Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
Bump lxml from 4.6.2 to 4.6.3 in /desktop/core (#1952)
Bumps [lxml](https://github.com/lxml/lxml) from 4.6.2 to 4.6.3.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/lxml/lxml/blob/master/CHANGES.txt">lxml's changelog</a>.</em></p>
<blockquote>
<h1>4.6.3 (2021-03-21)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>A vulnerability (CVE-2021-28957) was discovered in the HTML Cleaner by Kevin Chung,
which allowed JavaScript to pass through.  The cleaner now removes the HTML5
<code>formaction</code> attribute.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999"><code>a5f9cb5</code></a> Prepare release of lxml 4.6.3.</li>
<li><a href="https://github.com/lxml/lxml/commit/2d01a1ba8984e0483ce6619b972832377f208a0d"><code>2d01a1b</code></a> Add HTML-5 &quot;formaction&quot; attribute to &quot;defs.link_attrs&quot; (<a href="https://github-redirect.dependabot.com/lxml/lxml/issues/316">GH-316</a>)</li>
<li><a href="https://github.com/lxml/lxml/commit/e986a9cb5d54827c59aefa8803bc90954d67221e"><code>e986a9c</code></a> Fix reference in docs.</li>
<li>See full diff in <a href="https://github.com/lxml/lxml/compare/lxml-4.6.2...lxml-4.6.3">compare view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=lxml&package-manager=pip&previous-version=4.6.2&new-version=4.6.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
  • Loading branch information
dependabot[bot] committed Mar 30, 2021
1 parent 9055ef8 commit 0001b34
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion desktop/core/requirements.txt
Expand Up @@ -33,7 +33,7 @@ jdcal==1.0.1
kazoo==2.8.0
kerberos==1.3.0
lockfile==0.12.2
lxml==4.6.2
lxml==4.6.3
Mako==1.1.4
Markdown==3.1
mysqlclient==1.4.6
Expand Down

0 comments on commit 0001b34

Please sign in to comment.