Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 29, 2023

This PR contains the following updates:

Package Change Age Confidence
ansible (source) ==7.2.0 -> ==8.5.0 age confidence

GitHub Vulnerability Alerts

CVE-2023-5115

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.


Release Notes

ansible-community/ansible-build-data (ansible)

v8.3.0

Compare Source

v8.2.0

Compare Source

v8.1.0

Compare Source

v8.0.0

Compare Source

v7.7.0

Compare Source

v7.6.0

Compare Source

v7.5.0

Compare Source

v7.4.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Dec 29, 2023
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch 2 times, most recently from ce400d4 to d8921c7 Compare March 5, 2024 12:00
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from d8921c7 to 886ec7e Compare March 19, 2024 09:47
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 886ec7e to b6bf12b Compare April 5, 2024 10:04
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from b6bf12b to 8c8201b Compare July 24, 2024 15:25
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 8c8201b to 0532999 Compare September 23, 2024 16:26
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 0532999 to 45cebbf Compare October 3, 2024 09:02
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from 45cebbf to aaa2715 Compare January 10, 2025 13:59
| datasource | package | from  | to    |
| ---------- | ------- | ----- | ----- |
| pypi       | ansible | 7.2.0 | 8.5.0 |
@renovate renovate bot force-pushed the renovate/pypi-ansible-vulnerability branch from aaa2715 to cafd626 Compare January 10, 2025 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants