Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sync security updates to main. #897

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open

Sync security updates to main. #897

wants to merge 4 commits into from

Commits on Jan 5, 2024

  1. RDISCROWD-6713 Lib upgrades to fix Critical and High severity alerts (#…

    …890)
    
    * Bump requests from 2.26.0 to 2.31.0
    
    Bumps [requests](https://github.com/psf/requests) from 2.26.0 to 2.31.0.
    - [Release notes](https://github.com/psf/requests/releases)
    - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
    - [Commits](psf/requests@v2.26.0...v2.31.0)
    
    ---
    updated-dependencies:
    - dependency-name: requests
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * Bump cryptography from 3.4.8 to 41.0.2
    
    Bumps [cryptography](https://github.com/pyca/cryptography) from 3.4.8 to 41.0.2.
    - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
    - [Commits](pyca/cryptography@3.4.8...41.0.2)
    
    ---
    updated-dependencies:
    - dependency-name: cryptography
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * Bump certifi from 2021.5.30 to 2023.7.22
    
    Bumps [certifi](https://github.com/certifi/python-certifi) from 2021.5.30 to 2023.7.22.
    - [Commits](certifi/python-certifi@2021.05.30...2023.07.22)
    
    ---
    updated-dependencies:
    - dependency-name: certifi
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * Updated libs to address all Critical and High severity alerts.
    
    * up
    
    * up
    
    * up
    
    * Updated libs.
    
    * fix
    
    * up
    
    * up
    
    * up
    
    * up
    
    ---------
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    kbecker42 and dependabot[bot] authored Jan 5, 2024
    Configuration menu
    Copy the full SHA
    3d7db4d View commit details
    Browse the repository at this point in the history

Commits on Jan 8, 2024

  1. RDISCROWD-6713 Pillow 10.1.0 (#895)

    * Bump requests from 2.26.0 to 2.31.0
    
    Bumps [requests](https://github.com/psf/requests) from 2.26.0 to 2.31.0.
    - [Release notes](https://github.com/psf/requests/releases)
    - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
    - [Commits](psf/requests@v2.26.0...v2.31.0)
    
    ---
    updated-dependencies:
    - dependency-name: requests
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * Bump cryptography from 3.4.8 to 41.0.2
    
    Bumps [cryptography](https://github.com/pyca/cryptography) from 3.4.8 to 41.0.2.
    - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
    - [Commits](pyca/cryptography@3.4.8...41.0.2)
    
    ---
    updated-dependencies:
    - dependency-name: cryptography
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * Bump certifi from 2021.5.30 to 2023.7.22
    
    Bumps [certifi](https://github.com/certifi/python-certifi) from 2021.5.30 to 2023.7.22.
    - [Commits](certifi/python-certifi@2021.05.30...2023.07.22)
    
    ---
    updated-dependencies:
    - dependency-name: certifi
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * Updated libs to address all Critical and High severity alerts.
    
    * up
    
    * up
    
    * up
    
    * Updated libs.
    
    * fix
    
    * up
    
    * up
    
    * up
    
    * up
    
    * Pillow 10.1.0
    
    ---------
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    kbecker42 and dependabot[bot] authored Jan 8, 2024
    Configuration menu
    Copy the full SHA
    a7dc939 View commit details
    Browse the repository at this point in the history
  2. pyOpenSSL==22.1.0

    kbecker42 committed Jan 8, 2024
    Configuration menu
    Copy the full SHA
    488f49b View commit details
    Browse the repository at this point in the history
  3. Merge branch 'main' into security-updates

    # Conflicts:
    #	pybossa/themes/default
    kbecker42 committed Jan 8, 2024
    Configuration menu
    Copy the full SHA
    734c649 View commit details
    Browse the repository at this point in the history