opendatadiscovery / odd-collectors

Apache License 2.0
8 stars 9 forks source link

Issue regarding the high CVE Score for the associated packages in the ODD collector Image #58

Closed mavenzer closed 4 months ago

mavenzer commented 5 months ago

So we are trying to pull the ODD collector image with the tag 0.1.54, But it has couple of critical CVEs in the image. I'm listing all the critical CVE's and associated security implications.

mlflow:2.7.1

PyArrow:

ValeriyWorld commented 5 months ago

We are currently working on bumping our dependency versions for collector. But due to complex cross-dependencies we are forced to do it in multiple packages, so we need some time to do it properly.

mavenzer commented 5 months ago

Understood your points @ValeriyWorld

ValeriyWorld commented 4 months ago

@mavenzer We bumped dependency versions with this PR so I close this issue. Also we bumped our odd-models package and oddrn-generator as odd-collector depends on them.