build(deps-dev): update dependency tqdm to v4.66.3 [security] - autoclosed #358
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==4.62.0
->==4.66.3
GitHub Vulnerability Alerts
CVE-2024-34062
Impact
Any optional non-boolean CLI arguments (e.g.
--delim
,--buf-size
,--manpath
) are passed through python'seval
, allowing arbitrary code execution. Example:python -m tqdm --manpath="\" + str(exec(\"import os\nos.system('echo hi && killall python3')\")) + \""
Patches
tqdm/tqdm@4e613f8 released in
tqdm>=4.66.3
Workarounds
None
References
Release Notes
tqdm/tqdm (tqdm)
v4.66.3
: tqdm v4.66.3 stableCompare Source
cli
:eval
safety (fixes CVE-2024-34062, GHSA-g7vv-2v7x-gj9p)v4.66.2
: tqdm v4.66.2 stableCompare Source
pandas
: addDataFrame.progress_map
(#1549)notebook
: fix HTML padding (#1506)keras
: fix resuming training whenverbose>=2
(#1508)format_num
negative fractions missing leading zero (#1548)DeprecationWarning
onimport
(#1519)pandas
warningsasv
(https://github.com/airspeed-velocity/asv/issues/1323)notebook
docstring indentationv4.66.1
: tqdm v4.66.1 stableCompare Source
utils.envwrap
types (#1493 <- #1491, #1320 <- #966, #1319)export TQDM_POSITION=-1
v4.66.0
: tqdm v4.66.0 stableCompare Source
TQDM_*
) (#1491 <- #1061, #950 <- #614, #1318, #619, #612, #370)export TQDM_MININTERVAL=5
to avoid log spamtqdm.utils.envwrap
os.path
=>pathlib.Path
v4.65.2
: tqdm v4.65.2 stableCompare Source
examples
from distributed wheel (#1492)v4.65.1
: tqdm v4.65.1 stableCompare Source
setup.{cfg,py}
=>pyproject.toml
(#1490)asv
benchmarkspre-commit
v4.65.0
: tqdm v4.65.0 stableCompare Source
v4.64.1
: tqdm v4.64.1 stableCompare Source
ipywidgets>=8
(#1366, #1361 <- #1310, #1359, #1360, #1364)v4.64.0
: tqdm v4.64.0 stableCompare Source
contrib.slack
(#1313)v4.63.2
: tqdm v4.63.2 stableCompare Source
rich
: exposeoptions
kwargs (#1282)autonotebook
: re-enable VSCode (#1309)v4.63.1
: tqdm v4.63.1 stableCompare Source
flush()
(#1248 <- #1177)v4.63.0
: tqdm v4.63.0 stableCompare Source
__reversed__()
__contains__()
pkg_resources
=>importlib
)tqdm.autonotebook
warning &std
fallback on missingipywidgets
(#1218 <- #1082, #1217)py3.10
testsconda
dependenciespytest
config (nbval
,asyncio
)v4.62.3
: tqdm v4.62.3 stableCompare Source
v4.62.2
: tqdm v4.62.2 stableCompare Source
contrib.concurrent
with generators (#1233 <- #1231)v4.62.1
: tqdm v4.62.1 stableCompare Source
contrib.logging
: inherit existing handler output stream (#1191)PermissionError
by usingweakref
inDisableOnWriteError
(#1207)contrib.telegram
creation rate limit handling (#1223, #1221 <- #1220, #1076)keras
dependencies (#1222)Configuration
📅 Schedule: Branch creation - "" in timezone Africa/Lusaka, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.