-
Notifications
You must be signed in to change notification settings - Fork 3.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Older version of setup tool and setuptool dist-info getting flagged by S360 and other scans #25682
Comments
@bebound for awareness |
Per my understanding, |
We use default |
@jiasli |
@bebound I guess that needs to be updated. root [ / ]# find / -name python3.9 This is the location /usr/lib/az/lib/python3.9 where S360 and other scans are flagging for vulnerability and an older version of setup tools exist. Would be happy to go on a quick call as well. |
On Mariner, CLI uses the standard python3.9 with a special |
Sure, thanks for the reply. This is helpful. Any leads on when the next az cli release is planned for? With maybe the fix? |
2.47 will be released on April 4. |
An older version of setup tools is installed in the latest release version of az cli == 2.45.0.
I have noticed that in dev the version is upgraded, but not sure when the release will happen.
### Our deployments are getting flagged. Let us know if there is a way around this before the next release as the setup tools inside the usr/lib/az is getting flagged, so installing an updated version overall is not helping.
The text was updated successfully, but these errors were encountered: