Skip to content

Conversation

@blag
Copy link
Collaborator

@blag blag commented Jan 30, 2019

This PR updates the dependency version constraints in setup.py to match those in requirements.txt.

This is mostly to update to a 4.2b version of PyYAML due to CVE-2017-18342, and eventually allow updating to version 5.1+, especially because the 4.2b versions will likely be removed from PyPI once 5.1 is released (source).

Removing maximum version constraints lowers our maintenance burden.

@Kami
Copy link
Collaborator

Kami commented Jan 30, 2019

LGTM, thanks for working on this 👍

All the tests pass so we should be good to go.

@Kami
Copy link
Collaborator

Kami commented Jan 31, 2019

Related PR for another dependency upgrade - #211.

@blag blag merged commit bef0ef7 into master Feb 1, 2019
@blag blag deleted the pyyaml_pin_fix branch February 1, 2019 21:14
@blag blag mentioned this pull request Feb 1, 2019
@blag blag mentioned this pull request Feb 12, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants