pkgsrc/www/py-scrapy/ALTERNATIVES
adam 1b7dade2d4 py-scrapy: updated to 1.5.2
Scrapy 1.5.2:

* *Security bugfix*: Telnet console extension can be easily exploited by rogue
  websites POSTing content to http://localhost:6023, we haven't found a way to
  exploit it from Scrapy, but it is very easy to trick a browser to do so and
  elevates the risk for local development environment.

  *The fix is backwards incompatible*, it enables telnet user-password
  authentication by default with a random generated password. If you can't
  upgrade right away, please consider setting :setting:TELNET_CONSOLE_PORT
  out of its default value.

  See :ref:telnet console <topics-telnetconsole> documentation for more info

* Backport CI build failure under GCE environemnt due to boto import error.
2019-01-24 14:11:48 +00:00

1 line
46 B
Text

bin/scrapy @PREFIX@/bin/scrapy-@PYVERSSUFFIX@