From aafbcfcf8f5206dceb58132dce6e90cd863c1d2c Mon Sep 17 00:00:00 2001 From: Bradley Dice Date: Mon, 9 Dec 2024 13:45:38 -0800 Subject: [PATCH] Use curl >=8.5.0 to align with conda-forge and avoid CVEs. --- conda/environments/all_cuda-118_arch-aarch64.yaml | 2 +- conda/environments/all_cuda-118_arch-x86_64.yaml | 2 +- conda/environments/all_cuda-125_arch-aarch64.yaml | 2 +- conda/environments/all_cuda-125_arch-x86_64.yaml | 2 +- conda/recipes/kvikio/conda_build_config.yaml | 2 +- conda/recipes/libkvikio/conda_build_config.yaml | 2 +- cpp/cmake/thirdparty/get_libcurl.cmake | 6 +++--- dependencies.yaml | 2 +- 8 files changed, 10 insertions(+), 10 deletions(-) diff --git a/conda/environments/all_cuda-118_arch-aarch64.yaml b/conda/environments/all_cuda-118_arch-aarch64.yaml index 7fee941a1d..26f3703daf 100644 --- a/conda/environments/all_cuda-118_arch-aarch64.yaml +++ b/conda/environments/all_cuda-118_arch-aarch64.yaml @@ -17,7 +17,7 @@ dependencies: - cython>=3.0.0 - doxygen=1.9.1 - gcc_linux-aarch64=11.* -- libcurl>=7.87.0 +- libcurl>=8.5.0 - moto>=4.0.8 - ninja - numcodecs !=0.12.0 diff --git a/conda/environments/all_cuda-118_arch-x86_64.yaml b/conda/environments/all_cuda-118_arch-x86_64.yaml index b89468e062..4e206bbe6e 100644 --- a/conda/environments/all_cuda-118_arch-x86_64.yaml +++ b/conda/environments/all_cuda-118_arch-x86_64.yaml @@ -19,7 +19,7 @@ dependencies: - gcc_linux-64=11.* - libcufile-dev=1.4.0.31 - libcufile=1.4.0.31 -- libcurl>=7.87.0 +- libcurl>=8.5.0 - moto>=4.0.8 - ninja - numcodecs !=0.12.0 diff --git a/conda/environments/all_cuda-125_arch-aarch64.yaml b/conda/environments/all_cuda-125_arch-aarch64.yaml index e12ab092ef..09038a7d08 100644 --- a/conda/environments/all_cuda-125_arch-aarch64.yaml +++ b/conda/environments/all_cuda-125_arch-aarch64.yaml @@ -18,7 +18,7 @@ dependencies: - doxygen=1.9.1 - gcc_linux-aarch64=11.* - libcufile-dev -- libcurl>=7.87.0 +- libcurl>=8.5.0 - moto>=4.0.8 - ninja - numcodecs !=0.12.0 diff --git a/conda/environments/all_cuda-125_arch-x86_64.yaml b/conda/environments/all_cuda-125_arch-x86_64.yaml index 131efa85d5..7c70359d57 100644 --- a/conda/environments/all_cuda-125_arch-x86_64.yaml +++ b/conda/environments/all_cuda-125_arch-x86_64.yaml @@ -18,7 +18,7 @@ dependencies: - doxygen=1.9.1 - gcc_linux-64=11.* - libcufile-dev -- libcurl>=7.87.0 +- libcurl>=8.5.0 - moto>=4.0.8 - ninja - numcodecs !=0.12.0 diff --git a/conda/recipes/kvikio/conda_build_config.yaml b/conda/recipes/kvikio/conda_build_config.yaml index 639a56f509..776c2623e5 100644 --- a/conda/recipes/kvikio/conda_build_config.yaml +++ b/conda/recipes/kvikio/conda_build_config.yaml @@ -30,7 +30,7 @@ cuda11_libcufile_run_version: - ">=1.0.0.82,<=1.4.0.31" libcurl_version: - - "==7.87.0" + - "==8.5.0" nvcomp_version: - "=4.1.0.6" diff --git a/conda/recipes/libkvikio/conda_build_config.yaml b/conda/recipes/libkvikio/conda_build_config.yaml index b895b842f3..bacf9b8273 100644 --- a/conda/recipes/libkvikio/conda_build_config.yaml +++ b/conda/recipes/libkvikio/conda_build_config.yaml @@ -30,4 +30,4 @@ cuda11_libcufile_run_version: - ">=1.0.0.82,<=1.4.0.31" libcurl_version: - - "==7.87.0" + - "==8.5.0" diff --git a/cpp/cmake/thirdparty/get_libcurl.cmake b/cpp/cmake/thirdparty/get_libcurl.cmake index 6b137bbde2..2fc73ab2cf 100644 --- a/cpp/cmake/thirdparty/get_libcurl.cmake +++ b/cpp/cmake/thirdparty/get_libcurl.cmake @@ -22,13 +22,13 @@ function(find_and_configure_libcurl) endif() rapids_cpm_find( - CURL 7.87.0 + CURL 8.5.0 GLOBAL_TARGETS libcurl BUILD_EXPORT_SET kvikio-exports INSTALL_EXPORT_SET kvikio-exports CPM_ARGS - GIT_REPOSITORY https://github.com/curl/curl - GIT_TAG curl-7_87_0 + GIT_REPOSITORY https://github.com/curl/curl + GIT_TAG curl-8_5_0 OPTIONS "BUILD_CURL_EXE OFF" "BUILD_SHARED_LIBS OFF" "BUILD_TESTING OFF" "CURL_USE_LIBPSL OFF" "CURL_DISABLE_LDAP ON" "CMAKE_POSITION_INDEPENDENT_CODE ON" EXCLUDE_FROM_ALL YES # Don't install libcurl.a (only needed when building libkvikio.so) diff --git a/dependencies.yaml b/dependencies.yaml index 5c35e5192c..3a4e98a3c2 100644 --- a/dependencies.yaml +++ b/dependencies.yaml @@ -114,7 +114,7 @@ dependencies: packages: - c-compiler - cxx-compiler - - libcurl>=7.87.0 # Need CURL_WRITEFUNC_ERROR + - libcurl>=8.5.0 specific: - output_types: conda matrices: