mirror of
https://github.com/ansible/awx.git
synced 2026-05-20 15:27:47 -02:30
Fix CVEs and bump receptorctl (#14925)
CVE-2023-47627 CVE-2023-49083 CVE-2023-41040 CVE-2024-22195 CVE-2023-46137
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
aiohttp
|
aiohttp>=3.8.6 # CVE-2023-47627
|
||||||
ansiconv==1.0.0 # UPGRADE BLOCKER: from 2013, consider replacing instead of upgrading
|
ansiconv==1.0.0 # UPGRADE BLOCKER: from 2013, consider replacing instead of upgrading
|
||||||
asciichartpy
|
asciichartpy
|
||||||
asn1
|
asn1
|
||||||
@@ -8,7 +8,7 @@ boto3
|
|||||||
botocore
|
botocore
|
||||||
channels
|
channels
|
||||||
channels-redis==3.4.1 # see UPGRADE BLOCKERs
|
channels-redis==3.4.1 # see UPGRADE BLOCKERs
|
||||||
cryptography>=41.0.2 # CVE-2023-38325
|
cryptography>=41.0.6 # CVE-2023-49083
|
||||||
Cython<3 # this is needed as a build dependency, one day we may have separated build deps
|
Cython<3 # this is needed as a build dependency, one day we may have separated build deps
|
||||||
daphne
|
daphne
|
||||||
distro
|
distro
|
||||||
@@ -26,15 +26,15 @@ django-split-settings==1.0.0 # We hit a strange issue where the release proce
|
|||||||
djangorestframework
|
djangorestframework
|
||||||
djangorestframework-yaml
|
djangorestframework-yaml
|
||||||
filelock
|
filelock
|
||||||
GitPython>=3.1.32 # CVE-2023-40267
|
GitPython>=3.1.37 # CVE-2023-41040
|
||||||
hiredis==2.0.0 # see UPGRADE BLOCKERs
|
hiredis==2.0.0 # see UPGRADE BLOCKERs
|
||||||
irc
|
irc
|
||||||
jinja2
|
jinja2>=3.1.3 # CVE-2024-22195
|
||||||
JSON-log-formatter
|
JSON-log-formatter
|
||||||
jsonschema
|
jsonschema
|
||||||
Markdown # used for formatting API help
|
Markdown # used for formatting API help
|
||||||
openshift
|
openshift
|
||||||
pexpect==4.7.0 # see library notes
|
pexpect==4.7.0 # see library notes
|
||||||
prometheus_client
|
prometheus_client
|
||||||
psycopg
|
psycopg
|
||||||
psutil
|
psutil
|
||||||
@@ -49,20 +49,20 @@ pyyaml>=6.0.1
|
|||||||
receptorctl
|
receptorctl
|
||||||
social-auth-core[openidconnect]==4.4.2 # see UPGRADE BLOCKERs
|
social-auth-core[openidconnect]==4.4.2 # see UPGRADE BLOCKERs
|
||||||
social-auth-app-django==5.4.0 # see UPGRADE BLOCKERs
|
social-auth-app-django==5.4.0 # see UPGRADE BLOCKERs
|
||||||
sqlparse >= 0.4.4 # Required by django https://github.com/ansible/awx/security/dependabot/96
|
sqlparse>=0.4.4 # Required by django https://github.com/ansible/awx/security/dependabot/96
|
||||||
redis
|
redis
|
||||||
requests
|
requests
|
||||||
slack-sdk
|
slack-sdk
|
||||||
tacacs_plus==1.0 # UPGRADE BLOCKER: auth does not work with later versions
|
tacacs_plus==1.0 # UPGRADE BLOCKER: auth does not work with later versions
|
||||||
twilio
|
twilio
|
||||||
twisted[tls]
|
twisted[tls]>=23.10.0 # CVE-2023-46137
|
||||||
uWSGI
|
uWSGI
|
||||||
uwsgitop
|
uwsgitop
|
||||||
wheel>=0.38.1 # CVE-2022-40898
|
wheel>=0.38.1 # CVE-2022-40898
|
||||||
pip==21.2.4 # see UPGRADE BLOCKERs
|
pip==21.2.4 # see UPGRADE BLOCKERs
|
||||||
setuptools # see UPGRADE BLOCKERs
|
setuptools # see UPGRADE BLOCKERs
