From 17694824fa9547a459ca83f121c4e881bb146e94 Mon Sep 17 00:00:00 2001 From: MarleneKress79789 Date: Fri, 24 Nov 2023 12:48:50 +0100 Subject: [PATCH] prepare release --- doc/changes/changelog.md | 1 + doc/changes/changes_0.18.1.md | 13 +++++++++++++ pyproject.toml | 2 +- .../test_container/full/build/deps/requirements.txt | 2 +- 4 files changed, 16 insertions(+), 2 deletions(-) create mode 100644 doc/changes/changes_0.18.1.md diff --git a/doc/changes/changelog.md b/doc/changes/changelog.md index 90670829..ad256c00 100644 --- a/doc/changes/changelog.md +++ b/doc/changes/changelog.md @@ -1,5 +1,6 @@ # Changes +* [0.18.1](changes_0.18.1.md) * [0.18.0](changes_0.18.0.md) * [0.17.0](changes_0.17.0.md) * [0.16.0](changes_0.16.0.md) diff --git a/doc/changes/changes_0.18.1.md b/doc/changes/changes_0.18.1.md new file mode 100644 index 00000000..e1669d1c --- /dev/null +++ b/doc/changes/changes_0.18.1.md @@ -0,0 +1,13 @@ +# Script-Languages-Container-Tool 0.18.0, released 2023-11-24 + +Code name: Configobj moved + +## Summary + +This release moves configobj from dependencies to dev dependencies so the security alert +regarding ReDoS exploit does not propagate + +## Security + + - moved configobj to dev dependencies + diff --git a/pyproject.toml b/pyproject.toml index 5e23320c..5a53498b 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [tool.poetry] name = "exasol-script-languages-container-tool" -version = "0.18.0" +version = "0.18.1" description = "Script Languages Container Tool" license = "MIT" diff --git a/test/resources/test_container/full/build/deps/requirements.txt b/test/resources/test_container/full/build/deps/requirements.txt index babfe230..c32a64a5 100644 --- a/test/resources/test_container/full/build/deps/requirements.txt +++ b/test/resources/test_container/full/build/deps/requirements.txt @@ -1,4 +1,4 @@ -pyodbc>=4.0.27 +pyodbc<5.0.0 pytz lxml docker