[anaconda]-Fix for vulnerability issue CVE-2024-52338 and CVE-2025-6176 #1742
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Devcontainer Image
Anaconda
Description of changes
This PR fixes the vulnerabilities mentioned here CVE-2024-52338 and CVE-2025-6176
Fixing vulnerable packages pyarrow and brotli
Changelog :
Updated tests to have pyarrow and brotli packages are in the required fixed versions.
For protobuf package the pinned version 5.29.5 is incompatible with other existing packages in base anaconda image ref. So removed it from the pinned versions, now the latest version is 6.33.0
Version bump.
Checklist:
Checked that applied changes work as expected