From 6d07ad651120d2fec79eddf330b09d42028ca34c Mon Sep 17 00:00:00 2001 From: Zedifus Date: Tue, 10 Dec 2024 22:39:56 +0000 Subject: [PATCH 1/2] Bump tornado for CVE-2024-52804 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52804 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 7bc5ae87..b01144c8 100644 --- a/requirements.txt +++ b/requirements.txt @@ -15,7 +15,7 @@ pyjwt==2.8.0 PyYAML==6.0.1 requests==2.32.3 termcolor==1.1 -tornado==6.4.1 +tornado==6.4.2 tzlocal==5.1 jsonschema==4.19.1 orjson==3.9.15 From 284a177580235ca8a761f90e70738628fdaf4de1 Mon Sep 17 00:00:00 2001 From: Zedifus Date: Tue, 10 Dec 2024 22:44:10 +0000 Subject: [PATCH 2/2] Update changelog !814 --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9a725bcc..68261b23 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ TBD - Bump Docker base image `22.04` -> `24.04` ([Merge Request](https://gitlab.com/crafty-controller/crafty-4/-/merge_requests/812)) - Bump python pip `2.0.3` -> `24.3.1` ([Merge Request](https://gitlab.com/crafty-controller/crafty-4/-/merge_requests/812)) - Bump python setuptools `50.3.2` -> `75.6.0` ([Merge Request](https://gitlab.com/crafty-controller/crafty-4/-/merge_requests/812)) +- Bump tornado for CVE-2024-52804 ([Merge Request](https://gitlab.com/crafty-controller/crafty-4/-/merge_requests/814)) ### Lang - Weblate Translation Platform Integration - Remove incomplete labels from translation files to better support new translation workflow ([Merge Request](https://gitlab.com/crafty-controller/crafty-4/-/merge_requests/810))