main/py3-jinja2: security upgrade to 3.1.4

- https://jinja.palletsprojects.com/en/3.1.x/changes/#version-3-1-4
- https://github.com/advisories/GHSA-h75v-3vvj-5mfj

Also add secfixes entry for version 3.1.3.
This commit is contained in:
Daniel Néri 2024-05-19 01:01:36 +02:00 committed by Natanael Copa
parent 4fcc502fd7
commit e46f815da0

View file

@ -1,21 +1,25 @@
# Contributor: Matt Smith <mcs@darkregion.net>
# Maintainer: Matt Smith <mcs@darkregion.net>
pkgname=py3-jinja2
_pkgname=Jinja2
pkgver=3.1.3
pkgrel=1
_pkgname=jinja2
pkgver=3.1.4
pkgrel=0
pkgdesc="A small but fast and easy to use stand-alone python template engine"
url="https://palletsprojects.com/p/jinja/"
arch="noarch"
license="BSD-3-Clause"
depends="py3-markupsafe"
checkdepends="py3-pytest"
makedepends="python3-dev py3-gpep517 py3-setuptools py3-wheel"
makedepends="python3-dev py3-gpep517 py3-flit-core py3-wheel"
subpackages="$pkgname-pyc $pkgname-doc"
source="https://files.pythonhosted.org/packages/source/${_pkgname:0:1}/$_pkgname/$_pkgname-$pkgver.tar.gz"
builddir="$srcdir/$_pkgname-$pkgver"
# secfixes:
# 3.1.4-r0:
# - CVE-2024-34064 GHSA-h75v-3vvj-5mfj
# 3.1.3-r0:
# - CVE-2024-22195 GHSA-h5c8-rqwp-cp95
# 1.11.3-r0:
# - CVE-2020-28493
@ -39,11 +43,11 @@ package() {
# by py-sphinx, however, this package (py-jinja2) is a dependency of
# Sphinx itself!
mkdir -p "$docdir"
cp -R docs examples "$docdir"/
cp -R docs "$docdir"/
install -m 644 -D LICENSE.rst "$pkgdir"/usr/share/licenses/$pkgname/LICENSE.rst
install -m 644 -D LICENSE.txt "$pkgdir"/usr/share/licenses/$pkgname/LICENSE.txt
}
sha512sums="
5c36d0cd094b40626511f30c561176c095c49ef4066c2752a9edc3e6feb2430dafa866c17deebddcd0168aa1f0fd3944916d592c5c999639b8152e7c1009c700 Jinja2-3.1.3.tar.gz
d07d68a2687af68c705d3b7f5a2c67aca7b9d125316b15085888b9d0d6e769981af76f6f524728b89b5501bd671d518fcb2638f9ae112e57ca2bf2a53482cd89 jinja2-3.1.4.tar.gz
"