Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Aug 21, 2024

Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Aug 21, 2024
@github-actions
Copy link
Contributor

Package py3-werkzeug: Click to expand/collapse

Package py3-werkzeug:

.PKGINFO metadata:

  (
  	"""
- 	# Generated by melange v0.16.6-18-gf2fd84a
+ 	# Generated by melange
  	pkgname = py3-werkzeug
- 	pkgver = 3.0.3-r0
+ 	pkgver = 3.0.4-r0
  	arch = x86_64
- 	size = 868114
+ 	size = 869938
  	origin = py3-werkzeug
  	pkgdesc = The comprehensive WSGI web application library.
  	url = 
- 	commit = e6eb9e7950846cb02d2dd8bf4d18bc97f34c147a
- 	builddate = 1714969651
+ 	commit = 6324c725770909f1c5e6b3cfbc158c1449935acc
  	license = BSD-3-Clause
  	depend = py3-markupsafe
  	depend = python-3
- 	datahash = 6d2079e23357427586b98f4c4ed927923003e36411b657838581861a39c56787
+ 	datahash = 57579e457bf35d4cf684425068d47eaa93d33ad52fe61926d5cc48b088b191fe
  	"""
  )

Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/LICENSE.txt
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/METADATA
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/RECORD
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/WHEEL
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/init.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/shared/debugger.js
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/tbtools.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/formparser.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/http.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/routing/rules.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/serving.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/wrappers/request.py
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/LICENSE.txt
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/METADATA
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/RECORD
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/WHEEL

bincapz found differences: Click to expand/collapse

Deleted: py3-werkzeug/var/lib/db/sbom/py3-werkzeug-3.0.3-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/23269a7f816365aee4382e0901c9

Added: py3-werkzeug/var/lib/db/sbom/py3-werkzeug-3.0.4-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/d3bf620eba76c53c86cfa367aedc

@octo-sts
Copy link
Contributor Author

octo-sts bot commented Aug 21, 2024

Open AI suggestions to solve the build error:

The error message is: "fatal: detected dubious ownership in repository at '/github/home'\nTo add an exception for this directory, call:\n\ngit config --global --add safe.directory /github/home"

To fix this error:
1. Open your terminal.
2. Run the command: `git config --global --add safe.directory /github/home`
3. Verify the configuration by running: `git config --global --get-all safe.directory`

@github-actions
Copy link
Contributor

Package py3-werkzeug: Click to expand/collapse

Package py3-werkzeug:

.PKGINFO metadata:

  (
  	"""
- 	# Generated by melange v0.16.6-18-gf2fd84a
+ 	# Generated by melange
  	pkgname = py3-werkzeug
- 	pkgver = 3.0.3-r0
+ 	pkgver = 3.0.4-r0
  	arch = x86_64
- 	size = 868114
+ 	size = 869938
  	origin = py3-werkzeug
  	pkgdesc = The comprehensive WSGI web application library.
  	url = 
- 	commit = e6eb9e7950846cb02d2dd8bf4d18bc97f34c147a
- 	builddate = 1714969651
+ 	commit = 6324c725770909f1c5e6b3cfbc158c1449935acc
  	license = BSD-3-Clause
  	depend = py3-markupsafe
  	depend = python-3
- 	datahash = 6d2079e23357427586b98f4c4ed927923003e36411b657838581861a39c56787
+ 	datahash = 57579e457bf35d4cf684425068d47eaa93d33ad52fe61926d5cc48b088b191fe
  	"""
  )

Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/LICENSE.txt
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/METADATA
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/RECORD
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/WHEEL
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/init.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/shared/debugger.js
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/tbtools.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/formparser.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/http.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/routing/rules.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/serving.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/wrappers/request.py
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/LICENSE.txt
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/METADATA
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/RECORD
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/WHEEL

bincapz found differences: Click to expand/collapse

Deleted: py3-werkzeug/var/lib/db/sbom/py3-werkzeug-3.0.3-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/23269a7f816365aee4382e0901c9

