From 468a752bdc8f4ffcb51ad0b4e7a7a297199379ef Mon Sep 17 00:00:00 2001 From: Guen Prawiroatmodjo Date: Fri, 22 Jan 2021 10:23:31 -0800 Subject: [PATCH 1/2] reactivate summarizer, rename requirements-disabled.txt to requirements.txt, update README --- src/Documentation/Summarizer/README.md | 5 ----- .../{requirements-disabled.txt => requirements.txt} | 0 2 files changed, 5 deletions(-) rename src/Documentation/Summarizer/{requirements-disabled.txt => requirements.txt} (100%) diff --git a/src/Documentation/Summarizer/README.md b/src/Documentation/Summarizer/README.md index 7649d4ab3f..864fb093a8 100644 --- a/src/Documentation/Summarizer/README.md +++ b/src/Documentation/Summarizer/README.md @@ -1,10 +1,5 @@ # summarize_documentation -**NOTICE**: This utility is temporarily disabled because of a dependency on PyYAML, which is vulnerable to [CVE-2020-14343](https://access.redhat.com/security/cve/cve-2020-14343). -`requirements-disabled.txt` should be renamed back to `requirements.txt` and this notice removed when the CVE is resolved. - ---- - This utility summarizes Markdown documentation gathered from one or more compilation units, producing namespace and TOC files from the gathered documentation. diff --git a/src/Documentation/Summarizer/requirements-disabled.txt b/src/Documentation/Summarizer/requirements.txt similarity index 100% rename from src/Documentation/Summarizer/requirements-disabled.txt rename to src/Documentation/Summarizer/requirements.txt From b68024ecbb43b2f4cfb9abbdee5ed0e5357fa0a2 Mon Sep 17 00:00:00 2001 From: Guen Prawiroatmodjo Date: Fri, 22 Jan 2021 12:06:45 -0800 Subject: [PATCH 2/2] add pyyaml >= 5.4 to requirements.txt --- src/Documentation/Summarizer/requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/src/Documentation/Summarizer/requirements.txt b/src/Documentation/Summarizer/requirements.txt index eb24756324..17d5a0e0d4 100644 --- a/src/Documentation/Summarizer/requirements.txt +++ b/src/Documentation/Summarizer/requirements.txt @@ -1,3 +1,4 @@ python-frontmatter click ruamel-yaml +pyyaml>=5.4 # This version resolves CVE-2020-14343