From 67cc86b35352cefcb793616c5b1123e3f4bffde0 Mon Sep 17 00:00:00 2001 From: Mehdy Bohlool Date: Mon, 17 Dec 2018 10:19:33 +1100 Subject: [PATCH 1/2] Potential security fix CVE-2018-20060 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 3bf9656a5..5d8459932 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,7 +2,7 @@ certifi>=14.05.14 # MPL six>=1.9.0 # MIT python-dateutil>=2.5.3 # BSD setuptools>=21.0.0 # PSF/ZPL -urllib3>=1.19.1,!=1.21 # MIT +urllib3>=1.23 # MIT pyyaml>=3.12 # MIT google-auth>=1.0.1 # Apache-2.0 ipaddress>=1.0.17;python_version=="2.7" # PSF From 11979c123affd36448f5beb98e3828389da66b20 Mon Sep 17 00:00:00 2001 From: Haowei Cai Date: Wed, 26 Dec 2018 23:18:48 -0800 Subject: [PATCH 2/2] Add CHANGELOG for security fix in 7.0.1 --- CHANGELOG.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 17c3b3e39..abc822a4f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,7 @@ +# v7.0.1 +**Security Fix:** +- Bump urllib3 version to pick up security fix for CVE-2018-20060 [kubernetes-client/python#707](https://github.com/kubernetes-client/python/pull/707) + # v7.0.0 **New Features:** - Add support for refreshing Azure tokens [kubernetes-client/python-base#77](https://github.com/kubernetes-client/python-base/pull/77)