Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Nov 20, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
jupyter-core ==4.9.1 -> ==4.11.2 age adoption passing confidence

⚠ Dependency Lookup Warnings ⚠

Warnings were logged while processing this repo. Please check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2022-39286

Impact

What kind of vulnerability is it? Who is impacted?
We’d like to disclose an arbitrary code execution vulnerability in jupyter_core that stems from jupyter_core executing untrusted files in the current working directory. This vulnerability allows one user to run code as another.

Patches

Has the problem been patched? What versions should users upgrade to?
Users should upgrade to jupyter_core>=4.11.2.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?
No

References

Are there any links users can visit to find out more?
Similar advisory in IPython


Release Notes

jupyter/jupyter_core

v4.11.2

Compare Source

v4.11.1

Compare Source

on GitHub

  • Fix inclusion of jupyter file and check in CI.
    (#​276)

v4.11.0

Compare Source

on GitHub

  • Use hatch build backend. (#​265)
  • is_hidden: Use normalized paths. (#​271)

v4.10.0

Compare Source

on GitHub

  • Include all files from jupyter_core. (#​253)
  • Add project URLs to setup.cfg. (#​254)
  • Set up pre-commit. (#​255)
  • Add flake8 and mypy settings. (#​256)
  • Clean up CI. (#​258)

v4.9.2

Compare Source

on GitHub

  • Set proper sys.argv[0] for subcommand. (#​248)
  • Add explicit encoding in open calls. (#​249)
  • jupyter_config_dir - reorder home_dir initialization.
    (#​251)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@github-actions
Copy link

Stale pull request message

@renovate
Copy link
Author

renovate bot commented Jan 27, 2023

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (==4.11.2). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/pypi-jupyter-core-vulnerability branch January 27, 2023 23:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant