tbrittain / vault-bot

Collaborative, unique music management and tracking application using Discord and Spotify
https://www.tbrittain.com/projects/vaultbot
1 stars 0 forks source link

Bump spotipy from 2.22.0 to 2.22.1 in /discord #682

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps spotipy from 2.22.0 to 2.22.1.

Release notes

Sourced from spotipy's releases.

2.22.1: CVE-2023-23608

Fixed

Changed

  • Modified docstring for deprecated playlist_add_items() to accept "only URIs or URLs", with intended fix for IDs in v3.
    • The bug still exists for developers dealing with episodes IDs rather than just track IDs. However it is recommended to use the new playlist_add_tracks() or playlist_add_episodes() if dealing with episodes or simply to avoid confusion. See spotipy-dev/spotipy#919 by @​oliveraw for context
Changelog

Sourced from spotipy's changelog.

[2.22.1] - 2023-01-23

Added

  • Add alternative module installation instruction to README
  • Added Comment to README - Getting Started for user to add URI to app in Spotify Developer Dashboard.
  • Added playlist_add_tracks.py to example folder

Changed

  • Modified docstring for playlist_add_items() to accept "only URIs or URLs", with intended deprecation for IDs in v3

Fixed

  • Path traversal vulnerability that may lead to type confusion in URI handling code
  • Update contributing.md
Commits
  • c53511b Bump to 2.22.1
  • beec3da Fix flake8
  • b1db0b6 Merge pull request from GHSA-q764-g6fm-555v
  • 262e7a0 Rename simple files (#933)
  • d884ae1 Fix typo in start_playback function (#930)
  • f669966 Update SECURITY.md
  • 0b90627 Create SECURITY.md
  • d0bbe67 Add additional video tutorial reference to documentation. (#921)
  • 922d51d modified docstring for playlist_add_items to no longer accept IDs
  • edd3f29 Getting Started Clarifications and Example Code File (#904)
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)