|
||||||
setuptools_scm[toml] # see UPGRADE BLOCKERs, xmlsec build dep
|
setuptools_scm[toml] # see UPGRADE BLOCKERs, xmlsec build dep
|
||||||
setuptools-rust >= 0.11.4 # cryptography build dep
|
setuptools-rust>=0.11.4 # cryptography build dep
|
||||||
pkgconfig>=1.5.1 # xmlsec build dep - needed for offline build
|
pkgconfig>=1.5.1 # xmlsec build dep - needed for offline build
|
||||||
|
|
||||||
# Temporarily added to use ansible-runner from git branch, to be removed
|
# Temporarily added to use ansible-runner from git branch, to be removed
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
adal==1.2.7
|
adal==1.2.7
|
||||||
# via msrestazure
|
# via msrestazure
|
||||||
aiohttp==3.8.3
|
aiohttp==3.9.3
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
aioredis==1.3.1
|
aioredis==1.3.1
|
||||||
# via channels-redis
|
# via channels-redis
|
||||||
@@ -70,14 +70,12 @@ channels==3.0.5
|
|||||||
channels-redis==3.4.1
|
channels-redis==3.4.1
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
charset-normalizer==2.1.1
|
charset-normalizer==2.1.1
|
||||||
# via
|
# via requests
|
||||||
# aiohttp
|
|
||||||
# requests
|
|
||||||
click==8.1.3
|
click==8.1.3
|
||||||
# via receptorctl
|
# via receptorctl
|
||||||
constantly==15.1.0
|
constantly==15.1.0
|
||||||
# via twisted
|
# via twisted
|
||||||
cryptography==41.0.3
|
cryptography==41.0.7
|
||||||
# via
|
# via
|
||||||
# -r /awx_devel/requirements/requirements.in
|
# -r /awx_devel/requirements/requirements.in
|
||||||
# adal
|
# adal
|
||||||
@@ -163,7 +161,7 @@ frozenlist==1.3.3
|
|||||||
# aiosignal
|
# aiosignal
|
||||||
gitdb==4.0.10
|
gitdb==4.0.10
|
||||||
# via gitpython
|
# via gitpython
|
||||||
gitpython==3.1.32
|
gitpython==3.1.42
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
google-auth==2.14.1
|
google-auth==2.14.1
|
||||||
# via kubernetes
|
# via kubernetes
|
||||||
@@ -216,7 +214,7 @@ jaraco-text==3.11.0
|
|||||||
# via
|
# via
|
||||||
# irc
|
# irc
|
||||||
# jaraco-collections
|
# jaraco-collections
|
||||||
jinja2==3.1.2
|
jinja2==3.1.3
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
jmespath==1.0.1
|
jmespath==1.0.1
|
||||||
# via
|
# via
|
||||||
@@ -362,7 +360,7 @@ pyyaml==6.0.1
|
|||||||
# djangorestframework-yaml
|
# djangorestframework-yaml
|
||||||
# kubernetes
|
# kubernetes
|
||||||
# receptorctl
|
# receptorctl
|
||||||
receptorctl==1.4.2
|
receptorctl==1.4.4
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
redis==4.3.5
|
redis==4.3.5
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
@@ -440,7 +438,7 @@ tomli==2.0.1
|
|||||||
# via setuptools-scm
|
# via setuptools-scm
|
||||||
twilio==7.15.3
|
twilio==7.15.3
|
||||||
# via -r /awx_devel/requirements/requirements.in
|
# via -r /awx_devel/requirements/requirements.in
|
||||||
twisted[tls]==22.10.0
|
twisted[tls]==23.10.0
|
||||||
# via
|
# via
|
||||||
# -r /awx_devel/requirements/requirements.in
|
# -r /awx_devel/requirements/requirements.in
|
||||||
# daphne
|
# daphne
|
||||||
|
|||||||
Reference in New Issue
Block a user