Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Maintenance: update mako to fix CVE #1523

Closed
1 of 2 tasks
rubenfonseca opened this issue Sep 19, 2022 · 1 comment
Closed
1 of 2 tasks

Maintenance: update mako to fix CVE #1523

rubenfonseca opened this issue Sep 19, 2022 · 1 comment
Labels
internal Maintenance changes

Comments

@rubenfonseca
Copy link
Contributor

Summary

We should update mako dependency to at least 1.2.2.

Why is this needed?

CVE on mako https://nvd.nist.gov/vuln/detail/CVE-2022-40023.

This only affects documentation generation (poetry dev environment). It doesn't impact users of the library.

Which area does this relate to?

No response

Solution

Mako 1.2.2 only supports python >= 3.7. So we should pin mako as a dev dependency and add a note to remove it on v2.

Acknowledgment

@rubenfonseca rubenfonseca added triage Pending triage from maintainers internal Maintenance changes and removed triage Pending triage from maintainers labels Sep 19, 2022
@github-actions github-actions bot added the pending-release Fix or implementation already in dev waiting to be released label Sep 19, 2022
@github-actions
Copy link
Contributor

This is now released under 1.29.2 version!

@github-actions github-actions bot removed the pending-release Fix or implementation already in dev waiting to be released label Sep 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
internal Maintenance changes
Projects
None yet
Development

No branches or pull requests

1 participant