From bca763a59a4b72e3e97e7c9519070d0e086e5585 Mon Sep 17 00:00:00 2001 From: Eric Bouchut Date: Fri, 7 Mar 2025 16:36:21 +0100 Subject: [PATCH] =?UTF-8?q?=E2=AC=86=EF=B8=8F=20Upgrade=20Dependencies?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fix a security vulnerability with Jinja2 > Jinja2 vulnerable to sandbox breakout through attr filter selecting format method --- requirements.in | 4 +-- requirements.txt | 89 +++++++++++++++++++++++++++++++++++++++++------- 2 files changed, 79 insertions(+), 14 deletions(-) diff --git a/requirements.in b/requirements.in index 1c322c0..7896e39 100644 --- a/requirements.in +++ b/requirements.in @@ -1,5 +1,5 @@ -certifi==2024.7.4 +certifi==2025.1.31 mkdocs==1.6.1 mkdocs-htmlproofer-plugin==1.3.0 -mkdocs-material==9.5.49 +mkdocs-material==9.6.7 mkdocs-unused-files==0.2.0 diff --git a/requirements.txt b/requirements.txt index 1f46042..06f6f78 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,33 +1,98 @@ -babel==2.16.0 -beautifulsoup4==4.12.3 -certifi==2024.7.4 +# +# This file is autogenerated by pip-compile with Python 3.13 +# by the following command: +# +# pip-compile requirements.in +# +babel==2.17.0 + # via mkdocs-material +backrefs==5.8 + # via mkdocs-material +beautifulsoup4==4.13.3 + # via + # mkdocs-htmlproofer-plugin + # mkdocs-unused-files +certifi==2025.1.31 + # via + # -r requirements.in + # requests charset-normalizer==3.4.1 + # via requests click==8.1.8 + # via mkdocs colorama==0.4.6 + # via mkdocs-material ghp-import==2.1.0 + # via mkdocs idna==3.10 -Jinja2==3.1.5 -Markdown==3.7 -MarkupSafe==3.0.2 + # via requests +jinja2==3.1.6 + # via + # mkdocs + # mkdocs-material +markdown==3.7 + # via + # mkdocs + # mkdocs-htmlproofer-plugin + # mkdocs-material + # pymdown-extensions +markupsafe==3.0.2 + # via + # jinja2 + # mkdocs mergedeep==1.3.4 + # via + # mkdocs + # mkdocs-get-deps mkdocs==1.6.1 + # via + # -r requirements.in + # mkdocs-htmlproofer-plugin + # mkdocs-material + # mkdocs-unused-files mkdocs-get-deps==0.2.0 + # via mkdocs mkdocs-htmlproofer-plugin==1.3.0 -mkdocs-material==9.5.49 + # via -r requirements.in +mkdocs-material==9.6.7 + # via -r requirements.in mkdocs-material-extensions==1.3.1 + # via mkdocs-material mkdocs-unused-files==0.2.0 + # via -r requirements.in packaging==24.2 + # via mkdocs paginate==0.5.7 + # via mkdocs-material pathspec==0.12.1 + # via mkdocs platformdirs==4.3.6 -Pygments==2.18.0 -pymdown-extensions==10.13 + # via mkdocs-get-deps +pygments==2.19.1 + # via mkdocs-material +pymdown-extensions==10.14.3 + # via mkdocs-material python-dateutil==2.9.0.post0 -PyYAML==6.0.2 -pyyaml_env_tag==0.1 -regex==2024.11.6 + # via ghp-import +pyyaml==6.0.2 + # via + # mkdocs + # mkdocs-get-deps + # pymdown-extensions + # pyyaml-env-tag +pyyaml-env-tag==0.1 + # via mkdocs requests==2.32.3 + # via + # mkdocs-htmlproofer-plugin + # mkdocs-material six==1.17.0 + # via python-dateutil soupsieve==2.6 + # via beautifulsoup4 +typing-extensions==4.12.2 + # via beautifulsoup4 urllib3==2.3.0 + # via requests watchdog==6.0.0 + # via mkdocs