mirror of https://github.com/scrapy/scrapy.git
Add release notes for v1.5.2
This commit is contained in:
parent
094dde6fdb
commit
71743a6546
|
|
@ -12,6 +12,22 @@ Cleanups
|
|||
* Remove deprecated ``CrawlerSettings`` class.
|
||||
* Remove deprecated ``Settings.overrides`` and ``Settings.defaults`` attributes.
|
||||
|
||||
Scrapy 1.5.2 (2019-01-22)
|
||||
-------------------------
|
||||
|
||||
* *Security bugfix*: Telnet console extension can be easily exploited by rogue
|
||||
websites POSTing content to http://localhost:6023, we haven't found a way to
|
||||
exploit it from Scrapy, but it is very easy to trick a browser to do so and
|
||||
elevates the risk for local development environment.
|
||||
|
||||
*The fix is backwards incompatible*, it enables telnet user-password
|
||||
authentication by default with a random generated password. If you can't
|
||||
upgrade right away, please consider setting :setting:`TELNET_CONSOLE_PORT`
|
||||
out of its default value.
|
||||
|
||||
See :ref:`telnet console <topics-telnetconsole>` documentation for more info
|
||||
|
||||
* Backport CI build failure under GCE environemnt due to boto import error.
|
||||
|
||||
Scrapy 1.5.1 (2018-07-12)
|
||||
-------------------------
|
||||
|
|
|
|||
Loading…
Reference in New Issue