Skip to content

Commit ecb8b35

Browse files
authored
🔒️ ⬆️ Maintenance/fixes security vulnerabilities in mako (ITISFoundation#3376)
1 parent 1e08132 commit ecb8b35

File tree

17 files changed

+110
-19
lines changed

17 files changed

+110
-19
lines changed

packages/models-library/requirements/_test.txt

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,10 @@ isort==5.10.1
6161
lazy-object-proxy==1.7.1
6262
# via astroid
6363
mako==1.2.2
64-
# via alembic
64+
# via
65+
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
66+
# -c requirements/../../../requirements/constraints.txt
67+
# alembic
6568
markupsafe==2.1.1
6669
# via mako
6770
mccabe==0.7.0

packages/postgres-database/requirements/_base.txt

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,9 @@ greenlet==1.1.3
1111
idna==3.3
1212
# via yarl
1313
mako==1.2.2
14-
# via alembic
14+
# via
15+
# -c requirements/../../../requirements/constraints.txt
16+
# alembic
1517
markupsafe==2.1.1
1618
# via mako
1719
multidict==6.0.2

packages/postgres-database/requirements/_migration.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ idna==3.3
2626
# requests
2727
mako==1.2.2
2828
# via
29+
# -c requirements/../../../requirements/constraints.txt
2930
# -c requirements/_base.txt
3031
# alembic
3132
markupsafe==2.1.1

packages/simcore-sdk/requirements/_base.txt

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,13 @@ jsonschema==3.2.0
5858
# -c requirements/../../../packages/service-library/requirements/./constraints.txt
5959
# -r requirements/../../../packages/models-library/requirements/_base.in
6060
mako==1.2.2
61-
# via alembic
61+
# via
62+
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
63+
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
64+
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
65+
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
66+
# -c requirements/../../../requirements/constraints.txt
67+
# alembic
6268
markupsafe==2.1.1
6369
# via mako
6470
multidict==6.0.2

packages/simcore-sdk/requirements/_test.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -105,6 +105,7 @@ lazy-object-proxy==1.7.1
105105
# via astroid
106106
mako==1.2.2
107107
# via
108+
# -c requirements/../../../requirements/constraints.txt
108109
# -c requirements/_base.txt
109110
# alembic
110111
markupsafe==2.1.1

requirements/constraints.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ aiohttp>=3.7.4 # https://github.com/advisories/GH
1212
cryptography>=3.3.2 # https://github.com/advisories/GHSA-rhm9-p9w5-fwm7 Feb.2021
1313
httpx>=0.23.0 # https://github.com/advisories/GHSA-h8pj-cxx2-jfg2 / CVE-2021-41945
1414
jinja2>=2.11.3 # https://github.com/advisories/GHSA-g3rq-g295-4j3m
15+
mako>=1.2.2 # https://github.com/advisories/GHSA-v973-fxgf-6xhp
1516
paramiko>=2.10.1 # https://github.com/advisories/GHSA-f8q4-jwww-x3wv
1617
pydantic>=1.8.2 # https://github.com/advisories/GHSA-5jqp-qgf6-3pvh
1718
pyyaml>=5.4 # https://github.com/advisories/GHSA-8q59-q68h-6hv4

services/api-server/requirements/_base.txt

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -164,8 +164,20 @@ jsonschema==3.2.0
164164
# -c requirements/./constraints.txt
165165
# -r requirements/../../../packages/models-library/requirements/_base.in
166166
# -r requirements/../../../packages/simcore-sdk/requirements/../../../packages/models-library/requirements/_base.in
167-
mako==1.2.0
168-
# via alembic
167+
mako==1.2.2
168+
# via
169+
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
170+
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
171+
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
172+
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
173+
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
174+
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
175+
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
176+
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
177+
# -c requirements/../../../packages/simcore-sdk/requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
178+
# -c requirements/../../../packages/simcore-sdk/requirements/../../../requirements/constraints.txt
179+
# -c requirements/../../../requirements/constraints.txt
180+
# alembic
169181
markupsafe==2.1.1
170182
# via
171183
# jinja2

services/api-server/requirements/_test.txt

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -170,8 +170,9 @@ junit-xml==1.9
170170
# via cfn-lint
171171
lazy-object-proxy==1.7.1
172172
# via astroid
173-
mako==1.2.0
173+
mako==1.2.2
174174
# via
175+
# -c requirements/../../../requirements/constraints.txt
175176
# -c requirements/_base.txt
176177
# alembic
177178
markupsafe==2.1.1

services/catalog/requirements/_base.txt

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -103,8 +103,15 @@ jsonschema==3.2.0
103103
# -c requirements/../../../packages/service-library/requirements/././constraints.txt
104104
# -c requirements/../../../packages/service-library/requirements/./constraints.txt
105105
# -r requirements/../../../packages/models-library/requirements/_base.in
106-
mako==1.1.5
107-
# via alembic
106+
mako==1.2.2
107+
# via
108+
# -c requirements/../../../packages/models-library/requirements/../../../requirements/constraints.txt
109+
# -c requirements/../../../packages/postgres-database/requirements/../../../requirements/constraints.txt
110+
# -c requirements/../../../packages/service-library/requirements/../../../requirements/constraints.txt
111+
# -c requirements/../../../packages/service-library/requirements/./../../../requirements/constraints.txt
112+
# -c requirements/../../../packages/settings-library/requirements/../../../requirements/constraints.txt
113+
# -c requirements/../../../requirements/constraints.txt
114+
# alembic
108115
markupsafe==2.1.1
109116
# via
110117
# jinja2

services/catalog/requirements/_test.txt

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -101,8 +101,9 @@ jsonschema==3.2.0
101101
# -r requirements/_test.in
102102
lazy-object-proxy==1.7.1
103103
# via astroid
104-
mako==1.1.5
104+
mako==1.2.2
105105
# via
106+
# -c requirements/../../../requirements/constraints.txt
106107
# -c requirements/_base.txt
107108
# alembic
108109
markupsafe==2.1.1

0 commit comments

Comments
 (0)