Skip to content

ci: fix IPython and Werkzeug vulnerability#26325

Merged
vmittal-msft merged 1 commit intosonic-net:202511from
auspham:austinpham/36979761-fix-ipython-security-vulnerability
Mar 23, 2026
Merged

ci: fix IPython and Werkzeug vulnerability#26325
vmittal-msft merged 1 commit intosonic-net:202511from
auspham:austinpham/36979761-fix-ipython-security-vulnerability

Conversation

@auspham
Copy link
Contributor

@auspham auspham commented Mar 23, 2026

Why I did it

Ipython 5.4.1 will have security issue so we need to address this. This have already been addressed in #25876. Maybe was missing due to cherry-pick.

Werkzeug (GHSA-87hc-h4r5-73f7) also have vulnerability, solution is to upgrade to 3.1.5. It was reported in this branch

Work item tracking
  • Microsoft ADO (number only):

How I did it

How to verify it

Which release branch to backport (provide reason below if selected)

  • 202305
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@auspham auspham requested a review from lguohan as a code owner March 23, 2026 00:30
@mssonicbld
Copy link
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

Signed-off-by: Austin Pham <austinpham@microsoft.com>
@auspham auspham force-pushed the austinpham/36979761-fix-ipython-security-vulnerability branch from 830d81b to 569c7a1 Compare March 23, 2026 00:35
@mssonicbld
Copy link
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@vmittal-msft vmittal-msft merged commit 1647cbf into sonic-net:202511 Mar 23, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants