googleapis / python-crc32c

Apache License 2.0
24 stars 27 forks source link

chore(deps): update dependency pip to v23.3 [security] #180

Closed renovate-bot closed 11 months ago

renovate-bot commented 11 months ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
pip (source, changelog) ==23.2.1 -> ==23.3 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-5752

When installing a package from a Mercurial VCS URL, e.g. pip install hg+..., with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the hg clone call (e.g. --config). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.


Release Notes

pypa/pip (pip) ### [`v23.3`](https://togithub.com/pypa/pip/compare/23.2.1...23.3) [Compare Source](https://togithub.com/pypa/pip/compare/23.2.1...23.3)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.