Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Update vulnerable dependencies #9303

Merged
merged 2 commits into from Jan 18, 2020

Conversation

@adityahase
Copy link
Member Author

Some problem with PyYaml==4.1

@Thunderbottom
Copy link
Contributor

there's no PyYAML 4.1 according to PyPI: https://pypi.org/project/PyYAML/#history

@Thunderbottom Thunderbottom merged commit 76eba34 into frappe:develop Jan 18, 2020
@AdamN1
Copy link

AdamN1 commented Jan 26, 2020

Hi,
after marge there is dependency conflict with frontmatter==3.0.5 which has requirement PyYAML==3.13.

@Thunderbottom
Copy link
Contributor

@AdamN1 there's a pull request to update PyYAML to 5.1 on the frontmatter repository: jonbeebe/frontmatter#8

@AdamN1
Copy link

AdamN1 commented Jan 26, 2020

@AdamN1 there's a pull request to update PyYAML to 5.1 on the frontmatter repository: jonbeebe/frontmatter#8

Unfortunately until PR is accepted manual installation of frappe isn't possible.
Maybe postpone version change until PR is accepted or change wiki instruction to use stable frape branch?

@Thunderbottom
Copy link
Contributor

@AdamN1 the existing installation for frontmatter should work just fine, it's just that Python won't install it again because of dependency pinning.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Feb 15, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants