3121d88d42Accepting request 1225083 from devel:languages:python
factory
Ana Guerrero
2024-11-19 21:23:32 +00:00
27b6113a73- update to 6.2.0: * Dropped support for Python 3.8. (#737) * Add support for Python 3.13. (#736) * Remove six depdenncy. (#618) * Update known-good versions for tinycss2. (#732) * Fix additional < followed by characters and EOF issues.
devel
Dirk Mueller2024-11-19 12:15:21 +00:00
ca6b125ef0Accepting request 1120892 from devel:languages:python
Ana Guerrero
2023-10-29 18:39:48 +00:00
2b7a6ad3d7- update to 6.1.0: * Dropped support for Python 3.7. * Add support for Python 3.12. * Fix linkify with arrays in querystring * Handle more cases with < followed by character data * Fix entities inside a tags in linkification * Update cap for tinycss2 to <1.3 * Updated Sphinx requirement * Add dependabot for github actions and update github actions - Update to V3.1.1: Security update for CVE-2020-6802 * CVE-2020-6802: Fixed mutation XSS vulnerabilities (bsc#1165303).Dirk Mueller2023-10-28 09:51:39 +00:00
1dd5b37b3bAccepting request 1096012 from devel:languages:python
Dominique Leuenberger
2023-06-30 17:58:26 +00:00
6a4ad89810Accepting request 1095966 from home:mcalabkova:branches:devel:languages:python:DMatej Cepl2023-06-29 16:26:38 +00:00
264dc20c81Accepting request 1085516 from devel:languages:python
Dominique Leuenberger
2023-05-09 11:08:03 +00:00
a683d0f9c5- Update to 6.0.0: * bleach.clean, bleach.sanitizer.Cleaner, bleach.html5lib_shim.BleachHTMLParser: the tags and protocols arguments were changed from lists to sets. * bleach.linkify, bleach.linkifier.Linker: the skip_tags and recognized_tags arguments were changed from lists to sets. * bleach.sanitizer.BleachSanitizerFilter: strip_allowed_elements is now strip_allowed_tags. We now use “tags” everywhere rather than a mishmash of “tags” in some places and “elements” in others. # Bug fixes * Add support for Python 3.11. (#675) * Fix API weirness in BleachSanitizerFilter. (#649) * We’re using “tags” instead of “elements” everywhere–no more weird overloading of “elements” anymore. * Also, it no longer calls the superclass constructor. * Add warning when css_sanitizer isn’t set, but the style attribute is allowed. (#676) * Fix linkify handling of character entities. (#501) * Rework dev dependencies to use requirements-dev.txt and requirements-flake8.txt instead of extras. * Fix project infrastructure to be tox-based so it’s easier to have CI run the same things we’re running in development and with flake8 in an isolated environment. * Update action versions in CI. * Switch to f-strings where possible. Make tests parametrized to be easier to read/maintain.Daniel Garcia2023-05-08 12:00:20 +00:00
16af7538d4Accepting request 1081979 from devel:languages:python
Dominique Leuenberger
2023-04-22 20:01:47 +00:00
3ad0a28ce2Accepting request 1081348 from home:dirkmueller:acdc:as_python3_moduleDirk Mueller2023-04-21 14:52:15 +00:00
178fe72bbbAccepting request 1074154 from devel:languages:python
Dominique Leuenberger
2023-03-25 17:55:13 +00:00
177b1af6a1- Remove not needed dependency python-packagingDaniel Garcia2023-03-24 11:39:17 +00:00
865d6a5cebAccepting request 1033010 from devel:languages:python
Dominique Leuenberger
2022-11-04 16:31:40 +00:00
46a7d5b1cd- Remove not needed python-six dependency - Remove python_module macro definition - More specific python_sitelib in filesDaniel Garcia2022-11-03 09:01:34 +00:00
78606a7767Accepting request 1006839 from devel:languages:python
Richard Brown
2022-10-01 15:42:38 +00:00
2605210ed4- Update to 5.0.1: * Add missing comma to tinycss2 require. Thank you, @shadchin! * Add url parse tests based on wpt url tests. (#688) * Support scheme-less urls if "https" is in allow list. (#662) * Handle escaping `< in edge cases where it doesn't start a tag. (#544) * Correctly urlencode email address parts. Thank you, @larseggert! (#659) * clean and linkify` now preserve the order of HTML attributes. * Drop support for Python 3.6. Thank you, @hugovk! (#629) * CSS sanitization in style tags is completely different now. * Python 3.9 support * Drop support for unsupported Python versions <3.6. (#520) * add more tests for CVE-2021-23980 / GHSA-vv2x-vrpj-qqpq - Refresh de-vendor.patch, and convert to patch level 1
Steve Kowalik
2022-09-29 07:00:27 +00:00
ea092a2076Accepting request 884911 from devel:languages:python
Dominique Leuenberger
2021-04-14 11:05:10 +00:00
19b3ff6175Accepting request 884898 from home:AndreasStieger:branches:devel:languages:pythonMatej Cepl2021-04-13 10:30:56 +00:00
c20e423e50Accepting request 830713 from devel:languages:python
Dominique Leuenberger
2020-09-04 09:02:55 +00:00
efa22fed01- Skip tests that fail with html5lib 1.1 ref the upstream ticket * replace missing `setuptools dependency with packaging`. Thank you Benjamin Peterson.
Tomáš Chvátal
2020-08-31 09:15:54 +00:00
da3de4af4cAccepting request 800583 from devel:languages:python
Dominique Leuenberger
2020-05-08 21:02:04 +00:00
f264ca5fab- Update to 3.1.5: * * replace missing `setuptools dependency with packaging`. Thank you Benjamin Peterson.
Tomáš Chvátal
2020-05-06 07:14:32 +00:00
cf65231a75Accepting request 790549 from devel:languages:python
Dominique Leuenberger
2020-04-05 18:51:47 +00:00
5e4292f9bb- update to 3.1.4 (bsc#1168280, CVE-2020-6817): * `bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute were vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']})`. * Style attributes with dashes, or single or double quoted values are cleaned instead of passed through.Dirk Mueller2020-04-01 11:21:16 +00:00
48b9e746b6Accepting request 787398 from devel:languages:python
Dominique Leuenberger
2020-03-26 23:28:19 +00:00
2cc23971a9- update to 3.1.3 (bsc#1167379): * Add relative link to code of conduct. (#442) * Drop deprecated 'setup.py test' support. (#507) * Fix typo: curren -> current in tests/test_clean.py (#504) * Test on PyPy 7 * Drop test support for end of life Python 3.4 * `bleach.clean behavior parsing embedded MathML and SVG content with RCDATA tags did not match browser behavior and could result in a mutation XSS. Calls to bleach.clean with strip=False and math or svg tags and one or more of the RCDATA tags script, noscript, style, noframes, iframe, noembed, or xmp` in the allowed tags whitelist were vulnerable to a mutation XSS. This security issue was confirmed in Bleach version v3.1.1. Earlier versions are likely affected too.Dirk Mueller2020-03-23 10:22:56 +00:00
928b2ef5b5Accepting request 780475 from devel:languages:python
Dominique Leuenberger
2020-03-08 21:22:00 +00:00
394b9b98a6Accepting request 780338 from home:atopt:branches:devel:languages:python
Tomáš Chvátal
2020-02-29 10:05:37 +00:00