Skip to content

Update dependency Loguru to v0.5.3 [SECURITY]#72

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/pypi-loguru-vulnerability
Open

Update dependency Loguru to v0.5.3 [SECURITY]#72
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/pypi-loguru-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Aug 3, 2023

This PR contains the following updates:

Package Change Age Confidence
Loguru (changelog) 0.5.10.5.3 age confidence
loguru (changelog) ==0.5.1==0.5.3 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


loguru logs sensitive information

CVE-2022-0338 / GHSA-39ph-wr67-j4xq

More information

Details

Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

Delgan/loguru (Loguru)

v0.5.3

Compare Source

=====================

  • Fix child process possibly hanging at exit while combining enqueue=True with third party library like uwsgi (#&#8203;309 <https://github.com/Delgan/loguru/issues/309>, thanks @dstlmrk <https://github.com/dstlmrk>).
  • Fix possible exception during formatting of non-string messages (#&#8203;331 <https://github.com/Delgan/loguru/issues/331>_).

v0.5.2

Compare Source

=====================

  • Fix AttributeError within handlers using serialize=True when calling logger.exception() outside of the context of an exception (#&#8203;296 <https://github.com/Delgan/loguru/issues/296>_).
  • Fix error while logging an exception containing a non-picklable value to a handler with enqueue=True (#&#8203;298 <https://github.com/Delgan/loguru/issues/298>_).
  • Add support for async callable classes (with __call__ method) used as sinks (#&#8203;294 <https://github.com/Delgan/loguru/pull/294>, thanks @jessekrubin <https://github.com/jessekrubin>).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency loguru to v0.5.3 [SECURITY] Update dependency loguru to v0.5.3 [SECURITY] - autoclosed May 13, 2024
@renovate renovate Bot closed this May 13, 2024
@renovate renovate Bot deleted the renovate/pypi-loguru-vulnerability branch May 13, 2024 09:50
@renovate renovate Bot changed the title Update dependency loguru to v0.5.3 [SECURITY] - autoclosed Update dependency loguru to v0.5.3 [SECURITY] May 13, 2024
@renovate renovate Bot reopened this May 13, 2024
@renovate renovate Bot restored the renovate/pypi-loguru-vulnerability branch May 13, 2024 12:47
@renovate renovate Bot force-pushed the renovate/pypi-loguru-vulnerability branch from c643f0d to 70d70fa Compare May 13, 2024 12:47
@renovate renovate Bot force-pushed the renovate/pypi-loguru-vulnerability branch from 70d70fa to cbbdeb8 Compare August 10, 2025 12:55
@renovate renovate Bot changed the title Update dependency loguru to v0.5.3 [SECURITY] Update dependency Loguru to v0.5.3 [SECURITY] Apr 16, 2026
@renovate
Copy link
Copy Markdown
Author

renovate Bot commented Apr 16, 2026

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock

The "poetry.dev-dependencies" section is deprecated and will be removed in a future version. Use "poetry.group.dev.dependencies" instead.
Creating virtualenv biquery-sql-etl-GhDBIcS2-py3.14 in /home/ubuntu/.cache/pypoetry/virtualenvs

The lock file is not compatible with the current version of Poetry.
Regenerate the lock file with the `poetry lock` command.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants