-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 20 May 2022 16:14:25 -0400 Source: python-scrapy Architecture: source Version: 1.5.1-1+deb10u1 Distribution: buster Urgency: medium Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Stefano Rivera <stefanor@debian.org> Closes: 1008234 Changes: python-scrapy (1.5.1-1+deb10u1) buster; urgency=medium . * Team upload. * Security fix for CVE-2021-41125: Don't send authentication data with all requests. Provide a http_auth_domain spider attribute to control which domains are allowed to receive the configured HTTP authentication credentials. * Security fix CVE-2022-0577: Don't expose cookies cross-domain when redirected. (Closes: #1008234) Checksums-Sha1: 30626e3721bc6edf919369be9fb4ca6ea54a829e 2326 python-scrapy_1.5.1-1+deb10u1.dsc f5e8c38025c5c298b0dd9db36f62430777c1c3f9 12584 python-scrapy_1.5.1-1+deb10u1.debian.tar.xz 8da097e7e94c6196ebd6c3110aa0f1968bfbacee 6137 python-scrapy_1.5.1-1+deb10u1_source.buildinfo Checksums-Sha256: af620d59780644028b83bcd931297b487fdda30f86537fc0fce53d71f2be9519 2326 python-scrapy_1.5.1-1+deb10u1.dsc ac5ceb5af45eac0235285d6f11e7c9a27e1b087f6dd9045eacefeca62b5d4115 12584 python-scrapy_1.5.1-1+deb10u1.debian.tar.xz 31b5f24ae48ef4f3fe7fb96c5fa792ba5d71308f80204f8739e442063f6796c7 6137 python-scrapy_1.5.1-1+deb10u1_source.buildinfo Files: 0e59808a9e05bc03f3f1b0779fc7b5e2 2326 python optional python-scrapy_1.5.1-1+deb10u1.dsc 409ff762010a37bae1cb7e263f3316c1 12584 python optional python-scrapy_1.5.1-1+deb10u1.debian.tar.xz 417a329305e2337cde25fc5d9a70da1a 6137 python optional python-scrapy_1.5.1-1+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iIoEARYKADIWIQTumtb5BSD6EfafSCRHew2wJjpU2AUCYof2yhQcc3RlZmFub3JA ZGViaWFuLm9yZwAKCRBHew2wJjpU2FRaAQDg3vfjjE6XSFZaI96zTYF46aGyxZfT WQ0La3jhLR/6lgD9HWUq+3LFNJ2LTDnwje3Jft0sRP9ebQYEwLSCpvmu+Q0= =30Nz -----END PGP SIGNATURE-----