From 84d6d12fd89588a0855d7cb015b898cd66b6a0c6 Mon Sep 17 00:00:00 2001 From: Leon Anavi Date: Fri, 26 Jun 2020 14:29:35 +0300 Subject: [PATCH] python3-httplib2: Upgrade 0.17.3 -> 0.18.1 Upgrade to release 0.18.1: - explicit build-backend workaround for pip build isolation bug "AttributeError: 'module' object has no attribute '__legacy__'" on pip install https://github.com/httplib2/httplib2/issues/169 - IMPORTANT security vulnerability CWE-93 CRLF injection Force %xx quote of space, CR, LF characters in uri. https://cwe.mitre.org/data/definitions/93.html PKG-INFO md5 checksum changed, the license remains the same. Signed-off-by: Leon Anavi Acked-by: Trevor Gamblin Signed-off-by: Khem Raj --- ...ython3-httplib2_0.17.3.bb => python3-httplib2_0.18.1.bb} | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) rename meta-python/recipes-devtools/python/{python3-httplib2_0.17.3.bb => python3-httplib2_0.18.1.bb} (52%) diff --git a/meta-python/recipes-devtools/python/python3-httplib2_0.17.3.bb b/meta-python/recipes-devtools/python/python3-httplib2_0.18.1.bb similarity index 52% rename from meta-python/recipes-devtools/python/python3-httplib2_0.17.3.bb rename to meta-python/recipes-devtools/python/python3-httplib2_0.18.1.bb index 57047c9ac6b..9c9b6c5b015 100644 --- a/meta-python/recipes-devtools/python/python3-httplib2_0.17.3.bb +++ b/meta-python/recipes-devtools/python/python3-httplib2_0.18.1.bb @@ -2,9 +2,9 @@ SUMMARY = "A comprehensive HTTP client library, httplib2 supports many features HOMEPAGE = "https://github.com/httplib2/httplib2" SECTION = "devel/python" LICENSE = "MIT" -LIC_FILES_CHKSUM = "file://PKG-INFO;md5=4edb3f072a9d815734530f608039a167" +LIC_FILES_CHKSUM = "file://PKG-INFO;md5=7e04d1303d64a7b62421751ecb490dc2" -SRC_URI[md5sum] = "5730490cfe83350477b54b0a8a190c8a" -SRC_URI[sha256sum] = "39dd15a333f67bfb70798faa9de8a6e99c819da6ad82b77f9a259a5c7b1225a2" +SRC_URI[md5sum] = "0b331f96cdb2ae0e0342d4ea0f5f0502" +SRC_URI[sha256sum] = "8af66c1c52c7ffe1aa5dc4bcd7c769885254b0756e6e69f953c7f0ab49a70ba3" inherit pypi setuptools3