Skip to content

[AUTO-CHERRYPICK] Python3 patch CVE-2024-0397 - branch main #18855

[AUTO-CHERRYPICK] Python3 patch CVE-2024-0397 - branch main

[AUTO-CHERRYPICK] Python3 patch CVE-2024-0397 - branch main #18855

#!/bin/bash
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.
name: Static glibc version check
on:
push:
branches: [main, dev, 1.0*, 2.0*, fasttrack/*]
pull_request:
branches: [main, dev, 1.0*, 2.0*, fasttrack/*]
permissions: read-all
jobs:
spec-check:
name: Static glibc version check
runs-on: ubuntu-latest
steps:
# Checkout the branch of our repo that triggered this action
- name: Workflow trigger checkout
uses: actions/checkout@v4
# For consistency, we use the same major/minor version of Python that CBL-Mariner ships
- name: Setup Python 3.9
uses: actions/setup-python@v4
with:
python-version: 3.9
- name: Get Python dependencies
run: python3 -m pip install -r toolkit/scripts/requirements.txt
- name: Verify .spec files
run: python3 toolkit/scripts/check_static_glibc.py SPECS/**/*.spec SPECS-EXTENDED/**/*.spec SPECS-SIGNED/**/*.spec