Update dependency tqdm to v4.66.3 [SECURITY] #555
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==4.62.3->==4.66.3==4.62.0->==4.66.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2024-34062
Impact
Any optional non-boolean CLI arguments (e.g.
--delim,--buf-size,--manpath) are passed through python'seval, allowing arbitrary code execution. Example:python -m tqdm --manpath="\" + str(exec(\"import os\nos.system('echo hi && killall python3')\")) + \""Patches
tqdm/tqdm@4e613f8 released in
tqdm>=4.66.3Workarounds
None
References
Release Notes
tqdm/tqdm (tqdm)
v4.66.3Compare Source
v4.66.2: tqdm v4.66.2 stableCompare Source
pandas: addDataFrame.progress_map(#1549)notebook: fix HTML padding (#1506)keras: fix resuming training whenverbose>=2(#1508)format_numnegative fractions missing leading zero (#1548)DeprecationWarningonimport(#1519)pandaswarningsasv(https://github.com/airspeed-velocity/asv/issues/1323)notebookdocstring indentationv4.66.1: tqdm v4.66.1 stableCompare Source
utils.envwraptypes (#1493 <- #1491, #1320 <- #966, #1319)export TQDM_POSITION=-1v4.66.0: tqdm v4.66.0 stableCompare Source
TQDM_*) (#1491 <- #1061, #950 <- #614, #1318, #619, #612, #370)export TQDM_MININTERVAL=5to avoid log spamtqdm.utils.envwrapos.path=>pathlib.Pathv4.65.2: tqdm v4.65.2 stableCompare Source
examplesfrom distributed wheel (#1492)v4.65.1: tqdm v4.65.1 stableCompare Source
setup.{cfg,py}=>pyproject.toml(#1490)asvbenchmarkspre-commitv4.65.0: tqdm v4.65.0 stableCompare Source
v4.64.1: tqdm v4.64.1 stableCompare Source
ipywidgets>=8(#1366, #1361 <- #1310, #1359, #1360, #1364)v4.64.0: tqdm v4.64.0 stableCompare Source
contrib.slack(#1313)v4.63.2: tqdm v4.63.2 stableCompare Source
rich: exposeoptionskwargs (#1282)autonotebook: re-enable VSCode (#1309)v4.63.1: tqdm v4.63.1 stableCompare Source
flush()(#1248 <- #1177)v4.63.0: tqdm v4.63.0 stableCompare Source
__reversed__()__contains__()pkg_resources=>importlib)tqdm.autonotebookwarning &stdfallback on missingipywidgets(#1218 <- #1082, #1217)py3.10testscondadependenciespytestconfig (nbval,asyncio)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate. View repository job log here.