From 2491c1433a8be73f691872b06c4519c4602cb5b4 Mon Sep 17 00:00:00 2001 From: Waylan Limberg Date: Fri, 20 Dec 2019 13:38:53 -0500 Subject: [PATCH] Update min dependency to Jinja 2.10.1. Jinja 2.10.1 patched a security valnerability. See the release notes here: https://github.com/pallets/jinja/blob/master/CHANGES.rst#version-2101 Closes #1780. --- docs/about/release-notes.md | 2 ++ requirements/project-min.txt | 2 +- setup.py | 2 +- 3 files changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/about/release-notes.md b/docs/about/release-notes.md index a72e227a..e3eaf323 100644 --- a/docs/about/release-notes.md +++ b/docs/about/release-notes.md @@ -72,6 +72,8 @@ do, adding `--strict`, `--theme`, `--theme-dir`, and `--site-dir`. ### Other Changes and Additions to Version 1.1 +* Updated minimum dependancy to Jinja 2.10.1 to address security + concerns (#1780). * Add support for Python 3.8. * Drop support for Python 3.4. * Drop support for Python 2.7. MkDocs is PY3 only now (#1926). diff --git a/requirements/project-min.txt b/requirements/project-min.txt index 668e31db..a3117458 100644 --- a/requirements/project-min.txt +++ b/requirements/project-min.txt @@ -1,5 +1,5 @@ click==3.3 -Jinja2==2.7.1 +Jinja2==2.10.1 livereload==2.5.1 Markdown==2.5 PyYAML==3.13 diff --git a/setup.py b/setup.py index 45e5a149..18a8bb07 100755 --- a/setup.py +++ b/setup.py @@ -55,7 +55,7 @@ setup( include_package_data=True, install_requires=[ 'click>=3.3', - 'Jinja2>=2.7.1', + 'Jinja2>=2.10.1', 'livereload>=2.5.1', 'lunr[languages]>=0.5.2', 'Markdown>=2.3.1',