-
Notifications
You must be signed in to change notification settings - Fork 369
py3-setuptools/74.0.0 package update #27198
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package py3-supported-setuptools: Click to expand/collapsePackage py3-supported-setuptools: Package py3-setuptools: Click to expand/collapsePackage py3-setuptools: Package py3.10-setuptools: Click to expand/collapsePackage py3.10-setuptools: Package py3.11-setuptools: Click to expand/collapsePackage py3.11-setuptools: Package py3.12-setuptools: Click to expand/collapsePackage py3.12-setuptools: bincapz found differences: Click to expand/collapseDeleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/tests/test_msvc9compiler.py [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | fd/write | writes to a file handle | f.write(_MANIFEST_WITH_MULTIPLE_REFERENCES) f.write(_MANIFEST_WITH_ONLY_MSVC_REFERENCE) |
-LOW | fs/tempdir/create | creates temporary directory | mkdtemp |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/msvccompiler.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | env/get | Retrieve environment variable values | os.environ['Path'] os.environ['path'] |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/msvccompiler.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | env/get | Retrieve environment variable values | os.environ['Path'] os.environ['path'] |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools-73.0.1.post20240824.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/path/file/url | file url | file:///home |
-LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/tests/test_msvc9compiler.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | fd/write | writes to a file handle | f.write(_MANIFEST_WITH_MULTIPLE_REFERENCES) f.write(_MANIFEST_WITH_ONLY_MSVC_REFERENCE) |
-LOW | fs/tempdir/create | creates temporary directory | mkdtemp |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/command/wininst-10.0.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools-73.0.1.post20240824.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/path/file/url | file url | file:///home |
-LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/command/wininst-9.0.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/command/wininst-10.0.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/command/wininst-10.0-amd64.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/msvc9compiler.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.Popen( |
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | env/get | Retrieve environment variable values | os.environ['Path'] os.environ['include'] os.environ['lib'] os.environ['path'] |
-LOW | fd/read | reads from a file handle | manifest_f.read() |
-LOW | fd/write | writes to a file handle | manifest_f.write(manifest_buf) |
-LOW | fs/tempdir/create | creates temporary directory | temp dir |
-LOW | fs/tempfile/create | Uses mktemp to create temporary files | temp file |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://bugs.python.org/issue7833 https://learn.microsoft.com/en-us/cpp/build/understanding-manifest-genera |
Deleted: py3.12-setuptools/var/lib/db/sbom/py3.12-setuptools-73.0.1-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/282f3899bf6796d6b62a36cfd06f |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/command/wininst-9.0.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.10-setuptools/var/lib/db/sbom/py3.10-setuptools-73.0.1-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/52fa95406fa8cf4cfa2ded5c9647 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/tests/test_msvc9compiler.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | fd/write | writes to a file handle | f.write(_MANIFEST_WITH_MULTIPLE_REFERENCES) f.write(_MANIFEST_WITH_ONLY_MSVC_REFERENCE) |
-LOW | fs/tempdir/create | creates temporary directory | mkdtemp |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/msvc.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.CalledProcessError as exc subprocess.STDOUT, [subprocess.check_output( |
-MEDIUM | net/download | download files | msdownload |
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 https://visualstudio.microsoft.com |
Deleted: py3.11-setuptools/var/lib/db/sbom/py3.11-setuptools-73.0.1-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/d7020a5515afb658e7af8c3cf074 |
Deleted: py3-supported-setuptools/var/lib/db/sbom/py3-supported-setuptools-73.0.1-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/841cce43779f39fef55c907e5d60 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/command/wininst-10.0-amd64.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools-73.0.1.post20240824.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | ref/path/file/url | file url | file:///home |
-LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/tests/test_msvc14.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | system platform identification | sys.platform |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/command/wininst-9.0.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/tests/test_msvc14.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | system platform identification | sys.platform |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/msvc.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.CalledProcessError as exc subprocess.STDOUT, [subprocess.check_output( |
-MEDIUM | net/download | download files | msdownload |
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 https://visualstudio.microsoft.com |
Deleted: py3-setuptools/var/lib/db/sbom/py3-setuptools-73.0.1-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/7658fe423b399b7538e4d8967dc9 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/msvc9compiler.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.Popen( |
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | env/get | Retrieve environment variable values | os.environ['Path'] os.environ['include'] os.environ['lib'] os.environ['path'] |
-LOW | fd/read | reads from a file handle | manifest_f.read() |
-LOW | fd/write | writes to a file handle | manifest_f.write(manifest_buf) |
-LOW | fs/tempdir/create | creates temporary directory | temp dir |
-LOW | fs/tempfile/create | Uses mktemp to create temporary files | temp file |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://bugs.python.org/issue7833 https://learn.microsoft.com/en-us/cpp/build/understanding-manifest-genera |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/msvccompiler.py [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-LOW | env/get | Retrieve environment variable values | os.environ['Path'] os.environ['path'] |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/command/wininst-10.0-amd64.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/msvc9compiler.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.Popen( |
-MEDIUM | kernel/platform | system platform identification | sys.platform |
-LOW | env/get | Retrieve environment variable values | os.environ['Path'] os.environ['include'] os.environ['lib'] os.environ['path'] |
-LOW | fd/read | reads from a file handle | manifest_f.read() |
-LOW | fd/write | writes to a file handle | manifest_f.write(manifest_buf) |
-LOW | fs/tempdir/create | creates temporary directory | temp dir |
-LOW | fs/tempfile/create | Uses mktemp to create temporary files | temp file |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://bugs.python.org/issue7833 https://learn.microsoft.com/en-us/cpp/build/understanding-manifest-genera |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/tests/test_msvc14.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | kernel/platform | system platform identification | sys.platform |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/command/wininst-9.0-amd64.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/command/wininst-9.0-amd64.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/command/wininst-9.0-amd64.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/command/wininst-10.0.exe [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | data/emdedded/app/manifest | Contains embedded Microsoft Windows application manifest | requestedExecutionLevel requestedPrivileges |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/msvc.py [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | exec/program | execute external program | subprocess.CalledProcessError as exc subprocess.STDOUT, [subprocess.check_output( |
-MEDIUM | net/download | download files | msdownload |
-LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 https://visualstudio.microsoft.com |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/path/file/url | file url | file:///home |
+LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/path/file/url | file url | file:///home |
+LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.11-setuptools/var/lib/db/sbom/py3.11-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/9997350b1c1cdbe8d029e68dcab9 |
Added: py3-setuptools/var/lib/db/sbom/py3-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/0d14239bda53c228c100b28039b5 |
Added: py3-supported-setuptools/var/lib/db/sbom/py3-supported-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/2cf10f099b97c17098ed03f126c6 |
Added: py3.12-setuptools/var/lib/db/sbom/py3.12-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/4a4a6562ace6e61be494cc391440 |
Added: py3.10-setuptools/var/lib/db/sbom/py3.10-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/927a426a8feefa4516173d59c0c3 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+LOW | ref/path/file/url | file url | file:///home |
+LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |