pluralsh / plural

Deploy open source software on Kubernetes in record time. šŸš€
https://www.plural.sh
Other
1.35k stars 64 forks source link

chore(deps): update dependency tqdm to v4.66.3 [security] #1305

Open plural-renovate[bot] opened 3 months ago

plural-renovate[bot] commented 3 months ago

This PR contains the following updates:

Package Update Change
tqdm (changelog) minor ==4.65.0 -> ==4.66.3

GitHub Vulnerability Alerts

CVE-2024-34062

Impact

Any optional non-boolean CLI arguments (e.g. --delim, --buf-size, --manpath) are passed through python's eval, allowing arbitrary code execution. Example:

python -m tqdm --manpath="\" + str(exec(\"import os\nos.system('echo hi && killall python3')\")) + \""

Patches

https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316 released in tqdm>=4.66.3

Workarounds

None

References


Release Notes

tqdm/tqdm (tqdm) ### [`v4.66.3`](https://togithub.com/tqdm/tqdm/releases/tag/v4.66.3): tqdm v4.66.3 stable [Compare Source](https://togithub.com/tqdm/tqdm/compare/v4.66.2...v4.66.3) - `cli`: `eval` safety (fixes CVE-2024-34062, GHSA-g7vv-2v7x-gj9p) ### [`v4.66.2`](https://togithub.com/tqdm/tqdm/releases/tag/v4.66.2): tqdm v4.66.2 stable [Compare Source](https://togithub.com/tqdm/tqdm/compare/v4.66.1...v4.66.2) - `pandas`: add `DataFrame.progress_map` ([#​1549](https://togithub.com/tqdm/tqdm/issues/1549)) - `notebook`: fix HTML padding ([#​1506](https://togithub.com/tqdm/tqdm/issues/1506)) - `keras`: fix resuming training when `verbose>=2` ([#​1508](https://togithub.com/tqdm/tqdm/issues/1508)) - fix `format_num` negative fractions missing leading zero ([#​1548](https://togithub.com/tqdm/tqdm/issues/1548)) - fix Python 3.12 `DeprecationWarning` on `import` ([#​1519](https://togithub.com/tqdm/tqdm/issues/1519)) - linting: use f-strings ([#​1549](https://togithub.com/tqdm/tqdm/issues/1549)) - update tests ([#​1549](https://togithub.com/tqdm/tqdm/issues/1549)) - fix `pandas` warnings - fix `asv` ([https://github.com/airspeed-velocity/asv/issues/1323](https://togithub.com/airspeed-velocity/asv/issues/1323)) - fix macos `notebook` docstring indentation - CI: bump actions ([#​1549](https://togithub.com/tqdm/tqdm/issues/1549)) ### [`v4.66.1`](https://togithub.com/tqdm/tqdm/releases/tag/v4.66.1): tqdm v4.66.1 stable [Compare Source](https://togithub.com/tqdm/tqdm/compare/v4.66.0...v4.66.1) - fix `utils.envwrap` types ([#​1493](https://togithub.com/tqdm/tqdm/issues/1493) <- [#​1491](https://togithub.com/tqdm/tqdm/issues/1491), [#​1320](https://togithub.com/tqdm/tqdm/issues/1320) <- [#​966](https://togithub.com/tqdm/tqdm/issues/966), [#​1319](https://togithub.com/tqdm/tqdm/issues/1319)) - e.g. cloudwatch & kubernetes workaround: `export TQDM_POSITION=-1` - drop mentions of unsupported Python versions ### [`v4.66.0`](https://togithub.com/tqdm/tqdm/releases/tag/v4.66.0): tqdm v4.66.0 stable [Compare Source](https://togithub.com/tqdm/tqdm/compare/v4.65.2...v4.66.0) - environment variables to override defaults (`TQDM_*`) ([#​1491](https://togithub.com/tqdm/tqdm/issues/1491) <- [#​1061](https://togithub.com/tqdm/tqdm/issues/1061), [#​950](https://togithub.com/tqdm/tqdm/issues/950) <- [#​614](https://togithub.com/tqdm/tqdm/issues/614), [#​1318](https://togithub.com/tqdm/tqdm/issues/1318), [#​619](https://togithub.com/tqdm/tqdm/issues/619), [#​612](https://togithub.com/tqdm/tqdm/issues/612), [#​370](https://togithub.com/tqdm/tqdm/issues/370)) - e.g. in CI jobs, `export TQDM_MININTERVAL=5` to avoid log spam - add tests & docs for `tqdm.utils.envwrap` - fix & update CLI completion - fix & update API docs - minor code tidy: replace `os.path` => `pathlib.Path` - fix docs image hosting - release with CI bot account again ([https://github.com/cli/cli/issues/6680](https://togithub.com/cli/cli/issues/6680)) ### [`v4.65.2`](https://togithub.com/tqdm/tqdm/releases/tag/v4.65.2): tqdm v4.65.2 stable [Compare Source](https://togithub.com/tqdm/tqdm/compare/v4.65.1...v4.65.2) - exclude `examples` from distributed wheel ([#​1492](https://togithub.com/tqdm/tqdm/issues/1492)) ### [`v4.65.1`](https://togithub.com/tqdm/tqdm/releases/tag/v4.65.1): tqdm v4.65.1 stable [Compare Source](https://togithub.com/tqdm/tqdm/compare/v4.65.0...v4.65.1) - migrate `setup.{cfg,py}` => `pyproject.toml` ([#​1490](https://togithub.com/tqdm/tqdm/issues/1490)) - fix `asv` benchmarks - update docs - fix snap build ([#​1490](https://togithub.com/tqdm/tqdm/issues/1490)) - fix & update tests ([#​1490](https://togithub.com/tqdm/tqdm/issues/1490)) - fix flaky notebook tests - bump `pre-commit` - bump workflow actions

Configuration

šŸ“… Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

šŸš¦ Automerge: Disabled by config. Please merge this manually once you are satisfied.

ā™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

šŸ”• Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Renovate Bot.

stoat-app[bot] commented 3 months ago

Easy and customizable dashboards for your build system. Learn more about Stoat ā†—ļøŽ

Static Hosting

Name Link Commit Status
api-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
rtc-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
core-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
cron-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
email-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
worker-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
api-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
graphql-coverage Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
rtc-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
core-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
cron-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
email-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
worker-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…
graphql-test-results Visit 5dcdd2a23b9678973d5b6489475312c81f855d56 āœ…

Job Runtime

job runtime chart

debug

stoat-app[bot] commented 3 months ago

Easy and customizable dashboards for your build system. Learn more about Stoat ā†—ļøŽ

Static Hosting

Name Link Commit Status
api-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
rtc-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
core-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
cron-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
email-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
worker-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
api-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
graphql-coverage Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
rtc-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
core-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
cron-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
email-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
worker-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…
graphql-test-results Visit 9d0a3694ae69bcd6405010fc3371714415c23eab āœ…

Job Runtime

job runtime chart

debug