Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 May 2019 15:12:03 +0000
From:      bugzilla-noreply@freebsd.org
To:        python@FreeBSD.org
Subject:   [Bug 237501] devel/py-yaml: Update to 5.1
Message-ID:  <bug-237501-21822-hGKPb9xZb6@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-237501-21822@https.bugs.freebsd.org/bugzilla/>
References:  <bug-237501-21822@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D237501

--- Comment #9 from commit-hook@freebsd.org ---
A commit references this bug:

Author: jpaetzel
Date: Wed May 29 15:11:11 UTC 2019
New revision: 502966
URL: https://svnweb.freebsd.org/changeset/ports/502966

Log:
  MFH: r499857

  Update to 5.1

  https://github.com/yaml/pyyaml/blob/5.1/announcement.msg

  =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
   Announcing PyYAML-5.1
  =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

  A new MAJOR RELEASE of PyYAML is now available:
  https://pypi.org/project/PyYAML/

  This is the first major release of PyYAML under the new maintenance team.

  Among the many changes listed below, this release specifically addresses =
the
  arbitrary code execution issue raised by:

      https://nvd.nist.gov/vuln/detail/CVE-2017-18342

  (See https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecat=
ion
  for complete details).
  ...

  PR:   237501
  Reported by:  sergey@akhmatov.ru

  Approved by:  ports-secteam (joneum)
  Security:     f6ea18bb-65b9-11e9-8b31-002590045d9c

Changes:
_U  branches/2019Q2/
  branches/2019Q2/devel/py-yaml/Makefile
  branches/2019Q2/devel/py-yaml/distinfo

--=20
You are receiving this mail because:
You are on the CC list for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-237501-21822-hGKPb9xZb6>