Skip to content

Conversation

@sbkok
Copy link
Collaborator

@sbkok sbkok commented Mar 26, 2021

Why?

A vulnerability was reported on v2.11.2 of Jinja2, as reported per
CVE-2020-28493. Since we make use of this dependency, we need to link to
the version that resolved this issue.

Since ADF does not use the urlize that is impacted, it is not at risk.
Hence it is not required to release a new version or update your ADF
installation.

What?

Updated to 2.11.3.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

**Why?**

A vulnerability was reported on v2.11.2 of Jinja2, as reported per
CVE-2020-28493. Since we make use of this dependency, we need to link to
the version that resolved this issue.

Since ADF does not use the `urlize` that is impacted, it is not at risk.
Hence it is not required to release a new version or update your ADF
installation.

**What?**

Updated to 2.11.3.
Copy link

@deltagarrett deltagarrett left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Collaborator

@thomasmcgannon thomasmcgannon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sbkok sbkok merged commit 7abdb8c into awslabs:master Apr 7, 2021
@sbkok sbkok deleted the update-jinja2-dep branch April 7, 2021 15:34
@sbkok sbkok added this to the v3.2.0 milestone Nov 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants