ad6321660c
- A vulnerability (GHSL-2021-1038) in the HTML cleaner allowed sneaking script content through SVG images (CVE-2021-43818). - A vulnerability (GHSL-2021-1037) in the HTML cleaner allowed sneaking script content through CSS imports and other crafted constructs (CVE-2021-43818). https://github.com/lxml/lxml/blob/lxml-4.6.5/CHANGES.txt Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
39 lines
1.4 KiB
Makefile
39 lines
1.4 KiB
Makefile
################################################################################
|
|
#
|
|
# python-lxml
|
|
#
|
|
################################################################################
|
|
|
|
PYTHON_LXML_VERSION = 4.6.5
|
|
PYTHON_LXML_SITE = https://files.pythonhosted.org/packages/e6/e1/34b3ab08553fe9a30e15b2bb9d1803a49d7d907dd9f245638839190042f0
|
|
PYTHON_LXML_SOURCE = lxml-$(PYTHON_LXML_VERSION).tar.gz
|
|
|
|
# Not including the GPL, because it is used only for the test scripts.
|
|
PYTHON_LXML_LICENSE = BSD-3-Clause, Others
|
|
PYTHON_LXML_LICENSE_FILES = \
|
|
LICENSES.txt \
|
|
doc/licenses/BSD.txt \
|
|
doc/licenses/elementtree.txt \
|
|
src/lxml/isoschematron/resources/rng/iso-schematron.rng
|
|
PYTHON_LXML_CPE_ID_VENDOR = lxml
|
|
PYTHON_LXML_CPE_ID_PRODUCT = lxml
|
|
|
|
# python-lxml can use either setuptools, or distutils as a fallback.
|
|
# So, we use setuptools.
|
|
PYTHON_LXML_SETUP_TYPE = setuptools
|
|
|
|
PYTHON_LXML_DEPENDENCIES = libxml2 libxslt zlib
|
|
HOST_PYTHON_LXML_DEPENDENCIES = host-libxml2 host-libxslt host-zlib
|
|
|
|
# python-lxml needs these scripts in order to properly detect libxml2 and
|
|
# libxslt compiler and linker flags
|
|
PYTHON_LXML_BUILD_OPTS = \
|
|
--xslt-config=$(STAGING_DIR)/usr/bin/xslt-config \
|
|
--xml2-config=$(STAGING_DIR)/usr/bin/xml2-config
|
|
HOST_PYTHON_LXML_BUILD_OPTS = \
|
|
--xslt-config=$(HOST_DIR)/bin/xslt-config \
|
|
--xml2-config=$(HOST_DIR)/bin/xml2-config
|
|
|
|
$(eval $(python-package))
|
|
$(eval $(host-python-package))
|