From b4347dabc65ce31aa3ebaa11e412ce81d24dfb83 Mon Sep 17 00:00:00 2001 From: Ajmal Aboobacker <43377443+B3EF@users.noreply.github.com> Date: Tue, 26 Jan 2021 17:43:31 +0530 Subject: [PATCH 1/4] fixed ACE --- tensorflow/python/keras/saving/model_config.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tensorflow/python/keras/saving/model_config.py b/tensorflow/python/keras/saving/model_config.py index e203f45e093af9..b81640b55824e6 100644 --- a/tensorflow/python/keras/saving/model_config.py +++ b/tensorflow/python/keras/saving/model_config.py @@ -99,7 +99,7 @@ def model_from_yaml(yaml_string, custom_objects=None): # PyYAML 5.x+ config = yaml.unsafe_load(yaml_string) except AttributeError: - config = yaml.load(yaml_string) + config = yaml.safe_load(yaml_string) from tensorflow.python.keras.layers import deserialize # pylint: disable=g-import-not-at-top return deserialize(config, custom_objects=custom_objects) From 561d24aeec0e8a341cea60d85a10d32eafe2e712 Mon Sep 17 00:00:00 2001 From: Ajmal Aboobacker <43377443+B3EF@users.noreply.github.com> Date: Tue, 26 Jan 2021 22:11:53 +0530 Subject: [PATCH 2/4] Update model_config.py --- tensorflow/python/keras/saving/model_config.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tensorflow/python/keras/saving/model_config.py b/tensorflow/python/keras/saving/model_config.py index b81640b55824e6..2bde266540fda9 100644 --- a/tensorflow/python/keras/saving/model_config.py +++ b/tensorflow/python/keras/saving/model_config.py @@ -97,7 +97,7 @@ def model_from_yaml(yaml_string, custom_objects=None): # try block is covered by tests depends on the installed version of PyYAML. try: # PyYAML 5.x+ - config = yaml.unsafe_load(yaml_string) + config = yaml.safe_load(yaml_string) except AttributeError: config = yaml.safe_load(yaml_string) from tensorflow.python.keras.layers import deserialize # pylint: disable=g-import-not-at-top From bc8d5ff6cdf9847a66e3d2ca4993c1a3a7c2223a Mon Sep 17 00:00:00 2001 From: Ajmal Aboobacker <43377443+B3EF@users.noreply.github.com> Date: Tue, 26 Jan 2021 22:14:20 +0530 Subject: [PATCH 3/4] Update model_config.py --- tensorflow/python/keras/saving/model_config.py | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/tensorflow/python/keras/saving/model_config.py b/tensorflow/python/keras/saving/model_config.py index 2bde266540fda9..150d1cc4b6b084 100644 --- a/tensorflow/python/keras/saving/model_config.py +++ b/tensorflow/python/keras/saving/model_config.py @@ -95,11 +95,12 @@ def model_from_yaml(yaml_string, custom_objects=None): raise ImportError('Requires yaml module installed (`pip install pyyaml`).') # The method unsafe_load only exists in PyYAML 5.x+, so which branch of the # try block is covered by tests depends on the installed version of PyYAML. - try: + #try: # PyYAML 5.x+ - config = yaml.safe_load(yaml_string) - except AttributeError: - config = yaml.safe_load(yaml_string) + # config = yaml.safe_load(yaml_string) + #except AttributeError: + # config = yaml.safe_load(yaml_string) + config = yaml.safe_load(yaml_string) from tensorflow.python.keras.layers import deserialize # pylint: disable=g-import-not-at-top return deserialize(config, custom_objects=custom_objects) From 0574171602e13cf760e237d240db592ee5623d5b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 2 Feb 2022 11:07:58 +0000 Subject: [PATCH 4/4] fix: tensorflow/tools/ci_build/Dockerfile.micro to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN10-OPENSSL-1569403 - https://snyk.io/vuln/SNYK-DEBIAN10-OPENSSL-1569406 - https://snyk.io/vuln/SNYK-DEBIAN10-PYTHON37-1013422 - https://snyk.io/vuln/SNYK-DEBIAN10-PYTHON37-1063182 - https://snyk.io/vuln/SNYK-DEBIAN10-SUBVERSION-1071814 --- tensorflow/tools/ci_build/Dockerfile.micro | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tensorflow/tools/ci_build/Dockerfile.micro b/tensorflow/tools/ci_build/Dockerfile.micro index 9a2e2a4a2b87a9..77d247fc5b2f46 100644 --- a/tensorflow/tools/ci_build/Dockerfile.micro +++ b/tensorflow/tools/ci_build/Dockerfile.micro @@ -1,7 +1,7 @@ # Use a prebuilt Python image instead of base Ubuntu to speed up the build process, # since it has all the build dependencies we need for Micro and downloads much faster # than the install process. -FROM python:3.9.0-buster +FROM python:3.9-buster LABEL maintainer="Pete Warden "