-
Notifications
You must be signed in to change notification settings - Fork 38
fix(deps): Update dependency idna to v3.7 [SECURITY] #395
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate-bot
wants to merge
1
commit into
GoogleCloudPlatform:main
Choose a base branch
from
renovate-bot:renovate/pypi-idna-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
fix(deps): Update dependency idna to v3.7 [SECURITY] #395
renovate-bot
wants to merge
1
commit into
GoogleCloudPlatform:main
from
renovate-bot:renovate/pypi-idna-vulnerability
+1
−1
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
/gcbrun |
ce9039c
to
8c5a97e
Compare
/gcbrun |
8c5a97e
to
f874901
Compare
/gcbrun |
f874901
to
6c21b5d
Compare
/gcbrun |
6c21b5d
to
ded80b5
Compare
/gcbrun |
ded80b5
to
8ac9927
Compare
/gcbrun |
8ac9927
to
71cacd6
Compare
/gcbrun |
71cacd6
to
432f3f4
Compare
/gcbrun |
432f3f4
to
00ce405
Compare
/gcbrun |
00ce405
to
65573db
Compare
/gcbrun |
65573db
to
3c8cdfd
Compare
/gcbrun |
3c8cdfd
to
8856975
Compare
/gcbrun |
8856975
to
decc815
Compare
/gcbrun |
decc815
to
fcd5db4
Compare
/gcbrun |
/gcbrun |
c2bbeb2
to
9db6240
Compare
/gcbrun |
9db6240
to
3ae5b88
Compare
/gcbrun |
3ae5b88
to
d67c377
Compare
/gcbrun |
d67c377
to
990ad6e
Compare
/gcbrun |
990ad6e
to
2ac7d24
Compare
/gcbrun |
2ac7d24
to
0951e56
Compare
/gcbrun |
0951e56
to
0eeb555
Compare
/gcbrun |
0eeb555
to
77c30e7
Compare
/gcbrun |
77c30e7
to
6a5b899
Compare
/gcbrun |
6a5b899
to
dfafc88
Compare
/gcbrun |
dfafc88
to
d4da09f
Compare
/gcbrun |
d4da09f
to
20041aa
Compare
/gcbrun |
20041aa
to
91e9007
Compare
/gcbrun |
91e9007
to
f76d67a
Compare
/gcbrun |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==3.4
->==3.7
GitHub Vulnerability Alerts
CVE-2024-3651
Impact
A specially crafted argument to the
idna.encode()
function could consume significant resources. This may lead to a denial-of-service.Patches
The function has been refined to reject such strings without the associated resource consumption in version 3.7.
Workarounds
Domain names cannot exceed 253 characters in length, if this length limit is enforced prior to passing the domain to the
idna.encode()
function it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.References
Release Notes
kjd/idna (idna)
v3.7
Compare Source
What's Changed
Thanks to Guido Vranken for reporting the issue.
Full Changelog: kjd/idna@v3.6...v3.7
v3.6
Compare Source
v3.5
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.