopep8" autopep8 --version | ||
| check "black" black --version | ||
| check "yapf" yapf --version | ||
| check "bandit" bandit --version | ||
| check "flake8" flake8 --version | ||
| check "mypy" mypy --version | ||
| check "pycodestyle" pycodestyle --version | ||
| check "pydocstyle" pydocstyle --version | ||
| check "pylint" pylint --version | ||
| check "pytest" pytest --version | ||
| check "setuptools" pip list | grep setuptools | ||
|
|
||
| # Check paths in settings | ||
| check "current symlink is correct" bash -c "which python | grep /usr/local/python/current/bin/python" | ||
| check "current symlink works" /usr/local/python/current/bin/python --version | ||
| check "which autopep8" bash -c "which autopep8 | grep /usr/local/py-utils/bin/autopep8" | ||
| check "which black" bash -c "which black | grep /usr/local/py-utils/bin/black" | ||
| check "which yapf" bash -c "which yapf | grep /usr/local/py-utils/bin/yapf" | ||
| check "which bandit" bash -c "which bandit | grep /usr/local/py-utils/bin/bandit" | ||
| check "which flake8" bash -c "which flake8 | grep /usr/local/py-utils/bin/flake8" | ||
| check "which mypy" bash -c "which mypy | grep /usr/local/py-utils/bin/mypy" | ||
| check "which pycodestyle" bash -c "which pycodestyle | grep /usr/local/py-utils/bin/pycodestyle" | ||
| check "which pydocstyle" bash -c "which pydocstyle | grep /usr/local/py-utils/bin/pydocstyle" | ||
| check "which pylint" bash -c "which pylint | grep /usr/local/py-utils/bin/pylint" | ||
| check "which pytest" bash -c "which pytest | grep /usr/local/py-utils/bin/pytest" | ||
|
|
||
| echoStderr() | ||
| { | ||
| echo "$@" 1>&2 | ||
| } | ||
|
|
||
| checkVulnerableDir() | ||
| { | ||
| DIRECTORY=$1 | ||
| VERSION=$2 | ||
|
|
||
| if [ "${VERSION}" == "3.10" ] && [ -d $DIRECTORY ] ; then | ||
| echoStderr "❌ check for vulnerable setuptools version failed for python3.10." | ||
| return 1 | ||
| elif [ "${VERSION}" == "3.11" ] && [ -d $DIRECTORY ]; then | ||
| echoStderr "❌ check for vulnerable setuptools version failed for python3.11." | ||
| return 1 | ||
| else | ||
| echo "✅ Passed! Either the container does not have vulnerable version or vulnerable version specific directory got removed." | ||
| return 0 | ||
| fi | ||
| } | ||
|
|
||
| # only for 3.10 | ||
| checkVulnerableDir "/usr/local/py-utils/shared/lib/python3.10/site-packages/setuptools-65.5.0.dist-info" "3.10" | ||
| checkVulnerableDir "/usr/local/python/3.10.13/lib/python3.10/site-packages/setuptools-65.5.0.dist-info" "3.10" | ||
| # only for 3.11 | ||
| checkVulnerableDir "/usr/local/py-utils/shared/lib/python3.11/site-packages/setuptools-65.5.0.dist-info" "3.11" | ||
| checkVulnerableDir "/usr/local/python/3.11.7/lib/python3.11/site-packages/setuptools-65.5.0.dist-info" "3.11" | ||
|
|
||
| # Report result | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can you also add the following command? this way we can see the status of the files.
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Done |
||
| reportResults | ||
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -1,4 +1,13 @@ | ||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||
| "install_python_setuptools_vulnerability": { | ||||||||||||||||||||||||||
| "image": "debian:bookworm", | ||||||||||||||||||||||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Once you address previous comment, can you also add a new test scenario with image
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Done in PR # 815 |
||||||||||||||||||||||||||
| "features": { | ||||||||||||||||||||||||||
| "python": { | ||||||||||||||||||||||||||
| "version": "3.10", | ||||||||||||||||||||||||||
| "installTools": true | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
|
Comment on lines
+3
to
+8
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
Can we update the scenario to reflect the python image build?
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. These are the points that I wanted to discuss with you. The moment we move to version as "none" the code in install.sh will not work.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Can you help specify the code are you referring at? Can you paste some links?
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. |
||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||
| "install_additional_python": { | ||||||||||||||||||||||||||
| "image": "ubuntu:focal", | ||||||||||||||||||||||||||
| "features": { | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you remove this comment?
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I will remove that but I would like to highlight that sometime another directory will get created for setuptools-65.5.0 do so you want us to remove that or not?
The other option is to the check the version for dynamically which I can further look into that.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do you have a scenario or reproduction for this? Are you aware of the drawbacks of removing that directory?
We shouldn't add code or comments if it's not 💯 needed. However, if the scanners complain about it, then we can definitely add it back.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have implemented a way to dynamically fetch the python version so now no issue.