Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency ansible to v7 [SECURITY] #87

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Oct 18, 2021

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
ansible (source) ==3.4.0 -> ==7.0.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-3697

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.

CVE-2023-5115

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.


Release Notes

ansible-community/ansible-build-data (ansible)

v7.0.0

Compare Source

v6.7.0

Compare Source

v6.6.0

Compare Source

v6.5.0

Compare Source

v6.4.0

Compare Source

v6.3.0

Compare Source

v6.2.0

Compare Source

v6.1.0

Compare Source

v5.9.0

Compare Source

v5.8.0

Compare Source

v5.7.1

Compare Source

v5.7.0

Compare Source

v5.6.0

Compare Source

v5.5.0

Compare Source

v5.4.0

Compare Source

v5.3.0

Compare Source

v5.2.0

Compare Source

v5.1.0

Compare Source

v5.0.1

Compare Source

v4.10.0

Compare Source

v4.9.0

Compare Source

v4.8.0

Compare Source

v4.7.0

Compare Source

v4.6.0

Compare Source

v4.5.0

Compare Source

v4.4.0

Compare Source

v4.3.0

Compare Source

v4.2.0

Compare Source

v4.1.0

Compare Source

v4.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title Update dependency ansible to v4 [SECURITY] Update dependency ansible to v5 [SECURITY] Mar 7, 2022
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 9742685 to 9a80475 Compare March 7, 2022 09:54
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 9a80475 to d2e46d1 Compare March 26, 2022 14:33
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from d2e46d1 to eecbdff Compare April 25, 2022 01:01
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from eecbdff to 1c56156 Compare May 15, 2022 22:31
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch 2 times, most recently from 366782c to 65ad5cd Compare June 23, 2022 22:31
@renovate renovate bot changed the title Update dependency ansible to v5 [SECURITY] Update dependency ansible to v6 [SECURITY] Jun 23, 2022
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 65ad5cd to 7785109 Compare September 25, 2022 11:31
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 7785109 to 85a2c57 Compare November 20, 2022 08:29
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 85a2c57 to 18ff9ea Compare March 16, 2023 07:20
@renovate renovate bot changed the title Update dependency ansible to v6 [SECURITY] Update dependency ansible to v7 [SECURITY] Mar 16, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 18ff9ea to d47618a Compare March 25, 2023 02:37
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch 2 times, most recently from 77c593e to 76157b8 Compare April 17, 2023 15:08
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch 2 times, most recently from b103384 to 10bcdcd Compare May 28, 2023 13:56
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v8 [SECURITY] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch 2 times, most recently from ab35a6c to a9de132 Compare June 18, 2023 10:07
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from a9de132 to 0c2461b Compare June 19, 2023 07:27
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v8 [SECURITY] Jun 19, 2023
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Jun 19, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 0c2461b to 105ff17 Compare June 19, 2023 12:37
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 105ff17 to 7060b3f Compare July 9, 2023 09:04
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v8 [SECURITY] Jul 9, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 7060b3f to b0bd409 Compare July 9, 2023 12:25
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Jul 9, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from b0bd409 to 2de4a42 Compare August 9, 2023 12:19
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Sep 19, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from f33f976 to 9615a79 Compare September 26, 2023 14:09
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v8 [SECURITY] Sep 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 9615a79 to 2060c03 Compare September 26, 2023 17:10
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Sep 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 2060c03 to 8f1d3ed Compare November 6, 2023 07:49
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v8 [SECURITY] Nov 6, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 8f1d3ed to 88c23ec Compare November 6, 2023 10:00
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Nov 6, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 88c23ec to 207cdde Compare November 16, 2023 09:45
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v8 [SECURITY] Nov 16, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 207cdde to a18c59d Compare November 16, 2023 14:35
@renovate renovate bot changed the title Update dependency ansible to v8 [SECURITY] Update dependency ansible to v7 [SECURITY] Nov 16, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from a18c59d to 4360ab8 Compare December 3, 2023 09:19
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v9 [SECURITY] Dec 3, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 4360ab8 to f265e8a Compare December 3, 2023 15:19
@renovate renovate bot changed the title Update dependency ansible to v9 [SECURITY] Update dependency ansible to v7 [SECURITY] Dec 3, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from f265e8a to 197b942 Compare January 4, 2024 17:37
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v9 [SECURITY] Jan 4, 2024
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 197b942 to 98097d8 Compare January 4, 2024 19:06
@renovate renovate bot changed the title Update dependency ansible to v9 [SECURITY] Update dependency ansible to v7 [SECURITY] Jan 4, 2024
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 98097d8 to efce8b7 Compare January 9, 2024 12:02
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v9 [SECURITY] Jan 9, 2024
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from efce8b7 to bf78571 Compare January 9, 2024 17:50
@renovate renovate bot changed the title Update dependency ansible to v9 [SECURITY] Update dependency ansible to v7 [SECURITY] Jan 9, 2024
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from bf78571 to 29365e0 Compare January 16, 2024 12:47
@renovate renovate bot changed the title Update dependency ansible to v7 [SECURITY] Update dependency ansible to v9 [SECURITY] Jan 16, 2024
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 29365e0 to b9b9387 Compare January 16, 2024 16:48
@renovate renovate bot changed the title Update dependency ansible to v9 [SECURITY] Update dependency ansible to v7 [SECURITY] Jan 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants