Merge ~pelpsi/rutabaga/+git/dependencies:gunicorn-upgrade-HTTP-request-smuggling-vulnerability into rutabaga:master

Proposed by Simone Pelosi
Status: Superseded
Proposed branch: ~pelpsi/rutabaga/+git/dependencies:gunicorn-upgrade-HTTP-request-smuggling-vulnerability
Merge into: rutabaga:master
Diff against target: 228 lines (+0/-0)
0 files modified
Reviewer Review Type Date Requested Status
Launchpad code reviewers Pending
Review via email: mp+440150@code.launchpad.net

This proposal has been superseded by a proposal from 2023-03-31.

Commit message

Upgraded gunicorn to fix HTTP request smuggling vulnerability

A penetration test found that our gunicorn version is vulnerable, version 20.1.0 should be safe.

To post a comment you must log in.

Unmerged commits

e8f5f51... by Simone Pelosi

Upgraded gunicorn to fix HTTP request smuggling vulnerability

A penetration test found that our gunicorn version is vulnerable, version 20.1.0 should be safe.

3d89742... by Colin Watson

Add charm dependencies

Merged from https://code.launchpad.net/~cjwatson/rutabaga/+git/dependencies/+merge/408428

1c1b664... by Colin Watson

Add charm dependencies

3522fe1... by Colin Watson

Add pip 19.0.2, setuptools 42.0.2, and wheel 0.33.1

Merged from https://code.launchpad.net/~cjwatson/rutabaga/+git/dependencies/+merge/408089

c4063c0... by Colin Watson

Add pip 19.0.2, setuptools 42.0.2, and wheel 0.33.1

Upgrading these is enough to let us bootstrap test runs in Jenkins.

17e64bf... by Colin Watson

Add PyYAML 5.2, envdir 1.0.1, and pip 18.1

These are all needed to build on focal.

4336773... by Colin Watson

Add a unittest2 wheel

This works around https://github.com/pypa/setuptools/issues/409 with
current versions of the package installation toolchain.

61f1603... by Colin Watson

We don't need to have .bzr in .gitignore

9780692... by Kit Randel

Add .gitignore.

9dd790c... by Kit Randel

Upgrade to zope.interface 4.1.3

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
1diff --git a/Jinja2-2.10.1.tar.gz b/Jinja2-2.10.1.tar.gz
2new file mode 100644
3index 0000000..ffd1054
4Binary files /dev/null and b/Jinja2-2.10.1.tar.gz differ
5diff --git a/MarkupSafe-1.1.1.tar.gz b/MarkupSafe-1.1.1.tar.gz
6new file mode 100644
7index 0000000..a6dad8e
8Binary files /dev/null and b/MarkupSafe-1.1.1.tar.gz differ
9diff --git a/Paste-2.0.2.tar.gz b/Paste-2.0.2.tar.gz
10new file mode 100644
11index 0000000..1ebbce7
12Binary files /dev/null and b/Paste-2.0.2.tar.gz differ
13diff --git a/PasteDeploy-1.5.2.tar.gz b/PasteDeploy-1.5.2.tar.gz
14new file mode 100644
15index 0000000..fd4f9e1
16Binary files /dev/null and b/PasteDeploy-1.5.2.tar.gz differ
17diff --git a/PyYAML-3.11.tar.gz b/PyYAML-3.11.tar.gz
18new file mode 100644
19index 0000000..2a5d431
20Binary files /dev/null and b/PyYAML-3.11.tar.gz differ
21diff --git a/PyYAML-5.2.tar.gz b/PyYAML-5.2.tar.gz
22new file mode 100644
23index 0000000..666d12a
24Binary files /dev/null and b/PyYAML-5.2.tar.gz differ
25diff --git a/Tempita-0.5.2.tar.gz b/Tempita-0.5.2.tar.gz
26new file mode 100644
27index 0000000..755befc
28Binary files /dev/null and b/Tempita-0.5.2.tar.gz differ
29diff --git a/WebOb-1.5.1.tar.gz b/WebOb-1.5.1.tar.gz
30new file mode 100644
31index 0000000..689a47c
32Binary files /dev/null and b/WebOb-1.5.1.tar.gz differ
33diff --git a/WebTest-2.0.18.zip b/WebTest-2.0.18.zip
34new file mode 100644
35index 0000000..a4a22de
36Binary files /dev/null and b/WebTest-2.0.18.zip differ
37diff --git a/argparse-1.4.0.tar.gz b/argparse-1.4.0.tar.gz
38new file mode 100644
39index 0000000..937eea6
40Binary files /dev/null and b/argparse-1.4.0.tar.gz differ
41diff --git a/beautifulsoup4-4.4.1.tar.gz b/beautifulsoup4-4.4.1.tar.gz
42new file mode 100644
43index 0000000..5080765
44Binary files /dev/null and b/beautifulsoup4-4.4.1.tar.gz differ
45diff --git a/charmhelpers-0.20.22.tar.gz b/charmhelpers-0.20.22.tar.gz
46new file mode 100644
47index 0000000..bd5d222
48Binary files /dev/null and b/charmhelpers-0.20.22.tar.gz differ
49diff --git a/charms.reactive-1.4.1.tar.gz b/charms.reactive-1.4.1.tar.gz
50new file mode 100644
51index 0000000..03bc1fe
52Binary files /dev/null and b/charms.reactive-1.4.1.tar.gz differ
53diff --git a/colander-1.0.tar.gz b/colander-1.0.tar.gz
54new file mode 100644
55index 0000000..e60c8b4
56Binary files /dev/null and b/colander-1.0.tar.gz differ
57diff --git a/cornice-1.0.0.tar.gz b/cornice-1.0.0.tar.gz
58new file mode 100644
59index 0000000..624e4eb
60Binary files /dev/null and b/cornice-1.0.0.tar.gz differ
61diff --git a/envdir-0.7.tar.gz b/envdir-0.7.tar.gz
62new file mode 100644
63index 0000000..e5cff3d
64Binary files /dev/null and b/envdir-0.7.tar.gz differ
65diff --git a/envdir-1.0.1.tar.gz b/envdir-1.0.1.tar.gz
66new file mode 100644
67index 0000000..7b290d1
68Binary files /dev/null and b/envdir-1.0.1.tar.gz differ
69diff --git a/extras-0.0.3.tar.gz b/extras-0.0.3.tar.gz
70new file mode 100644
71index 0000000..46133fd
72Binary files /dev/null and b/extras-0.0.3.tar.gz differ
73diff --git a/fixtures-1.3.1.tar.gz b/fixtures-1.3.1.tar.gz
74new file mode 100644
75index 0000000..1d55ac2
76Binary files /dev/null and b/fixtures-1.3.1.tar.gz differ
77diff --git a/flake8-2.5.0.tar.gz b/flake8-2.5.0.tar.gz
78new file mode 100644
79index 0000000..890e6b8
80Binary files /dev/null and b/flake8-2.5.0.tar.gz differ
81diff --git a/gunicorn-19.3.0.tar.gz b/gunicorn-19.3.0.tar.gz
82new file mode 100644
83index 0000000..1d38258
84Binary files /dev/null and b/gunicorn-19.3.0.tar.gz differ
85diff --git a/gunicorn-20.1.0.tar.gz b/gunicorn-20.1.0.tar.gz
86new file mode 100644
87index 0000000..b5da493
88Binary files /dev/null and b/gunicorn-20.1.0.tar.gz differ
89diff --git a/iso8601-0.1.10.tar.gz b/iso8601-0.1.10.tar.gz
90new file mode 100644
91index 0000000..741df00
92Binary files /dev/null and b/iso8601-0.1.10.tar.gz differ
93diff --git a/linecache2-1.0.0.tar.gz b/linecache2-1.0.0.tar.gz
94new file mode 100644
95index 0000000..4604f93
96Binary files /dev/null and b/linecache2-1.0.0.tar.gz differ
97diff --git a/mccabe-0.3.1.tar.gz b/mccabe-0.3.1.tar.gz
98new file mode 100644
99index 0000000..c613d37
100Binary files /dev/null and b/mccabe-0.3.1.tar.gz differ
101diff --git a/netaddr-0.7.19.tar.gz b/netaddr-0.7.19.tar.gz
102new file mode 100644
103index 0000000..cc31d9d
104Binary files /dev/null and b/netaddr-0.7.19.tar.gz differ
105diff --git a/pbr-1.8.1.tar.gz b/pbr-1.8.1.tar.gz
106new file mode 100644
107index 0000000..245c14e
108Binary files /dev/null and b/pbr-1.8.1.tar.gz differ
109diff --git a/pbr-5.6.0.tar.gz b/pbr-5.6.0.tar.gz
110new file mode 100644
111index 0000000..0d5c965
112Binary files /dev/null and b/pbr-5.6.0.tar.gz differ
113diff --git a/pep8-1.5.7.tar.gz b/pep8-1.5.7.tar.gz
114new file mode 100644
115index 0000000..cdfd693
116Binary files /dev/null and b/pep8-1.5.7.tar.gz differ
117diff --git a/pip-18.1.tar.gz b/pip-18.1.tar.gz
118new file mode 100644
119index 0000000..a18192d
120Binary files /dev/null and b/pip-18.1.tar.gz differ
121diff --git a/pip-19.0.2.tar.gz b/pip-19.0.2.tar.gz
122new file mode 100644
123index 0000000..307a175
124Binary files /dev/null and b/pip-19.0.2.tar.gz differ
125diff --git a/pip-7.1.2.tar.gz b/pip-7.1.2.tar.gz
126new file mode 100644
127index 0000000..56ead41
128Binary files /dev/null and b/pip-7.1.2.tar.gz differ
129diff --git a/pyaml-21.8.3.tar.gz b/pyaml-21.8.3.tar.gz
130new file mode 100644
131index 0000000..6b6c197
132Binary files /dev/null and b/pyaml-21.8.3.tar.gz differ
133diff --git a/pyflakes-1.0.0.tar.gz b/pyflakes-1.0.0.tar.gz
134new file mode 100644
135index 0000000..ac9dc8b
136Binary files /dev/null and b/pyflakes-1.0.0.tar.gz differ
137diff --git a/pyramid-1.5.7.tar.gz b/pyramid-1.5.7.tar.gz
138new file mode 100644
139index 0000000..f1ced3b
140Binary files /dev/null and b/pyramid-1.5.7.tar.gz differ
141diff --git a/python-mimeparse-0.1.4.tar.gz b/python-mimeparse-0.1.4.tar.gz
142new file mode 100644
143index 0000000..f117f57
144Binary files /dev/null and b/python-mimeparse-0.1.4.tar.gz differ
145diff --git a/repoze.lru-0.6.tar.gz b/repoze.lru-0.6.tar.gz
146new file mode 100644
147index 0000000..81e8ee5
148Binary files /dev/null and b/repoze.lru-0.6.tar.gz differ
149diff --git a/requests-2.7.0.tar.gz b/requests-2.7.0.tar.gz
150new file mode 100644
151index 0000000..0a67c73
152Binary files /dev/null and b/requests-2.7.0.tar.gz differ
153diff --git a/setuptools-18.5.tar.gz b/setuptools-18.5.tar.gz
154new file mode 100644
155index 0000000..cd2ab62
156Binary files /dev/null and b/setuptools-18.5.tar.gz differ
157diff --git a/setuptools-41.6.0.zip b/setuptools-41.6.0.zip
158new file mode 100644
159index 0000000..3345759
160Binary files /dev/null and b/setuptools-41.6.0.zip differ
161diff --git a/setuptools-42.0.2.zip b/setuptools-42.0.2.zip
162new file mode 100644
163index 0000000..ab08097
164Binary files /dev/null and b/setuptools-42.0.2.zip differ
165diff --git a/setuptools_scm-1.17.0.tar.gz b/setuptools_scm-1.17.0.tar.gz
166new file mode 100644
167index 0000000..43b16c7
168Binary files /dev/null and b/setuptools_scm-1.17.0.tar.gz differ
169diff --git a/simplejson-3.8.1.tar.gz b/simplejson-3.8.1.tar.gz
170new file mode 100644
171index 0000000..417ade6
172Binary files /dev/null and b/simplejson-3.8.1.tar.gz differ
173diff --git a/six-1.10.0.tar.gz b/six-1.10.0.tar.gz
174new file mode 100644
175index 0000000..ac8eec5
176Binary files /dev/null and b/six-1.10.0.tar.gz differ
177diff --git a/six-1.16.0.tar.gz b/six-1.16.0.tar.gz
178new file mode 100644
179index 0000000..5bf3a27
180Binary files /dev/null and b/six-1.16.0.tar.gz differ
181diff --git a/testtools-1.8.0.tar.gz b/testtools-1.8.0.tar.gz
182new file mode 100644
183index 0000000..dd5f9ed
184Binary files /dev/null and b/testtools-1.8.0.tar.gz differ
185diff --git a/traceback2-1.4.0.tar.gz b/traceback2-1.4.0.tar.gz
186new file mode 100644
187index 0000000..7043739
188Binary files /dev/null and b/traceback2-1.4.0.tar.gz differ
189diff --git a/translationstring-1.3.tar.gz b/translationstring-1.3.tar.gz
190new file mode 100644
191index 0000000..52c8c1e
192Binary files /dev/null and b/translationstring-1.3.tar.gz differ
193diff --git a/unittest2-1.1.0-py2.py3-none-any.whl b/unittest2-1.1.0-py2.py3-none-any.whl
194new file mode 100644
195index 0000000..00bca37
196Binary files /dev/null and b/unittest2-1.1.0-py2.py3-none-any.whl differ
197diff --git a/unittest2-1.1.0.tar.gz b/unittest2-1.1.0.tar.gz
198new file mode 100644
199index 0000000..ec686eb
200Binary files /dev/null and b/unittest2-1.1.0.tar.gz differ
201diff --git a/venusian-1.0.tar.gz b/venusian-1.0.tar.gz
202new file mode 100644
203index 0000000..c8fc8cc
204Binary files /dev/null and b/venusian-1.0.tar.gz differ
205diff --git a/waitress-0.8.10.tar.gz b/waitress-0.8.10.tar.gz
206new file mode 100644
207index 0000000..b54e000
208Binary files /dev/null and b/waitress-0.8.10.tar.gz differ
209diff --git a/waitress-0.8.9.tar.gz b/waitress-0.8.9.tar.gz
210new file mode 100644
211index 0000000..73fb6e6
212Binary files /dev/null and b/waitress-0.8.9.tar.gz differ
213diff --git a/wheel-0.33.1.tar.gz b/wheel-0.33.1.tar.gz
214new file mode 100644
215index 0000000..bab94be
216Binary files /dev/null and b/wheel-0.33.1.tar.gz differ
217diff --git a/wheel-0.33.6.tar.gz b/wheel-0.33.6.tar.gz
218new file mode 100644
219index 0000000..c922c4e
220Binary files /dev/null and b/wheel-0.33.6.tar.gz differ
221diff --git a/zope.deprecation-4.1.2.tar.gz b/zope.deprecation-4.1.2.tar.gz
222new file mode 100644
223index 0000000..5522180
224Binary files /dev/null and b/zope.deprecation-4.1.2.tar.gz differ
225diff --git a/zope.interface-4.1.3.tar.gz b/zope.interface-4.1.3.tar.gz
226new file mode 100644
227index 0000000..c9e652f
228Binary files /dev/null and b/zope.interface-4.1.3.tar.gz differ

Subscribers

People subscribed via source and target branches