SharonKoch / skf-labs

Repo for all the OWASP-SKF Docker lab examples
Apache License 2.0
0 stars 1 forks source link

Update dependency redis to v4.4.4 #75

Open mend-for-github-com[bot] opened 11 months ago

mend-for-github-com[bot] commented 11 months ago

This PR contains the following updates:

Package Update Change
redis (changelog) minor ==4.3.4 -> ==4.4.4

By merging this PR, the issue #19 will be automatically resolved and closed:

Severity CVSS Score CVE
Medium Medium 6.5 CVE-2023-28859
Low Low 3.7 CVE-2023-28858

Release Notes

redis/redis-py (redis) ### [`v4.4.4`](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.4): 4.4.4 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.4.3...v4.4.4) ### Changes Upgrade urgency: SECURITY, contains fixes to security issues. - (CVE-2023-28859) - Cancelling an async future does not, properly trigger, leading to a potential data leak in specific cases. - (CVE-2023-28858) - Cancelling an async future does not, properly trigger, leading to a potential data leak in specific cases. #### πŸ› Bug Fixes - Fixing cancelled async futures ([#​2671](https://redirect.github.com/redis/redis-py/issues/2671) ) ### [`v4.4.3`](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.3): 4.4.3 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.4.2...v4.4.3) ### Changes Update urgency: HIGH: There is a critical bug that may affect a subset of users. Upgrade! #### πŸ› Bug Fixes - [CWE-404](https://cwe.mitre.org/data/definitions/404.html) AsyncIO Race Condition Fix ([#​2624](https://redirect.github.com/redis/redis-py/issues/2624), [#​2579](https://redirect.github.com/redis/redis-py/issues/2579)) ### [`v4.4.2`](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.2): 4.4.2 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.4.1...v4.4.2) ### Changes Note: this release include [#​2548](https://redirect.github.com/redis/redis-py/issues/2548) and it is suggested that users upgrade immediately. #### πŸ§ͺ Experimental Features - Add support for BF.CARD ([#​2545](https://redirect.github.com/redis/redis-py/issues/2545)) #### πŸš€ New Features - Add support for custom connection pool class in NodesManager ([#​2547](https://redirect.github.com/redis/redis-py/issues/2547)) #### πŸ› Bug Fixes - Allow replica to master promotion in nodes_cache ([#​2549](https://redirect.github.com/redis/redis-py/issues/2549)) - Security Fix: Updating graph parser for potential injection cases ([#​2548](https://redirect.github.com/redis/redis-py/issues/2548)) #### Contributors We'd like to thank all the contributors who worked on this release! [@​Threated](https://redirect.github.com/Threated), [@​dvora-h](https://redirect.github.com/dvora-h), [@​shacharPash](https://redirect.github.com/shacharPash) and [@​zakaf](https://redirect.github.com/zakaf) ### [`v4.4.1`](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.1): 4.4.1 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.4.0...v4.4.1) ### Changes #### πŸš€ New Features - Add dialect to `FT.AGGREGATE` ([#​2537](https://redirect.github.com/redis/redis-py/issues/2537)) - Add support for `resetchannels` in `ACL SETUSER` ([#​2514](https://redirect.github.com/redis/redis-py/issues/2514)) - Allow EVAL_RO and EVALSHA_RO to be routed to read replica ([#​2494](https://redirect.github.com/redis/redis-py/issues/2494)) - Add timeout parameter for SentinelManagedConnection ([#​2495](https://redirect.github.com/redis/redis-py/issues/2495)) - Add TIMEOUT to query class ([#​2519](https://redirect.github.com/redis/redis-py/issues/2519)) - Add support for certain LATENCY commands ([#​2503](https://redirect.github.com/redis/redis-py/issues/2503)) #### πŸ› Bug Fixes - Add type checking to `__eq__` in graph classes ([#​2531](https://redirect.github.com/redis/redis-py/issues/2531)) - Accept str for `ex` parameter in `set` command ([#​2529](https://redirect.github.com/redis/redis-py/issues/2529)) - Fix for Unhandled exception related to self.host with unix socket ([#​2520](https://redirect.github.com/redis/redis-py/issues/2520)) - Make PythonParser resumable ([#​2510](https://redirect.github.com/redis/redis-py/issues/2510)) #### 🧰 Maintenance - Fix incorrect \_disconnect_raise docstring ([#​2534](https://redirect.github.com/redis/redis-py/issues/2534)) - Remove `DeprecationWarning` by replace `get_event_loop` with `get_running_loop` ([#​2530](https://redirect.github.com/redis/redis-py/issues/2530)) - Fix AttributeError when trying to split library version ([#​2539](https://redirect.github.com/redis/redis-py/issues/2539)) - Including startup instructions via redis-stack docker ([#​2535](https://redirect.github.com/redis/redis-py/issues/2535)) - Fix `JSON.ARRINDEX` test ([#​2527](https://redirect.github.com/redis/redis-py/issues/2527)) - Add OpenTelemetry example with Uptrace backend ([#​2452](https://redirect.github.com/redis/redis-py/issues/2452)) - Switch docs to furo theme ([#​2492](https://redirect.github.com/redis/redis-py/issues/2492)) - Combine auto-concatenated strings ([#​2482](https://redirect.github.com/redis/redis-py/issues/2482)) - Updating graph tests to support new execution plan ([#​2486](https://redirect.github.com/redis/redis-py/issues/2486)) - Raising NotImplementedError for certain CLUSTER and LATENCY commands ([#​2504](https://redirect.github.com/redis/redis-py/issues/2504)) ([#​2501](https://redirect.github.com/redis/redis-py/issues/2501)) #### Contributors We'd like to thank all the contributors who worked on this release! [@​DvirDukhan](https://redirect.github.com/DvirDukhan), [@​SessionIssue](https://redirect.github.com/SessionIssue), [@​YiuRULE](https://redirect.github.com/YiuRULE), [@​chayim](https://redirect.github.com/chayim), [@​dgilmanAIDENTIFIED](https://redirect.github.com/dgilmanAIDENTIFIED), [@​dvora-h](https://redirect.github.com/dvora-h), [@​kristjanvalur](https://redirect.github.com/kristjanvalur), [@​mohsinhaider](https://redirect.github.com/mohsinhaider), [@​raz-mon](https://redirect.github.com/raz-mon), [@​shacharPash](https://redirect.github.com/shacharPash), [@​stitchWzc](https://redirect.github.com/stitchWzc), [@​uglide](https://redirect.github.com/uglide), [@​vmihailenco](https://redirect.github.com/vmihailenco), [@​winmorre](https://redirect.github.com/winmorre) and [@​zakaf](https://redirect.github.com/zakaf) ### [`v4.4.0`](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.0): Version 4.4.0 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.3.6...v4.4.0) ### Changes [4.4.0rc4 release notes](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.0rc4) [4.4.0rc3 release notes](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.0rc3) [4.4.0rc2 release notes](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.0rc2) [4.4.0rc1 release notes](https://redirect.github.com/redis/redis-py/releases/tag/v4.4.0rc1) #### πŸš€ New Features (since 4.4.0rc4) - Async clusters: Support creating locks inside async functions ([#​2471](https://redirect.github.com/redis/redis-py/issues/2471)) #### πŸ› Bug Fixes (since 4.4.0rc4) - Async: added 'blocking' argument to call lock method ([#​2454](https://redirect.github.com/redis/redis-py/issues/2454)) - Added a replacement for the default cluster node in the event of failure. ([#​2463](https://redirect.github.com/redis/redis-py/issues/2463)) - Fixed geosearch: Wrong number of arguments for `geosearch` command ([#​2464](https://redirect.github.com/redis/redis-py/issues/2464)) #### 🧰 Maintenance (since 4.4.0rc4) - Updating dev dependencies ([#​2475](https://redirect.github.com/redis/redis-py/issues/2475)) - Removing deprecated LGTM ([#​2473](https://redirect.github.com/redis/redis-py/issues/2473)) - Added an explicit index name in RediSearch example ([#​2466](https://redirect.github.com/redis/redis-py/issues/2466)) - Adding connection step to bloom filter examples ([#​2478](https://redirect.github.com/redis/redis-py/issues/2478)) #### Contributors (since 4.4.0rc4) We'd like to thank all