Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Cherry-Pick] Python vulnerability fixes (#3441) #235

Merged

Conversation

spolti
Copy link
Member

@spolti spolti commented Feb 26, 2024

sync security fixes from upstream

Cherry picks: 338e364 and 0d311b3

* Bump paddlepaddle to 2.6.0

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Bump transformers to version 4.37.2

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Bump cryptography to version 42.0.2

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Bump fastapi to version 0.109.2

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Bump pillow to version 10.2.0

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Bump aiohttp to version 3.9.3

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Revert fastapi bump

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Bump ray serve to 2.9.2

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Pin alibi to >=0.9.4

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

* Fix alibi version

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>

---------

Signed-off-by: Sivanantham Chinnaiyan <sivanantham.chinnaiyan@ideas2it.com>
@spolti spolti requested a review from israel-hdez February 26, 2024 18:21
@openshift-ci openshift-ci bot requested a review from Jooho February 26, 2024 18:22
ValueError: `detached=False` is no longer supported. In a future release, it will be removed altogether.

Signed-off-by: Spolti <fspolti@redhat.com>
@spolti spolti force-pushed the RHOAIENG-3381 branch 3 times, most recently from 099366c to 05199e7 Compare February 26, 2024 19:02
spolti and others added 3 commits February 26, 2024 16:34
Signed-off-by: Spolti <fspolti@redhat.com>
* Allow ray 2.6.1

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* PR suggestion

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Run poetry update --lock

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Support RayServeSyncHandle in ray>=2.5.0

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Run poetry update --lock

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Correct hashFiles cache for sklearn

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Run poetry update --lock

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Avoid faulty tritonclient release

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Run poetry update --lock

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Add and run make poetry-update-lockfiles

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Refrain from private imports and make poetry-update-lockfiles

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Revert paddle to max 3.10

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

* Revert "Revert paddle to max 3.10"

This reverts commit a5afe2b.

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>

---------

Signed-off-by: ddelange <14880945+ddelange@users.noreply.github.com>
Signed-off-by: Spolti <fspolti@redhat.com>
@spolti spolti requested a review from terrytangyuan February 27, 2024 13:55
@spolti spolti changed the title Python vulnerability fixes (#3441) [Cherry-Pick] Python vulnerability fixes (#3441) Feb 27, 2024
Copy link
Member

@terrytangyuan terrytangyuan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Copy link

openshift-ci bot commented Feb 27, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: spolti, terrytangyuan

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:
  • OWNERS [spolti,terrytangyuan]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot openshift-merge-bot bot merged commit 298fe40 into opendatahub-io:release-v0.11.1 Feb 27, 2024
20 checks passed
@spolti spolti deleted the RHOAIENG-3381 branch February 27, 2024 15:17
spolti referenced this pull request in spolti/kserve Apr 17, 2024
…dates/kserve-agent-29

Update kserve-agent-29 to 21201ea
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

4 participants