Skip to content
This repository was archived by the owner on Feb 8, 2024. It is now read-only.

Update dependency PyYAML to v5.4 [SECURITY] - autoclosed#430

Closed
renovate[bot] wants to merge 1 commit into
legacy-mainfrom
renovate/pypi-PyYAML-vulnerability
Closed

Update dependency PyYAML to v5.4 [SECURITY] - autoclosed#430
renovate[bot] wants to merge 1 commit into
legacy-mainfrom
renovate/pypi-PyYAML-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Aug 9, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
PyYAML (source) ==5.1.2 -> ==5.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-14343

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.


Release Notes

yaml/pyyaml

v5.4

Compare Source

v5.3.1

Compare Source

v5.3

Compare Source

v5.2

Compare Source


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@cortx-admin
Copy link
Copy Markdown

Can one of the admins verify this patch?

@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 5 times, most recently from e739e45 to 0647fb7 Compare August 16, 2021 08:44
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 8 times, most recently from 6d2284e to 9bfc95f Compare August 24, 2021 07:19
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 4 times, most recently from ecb77a3 to c025538 Compare August 26, 2021 08:42
@stale
Copy link
Copy Markdown

stale Bot commented Aug 30, 2021

This issue/pull request has been marked as needs attention as it has been left pending without new activity for 4 days. Tagging @s-arya @sachinpunadikar for appropriate assignment. Sorry for the delay & Thank you for contributing to CORTX. We will get back to you as soon as possible.

@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 2 times, most recently from 4bb9678 to ac8657c Compare September 1, 2021 12:08
vastradparayya pushed a commit to vastradparayya/cortx-utils that referenced this pull request Sep 1, 2021
* Added new file for transitional dependencies

Signed-off-by: Venkatesh K <venkatesh.k@seagate.com>

* Resolving the conflict 

Signed-off-by: Venkatesh K <venkatesh.k@seagate.com>

* Adding the dependency package 

Signed-off-by: Venkatesh K <venkatesh.k@seagate.com>

* Added review comments

Signed-off-by: Venkatesh K <venkatesh.k@seagate.com>

* Addressed the review comments

Signed-off-by: Venkatesh K <venkatesh.k@seagate.com>

* Updated comment on package

Signed-off-by: Venkatesh K <venkatesh.k@seagate.com>

Co-authored-by: Shailesh Vaidya <shailesh.vaidya@seagate.com>
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 4 times, most recently from 648fb81 to 7a5ffb3 Compare September 3, 2021 15:14
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 12 times, most recently from dfbcba9 to 7a47c15 Compare September 21, 2021 14:11
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 4 times, most recently from 7f5f30f to 3c80123 Compare September 29, 2021 13:29
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 7 times, most recently from 057eefe to da89dad Compare October 8, 2021 15:53
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 3 times, most recently from d75fa24 to 12c4739 Compare October 21, 2021 06:08
@renovate renovate Bot force-pushed the renovate/pypi-PyYAML-vulnerability branch 3 times, most recently from d039a93 to b0c9a95 Compare October 28, 2021 11:35
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants