Update dependency pymongo to v4 [SECURITY] - autoclosed #548
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==3.12.1
->==4.6.3
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2024-5629
Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.
Release Notes
mongodb/mongo-python-driver (pymongo)
v4.6.3
Compare Source
v4.6.2
: PyMongo 4.6.2Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-2-released/267404
v4.6.1
: PyMongo 4.6.1Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-1-released/255752
v4.6.0
: PyMongo 4.6.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-0-released/251866
v4.5.0
: PyMongo 4.5.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-5-0-released/240662
v4.4.1
: PyMongo 4.4.1Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-4-1-released/235045
v4.4.0
: PyMongo 4.4.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-4-released/232211
v4.3.3
: PyMongo 4.3.3Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-3-3-release/200145
v4.3.2
: PyMongo 4.3.2Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-3-2-released/194266
v4.2.0
: PyMongo 4.2.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-2-0-released/176012
v4.1.1
: PyMongo 4.1.1Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-1-1-released/157895
v4.1.0
: PyMongo 4.1.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-1-0-released/156029
v4.0.2
: PyMongo 4.0.2Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-0-2-released/150457
v4.0.1
: PyMongo 4.0.1Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-0-1-released/135979
v4.0
: PyMongo 4.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-0-released/134677
v3.13.0
: PyMongo 3.13.0Compare Source
Release notes https://www.mongodb.com/community/forums/t/pymongo-3-13-0-released/197141
v3.12.3
: PyMongo 3.12.3Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-3-12-3-released/135978
v3.12.2
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.