Skip to content

Require moto 5.2.2 or newer for the Amazon provider tests - #74224

Merged
potiuk merged 1 commit into
apache:mainfrom
potiuk:bump-moto-min-version
Oct 5, 2026
Merged

potiuk merged 1 commit into
apache:mainfrom
potiuk:bump-moto-min-version

Conversation

@potiuk

@potiuk potiuk commented Oct 5, 2026

Copy link
Copy Markdown
Member

moto releases before 5.2.2 load their bundled EC2 data through ../resources/… paths with
pkgutil.get_data(). Python builds that carry the CVE-2026-3479 patch for pkgutil.get_data reject ..
in resource paths. Docker Hardened Images are one such build. On those builds every EC2-backed test fails
in the lowest-dependency Providers[amazon] run. moto 5.2.2 loads the files with
load_resource("ec2/resources/…") instead, so this raises the test floor to 5.2.2.

Found while moving the CI/PROD images to hardened Python base images (#73038).

related: #73038


Was generative AI tooling used to co-author this PR?
  • Yes — Claude Code (Opus 5)

Generated-by: Claude Code (Opus 5) following the guidelines

🤖 Generated with Claude Code

Older moto loads its bundled EC2 data through ../ resource paths, which Python builds carrying the CVE-2026-3479 pkgutil.get_data patch (Docker Hardened Images among them) reject, so every EC2-backed test failed in the lowest-dependency run.

Generated-by: Claude Opus 5
@potiuk
potiuk requested a review from o-nikolas as a code owner October 5, 2026 08:54
@boring-cyborg boring-cyborg Bot added area:providers provider:amazon AWS/Amazon - related issues labels Oct 5, 2026
@potiuk
potiuk merged commit 48f6b51 into apache:main Oct 5, 2026
74 checks passed
@potiuk
potiuk deleted the bump-moto-min-version branch October 5, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:providers provider:amazon AWS/Amazon - related issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants