py3-setuptools/74.1.0 package update#27423
Conversation
octo-sts
bot
commented
Sep 2, 2024
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package py3-setuptools: Click to expand/collapsePackage py3-setuptools: Package py3.10-setuptools: Click to expand/collapsePackage py3.10-setuptools: Package py3.11-setuptools: Click to expand/collapsePackage py3.11-setuptools: Package py3.12-setuptools: Click to expand/collapsePackage py3.12-setuptools: Package py3-supported-setuptools: Click to expand/collapsePackage py3-supported-setuptools: bincapz found differences: Click to expand/collapseDeleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [
|
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | kernel/platform | system platform identification | sys.platform |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
| -LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
| -LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | core-metadata-download-url download_url |
| -MEDIUM | process/name/get | get the current process name | process_name |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | evasion/single_line_imports | imports built-in and executes more code on the same line | import platform; |
| -MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
| -LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | exec/shell_command | execute a shell command | system |
| -LOW | fd/read | reads from a file handle | self.read() |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | kernel/platform | system platform identification | sys.platform |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | evasion/single_line_imports | imports built-in and executes more code on the same line | import platform; |
| -MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
| -LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/tags.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | evasion/single_line_imports | imports built-in and executes more code on the same line | import platform; |
| -MEDIUM | exec/program | execute external program | subprocess.PIPE, subprocess.run( |
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
| -LOW | ref/site/url | contains embedded HTTPS URLs | pypa/pip#3383 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | core-metadata-download-url download_url |
| -MEDIUM | process/name/get | get the current process name | process_name |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
| -MEDIUM | process/name/get | get the current process name | process_name |
| -MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
| -MEDIUM | process/name/get | get the current process name | process_name |
| -MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/path/file/url | file url | file:///home |
| -LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
| -LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
| -LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_musllinux.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | exec/program | execute external program | subprocess.PIPE, text subprocess.run([ld], stderr |
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_elffile.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca https://refspecs.linuxfoundation.org/elf/gabi4 |
Deleted: py3-setuptools/var/lib/db/sbom/py3-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | downloadLocation |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/0d14239bda53c228c100b28039b5 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/specifiers.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#13475 |
Deleted: py3-supported-setuptools/var/lib/db/sbom/py3-supported-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | downloadLocation |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/2cf10f099b97c17098ed03f126c6 |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/_manylinux.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | process/executable_path | gets executable associated to this process | sys.executable |
| -MEDIUM | process/name/get | get the current process name | process_name |
| -MEDIUM | ref/site/download | http dropper url | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/python/cpython/blob/fcf1d003bf4f0100c/Lib/platform.py https://sourceware.org/bugzilla/show_bug.cgi?id=24636 https://static.docs.arm.com/ihi0044/g/aaelf32.pdf |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/path/file/url | file url | file:///home |
| -LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/_distutils/_vendor/packaging/init.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://github.com/pypa/packaging |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_parser.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | techniques/code_eval | evaluate code dynamically using eval() | eval(python |
| -LOW | fd/read | reads from a file handle | Op(tokenizer.read() append(tokenizer.read() process_env_var(tokenizer.read() process_python_str(tokenizer.read() |
| -LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#731 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/markers.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | kernel/platform | system platform identification | sys.platform |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://peps.python.org/pep-0685/ |
Deleted: py3.12-setuptools/var/lib/db/sbom/py3.12-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | downloadLocation |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/4a4a6562ace6e61be494cc391440 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | exec/shell_command | execute a shell command | system |
| -LOW | fd/read | reads from a file handle | self.read() |
Deleted: py3.10-setuptools/var/lib/db/sbom/py3.10-setuptools-74.0.0-r0.spdx.json [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | downloadLocation |
| -LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/927a426a8feefa4516173d59c0c3 |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/_distutils/_vendor/packaging/metadata.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | net/download | download files | core-metadata-download-url download_url |
| -MEDIUM | process/name/get | get the current process name | process_name |
Deleted: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools-74.0.0.post20240827.dist-info/direct_url.json [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -LOW | ref/path/file/url | file url | file:///home |
| -LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Deleted: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/_distutils/_vendor/packaging/_tokenizer.py [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| -MEDIUM | exec/shell_command | execute a shell command | system |
| -LOW | fd/read | reads from a file handle | self.read() |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools-74.1.0.post20240902.dist-info/direct_url.json [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/path/file/url | file url | file:///home |
| +LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/compat/py312.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/site/url | contains embedded HTTPS URLs | python/cpython#77102 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/msvc.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/compat/py312.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/site/url | contains embedded HTTPS URLs | python/cpython#77102 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools-74.1.0.post20240902.dist-info/direct_url.json [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/path/file/url | file url | file:///home |
| +LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |
Added: py3-supported-setuptools/var/lib/db/sbom/py3-supported-setuptools-74.1.0-r0.spdx.json [⚠️ MEDIUM]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +MEDIUM | net/download | download files | downloadLocation |
| +LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/7d84fa61fc289b60ed1c098271dc |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools/msvc.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 |
Added: py3.10-setuptools/usr/lib/python3.10/site-packages/setuptools/compat/py312.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/site/url | contains embedded HTTPS URLs | python/cpython#77102 |
Added: py3.12-setuptools/usr/lib/python3.12/site-packages/setuptools/msvc.py [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/site/url | contains embedded HTTPS URLs | python/mypy#8166 |
Added: py3.11-setuptools/usr/lib/python3.11/site-packages/setuptools-74.1.0.post20240902.dist-info/direct_url.json [✅ LOW]
| RISK | KEY | DESCRIPTION | EVIDENCE |
|---|---|---|---|
| +LOW | ref/path/file/url | file url | file:///home |
| +LOW | ref/path/hidden | possible hidden file path | /home/build/.wheels |