Skip to content

Conversation

peterzdeb
Copy link
Contributor

@peterzdeb peterzdeb commented Jul 3, 2025

This repository is public. Do not put here any private DataRobot or customer's data: code, datasets, model artifacts, .etc.

Summary

Pillow dependency for DRUM is unpinned but we have the pin in execution environments.
For CVE-2025-48379 we have to use Pillow version 11.3.0

Also I bumped version of requests to solve CVE-2024-47081 and urllib3 for CVE-2025-50181 and CVE-2025-50182 .

Rationale

All that CVEs are affecting release 11.1

peterzdeb and others added 2 commits July 3, 2025 15:20
…][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE
@peterzdeb peterzdeb changed the title [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE [VUL-14360][VUL-9146][VUL-11518][VUL-11519] Fixing CVE-2025-48379, CVE-2024-47081, CVE-2025-50181 and CVE-2025-50182 Jul 3, 2025
@devexp-slackbot
Copy link

The Needs Review labels were added based on the following file changes.

Team @datarobot/buzok (#buzok) was assigned because of changes in files:

public_dropin_environments/python311_genai_agents/requirements.txt

Team @datarobot/core-modeling (#predictive-ai) was assigned because of changes in files:

public_dropin_environments/python3_keras/env_info.json
public_dropin_environments/python3_keras/requirements.txt
public_dropin_environments/python3_pmml/env_info.json
public_dropin_environments/python3_pmml/requirements.txt
public_dropin_environments/python3_pytorch/env_info.json
public_dropin_environments/python3_pytorch/requirements.txt
public_dropin_environments/python3_sklearn/env_info.json
public_dropin_environments/python3_sklearn/requirements.txt
public_dropin_environments/python3_xgboost/env_info.json
public_dropin_environments/python3_xgboost/requirements.txt
public_dropin_environments/r_lang/env_info.json
public_dropin_environments/r_lang/requirements.txt

Team @datarobot/genai-systems (#genai-systems) was assigned because of changes in files:

public_dropin_environments/java_codegen/env_info.json
public_dropin_environments/java_codegen/requirements.txt
public_dropin_environments/python311/env_info.json
public_dropin_environments/python311/requirements.txt
public_dropin_environments/python3_keras/env_info.json
public_dropin_environments/python3_keras/requirements.txt
public_dropin_environments/python3_onnx/env_info.json
public_dropin_environments/python3_onnx/requirements.txt
public_dropin_environments/python3_pmml/env_info.json
public_dropin_environments/python3_pmml/requirements.txt
public_dropin_environments/python3_pytorch/env_info.json
public_dropin_environments/python3_pytorch/requirements.txt
public_dropin_environments/python3_sklearn/env_info.json
public_dropin_environments/python3_sklearn/requirements.txt
public_dropin_environments/python3_xgboost/env_info.json
public_dropin_environments/python3_xgboost/requirements.txt
public_dropin_environments/r_lang/env_info.json
public_dropin_environments/r_lang/requirements.txt

If you think that there are some issues with ownership, please discuss with C&A domain at #sdtk slack channel and create PR to update DRCODEOWNERS\CODEOWNERS file.

Copy link
Contributor

@akshoop akshoop left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@engprod-2
Copy link

engprod-2 bot commented Jul 3, 2025

Label Needs Review: Core Modeling was removed because @eric-s-s is part of Predictive AI domain.

@klichukb klichukb merged commit ca4bce2 into master Jul 3, 2025
39 checks passed
@svc-engprod-git1 svc-engprod-git1 deleted the peterzdeb/VUL-14360-raptor branch July 3, 2025 14:01
@klichukb klichukb restored the peterzdeb/VUL-14360-raptor branch July 3, 2025 14:01
@klichukb
Copy link
Collaborator

klichukb commented Jul 3, 2025

jarvis please cherry-pick this release/11.1

peterzdeb added a commit that referenced this pull request Jul 3, 2025
…E-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555)

