Subject: CVS commit: pkgsrc/www/py-cfscrape
From: Adam Ciarcinski
Date: 2017-07-28 09:04:36
Message id: 20170728070436.988A1FACD@cvs.NetBSD.org

Log Message:
1.8.0:
Remove insecure Js2Py library (code execution risk)

Please upgrade to 1.8.0 immediately.

Versions 1.6.6 to 1.7.1 are vulnerable to code execution. If you are running a \ 
vulnerable version, a malicious website owner could craft a page which executes \ 
arbitrary Python code on the machine that runs this script. This can only occur \ 
if the website that the user attempts to scrape has specifically prepared a page \ 
to exploit vulnerable versions of cfscrape.

Files:
RevisionActionfile
1.2modifypkgsrc/www/py-cfscrape/Makefile
1.2modifypkgsrc/www/py-cfscrape/distinfo