Skip to content

Update lock files and ImageStream dependency annotations#244

Merged
mtchoum1 merged 1 commit into
mainfrom
lockfile-update-20260722-0415
Jul 23, 2026
Merged

Update lock files and ImageStream dependency annotations#244
mtchoum1 merged 1 commit into
mainfrom
lockfile-update-20260722-0415

Update lock files and ImageStream dependency annotations

de8c783
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Jul 22, 2026 in 5s

15 new alerts including 14 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 14 high
  • 1 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 1 in runtimes/pytorch/ubi9-python-3.12/uv.lock.d/pylock.cuda.toml

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/pytorch/ubi9-python-3.12/uv.lock.d/pylock.cuda.toml

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 71 in runtimes/rocm-pytorch/ubi9-python-3.12/requirements.rocm.txt

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 313 in runtimes/rocm-pytorch/ubi9-python-3.12/requirements.rocm.txt

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/rocm-pytorch/ubi9-python-3.12/uv.lock.d/pylock.rocm.toml

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/rocm-pytorch/ubi9-python-3.12/uv.lock.d/pylock.rocm.toml

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 73 in runtimes/rocm-tensorflow/ubi9-python-3.12/requirements.rocm.txt

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 331 in runtimes/rocm-tensorflow/ubi9-python-3.12/requirements.rocm.txt

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/rocm-tensorflow/ubi9-python-3.12/uv.lock.d/pylock.rocm.toml

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/rocm-tensorflow/ubi9-python-3.12/uv.lock.d/pylock.rocm.toml

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 80 in runtimes/tensorflow/ubi9-python-3.12/requirements.cuda.txt

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 362 in runtimes/tensorflow/ubi9-python-3.12/requirements.cuda.txt

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/tensorflow/ubi9-python-3.12/uv.lock.d/pylock.cuda.toml

See this annotation in the file changed.

Code scanning / Trivy

python: protobuf: Protobuf: Denial of Service due to recursion depth bypass High library

Package: protobuf
Installed Version: 6.31.1
Vulnerability CVE-2026-0994
Severity: HIGH
Fixed Version: 6.33.5, 5.29.6
Link: CVE-2026-0994

Check failure on line 1 in runtimes/tensorflow/ubi9-python-3.12/uv.lock.d/pylock.cuda.toml

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High library

Package: cryptography
Installed Version: 46.0.7
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check warning on line 1 in runtimes/pytorch/ubi9-python-3.12/uv.lock.d/pylock.cuda.toml

See this annotation in the file changed.

Code scanning / Trivy

setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) Medium library

Package: setuptools
Installed Version: 81.0.0
Vulnerability CVE-2026-59890
Severity: MEDIUM
Fixed Version: 83.0.0
Link: CVE-2026-59890