Skip to content

Commit

Permalink
package/python-pyyaml: security bump to version 5.3.1
Browse files Browse the repository at this point in the history
Fixes the following security issue:

 386: Prevents arbitrary code execution during python/object/new
 constructor

yaml/pyyaml#386

The hash of the license file changed due to the following diff:

-Copyright (c) 2017-2019 Ingy döt Net
+Copyright (c) 2017-2020 Ingy döt Net

Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 9063df4)
[Peter: mention security impact]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
  • Loading branch information
jameshilliard authored and jacmet committed Apr 7, 2020
1 parent e11ad9e commit ae0bca6
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 5 deletions.
6 changes: 3 additions & 3 deletions package/python-pyyaml/python-pyyaml.hash
@@ -1,5 +1,5 @@
# md5, sha256 from https://pypi.org/pypi/PyYAML/json
md5 adbb0d336b509d6472d3b095a0f1cf30 PyYAML-5.3.tar.gz
sha256 e9f45bd5b92c7974e59bcd2dcc8631a6b6cc380a904725fce7bc08872e691615 PyYAML-5.3.tar.gz
md5 d3590b85917362e837298e733321962b PyYAML-5.3.1.tar.gz
sha256 b8eac752c5e14d3eca0e6dd9199cd627518cb5ec06add0de9d32baeee6fe645d PyYAML-5.3.1.tar.gz
# Locally computed sha256 checksums
sha256 a2adb9c959b797494a0ef80bdf60e22db2749ee3e0c0908556e3eb548f967c56 LICENSE
sha256 c40112449f254b9753045925248313e9270efa36d226b22d82d4cc6c43c57f29 LICENSE
4 changes: 2 additions & 2 deletions package/python-pyyaml/python-pyyaml.mk
Expand Up @@ -4,9 +4,9 @@
#
################################################################################

PYTHON_PYYAML_VERSION = 5.3
PYTHON_PYYAML_VERSION = 5.3.1
PYTHON_PYYAML_SOURCE = PyYAML-$(PYTHON_PYYAML_VERSION).tar.gz
PYTHON_PYYAML_SITE = https://files.pythonhosted.org/packages/3d/d9/ea9816aea31beeadccd03f1f8b625ecf8f645bd66744484d162d84803ce5
PYTHON_PYYAML_SITE = https://files.pythonhosted.org/packages/64/c2/b80047c7ac2478f9501676c988a5411ed5572f35d1beff9cae07d321512c
PYTHON_PYYAML_SETUP_TYPE = distutils
PYTHON_PYYAML_LICENSE = MIT
PYTHON_PYYAML_LICENSE_FILES = LICENSE
Expand Down

0 comments on commit ae0bca6

Please sign in to comment.