Skip to content

chore: upgrade test dependencies on urllib3 & pillow#17985

Merged
mergify[bot] merged 4 commits intomasterfrom
rmuller/urllib3
Dec 14, 2021
Merged

chore: upgrade test dependencies on urllib3 & pillow#17985
mergify[bot] merged 4 commits intomasterfrom
rmuller/urllib3

Conversation

@RomainMuller
Copy link
Copy Markdown
Contributor

The current pinned versions of urllib3 and Pillow have known security
vulnerabilities. Upgrading those to fixed versions to remove the
security advisory alerts against the repository.


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license

@RomainMuller RomainMuller requested a review from a team December 13, 2021 10:55
@RomainMuller RomainMuller self-assigned this Dec 13, 2021
@gitpod-io
Copy link
Copy Markdown

gitpod-io bot commented Dec 13, 2021

@mergify mergify bot added the contribution/core This is a PR that came from AWS. label Dec 13, 2021
Copy link
Copy Markdown
Contributor

@njlynch njlynch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks as though we may need to update requests as well?

@aws-cdk/aws-lambda-python: INFO: pip is looking at multiple versions of urllib3 to determine which version is compatible with other requirements. This could take a while.
@aws-cdk/aws-lambda-python: INFO: pip is looking at multiple versions of <Python from Requires-Python> to determine which version is compatible with other requirements. This could take a while.
@aws-cdk/aws-lambda-python: INFO: pip is looking at multiple versions of idna to determine which version is compatible with other requirements. This could take a while.
@aws-cdk/aws-lambda-python: INFO: pip is looking at multiple versions of chardet to determine which version is compatible with other requirements. This could take a while.
@aws-cdk/aws-lambda-python: INFO: pip is looking at multiple versions of certifi to determine which version is compatible with other requirements. This could take a while.
@aws-cdk/aws-lambda-python: �[91mERROR: Cannot install -r requirements.txt (line 7) and urllib3==1.26.7 because these package versions have conflicting dependencies.
@aws-cdk/aws-lambda-python: �[0m
@aws-cdk/aws-lambda-python: The conflict is caused by:
@aws-cdk/aws-lambda-python:     The user requested urllib3==1.26.7
@aws-cdk/aws-lambda-python:     requests 2.23.0 depends on urllib3!=1.25.0, !=1.25.1, <1.26 and >=1.21.1

The current pinned versions of urllib3 and Pillow have known security
vulnerabilities. Upgrading those to fixed versions to remove the
security advisory alerts against the repository.
@RomainMuller RomainMuller requested a review from njlynch December 14, 2021 15:28
@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Dec 14, 2021

Thank you for contributing! Your pull request will be updated from master and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

@mergify mergify bot merged commit 2d2c109 into master Dec 14, 2021
@aws-cdk-automation
Copy link
Copy Markdown
Collaborator

AWS CodeBuild CI Report

  • CodeBuild project: AutoBuildProject89A8053A-LhjRyN9kxr8o
  • Commit ID: a833dfd
  • Result: SUCCEEDED
  • Build Logs (available for 30 days)

Powered by github-codebuild-logs, available on the AWS Serverless Application Repository

@mergify mergify bot deleted the rmuller/urllib3 branch December 14, 2021 16:16
@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Dec 14, 2021

Thank you for contributing! Your pull request will be updated from master and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

TikiTDO pushed a commit to TikiTDO/aws-cdk that referenced this pull request Feb 21, 2022
The current pinned versions of urllib3 and Pillow have known security
vulnerabilities. Upgrading those to fixed versions to remove the
security advisory alerts against the repository.


----

*By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution/core This is a PR that came from AWS.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants