Skip to content

lxml < 6.1.0 has a high severity vulnerability. #274

@johanneswuerbach

Description

@johanneswuerbach

lxml < 6.1.0 has a high severity vulnerability GHSA-vfmq-68hx-4jfw and lxml is currently pinned to lxml>=4.6.5,<=6.0.2 here.

Based on 356583b I understand there was a particular parsing bug in lxml v6, but I'm not sure why the range wasn't set to lxml>=4.6.5,<7.0.0 as lxml seems to follow semver.

Would you support changing the range to lxml>=4.6.5,<7.0.0 or are there any other blockers?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions