kubeflow / pipelines

Machine Learning Pipelines for Kubeflow
https://www.kubeflow.org/docs/components/pipelines/
Apache License 2.0
3.5k stars 1.57k forks source link

chore(backend): update python from 3.7 to 3.12 #10950

Open juliusvonkohout opened 1 week ago

juliusvonkohout commented 1 week ago

Description of your changes:

Follow up of https://github.com/kubeflow/pipelines/pull/10750 @rimolive @chensun @rickyxie0929 @connor-mccarthy

@rickyxie0929 @rimolive this is a fast draft, i can add you to my pipelines for if you want to add changes here.

Checklist:

google-oss-prow[bot] commented 1 week ago

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Once this PR has been reviewed and has the lgtm label, please assign chensun for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files: - **[OWNERS](https://github.com/kubeflow/pipelines/blob/master/OWNERS)** Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
juliusvonkohout commented 1 week ago

We could also go to 3.11 first if that helps.

juliusvonkohout commented 1 week ago

/retest-required

google-oss-prow[bot] commented 1 week ago

@juliusvonkohout: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
kubeflow-pipeline-upgrade-test a6d551a40f783c2b66eea15735a00e91209b50eb link false /test kubeflow-pipeline-upgrade-test
kubeflow-pipelines-samples-v2 a6d551a40f783c2b66eea15735a00e91209b50eb link false /test kubeflow-pipelines-samples-v2
kubeflow-pipelines-components-google-cloud-python38 a6d551a40f783c2b66eea15735a00e91209b50eb link true /test kubeflow-pipelines-components-google-cloud-python38
kubeflow-pipelines-sdk-python310 a6d551a40f783c2b66eea15735a00e91209b50eb link true /test kubeflow-pipelines-sdk-python310
kubeflow-pipelines-sdk-python38 a6d551a40f783c2b66eea15735a00e91209b50eb link true /test kubeflow-pipelines-sdk-python38
kubeflow-pipelines-sdk-python39 a6d551a40f783c2b66eea15735a00e91209b50eb link true /test kubeflow-pipelines-sdk-python39
kubeflow-pipelines-sdk-python311 a6d551a40f783c2b66eea15735a00e91209b50eb link true /test kubeflow-pipelines-sdk-python311
kfp-kubernetes-execution-tests a6d551a40f783c2b66eea15735a00e91209b50eb link false /test kfp-kubernetes-execution-tests
kubeflow-pipelines-sdk-python312 a6d551a40f783c2b66eea15735a00e91209b50eb link true /test kubeflow-pipelines-sdk-python312
Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).
juliusvonkohout commented 6 days ago

CVE Scanning Automatic CVE scanning with Trivy on the master branch is relevant for DevSecOps and enterprise security guidelines https://github.com/kubeflow/manifests/blob/master/.github/workflows/trivy.yaml Here are some numbers from June 25 https://github.com/kubeflow/manifests/actions/runs/9658715319/job/26640495132 I need someone independent to verify the script and numbers.

Working Group Images Critical CVE High CVE Medium CVE Low CVE
AutoML 13 15 231 547 756
Pipelines 45 204 1909 7342 3236
Workbenches(Notebooks) 12 26 222 315 230
Kserve 13 43 522 1986 1418
Manifests 18 19 18 174 78
Training 1 1 1 1 0
Model Registry 3 18 71 104 147
All Images 105 326 2974 10469 5865