PyPi: Gordo

CVE-2023-30767

Safety vulnerability ID: 72077

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 14, 2024 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Gordo 6.0.0 updates its TensorFlow dependency from version 2.12.1 to 2.16.1 to address several vulnerabilities, including CVE-2023-30767.

Affected package

gordo

Latest version: 6.0.3

Train and build models for Argo / Kubernetes

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* AB141288 Feat: Equinor GitHub compliance by rkicz in https://github.com/equinor/gordo/pull/1363
* Add SCM compliance badge by toera in https://github.com/equinor/gordo/pull/1368
* Feat: Upgrade `tensorflow` to `2.16.1` and `keras` to `3.4.0` by RollerKnobster in https://github.com/equinor/gordo/pull/1385
* Fix: pin `keras` to `3.3.3` due to a bug in `keras==3.4.0` by RollerKnobster in https://github.com/equinor/gordo/pull/1386
* Remove catboost by koropets in https://github.com/equinor/gordo/pull/1387
* Correct username for docker/login-action GitHub action by koropets in https://github.com/equinor/gordo/pull/1388
* Fix: deserialize callbacks for fit params from dict definition by RollerKnobster in https://github.com/equinor/gordo/pull/1389
* Fix trivy security scan issues by koropets in https://github.com/equinor/gordo/pull/1391
* Fix(serializer): skip building callbacks that are already instantiated by RollerKnobster in https://github.com/equinor/gordo/pull/1390
* Update dependencies 07.2024 by koropets in https://github.com/equinor/gordo/pull/1392
* permissions.packages=write for master-ci.yml CI job by koropets in https://github.com/equinor/gordo/pull/1394
* Using secrets.GITHUB_TOKEN for ghcr auth by koropets in https://github.com/equinor/gordo/pull/1395
* Fix(requirements): bump dependencies, mainly to eliminate third-party security issues by RollerKnobster in https://github.com/equinor/gordo/pull/1383


**Full Changelog**: https://github.com/equinor/gordo/compare/5.3.1...6.0.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application