From 4d5e1d831fc7aa07595c5e8afd69e8fc6fdd6edb Mon Sep 17 00:00:00 2001 From: Samuel Williams Date: Fri, 9 Dec 2022 20:12:17 +0000 Subject: [PATCH] Bump bottle from v0.12.13 to v0.12.20 Addresses two CVEs flagged by dependabot: * Critical: CVE-2022-31799 * Moderate: CVE-2020-28473 --- CHANGELOG.md | 3 +++ requirements.txt | 2 +- setup.py | 2 +- 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 6f853049..d973c4a2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,8 @@ # Change log +### v0.15.1 +* Bump bottle dependency from 0.12.13 to 0.12.20 to address the critical CVE-2022-31799 and moderate CVE-2020-28473. + ### v0.15.0 * Add `shutdown_delay` as a `start()` function parameter ([#529](https://github.com/python-eel/Eel/pull/529)) diff --git a/requirements.txt b/requirements.txt index 36ac2932..3ed6fe71 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -bottle==0.12.13 +bottle==0.12.20 bottle-websocket==0.2.9 gevent==1.3.6 gevent-websocket==0.10.1 diff --git a/setup.py b/setup.py index 35eb2975..4e2c0250 100644 --- a/setup.py +++ b/setup.py @@ -6,7 +6,7 @@ setup( name='Eel', - version='0.15.0', + version='0.15.1', author='Python Eel Organisation', author_email='python-eel@protonmail.com', url='https://github.com/python-eel/Eel',