Update dependency PyPDF2 to v1.27.5 [SECURITY] #31
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==1.26.0
->==1.27.5
GitHub Vulnerability Alerts
CVE-2022-24859
Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if the PyPDF2 user wrote the following code:
Patches
PyPDF2==1.27.5
and later are patched.Credits to Sebastian Krause for finding (issue) and fixing (PR) it.
Release Notes
py-pdf/PyPDF2 (PyPDF2)
v1.27.5
: Version 1.27.5, 2022-04-15Compare Source
Security (SEC)
Bug fixes (BUG)
Robustness improvements (ROBUST)
Documentation (DOC)
Tests and Test setup (TST)
Developer Experience Improvements (DEV)
Miscellaneous
All changes: py-pdf/pypdf@1.27.4...1.27.5
v1.27.4
Compare Source
v1.27.3
Compare Source
v1.27.2
Compare Source
v1.27.1
Compare Source
v1.27.0
: Version 1.27.0Compare Source
Features
Bug fixes (BUG)
Documentation (DOC)
Tests and Test setup (TST)
static code analysis with Flake8 (#660)
Developer Experience Improvements (DEV)
pre-commit install
to avoid tiny issueslike trailing whitespaces
Miscallenious
You can see the full changelog at: py-pdf/pypdf@1.26.0...1.27.0
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.