Skip to content

[miniconda]: Security Update for pip (GHSA-jp4c-xjxw-mgf9)#1909

Open
V-Subhankar-infy wants to merge 1 commit into
devcontainers:mainfrom
V-Subhankar-infy:fix-miniconda
Open

[miniconda]: Security Update for pip (GHSA-jp4c-xjxw-mgf9)#1909
V-Subhankar-infy wants to merge 1 commit into
devcontainers:mainfrom
V-Subhankar-infy:fix-miniconda

Conversation

@V-Subhankar-infy

@V-Subhankar-infy V-Subhankar-infy commented Jun 25, 2026

Copy link
Copy Markdown
Member
GHSA ID Vulnerability ID Action Package Installed Version Required Version Language Install Path Image Digest
Python (Pip) Security Update for pip (GHSA-jp4c-xjxw-mgf9) 5011855 Yes, updated to 26.1.2 pip 26.0.1 26.1 Python opt/conda/lib/python3.13/site-packages/pip-26.0.1.dist-info/METADATA sha256:fdf01091b65d77e22186ae53328d9a9a77e050099297d0c6896e6e54e4aa1da5

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the miniconda devcontainer image to remediate GHSA-jp4c-xjxw-mgf9 by explicitly upgrading pip to 26.1.2, and aligns the image metadata/docs with a patch-version release.

Changes:

  • Pin/upgrade pip to 26.1.2 during the Miniconda image security patch step.
  • Bump the Miniconda image version from 1.2.7 to 1.2.8 in manifest.json.
  • Update the README’s example tag to 1.2.8-3.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
src/miniconda/.devcontainer/apply_security_patches.sh Adds an explicit pip==26.1.2 upgrade to address GHSA-jp4c-xjxw-mgf9.
src/miniconda/manifest.json Patch-bumps image version to 1.2.8 to reflect the security fix release.
src/miniconda/README.md Updates the documented example tag to match the new 1.2.8 version.

@V-Subhankar-infy V-Subhankar-infy marked this pull request as ready for review June 25, 2026 12:16
@V-Subhankar-infy V-Subhankar-infy requested a review from a team as a code owner June 25, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants