chore(deps): update dependency tqdm to v4.66.3 [security] #198
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Note
Mend has cancelled the proposed renaming of the Renovate GitHub app being renamed to
mend[bot]
.This notice will be removed on 2025-10-07.
This PR contains the following updates:
==4.50.0
->==4.66.3
GitHub Vulnerability Alerts
CVE-2024-34062
Impact
Any optional non-boolean CLI arguments (e.g.
--delim
,--buf-size
,--manpath
) are passed through python'seval
, allowing arbitrary code execution. Example:python -m tqdm --manpath="\" + str(exec(\"import os\nos.system('echo hi && killall python3')\")) + \""
Patches
tqdm/tqdm@4e613f8 released in
tqdm>=4.66.3
Workarounds
None
References
Release Notes
tqdm/tqdm (tqdm)
v4.66.3
: tqdm v4.66.3 stableCompare Source
cli
:eval
safety (fixes CVE-2024-34062, GHSA-g7vv-2v7x-gj9p)v4.66.2
: tqdm v4.66.2 stableCompare Source
pandas
: addDataFrame.progress_map
(#1549)notebook
: fix HTML padding (#1506)keras
: fix resuming training whenverbose>=2
(#1508)format_num
negative fractions missing leading zero (#1548)DeprecationWarning
onimport
(#1519)pandas
warningsasv
(airspeed-velocity/asv#1323)notebook
docstring indentationv4.66.1
: tqdm v4.66.1 stableCompare Source
utils.envwrap
types (#1493 <- #1491, #1320 <- #966, #1319)export TQDM_POSITION=-1
v4.66.0
: tqdm v4.66.0 stableCompare Source
TQDM_*
) (#1491 <- #1061, #950 <- #614, #1318, #619, #612, #370)export TQDM_MININTERVAL=5
to avoid log spamtqdm.utils.envwrap
os.path
=>pathlib.Path
v4.65.2
: tqdm v4.65.2 stableCompare Source
examples
from distributed wheel (#1492)v4.65.1
: tqdm v4.65.1 stableCompare Source
setup.{cfg,py}
=>pyproject.toml
(#1490)asv
benchmarkspre-commit
v4.65.0
: tqdm v4.65.0 stableCompare Source
v4.64.1
: tqdm v4.64.1 stableCompare Source
ipywidgets>=8
(#1366, #1361 <- #1310, #1359, #1360, #1364)v4.64.0
: tqdm v4.64.0 stableCompare Source
contrib.slack
(#1313)v4.63.2
: tqdm v4.63.2 stableCompare Source
rich
: exposeoptions
kwargs (#1282)autonotebook
: re-enable VSCode (#1309)v4.63.1
: tqdm v4.63.1 stableCompare Source
flush()
(#1248 <- #1177)v4.63.0
: tqdm v4.63.0 stableCompare Source
__reversed__()
__contains__()
pkg_resources
=>importlib
)tqdm.autonotebook
warning &std
fallback on missingipywidgets
(#1218 <- #1082, #1217)py3.10
testsconda
dependenciespytest
config (nbval
,asyncio
)v4.62.3
: tqdm v4.62.3 stableCompare Source
v4.62.2
: tqdm v4.62.2 stableCompare Source
contrib.concurrent
with generators (#1233 <- #1231)v4.62.1
: tqdm v4.62.1 stableCompare Source
contrib.logging
: inherit existing handler output stream (#1191)PermissionError
by usingweakref
inDisableOnWriteError
(#1207)contrib.telegram
creation rate limit handling (#1223, #1221 <- #1220, #1076)keras
dependencies (#1222)v4.62.0
: tqdm v4.62.0 stableCompare Source
asyncio.gather
API consistency with stdlib (#1212)v4.61.2
: tqdm v4.61.2 stableCompare Source
colorama
on Windows (#1139, #454)leave=False
(#1189)pandas==1.3.0
(#1199)keras
potentialAttributeError
(#1184 <- #1183)asyncio
tests (#1176)stdout
/err
before first render (#1177)v4.61.1
: tqdm v4.61.1 stableCompare Source
utils._screen_shape_linux()
sometimes raisingValueError
(#1174)v4.61.0
: tqdm v4.61.0 stableCompare Source
keras
support forinitial_epoch
(#1150 <- #1138)v4.60.0
: tqdm v4.60.0 stableCompare Source
contrib.logging
helpers for redirecting totqdm.write()
(#1155 <- #786)delay
innotebook
(#1142)contrib.tmap
,tzip
not usingtqdm_class
(#1148)notebook
tests (#1143)v4.59.0
: tqdm v4.59.0 stableCompare Source
tqdm.dask.TqdmCallback
(#1079, #279 <- #278)asyncio.gather()
(#1136)length_hint
(#1068)--delay
[notebook]
extra (#1135)v4.58.0
: tqdm v4.58.0 stableCompare Source
delay
in seconds (#836 <- #1069, #704)v4.57.0
: tqdm v4.57.0 stableCompare Source
DummyTqdmFile
(#960)pandas
warnings (#824, #1094)v4.56.2
: tqdm v4.56.2 stableCompare Source
reset()
(#1125)unpause()
v4.56.1
: tqdm v4.56.1 stableCompare Source
repr()
&format_dict
when disabled (#1113 <- #624)__repr__()
=>__str__()
v4.56.0
: tqdm v4.56.0 stableCompare Source
tqdm.tk
(#1006)tqdm.rich
tqdm.gui
display()
inheritance/overridev4.55.2
: tqdm v4.55.2 stableCompare Source
pytest
quickermake
topython
.gitignore
v4.55.1
: tqdm v4.55.1 stableCompare Source
(Rolling|Expanding).progress_apply()
onpandas==1.2.0
(#1106)v4.55.0
: tqdm v4.55.0 stableCompare Source
tqdm.gui
tqdm.notebook
tqdm.contrib.telegram
tqdm.contrib.discord
v4.54.1
: tqdm v4.54.1 stableCompare Source
py3.4
(no longer tested) (#1091)snap
build & deploy methodv4.54.0
: tqdm v4.54.0 stableCompare Source
get_new
(#1085 <- #1084, #509)v4.53.0
: tqdm v4.53.0 stableCompare Source
get_new()
helper for mixed subclasses in nested mode (#509)asyncio
(#1074)break
hazarddistutils
in favour ofsetuptools
/setup.cfg
(#723, #721)devel
PRssetuptools_scm
(#722)v4.52.0
: tqdm v4.52.0 stableCompare Source
display()
to a different notebook cell (#1059 <- #909, #954)notebook
argumentdisplay=True
(usedisplay=False
withdisplay(tqdm_object.container)
)keras.TqdmCallback
support for initialiser arguments (usedisplay=False
withtqdm_callback_object.display()
) (#1059 <- #1065)v4.51.0
: tqdm v4.51.0 stableCompare Source
{eta}
datetimebar_format
argument (#1055 <- #1051)bar_format='{l_bar}{bar}| {n_fmt}/{total_fmt} [{rate_fmt} ETA:{eta:%y-%m-%d %H:%M}{postfix}]'
--update
&--update_to
nosetests
withpytest
(#1052, #1045)v4.50.2
: tqdm v4.50.2 stableCompare Source
platform.system()
causingfork()
warnings (#691)contrib.concurrent.process_map
pickling error withthreading.RLock
(#920)v4.50.1
: tqdm v4.50.1 stableCompare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.