From 5773dbdf51fa9e99fc81043d39a604308022fd96 Mon Sep 17 00:00:00 2001 From: Adam Martin Date: Tue, 6 Apr 2021 11:42:55 -0400 Subject: [PATCH] update pyyaml and jinja --- Dockerfile | 9 ++++----- hardening_manifest.yaml | 10 ++++++++++ 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/Dockerfile b/Dockerfile index 1a909da..787c331 100644 --- a/Dockerfile +++ b/Dockerfile @@ -7,8 +7,9 @@ FROM ${BASE_REGISTRY}/${BASE_IMAGE}:${BASE_TAG} as build USER 0 COPY *.whl *.tar.gz /wheel/ -RUN pip install --no-index --find-links=/wheel/ truffleHog3 - +RUN pip install --no-index --find-links=/wheel/ truffleHog3 && \ + pip install --upgrade --no-index --find-links=/wheel/ PyYAML Jinja2 + FROM ${BASE_REGISTRY}/${BASE_IMAGE}:${BASE_TAG} COPY --from=build /usr/local/lib/python3.9/site-packages/ /usr/local/lib/python3.9/site-packages/ @@ -29,6 +30,4 @@ USER truffleHog WORKDIR /proj ENTRYPOINT ["trufflehog3"] -CMD ["-h"] - - +CMD ["-h"] \ No newline at end of file diff --git a/hardening_manifest.yaml b/hardening_manifest.yaml index a7b08ac..ebbcc56 100644 --- a/hardening_manifest.yaml +++ b/hardening_manifest.yaml @@ -47,6 +47,11 @@ resources: validation: type: sha256 value: b0eaf100007721b5c16c1fc1eecb87409464edc10469ddc9a22a27a99123be49 +- filename: Jinja2-2.11.3-py2.py3-none-any.whl + url: https://files.pythonhosted.org/packages/7e/c2/1eece8c95ddbc9b1aeb64f5783a9e07a286de42191b7204d67b7496ddf35/Jinja2-2.11.3-py2.py3-none-any.whl + validation: + type: sha256 + value: 03e47ad063331dd6a3f04a43eddca8a966a26ba0c5b7207a9a9e4e08f1b29419 - filename: GitPython-3.1.0-py3-none-any.whl url: https://files.pythonhosted.org/packages/d3/2f/6a366d56c9b1355b0880be9ea66b166cb3536392638d8d91413ec66305ad/GitPython-3.1.0-py3-none-any.whl validation: @@ -57,6 +62,11 @@ resources: validation: type: sha256 value: b8eac752c5e14d3eca0e6dd9199cd627518cb5ec06add0de9d32baeee6fe645d +- filename: PyYAML-5.4.1-cp39-cp39-manylinux1_x86_64.whl + url: https://files.pythonhosted.org/packages/3d/1f/2a3705efca3b47161ceaaf52970a9d4b81cc84600818686ecd75093a00a5/PyYAML-5.4.1-cp39-cp39-manylinux1_x86_64.whl + validation: + type: sha256 + value: 74c1485f7707cf707a7aef42ef6322b8f97921bd89be2ab6317fd782c2d53183 - filename: gitdb-4.0.7-py3-none-any.whl url: https://files.pythonhosted.org/packages/ea/e8/f414d1a4f0bbc668ed441f74f44c116d9816833a48bf81d22b697090dba8/gitdb-4.0.7-py3-none-any.whl validation: -- GitLab