From 6f1e83065c7cbc99efcbc67d9d2b6822750aeadb Mon Sep 17 00:00:00 2001 From: Peter Korsgaard Date: Mon, 30 Oct 2023 22:52:24 +0100 Subject: [PATCH] package/python-urllib3: security bump to version 1.26.18 Fixes CVE-2023-43804 and CVE-2023-45803 https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4 Signed-off-by: Peter Korsgaard --- package/python-urllib3/python-urllib3.hash | 4 ++-- package/python-urllib3/python-urllib3.mk | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/package/python-urllib3/python-urllib3.hash b/package/python-urllib3/python-urllib3.hash index 963967332e..aa42f1a711 100644 --- a/package/python-urllib3/python-urllib3.hash +++ b/package/python-urllib3/python-urllib3.hash @@ -1,5 +1,5 @@ # md5, sha256 from https://pypi.org/pypi/urllib3/json -md5 38f7d1589aa9720101316d07fcbd05c8 urllib3-1.26.13.tar.gz -sha256 c083dd0dce68dbfbe1129d5271cb90f9447dea7d52097c6e0126120c521ddea8 urllib3-1.26.13.tar.gz +md5 f986d8e9616d2a43389f678d5dad9893 urllib3-1.26.18.tar.gz +sha256 f8ecc1bba5667413457c529ab955bf8c67b45db799d159066261719e328580a0 urllib3-1.26.18.tar.gz # Locally computed sha256 checksums sha256 c37bf186e27cf9dbe9619e55edfe3cea7b30091ceb3da63c7dacbe0e6d77907b LICENSE.txt diff --git a/package/python-urllib3/python-urllib3.mk b/package/python-urllib3/python-urllib3.mk index 5868927440..b22a11361f 100644 --- a/package/python-urllib3/python-urllib3.mk +++ b/package/python-urllib3/python-urllib3.mk @@ -4,9 +4,9 @@ # ################################################################################ -PYTHON_URLLIB3_VERSION = 1.26.13 +PYTHON_URLLIB3_VERSION = 1.26.18 PYTHON_URLLIB3_SOURCE = urllib3-$(PYTHON_URLLIB3_VERSION).tar.gz -PYTHON_URLLIB3_SITE = https://files.pythonhosted.org/packages/c2/51/32da03cf19d17d46cce5c731967bf58de9bd71db3a379932f53b094deda4 +PYTHON_URLLIB3_SITE = https://files.pythonhosted.org/packages/0c/39/64487bf07df2ed854cc06078c27c0d0abc59bd27b32232876e403c333a08 PYTHON_URLLIB3_LICENSE = MIT PYTHON_URLLIB3_LICENSE_FILES = LICENSE.txt PYTHON_URLLIB3_CPE_ID_VENDOR = python