SocialGouv / recosante

https://recosante.beta.gouv.fr/
Apache License 2.0
6 stars 1 forks source link

fix(deps): update dependency uwsgi to v2.0.22 [security] #528

Closed renovate[bot] closed 4 months ago

renovate[bot] commented 4 months ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
uwsgi (changelog) 2.0.21 -> 2.0.22 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-27522

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

SocialGroovyBot commented 1 month ago

:tada: This PR is included in version 1.37.0 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: