Chore(deps-dev): bump jinja2 from 3.1.3 to 3.1.4
Bumps jinja2 from 3.1.3 to 3.1.4.
Release notes
Sourced from jinja2's releases.
3.1.4
This is the Jinja 3.1.4 security release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes.
PyPI: https://pypi.org/project/Jinja2/3.1.4/ Changes: https://jinja.palletsprojects.com/en/3.1.x/changes/#version-3-1-4
- The
xmlattr
filter does not allow keys with/
solidus,>
greater-than sign, or=
equals sign, in addition to disallowing spaces. Regardless of any validation done by Jinja, user input should never be used as keys to this filter, or must be separately validated first. GHSA-h75v-3vvj-5mfj
Changelog
Sourced from jinja2's changelog.
Version 3.1.4
Released 2024-05-05
- The
xmlattr
filter does not allow keys with/
solidus,>
greater-than sign, or=
equals sign, in addition to disallowing spaces. Regardless of any validation done by Jinja, user input should never be used as keys to this filter, or must be separately validated first. :ghsa:h75v-3vvj-5mfj
Commits
-
dd4a8b5
release version 3.1.4 -
0668239
Merge pull request from GHSA-h75v-3vvj-5mfj -
d655030
disallow invalid characters in keys to xmlattr filter -
a7863ba
add ghsa links -
b5c98e7
start version 3.1.4 -
da3a9f0
update project files (#1968) -
0ee5eb4
satisfy formatter, linter, and strict mypy -
20477c6
update project files (#5457) -
e491223
update pyyaml dev dependency -
36f9885
fix pr link - Additional commits viewable in compare view