the contributors who worked on this release! [@​Sibuken](https://redirect.github.com/Sibuken), [@​barshaul](https://redirect.github.com/barshaul), [@​chayim](https://redirect.github.com/chayim), [@​dvora-h](https://redirect.github.com/dvora-h), [@​nermiller](https://redirect.github.com/nermiller), [@​uglide](https://redirect.github.com/uglide) and [@​utkarshgupta137](https://redirect.github.com/utkarshgupta137) ### [`v4.3.6`](https://redirect.github.com/redis/redis-py/releases/tag/v4.3.6): 4.3.6 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.3.5...v4.3.6) ### Changes Update urgency: HIGH: There is a critical bug that may affect a subset of users. Upgrade! #### πŸ› Bug Fixes - [CWE-404](https://cwe.mitre.org/data/definitions/404.html) AsyncIO Race Condition Fix ([#​2624](https://redirect.github.com/redis/redis-py/issues/2624), [#​2579](https://redirect.github.com/redis/redis-py/issues/2579)) ### [`v4.3.5`](https://redirect.github.com/redis/redis-py/releases/tag/v4.3.5): Version 4.3.5 [Compare Source](https://redirect.github.com/redis/redis-py/compare/v4.3.4...v4.3.5) ### Changes This is a maintenance release of redis-py, prior to the release of 4.4.0. This release contains both bug fixes, and features, keeping pace with the release of [redis-stack](https://redis.io/docs/stack/) capabilities. #### πŸš€ New Features - Add support for TIMESERIES 1.8 ([#​2296](https://redirect.github.com/redis/redis-py/issues/2296)) - Graph - add counters for removed labels and properties ([#​2292](https://redirect.github.com/redis/redis-py/issues/2292)) - Add support for TDIGEST.QUANTILE extensions ([#​2317](https://redirect.github.com/redis/redis-py/issues/2317)) - Add TDIGEST.TRIMMED_MEAN ([#​2300](https://redirect.github.com/redis/redis-py/issues/2300)) - Add support for async GRAPH module ([#​2273](https://redirect.github.com/redis/redis-py/issues/2273)) - Support TDIGEST.MERGESTORE and make compression optional on TDIGEST.CREATE ([#​2319](https://redirect.github.com/redis/redis-py/issues/2319)) - Adding reserve as an alias for create, so that we have BF.RESERVE and CF.RESERVE accuratenly supported ([#​2331](https://redirect.github.com/redis/redis-py/issues/2331)) #### πŸ› Bug Fixes - Fix async connection.is_connected to return a boolean value ([#​2278](https://redirect.github.com/redis/redis-py/issues/2278)) - Fix: workaround asyncio bug on connection reset by peer ([#​2259](https://redirect.github.com/redis/redis-py/issues/2259)) - Fix crash: key expire while search ([#​2270](https://redirect.github.com/redis/redis-py/issues/2270)) - Async cluster: fix concurrent pipeline ([#​2280](https://redirect.github.com/redis/redis-py/issues/2280)) - Fix async SEARCH pipeline ([#​2316](https://redirect.github.com/redis/redis-py/issues/2316)) - Fix KeyError in async cluster - initialize before execute multi key commands ([#​2439](https://redirect.github.com/redis/redis-py/issues/2439)) #### 🧰 Maintenance - Supply chain risk reduction: remove dependency on library named deprecated ([#​2386](https://redirect.github.com/redis/redis-py/issues/2386)) - Search test - Ignore order of the items in the response ([#​2322](https://redirect.github.com/redis/redis-py/issues/2322)) - Fix GRAPH.LIST & TDIGEST.QUANTILE tests ([#​2335](https://redirect.github.com/redis/redis-py/issues/2335)) - Fix TimeSeries range aggregation (twa) tests ([#​2358](https://redirect.github.com/redis/redis-py/issues/2358)) - Mark TOPK.COUNT as deprecated ([#​2363](https://redirect.github.com/redis/redis-py/issues/2363)) #### Contributors We'd like to thank all the contributors who worked on this release! [@​sileht](https://redirect.github.com/sileht), [@​utkarshgupta137](https://redirect.github.com/utkarshgupta137), [@​dvora-h](https://redirect.github.com/dvora-h), [@​akx](https://redirect.github.com/akx), [@​bodevone](https://redirect.github.com/bodevone), [@​chayim](https://redirect.github.com/chayim), [@​DvirDukhan](https://redirect.github.com/DvirDukhan)