mirror of
https://github.com/zed-industries/zed.git
synced 2026-05-31 19:05:00 +07:00
|
Some checks are pending
Congratsbot / check-author (push) Waiting to run
Congratsbot / congrats (push) Blocked by required conditions
run_tests / orchestrate (push) Waiting to run
run_tests / check_style (push) Waiting to run
run_tests / clippy_windows (push) Blocked by required conditions
deploy_nightly_docs / deploy_docs (push) Has been skipped
run_tests / clippy_linux (push) Blocked by required conditions
run_tests / clippy_mac (push) Blocked by required conditions
run_tests / clippy_mac_x86_64 (push) Blocked by required conditions
run_tests / run_tests_windows (push) Blocked by required conditions
run_tests / run_tests_linux (push) Blocked by required conditions
run_tests / run_tests_mac (push) Blocked by required conditions
run_tests / miri_scheduler (push) Blocked by required conditions
run_tests / doctests (push) Blocked by required conditions
run_tests / check_workspace_binaries (push) Blocked by required conditions
run_tests / build_visual_tests_binary (push) Blocked by required conditions
run_tests / check_wasm (push) Blocked by required conditions
run_tests / check_dependencies (push) Blocked by required conditions
run_tests / check_docs (push) Blocked by required conditions
run_tests / check_licenses (push) Blocked by required conditions
run_tests / check_scripts (push) Blocked by required conditions
run_tests / check_postgres_and_protobuf_migrations (push) Blocked by required conditions
run_tests / extension_tests (push) Blocked by required conditions
run_tests / tests_pass (push) Blocked by required conditions
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [requests](https://redirect.github.com/psf/requests) ([changelog](https://redirect.github.com/psf/requests/blob/master/HISTORY.md)) | `2.32.3` → `2.33.0` |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/15138) for more information. --- ### Requests vulnerable to .netrc credentials leak via malicious URLs [CVE-2024-47081](https://nvd.nist.gov/vuln/detail/CVE-2024-47081) / [GHSA-9hjg-9r4m-mvj7](https://redirect.github.com/advisories/GHSA-9hjg-9r4m-mvj7) <details> <summary>More information</summary> #### Details ##### Impact Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. ##### Workarounds For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on your Requests Session ([docs](https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env)). ##### References [https://github.com/psf/requests/pull/6965](https://redirect.github.com/psf/requests/pull/6965) https://seclists.org/fulldisclosure/2025/Jun/2 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N` #### References - [https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7](https://redirect.github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7) - [https://nvd.nist.gov/vuln/detail/CVE-2024-47081](https://nvd.nist.gov/vuln/detail/CVE-2024-47081) - [https://github.com/psf/requests/pull/6965](https://redirect.github.com/psf/requests/pull/6965) - [ |
||
|---|---|---|
| .. | ||
| danger | ||
| flatpak | ||
| lib | ||
| licenses | ||
| terms | ||
| update_top_ranking_issues | ||
| analyze_highlights.py | ||
| bootstrap | ||
| bootstrap.ps1 | ||
| build-docker | ||
| bump-extension-cli | ||
| bump-gpui-version | ||
| bump-nightly | ||
| bump-zed-version | ||
| bundle-freebsd | ||
| bundle-linux | ||
| bundle-mac | ||
| bundle-windows.ps1 | ||
| cargo | ||
| cargo-timing-info.js | ||
| check-keymaps | ||
| check-licenses | ||
| check-links | ||
| check-todos | ||
| cherry-pick | ||
| clear-target-dir-if-larger-than | ||
| clear-target-dir-if-larger-than.ps1 | ||
| clippy | ||
| clippy.ps1 | ||
| collab-flamegraph | ||
| community-pr-track-mapping.json | ||
| crate-dep-graph | ||
| create-draft-release | ||
| debug-cli | ||
| deploy-collab | ||
| determine-release-channel | ||
| determine-release-channel.ps1 | ||
| digital-ocean-db.sh | ||
| docs-strip-preview-callouts | ||
| docs-suggest | ||
| docs-suggest-publish | ||
| download-wasi-sdk | ||
| draft-release-notes | ||
| drop-test-dbs | ||
| exit-ci-if-dev-drive-is-full.ps1 | ||
| freebsd | ||
| generate-action-metadata | ||
| generate-licenses | ||
| generate-licenses-csv | ||
| generate-licenses.ps1 | ||
| generate-terms-rtf | ||
| get-crate-version | ||
| get-crate-version.ps1 | ||
| get-pull-requests-since | ||
| get-release-notes-since | ||
| get-released-version | ||
| github-assign-contributor-issue.py | ||
| github-check-new-issue-for-duplicates.py | ||
| github-clean-issue-types.py | ||
| github-community-pr-board.py | ||
| github-find-top-duplicated-bugs.py | ||
| github-label-issues-to-triage.py | ||
| github-pr-status | ||
| github-track-duplicate-bot-effectiveness.py | ||
| histogram | ||
| import-themes | ||
| install-cmake | ||
| install-linux | ||
| install-rustup.ps1 | ||
| install.sh | ||
| kube-shell | ||
| linux | ||
| metal-debug | ||
| mitm-proxy.sh | ||
| new-crate | ||
| prettier | ||
| prompts | ||
| randomized-test-ci | ||
| randomized-test-minimize | ||
| redeploy-vercel | ||
| remote-server | ||
| reset_db | ||
| run-background-agent-mvp-local | ||
| run-local-minio | ||
| run-unit-evals | ||
| seed-db | ||
| select-sentry-crash-candidates | ||
| sentry-fetch | ||
| setup-dev-driver.ps1 | ||
| setup-sccache | ||
| setup-sccache.ps1 | ||
| shellcheck-scripts | ||
| snap-build | ||
| snap-try | ||
| squawk | ||
| storybook | ||
| test-docs-suggest-batch | ||
| triage_project_sync.py | ||
| triage_watcher.jl | ||
| trigger-docs-build | ||
| trigger-release | ||
| uninstall.sh | ||
| update-json-schemas | ||
| upload-extension-cli | ||
| upload-nightly | ||
| upload-nightly.ps1 | ||
| verify-macos-document-icon | ||
| what-is-deployed | ||
| zed-local | ||