Subject: CVS commit: pkgsrc/www/py-scrapy
From: Adam Ciarcinski
Date: 2019-01-24 15:11:49
Message id: 20190124141149.2576CFB16@cvs.NetBSD.org

Log Message:
py-scrapy: updated to 1.5.2

Scrapy 1.5.2:

* *Security bugfix*: Telnet console extension can be easily exploited by rogue
  websites POSTing content to http://localhost:6023, we haven't found a way to
  exploit it from Scrapy, but it is very easy to trick a browser to do so and
  elevates the risk for local development environment.

  *The fix is backwards incompatible*, it enables telnet user-password
  authentication by default with a random generated password. If you can't
  upgrade right away, please consider setting :setting:TELNET_CONSOLE_PORT
  out of its default value.

  See :ref:telnet console <topics-telnetconsole> documentation for more info

* Backport CI build failure under GCE environemnt due to boto import error.

Files:
RevisionActionfile
1.2modifypkgsrc/www/py-scrapy/ALTERNATIVES
1.7modifypkgsrc/www/py-scrapy/Makefile
1.4modifypkgsrc/www/py-scrapy/PLIST
1.6modifypkgsrc/www/py-scrapy/distinfo