underscore.js dependency: security warning

43 views
Skip to first unread message

Ben Hourahine

unread,
May 12, 2021, 9:29:03 AM5/12/21
to sphinx-users
Hi,
Thanks for this excellent tool!

We use it for various things in a quantum chemistry tool-chain, but have recently received a warning from github's dependabot scanning about one of the packages upstream from you:  underscore.js has a security announcement ( CVE-2021-23358 ) for arbitrary code execution. Unfortunately this is fixed in underscore 1.12.1, but Sphinx-4.0.1 is still on 1.12.0.

Regards
Ben


Komiya Takeshi

unread,
May 12, 2021, 1:09:00 PM5/12/21
to sphinx...@googlegroups.com
Hi,

Thank you for letting us know. I'll upgrade it on 4.0.2 soon (will be
released this weekend).

Thanks,
Takeshi KOMIYA

2021年5月12日(水) 22:29 Ben Hourahine <bhour...@gmail.com>:
> --
> You received this message because you are subscribed to the Google Groups "sphinx-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to sphinx-users...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/sphinx-users/8d539903-4300-4162-afc6-c08a8e741d19n%40googlegroups.com.

Ben Hourahine

unread,
May 12, 2021, 2:29:16 PM5/12/21
to sphinx-users
Great, thank you!

Incidentally, any tips on upgrading an existing Sphinx project to a newer releases?  (In the past, we've tended to populate a fresh quickstart template.)

Regards

Ben

Start Export

unread,
May 12, 2021, 4:07:38 PM5/12/21
to sphinx...@googlegroups.com
hi thank you 
great work 
im appy to learn with 
blessing

Komiya Takeshi

unread,
May 13, 2021, 9:54:23 AM5/13/21
to sphinx...@googlegroups.com
I think there is nothing to do on upgrading Sphinx basically. If you
have time, I recommend you to read the CHANGES file to understand
breaking change.

Thanks,
Takeshi KOMIYA

2021年5月13日(木) 3:29 Ben Hourahine <bhour...@gmail.com>:
> To view this discussion on the web visit https://groups.google.com/d/msgid/sphinx-users/8a049b75-ad1d-4ffc-a7ac-4fcb2bebb0bfn%40googlegroups.com.
Reply all
Reply to author
Forward
0 new messages