-
Notifications
You must be signed in to change notification settings - Fork 32
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: Update dependency flask to v2.2.5 [SECURITY] #88
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/pypi-flask-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
chore: Update dependency flask to v2.3.2 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
May 28, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
May 28, 2023 12:42
246e723
to
b8a9fb9
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.2 [SECURITY]
Jun 18, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 18, 2023 08:01
b8a9fb9
to
3295b3c
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.2 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Jun 18, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 18, 2023 10:06
3295b3c
to
f77e59f
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.2 [SECURITY]
Aug 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 9, 2023 14:37
f77e59f
to
dd46e0a
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.2 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Aug 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 9, 2023 17:43
dd46e0a
to
d333cfc
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Sep 19, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 19, 2023 15:01
d333cfc
to
41824eb
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Sep 19, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 19, 2023 19:08
41824eb
to
8c56581
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Sep 26, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 26, 2023 12:28
8c56581
to
a406811
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Sep 26, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 26, 2023 17:21
a406811
to
d3e0594
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
November 16, 2023 12:04
d3e0594
to
5b585b9
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
November 16, 2023 17:10
5b585b9
to
91fd5b0
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Dec 3, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
December 3, 2023 12:08
91fd5b0
to
54fc60b
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Dec 3, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
December 3, 2023 16:24
54fc60b
to
b99de08
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Jan 4, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
2 times, most recently
from
January 4, 2024 19:39
de56ae3
to
6351ed8
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Apr 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
April 14, 2024 13:51
aa4f2cb
to
4ff6e1a
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Apr 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
May 1, 2024 14:38
4ff6e1a
to
17212b4
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
May 1, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
May 1, 2024 16:46
17212b4
to
b5c2df5
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
May 1, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
May 9, 2024 08:47
b5c2df5
to
fe24d67
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
May 9, 2024
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
May 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
2 times, most recently
from
May 15, 2024 17:14
f5961d7
to
10772c1
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
May 15, 2024
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
May 16, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
May 16, 2024 00:42
10772c1
to
f7b4fdd
Compare
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 27, 2024 11:10
f7b4fdd
to
72d9c17
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Jun 27, 2024
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Jun 27, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 27, 2024 14:25
72d9c17
to
b3de3c3
Compare
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
July 14, 2024 08:01
b3de3c3
to
60f149d
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Jul 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
July 14, 2024 11:56
60f149d
to
3783b26
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Jul 14, 2024
renovate
bot
changed the title
chore: Update dependency flask to v2.2.5 [SECURITY]
chore: Update dependency flask to v2.3.3 [SECURITY]
Jul 28, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
July 28, 2024 14:31
3783b26
to
9822ab7
Compare
renovate
bot
changed the title
chore: Update dependency flask to v2.3.3 [SECURITY]
chore: Update dependency flask to v2.2.5 [SECURITY]
Jul 28, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
July 28, 2024 17:12
9822ab7
to
05b0407
Compare
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 6, 2024 16:13
05b0407
to
d74c38e
Compare
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 7, 2024 12:52
d74c38e
to
9d0bfba
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==2.2.2
->==2.2.5
GitHub Vulnerability Alerts
CVE-2023-30861
When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by a proxy to other clients. If the proxy also caches
Set-Cookie
headers, it may send one client'ssession
cookie to other clients. The severity depends on the application's use of the session, and the proxy's behavior regarding cookies. The risk depends on all these conditions being met.session.permanent = True
.SESSION_REFRESH_EACH_REQUEST
is enabled (the default).Cache-Control
header to indicate that a page is private or should not be cached.This happens because vulnerable versions of Flask only set the
Vary: Cookie
header when the session is accessed or modified, not when it is refreshed (re-sent to update the expiration) without being accessed or modified.Release Notes
pallets/flask (flask)
v2.2.5
Compare Source
Released 2023-05-02
Vary: Cookie
header when the session is accessed, modified, or refreshed.v2.2.4
Compare Source
Released 2023-04-25
v2.2.3
Compare Source
Released 2023-02-15
.svg
template files. :issue:4831
template_folder
to acceptpathlib.Path
. :issue:4892
--debug
option to theflask run
command. :issue:4777
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.