* [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE

* Reconcile dependencies, updated IDs, tags

* [RAPTOR-13877] Bumped up a version of urllib3 for CVE

* [RAPTOR-13875] Bumped up a version of urllib3 for CVE

* [RAPTOR-13873] Bumped up a version of urllib3 for CVE

* [RAPTOR-13871] Bumped up a version of urllib3 for CVE

* [RAPTOR-13868] Bumped up a version of urllib3 for CVE

* [RAPTOR-13866] Bumped up a version of urllib3 for CVE

* [RAPTOR-13864] Bumped up a version of urllib3 for CVE

* [RAPTOR-13862] Bumped up a version of urllib3 for CVE

* [RAPTOR-13879] Bumped up a version of urllib3 for CVE

* [BUZZOK-26501] Bumped up a version of urllib3 for CVE

* [RAPTOR-12952] Bumped up a version of requests for CVE

* [RAPTOR-12949] Bumped up a version of requests for CVE

* [RAPTOR-12947] Bumped up a version of requests for CVE

* [RAPTOR-12945] Bumped up a version of requests for CVE

* [RAPTOR-12942] Bumped up a version of requests for CVE

* [RAPTOR-12940] Bumped up a version of requests for CVE

* [RAPTOR-12938] Bumped up a version of requests for CVE

* [RAPTOR-12936] Bumped up a version of requests for CVE

* [RAPTOR-12933] Bumped up a version of requests for CVE

* Reconcile dependencies, updated IDs, tags

---------

Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>
peterzdeb added a commit that referenced this pull request Jul 3, 2025
…E-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555)

* [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE

* Reconcile dependencies, updated IDs, tags

* [RAPTOR-13877] Bumped up a version of urllib3 for CVE

* [RAPTOR-13875] Bumped up a version of urllib3 for CVE

* [RAPTOR-13873] Bumped up a version of urllib3 for CVE

* [RAPTOR-13871] Bumped up a version of urllib3 for CVE

* [RAPTOR-13868] Bumped up a version of urllib3 for CVE

* [RAPTOR-13866] Bumped up a version of urllib3 for CVE

* [RAPTOR-13864] Bumped up a version of urllib3 for CVE

* [RAPTOR-13862] Bumped up a version of urllib3 for CVE

* [RAPTOR-13879] Bumped up a version of urllib3 for CVE

* [BUZZOK-26501] Bumped up a version of urllib3 for CVE

* [RAPTOR-12952] Bumped up a version of requests for CVE

* [RAPTOR-12949] Bumped up a version of requests for CVE

* [RAPTOR-12947] Bumped up a version of requests for CVE

* [RAPTOR-12945] Bumped up a version of requests for CVE

* [RAPTOR-12942] Bumped up a version of requests for CVE

* [RAPTOR-12940] Bumped up a version of requests for CVE

* [RAPTOR-12938] Bumped up a version of requests for CVE

* [RAPTOR-12936] Bumped up a version of requests for CVE

* [RAPTOR-12933] Bumped up a version of requests for CVE

* Reconcile dependencies, updated IDs, tags

---------

Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>
annaaliieva pushed a commit that referenced this pull request Jul 3, 2025
…19] Fixing CVE-2025-48379, CVE-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555) (#1556)

* [VUL-14360][VUL-9146][VUL-11518][VUL-11519] Fixing CVE-2025-48379, CVE-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555)

* [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE

* Reconcile dependencies, updated IDs, tags

* [RAPTOR-13877] Bumped up a version of urllib3 for CVE

* [RAPTOR-13875] Bumped up a version of urllib3 for CVE

* [RAPTOR-13873] Bumped up a version of urllib3 for CVE

* [RAPTOR-13871] Bumped up a version of urllib3 for CVE

* [RAPTOR-13868] Bumped up a version of urllib3 for CVE

* [RAPTOR-13866] Bumped up a version of urllib3 for CVE

* [RAPTOR-13864] Bumped up a version of urllib3 for CVE

* [RAPTOR-13862] Bumped up a version of urllib3 for CVE

* [RAPTOR-13879] Bumped up a version of urllib3 for CVE

* [BUZZOK-26501] Bumped up a version of urllib3 for CVE

* [RAPTOR-12952] Bumped up a version of requests for CVE

* [RAPTOR-12949] Bumped up a version of requests for CVE

* [RAPTOR-12947] Bumped up a version of requests for CVE

* [RAPTOR-12945] Bumped up a version of requests for CVE

* [RAPTOR-12942] Bumped up a version of requests for CVE

* [RAPTOR-12940] Bumped up a version of requests for CVE

* [RAPTOR-12938] Bumped up a version of requests for CVE

* [RAPTOR-12936] Bumped up a version of requests for CVE

* [RAPTOR-12933] Bumped up a version of requests for CVE

* Reconcile dependencies, updated IDs, tags

---------

Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>

* Reconcile dependencies, updated IDs, tags

---------

Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants