-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency flask to v2.2.5 [SECURITY] #20
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/pypi-flask-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
Update dependency flask to v2.3.2 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
May 28, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
May 28, 2023 13:31
abb2be2
to
d6d5387
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.2 [SECURITY]
Jun 18, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 18, 2023 09:36
d6d5387
to
d18c974
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.2 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jun 18, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 18, 2023 12:24
d18c974
to
a290be4
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.2 [SECURITY]
Jun 19, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 19, 2023 10:26
a290be4
to
424e2a8
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.2 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jun 19, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
June 19, 2023 15:15
424e2a8
to
0e09f71
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.2 [SECURITY]
Jul 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
July 9, 2023 11:22
0e09f71
to
7ef9501
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.2 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jul 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
July 9, 2023 12:17
7ef9501
to
b82a279
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.2 [SECURITY]
Aug 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 9, 2023 15:29
b82a279
to
32067e1
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.2 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Aug 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 9, 2023 19:57
32067e1
to
f669b96
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Aug 22, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 22, 2023 18:17
f669b96
to
e764516
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Aug 22, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
August 22, 2023 22:27
e764516
to
916a070
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Sep 7, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 7, 2023 04:31
916a070
to
aec557a
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Sep 7, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 7, 2023 08:23
aec557a
to
c63f350
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Sep 19, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 19, 2023 11:39
c63f350
to
6ad1f8c
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Sep 19, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
September 19, 2023 13:27
6ad1f8c
to
415e515
Compare
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
October 1, 2023 18:36
f48ef0d
to
37947ec
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
November 16, 2023 11:36
37947ec
to
ce10757
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
November 16, 2023 14:00
ce10757
to
e66e2ec
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Nov 30, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
November 30, 2023 09:09
e66e2ec
to
a3e29c1
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Nov 30, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
November 30, 2023 12:46
a3e29c1
to
f11ecc0
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Dec 3, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
December 3, 2023 09:24
f11ecc0
to
ccab1ca
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Dec 3, 2023
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
December 3, 2023 13:36
ccab1ca
to
41494d7
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Jan 4, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 4, 2024 17:05
41494d7
to
8fe0b40
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jan 4, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 4, 2024 18:02
8fe0b40
to
bb8e687
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Jan 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 9, 2024 11:52
bb8e687
to
df66acc
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jan 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 9, 2024 13:38
df66acc
to
1275efd
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Jan 16, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 16, 2024 13:05
1275efd
to
32f6adb
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jan 16, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 16, 2024 17:37
32f6adb
to
85a8033
Compare
renovate
bot
changed the title
Update dependency flask to v2.2.5 [SECURITY]
Update dependency flask to v2.3.3 [SECURITY]
Jan 17, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 17, 2024 17:30
85a8033
to
031a3fa
Compare
renovate
bot
changed the title
Update dependency flask to v2.3.3 [SECURITY]
Update dependency flask to v2.2.5 [SECURITY]
Jan 17, 2024
renovate
bot
force-pushed
the
renovate/pypi-flask-vulnerability
branch
from
January 17, 2024 18:46
031a3fa
to
5ba6edb
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==2.0.3
->==2.2.5
GitHub Vulnerability Alerts
CVE-2023-30861
When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by a proxy to other clients. If the proxy also caches
Set-Cookie
headers, it may send one client'ssession
cookie to other clients. The severity depends on the application's use of the session, and the proxy's behavior regarding cookies. The risk depends on all these conditions being met.session.permanent = True
.SESSION_REFRESH_EACH_REQUEST
is enabled (the default).Cache-Control
header to indicate that a page is private or should not be cached.This happens because vulnerable versions of Flask only set the
Vary: Cookie
header when the session is accessed or modified, not when it is refreshed (re-sent to update the expiration) without being accessed or modified.Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.