Skip to content
This repository has been archived by the owner on May 22, 2024. It is now read-only.

Update gunicorn to 19.10.0, fix failing build #467

Merged
merged 2 commits into from
Feb 20, 2020

Conversation

lbeaufort
Copy link
Member

@lbeaufort lbeaufort commented Feb 18, 2020

Summary (required)

Update gunicorn to 19.10.0. See https://snyk.io/vuln/SNYK-PYTHON-GUNICORN-541164
Update GitPython to 2.1.15 due to breaking change in gitdb2 (see gitpython-developers/GitPython#983)

How to test the changes locally

  • Gunicorn is only used in production, so you need to deploy to dev to test

Impacted areas of the application

List general components of the application that this PR will affect:

@lbeaufort lbeaufort changed the title [WIP] Update gunicorn to 19.10.0 [Blocked] Update gunicorn to 19.10.0 Feb 18, 2020
@lbeaufort lbeaufort changed the title [Blocked] Update gunicorn to 19.10.0 Update gunicorn to 19.10.0, fix failing build Feb 19, 2020
@jason-upchurch
Copy link
Contributor

@pkfec just copying you as a potential reviewer--probably just fine for one reviewer but a chance for more eyes. You and I can coordinate if needed.

Copy link
Contributor

@jason-upchurch jason-upchurch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for doing this work @lbeaufort, looks good. Up to you if you want to squash to a single commit. Test steps included snyk test to verify vulnerability is resolved and manual deploy using tasks.py then clicking around. If you want to merge as is, let me know. Thanks!

@lbeaufort
Copy link
Member Author

@jason-upchurch the commits aren't related, so I'd prefer to keep them separate. Thanks for reviewing!

@jason-upchurch jason-upchurch merged commit 86f77b2 into develop Feb 20, 2020
@lbeaufort lbeaufort deleted the feature/466-update-gunicorn branch March 2, 2020 16:01
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Fix failing build [Snyk: Medium Severity] HTTP Request Smuggling (Due 3/15/2020)
2 participants