Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Commit da3609c

Browse files
authored
feat(kubeflow-pipelines-visualization-server): pending upstream fix GHSA-h95x-26f3-88hr (#8661)
Marking as pending upstream fix: > There is not currently a fixed version of the js2py package. So, the upstream project must migrate away from using js2py or wait for js2py to release a fixed version (and upgrade to it). Upstream PR @ PiotrDabkowski/Js2Py#323 which is yet to be merged. This follows on from the same advisory filed for apache-beam-python-3.11-sdk @ chainguard-dev/enterprise-advisories#5130 Signed-off-by: philroche <phil.roche@chainguard.dev>
1 parent 85f83fe commit da3609c

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

kubeflow-pipelines-visualization-server.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -572,6 +572,10 @@ advisories:
572572
componentType: python
573573
componentLocation: /usr/lib/python3.10/site-packages/Js2Py-0.74.dist-info/METADATA, /usr/lib/python3.10/site-packages/Js2Py-0.74.dist-info/RECORD, /usr/lib/python3.10/site-packages/Js2Py-0.74.dist-info/top_level.txt
574574
scanner: grype
575+
- timestamp: 2024-10-14T15:09:26Z
576+
type: pending-upstream-fix
577+
data:
578+
note: There is not currently a fixed version of the js2py package. So, the upstream project must migrate away from using js2py or wait for js2py to release a fixed version (and upgrade to it). Upstream PR @ https://github.com/PiotrDabkowski/Js2Py/pull/323 which is yet to be merged.
575579

576580
- id: CGA-r33j-gmf8-rqgp
577581
aliases:

0 commit comments

Comments
 (0)