Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions src/python/install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -454,6 +454,18 @@ if [[ "${INSTALL_PYTHON_TOOLS}" = "true" ]] && [[ $(python --version) != "" ]];
echo "${util} already installed. Skipping."
fi
done

# Temporary: Removes “setup tools” metadata directory due to https://github.com/advisories/GHSA-r9hx-vwmv-q579

VULNERABLE_VERSIONS=("3.10" "3.11")

for vv in "${VULNERABLE_VERSIONS[@]}"; do

if [ "${PYTHON_VERSION}" == "${vv}" ]; then
rm -rf ${PIPX_HOME}/shared/lib/"python${vv}"/site-packages/setuptools-65.5.0.dist-info
fi
done

rm -rf /tmp/pip-tmp

updaterc "export PIPX_HOME=\"${PIPX_HOME}\""
Expand Down
68 changes: 68 additions & 0 deletions test/python/install_python_setuptools_vulnerability.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
#!/bin/bash

set -e

# Optional: Import test library
source dev-container-features-test-lib

#check "setuptools version 65.5.0 not installed" bash -c "ls -lrt /usr/local/py-utils/shared/lib/python3.11/site-packages/setuptools-65.5.0.dist-info"
#checkPythonPackageVersion "setuptools" "65.5.1"

# Check that tools can execute - make sure something didn't get messed up in this scenario
check "autopep8" autopep8 --version
check "black" black --version
check "yapf" yapf --version
check "bandit" bandit --version
check "flake8" flake8 --version
check "mypy" mypy --version
check "pycodestyle" pycodestyle --version
check "pydocstyle" pydocstyle --version
check "pylint" pylint --version
check "pytest" pytest --version
check "setuptools" pip list | grep setuptools

# Check paths in settings
check "current symlink is correct" bash -c "which python | grep /usr/local/python/current/bin/python"
check "current symlink works" /usr/local/python/current/bin/python --version
check "which autopep8" bash -c "which autopep8 | grep /usr/local/py-utils/bin/autopep8"
check "which black" bash -c "which black | grep /usr/local/py-utils/bin/black"
check "which yapf" bash -c "which yapf | grep /usr/local/py-utils/bin/yapf"
check "which bandit" bash -c "which bandit | grep /usr/local/py-utils/bin/bandit"
check "which flake8" bash -c "which flake8 | grep /usr/local/py-utils/bin/flake8"
check "which mypy" bash -c "which mypy | grep /usr/local/py-utils/bin/mypy"
check "which pycodestyle" bash -c "which pycodestyle | grep /usr/local/py-utils/bin/pycodestyle"
check "which pydocstyle" bash -c "which pydocstyle | grep /usr/local/py-utils/bin/pydocstyle"
check "which pylint" bash -c "which pylint | grep /usr/local/py-utils/bin/pylint"
check "which pytest" bash -c "which pytest | grep /usr/local/py-utils/bin/pytest"

echoStderr()
{
echo "$@" 1>&2
}

checkVulnerableDir()
{
DIRECTORY=$1
VERSION=$2

if [ "${VERSION}" == "3.10" ] && [ -d $DIRECTORY ] ; then
echoStderr "❌ check for vulnerable setuptools version failed for python3.10."
return 1
elif [ "${VERSION}" == "3.11" ] && [ -d $DIRECTORY ]; then
echoStderr "❌ check for vulnerable setuptools version failed for python3.11."
return 1
else
echo "✅ Passed! Either the container does not have vulnerable version or vulnerable version specific directory got removed."
return 0
fi
}

# only for 3.10
checkVulnerableDir "/usr/local/py-utils/shared/lib/python3.10/site-packages/setuptools-65.5.0.dist-info" "3.10"
checkVulnerableDir "/usr/local/python/3.10.13/lib/python3.10/site-packages/setuptools-65.5.0.dist-info" "3.10"
# only for 3.11
checkVulnerableDir "/usr/local/py-utils/shared/lib/python3.11/site-packages/setuptools-65.5.0.dist-info" "3.11"
checkVulnerableDir "/usr/local/python/3.11.7/lib/python3.11/site-packages/setuptools-65.5.0.dist-info" "3.11"

# Report result
reportResults
9 changes: 9 additions & 0 deletions test/python/scenarios.json
Original file line number Diff line number Diff line change
@@ -1,4 +1,13 @@
{
"install_python_setuptools_vulnerability": {
"image": "debian:bookworm",
"features": {
"python": {
"version": "3.10",
"installTools": true
}
}
},
Comment on lines +2 to +10

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Feel free to add this scenario and test file to #809.
It would be great to validate if we are breaking any other scenarios.

"install_additional_python": {
"image": "ubuntu:focal",
"features": {
Expand Down