目录
deeppcs

fix: patch HIGH/MEDIUM CVEs in spark-processing image (v1.5) (#188)

  • fix: patch HIGH/MEDIUM CVEs in spark-processing image (v1.5)

Patch all fixable vulnerability findings reported by Inspector v2 against the released 3.5-cpu-py312-v1.4 image (36 HIGH / 34 MEDIUM / 9 LOW, no CRITICAL).

Python dependency bumps (runtime and test Pipfiles, locks regenerated in an AL2023 container):

  • click 8.1.8 -> 8.3.3 (CVE-2026-7246, HIGH)
  • cryptography 46.0.7 -> 48.0.1 (GHSA-537c-gmf6-5ccf, HIGH)
  • nltk pinned to 3.10.0 (CVE-2026-54293, HIGH; previously pulled transitively at 3.9.4 via safety)
  • setuptools pinned to 83.0.0 (CVE-2026-59890, MEDIUM)

All OS-level findings (kernel6.18, openssl, vim, util-linux, expat, sqlite, nginx, python3.9/3.12, pip, perl-IO-Compress, poppler, graphite2, libjxl, and others) have fixed versions in AL2023 repos and are resolved by rebuilding on the latest base image via the existing dnf update in the Dockerfile.

Known accepted finding: nltk CVE-2026-12243 has no upstream fix available at this time.

Bump sm_version to 1.5 in new_images.yml.

  • fix: bump sagemaker test dep to 2.257.5 for new safety advisories

The safety check lint gate fails on two advisories published against sagemaker <=2.257.1 after the v1.4 release:

  • 98667 / CVE-2026-8597 (Insecure Deserialization, ModelBuilder Triton)
  • 98666 / CVE-2026-8596 (Cleartext Storage of Sensitive Information)

sagemaker is a test-only dependency; bump to 2.257.5 (above the affected spec) instead of adding ignores. Test lock regenerated in an AL2023 container.

6天前67次提交

SageMaker Spark Container

Spark Overview

Apache Spark™ is a unified analytics engine for large-scale data processing. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. It also supports a rich set of higher-level tools including Spark SQL for SQL and DataFrames, MLlib for machine learning, GraphX for graph processing, and Structured Streaming for stream processing.

SageMaker Spark Container

The SageMaker Spark Container is a Docker image used to run batch data processing workloads on Amazon SageMaker using the Apache Spark framework. The container images in this repository are used to build the pre-built container images that are used when running Spark jobs on Amazon SageMaker using the SageMaker Python SDK. The pre-built images are available in the Amazon Elastic Container Registry (Amazon ECR), and this repository serves as a reference for those wishing to build their own customized Spark containers for use in Amazon SageMaker.

For the list of available Spark images, see Available SageMaker Spark Images.

License

This project is licensed under the Apache-2.0 License.

Usage in the SageMaker Python SDK

The simplest way to get started with the SageMaker Spark Container is to use the pre-built images via the SageMaker Python SDK.

Amazon SageMaker Processing — sagemaker 2.5.3 documentation

Getting Started With Development

To get started building and testing the SageMaker Spark container, you will have to setup a local development environment.

See instructions in DEVELOPMENT.md

Contributing

To contribute to this project, please read through CONTRIBUTING.md

邀请码
    Gitlink(确实开源)
  • 加入我们
  • 官网邮箱:gitlink@ccf.org.cn
  • QQ群
  • QQ群
  • 公众号
  • 公众号

版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9 京公网安备 11010802047560号