From 614ef659a61bd1fccc0af4241bf60b69e87f5706 Mon Sep 17 00:00:00 2001 From: Lon Hohberger Date: Mon, 9 Jan 2023 16:20:41 -0500 Subject: [PATCH] Bump GitPython to 3.1.30 3.1.30 includes 2 sets of fixes for CVE-2022-24439: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24439 https://github.com/gitpython-developers/GitPython/issues/1515 PRs: https://github.com/gitpython-developers/GitPython/pull/1518 https://github.com/gitpython-developers/GitPython/pull/1521 Signed-off-by: Lon Hohberger Change-Id: I0def2d9801f0b20fcc9b613165a29dbced1fd2d7 --- upper-constraints.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/upper-constraints.txt b/upper-constraints.txt index 95ea89337..29270ae8a 100644 --- a/upper-constraints.txt +++ b/upper-constraints.txt @@ -463,7 +463,7 @@ testresources===2.0.1 falcon===3.1.0 etcd3gw===2.1.0 Flask-RESTful===0.3.9 -GitPython===3.1.28 +GitPython===3.1.30 python-ironicclient===5.0.1 XStatic===1.0.2 XStatic-Angular-FileUpload===12.0.4.0