-
Notifications
You must be signed in to change notification settings - Fork 290
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
py3-setuptools/70.2.0 package update #22941
Conversation
octo-sts
bot
commented
Jul 1, 2024
Signed-off-by: wolfi-bot <[email protected]>
Package py3-setuptools: Click to expand/collapsePackage py3-setuptools: Package py3.10-setuptools: Click to expand/collapsePackage py3.10-setuptools: Package py3.11-setuptools: Click to expand/collapsePackage py3.11-setuptools: Package py3.12-setuptools: Click to expand/collapsePackage py3.12-setuptools: Package py3-supported-setuptools: Click to expand/collapsePackage py3-supported-setuptools: bincapz found differences: Click to expand/collapseDeleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/py39compat.py [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af254 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/py39compat.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af254 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/py39compat.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af254 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | kernel/platform | system platform identification | sys.platform |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | process/name/get | get the current process name | process_name |
+MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/compat/py39.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af254 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | core-metadata-download-url download_url |
+MEDIUM | process/name/get | get the current process name | process_name |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | kernel/platform | system platform identification | sys.platform |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/compat/py39.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af254 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
+LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | core-metadata-download-url download_url |
+MEDIUM | process/name/get | get the current process name | process_name |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | kernel/platform | system platform identification | sys.platform |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
+LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/shell_command | execute a shell command | system |
+LOW | fd/read | reads from a file handle | self.read() |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
+LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
+LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/shell_command | execute a shell command | system |
+LOW | fd/read | reads from a file handle | self.read() |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | process/name/get | get the current process name | process_name |
+MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/shell_command | execute a shell command | system |
+LOW | fd/read | reads from a file handle | self.read() |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/compat/py39.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af2542be208/Lib/sysconfig.py |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/785cc6770588de087d09e89a69110af254 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
+LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
+LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | core-metadata-download-url download_url |
+MEDIUM | process/name/get | get the current process name | process_name |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | process/name/get | get the current process name | process_name |
+MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Changed: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/sandbox.py
Changed: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/sandbox.py
Changed: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/package_index.py
Changed: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/package_index.py
Changed: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/command/bdist_egg.py
Changed: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/build_meta.py
Changed: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/discovery.py
Changed: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/command/easy_install.py
Changed: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/package_index.py
Changed: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/build_meta.py
Changed: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/command/bdist_egg.py
Changed: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/discovery.py
Changed: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/sandbox.py
Changed: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/command/easy_install.py
Changed: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/discovery.py
Changed: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/build_meta.py
Changed: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/command/bdist_egg.py
Changed: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/command/easy_install.py
CRITICAL bincapz score needs investigating |
Approved for security - false positives were fixed in bincapz v0.13.2. |