Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 24 Apr 2019 15:34:45 +0000
From:      bugzilla-noreply@freebsd.org
To:        python@FreeBSD.org
Subject:   [Bug 237501] devel/py-yaml: Update to 5.1
Message-ID:  <bug-237501-21822-vbcucT6DjN@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-237501-21822@https.bugs.freebsd.org/bugzilla/>
References:  <bug-237501-21822@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D237501

--- Comment #4 from commit-hook@freebsd.org ---
A commit references this bug:

Author: jpaetzel
Date: Wed Apr 24 15:33:51 UTC 2019
New revision: 499857
URL: https://svnweb.freebsd.org/changeset/ports/499857

Log:
  Update to 5.1

  https://github.com/yaml/pyyaml/blob/5.1/announcement.msg

  =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
   Announcing PyYAML-5.1
  =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

  A new MAJOR RELEASE of PyYAML is now available:
  https://pypi.org/project/PyYAML/

  This is the first major release of PyYAML under the new maintenance team.

  Among the many changes listed below, this release specifically addresses =
the
  arbitrary code execution issue raised by:

      https://nvd.nist.gov/vuln/detail/CVE-2017-18342

  (See https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecat=
ion
  for complete details).
  ...

  PR:   237501
  Reported by:  sergey@akhmatov.ru

Changes:
  head/devel/py-yaml/Makefile
  head/devel/py-yaml/distinfo

--=20
You are receiving this mail because:
You are on the CC list for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-237501-21822-vbcucT6DjN>