Added: py3-werkzeug/var/lib/db/sbom/py3-werkzeug-3.0.4-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/d3bf620eba76c53c86cfa367aedc

@octo-sts
Copy link
Contributor Author

octo-sts bot commented Aug 22, 2024

Open AI suggestions to solve the build error:

The error message is: "fatal: detected dubious ownership in repository at '/github/home'\nTo add an exception for this directory, call:\n\ngit config --global --add safe.directory /github/home"

To fix this error, follow these steps:
1. Open your terminal.
2. Run: `git config --global --add safe.directory /github/home`
3. Verify by running: `git config --global --get-all safe.directory`

@github-actions
Copy link
Contributor

Package py3-werkzeug: Click to expand/collapse

Package py3-werkzeug:

.PKGINFO metadata:

  (
  	"""
- 	# Generated by melange v0.16.6-18-gf2fd84a
+ 	# Generated by melange
  	pkgname = py3-werkzeug
- 	pkgver = 3.0.3-r0
+ 	pkgver = 3.0.4-r0
  	arch = x86_64
- 	size = 868114
+ 	size = 869938
  	origin = py3-werkzeug
  	pkgdesc = The comprehensive WSGI web application library.
  	url = 
- 	commit = e6eb9e7950846cb02d2dd8bf4d18bc97f34c147a
- 	builddate = 1714969651
+ 	commit = 6324c725770909f1c5e6b3cfbc158c1449935acc
  	license = BSD-3-Clause
  	depend = py3-markupsafe
  	depend = python-3
- 	datahash = 6d2079e23357427586b98f4c4ed927923003e36411b657838581861a39c56787
+ 	datahash = 57579e457bf35d4cf684425068d47eaa93d33ad52fe61926d5cc48b088b191fe
  	"""
  )

Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/LICENSE.txt
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/METADATA
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/RECORD
Added: /usr/lib/python3.12/site-packages/werkzeug-3.0.4.dist-info/WHEEL
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/init.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/shared/debugger.js
Modified: /usr/lib/python3.12/site-packages/werkzeug/debug/tbtools.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/formparser.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/http.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/routing/rules.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/serving.py
Modified: /usr/lib/python3.12/site-packages/werkzeug/wrappers/request.py
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/LICENSE.txt
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/METADATA
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/RECORD
Deleted: /usr/lib/python3.12/site-packages/werkzeug-3.0.3.dist-info/WHEEL

bincapz found differences: Click to expand/collapse

Deleted: py3-werkzeug/var/lib/db/sbom/py3-werkzeug-3.0.3-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/23269a7f816365aee4382e0901c9

Added: py3-werkzeug/var/lib/db/sbom/py3-werkzeug-3.0.4-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/d3bf620eba76c53c86cfa367aedc

@octo-sts
Copy link
Contributor Author

octo-sts bot commented Aug 22, 2024

Open AI suggestions to solve the build error:

The error message is: "fatal: detected dubious ownership in repository at '/github/home'
To add an exception for this directory, call:

git config --global --add safe.directory /github/home"

To fix this error, follow these steps:
1. Open your terminal.
2. Run: `git config --global --add safe.directory /github/home`
3. Verify with: `git config --global --get-all safe.directory`

@ajayk ajayk enabled auto-merge (squash) August 22, 2024 20:37
@philroche
Copy link
Member

Changes summay:
Total files changed: 21

Total changes: 353
Total additions: 206
Total deletions: 147

Total commits: 22

GitHub compare URL: pallets/werkzeug@f9995e9...b933ccb

@philroche philroche self-assigned this Aug 22, 2024
Copy link
Member

@philroche philroche left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a patch version bump with mainly dependency version bumps included.

All checks pass apart from CVE check but these CVE check failures will be picked up with automated CVE remediation.

@ajayk ajayk merged commit eec2088 into main Aug 22, 2024
@ajayk ajayk deleted the wolfictl-f6edd872-58d4-4133-8971-394f92f76b41 branch August 22, 2024 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated pr request-version-update request for a newer version of a package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants