Commit 5d00963
[fix]: proj 24 25 and training images vulnerability fixes (#4977)
* [feat]: Fix image vulnerabilities
* Update Dockerfile to fix vulnerabilities and upgrade packages
Removed onnx installation and upgraded several packages including onnx to version 1.21.0 to address vulnerabilities.
* fix: add CVE justifications and missing security pins for acpt-rft and acpt-pytorch-2.8
acpt-rft Dockerfile:
- Add per-package CVE/GHSA justification comments for all security overrides
- Document transitive dep chains explaining why parent upgrades don't resolve each CVE
acpt-pytorch-2.8-cuda12.6 Dockerfile:
- cryptography >=46.0.5 -> >=46.0.7 (CVE-2026-41727)
- Add python-dotenv>=1.2.2, requests>=2.33.0, urllib3>=2.6.3 to base conda env
- Add per-package CVE justification comments with dep chain analysis
acpt-pytorch-2.8-cuda12.6 requirements.txt:
- requests: unpinned -> >=2.33.0 (GHSA-gc5v-m9x4-r6x2)
- Add starlette>=0.49.1, wheel>=0.46.2, protobuf>=6.33.5
- Add onnx>=1.21.0 (5 GHSAs, parent onnxruntime uses >=1.16.0)
- Add python-dotenv>=1.2.2 (CVE-2026-28684, pydantic-settings only requires >=0.21.0)
- Add PyJWT>=2.12.0 (CVE-2026-32597, msal/azureml-core use loose floors)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chore: align ai-ml-automl-dnn-text-gpu-ptca Dockerfile with main
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix: add python-dotenv CVE justification and pin across all conda envs in automl-dnn-vision-gpu
python-dotenv>=1.2.2: CVE-2026-28684 (GHSA-mf9w-mj56-hr94); transitive dep chain:
azureml-defaults -> azureml-inference-server-http -> pydantic-settings
-> python-dotenv>=0.21.0. pydantic-settings (all versions through 2.14.0)
only requires >=0.21.0, no parent upgrade resolves this.
- Added to base conda env (was present, added justification comment)
- Added to ptca conda env (was missing)
- Added to active conda env (was missing)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* [fix]: Update vulnerability fixes
* chore: revert ai-ml-automl-dnn-text-gpu Dockerfile to match main
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix: upgrade transformers to >=5.0.0rc3 in acpt-rft for GHSA-69w3-r845-3855
CVE-2026-1839: arbitrary code execution in Trainer._load_rng_state() via
torch.load() without weights_only=True. Fixed in transformers 5.0.0rc3.
- requirements.txt: 4.57.6 -> >=5.0.0rc3 (direct dep, major version bump)
- Dockerfile: added transformers>=5.0.0rc3 to security override RUN
- Removed stale comment claiming 5.0.0rc3 not on PyPI (latest is 5.6.2)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Yeshwanth Nagaraj <ynagaraj@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: HarshaVardhanBabu <hnamburi@microsoft.com>1 parent 37c3633 commit 5d00963
7 files changed
Lines changed: 82 additions & 29 deletions
File tree
- assets/training
- finetune_acft_hf_nlp/environments/acpt-rft/context
- finetune_acft_image/environments/acft_image_medimageparse_finetune/context
- general/environments
- acpt-pytorch-2.2-cuda12.1/context
- acpt-pytorch-2.8-cuda12.6/context
- vision/environments/automl-dnn-vision-gpu/context
Lines changed: 27 additions & 10 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
| 7 | + | |
6 | 8 | | |
7 | 9 | | |
8 | 10 | | |
| |||
42 | 44 | | |
43 | 45 | | |
44 | 46 | | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
53 | 69 | | |
54 | | - | |
| 70 | + | |
| 71 | + | |
55 | 72 | | |
56 | 73 | | |
57 | 74 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
| 8 | + | |
| 9 | + | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
| |||
Lines changed: 24 additions & 11 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
32 | | - | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
33 | 36 | | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
34 | 46 | | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
44 | 57 | | |
45 | 58 | | |
46 | 59 | | |
Lines changed: 16 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
Lines changed: 11 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
90 | 90 | | |
91 | 91 | | |
92 | 92 | | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
93 | 96 | | |
94 | 97 | | |
95 | 98 | | |
96 | | - | |
| 99 | + | |
| 100 | + | |
97 | 101 | | |
98 | 102 | | |
99 | 103 | | |
100 | 104 | | |
101 | 105 | | |
102 | 106 | | |
103 | 107 | | |
104 | | - | |
| 108 | + | |
105 | 109 | | |
106 | 110 | | |
107 | 111 | | |
| |||
115 | 119 | | |
116 | 120 | | |
117 | 121 | | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
118 | 125 | | |
119 | 126 | | |
120 | | - | |
121 | | - | |
| 127 | + | |
| 128 | + | |
122 | 129 | | |
123 | 130 | | |
124 | 131 | | |
| |||
0 commit comments