Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependencies: fix several packages version for security reasons #686

Merged
merged 1 commit into from
Nov 3, 2021

Conversation

jma
Copy link
Contributor

@jma jma commented Nov 2, 2021

  • Adds a new contraint for werkzeug > 2.0.1.
  • Adds a new contraint for bleach > 3.11.
  • Adds a new excption for sqlalchemy-utils as this package has no safe
    version.

Co-Authored-by:Johnny Mariéthoz johnny.mariethoz@rero.ch

Why are you opening this PR?

  • Which task/US does it implement?
  • Which issue does it fix?

How to test?

  • What command should I have to run to test your PR?
  • What should I test through the UI?

Code review check list

  • Commit message template compliance.
  • Commit message without typos.
  • File names.
  • Functions names.
  • Functions docstrings.
  • Unnecessary commited files?
  • Extracted translations?

@jma jma force-pushed the maj-fix-vulnerability branch 3 times, most recently from f1ef391 to 7dc7a17 Compare November 2, 2021 14:33
* Adds new exception for werkzeug > 2.0.1 as this version is not yet
  compatible with the SONAR application.
* Adds a new contraint for  bleach > 3.11.
* Adds a new execption for sqlalchemy-utils as this package has no safe
  version.

Co-Authored-by:Johnny Mariéthoz <johnny.mariethoz@rero.ch>
@jma jma force-pushed the maj-fix-vulnerability branch from 7dc7a17 to e5332b8 Compare November 2, 2021 14:50
@jma jma requested review from Garfield-fr and mmo November 2, 2021 15:41
@jma jma merged commit dcd9574 into rero:staging Nov 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants