From 3b71ac2ec9901db822bc1c554f55e6dbbd6c4ed1 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 16 Jan 2021 20:45:54 +0100 Subject: [PATCH 1/5] Update python-mpd2 to 3.0.3 (#45141) Fixes: #44931 --- homeassistant/components/mpd/manifest.json | 2 +- requirements_all.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/homeassistant/components/mpd/manifest.json b/homeassistant/components/mpd/manifest.json index 5e9b4f8e690..12ce5b61b74 100644 --- a/homeassistant/components/mpd/manifest.json +++ b/homeassistant/components/mpd/manifest.json @@ -2,6 +2,6 @@ "domain": "mpd", "name": "Music Player Daemon (MPD)", "documentation": "https://www.home-assistant.io/integrations/mpd", - "requirements": ["python-mpd2==3.0.1"], + "requirements": ["python-mpd2==3.0.3"], "codeowners": ["@fabaff"] } diff --git a/requirements_all.txt b/requirements_all.txt index f95bcd194aa..8f81a09162e 100644 --- a/requirements_all.txt +++ b/requirements_all.txt @@ -1780,7 +1780,7 @@ python-juicenet==1.0.1 python-miio==0.5.4 # homeassistant.components.mpd -python-mpd2==3.0.1 +python-mpd2==3.0.3 # homeassistant.components.mystrom python-mystrom==1.1.2 From 09f5c7f4c51eb1cee7d8c363d9348423e19ff88c Mon Sep 17 00:00:00 2001 From: Santobert Date: Wed, 20 Jan 2021 21:08:44 +0100 Subject: [PATCH 2/5] Bump pybotvac to 0.0.20 (#45367) --- homeassistant/components/neato/manifest.json | 2 +- requirements_all.txt | 2 +- requirements_test_all.txt | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/homeassistant/components/neato/manifest.json b/homeassistant/components/neato/manifest.json index d3ea8a8525c..5cd6a7558b1 100644 --- a/homeassistant/components/neato/manifest.json +++ b/homeassistant/components/neato/manifest.json @@ -4,7 +4,7 @@ "config_flow": true, "documentation": "https://www.home-assistant.io/integrations/neato", "requirements": [ - "pybotvac==0.0.19" + "pybotvac==0.0.20" ], "codeowners": [ "@dshokouhi", diff --git a/requirements_all.txt b/requirements_all.txt index 8f81a09162e..d19ac5a4d0c 100644 --- a/requirements_all.txt +++ b/requirements_all.txt @@ -1289,7 +1289,7 @@ pyblackbird==0.5 # pybluez==0.22 # homeassistant.components.neato -pybotvac==0.0.19 +pybotvac==0.0.20 # homeassistant.components.nissan_leaf pycarwings2==2.10 diff --git a/requirements_test_all.txt b/requirements_test_all.txt index 0d737ccc77d..dffc55f56af 100644 --- a/requirements_test_all.txt +++ b/requirements_test_all.txt @@ -655,7 +655,7 @@ pyatv==0.7.5 pyblackbird==0.5 # homeassistant.components.neato -pybotvac==0.0.19 +pybotvac==0.0.20 # homeassistant.components.cloudflare pycfdns==1.2.1 From f7df00bbbd11622b0fc42f72ec06c3a585df7ed6 Mon Sep 17 00:00:00 2001 From: Tobias Sauerwein Date: Thu, 21 Jan 2021 08:30:28 +0100 Subject: [PATCH 3/5] Bump pyatmo to v4.2.2 (#45386) --- homeassistant/components/netatmo/manifest.json | 2 +- requirements_all.txt | 2 +- requirements_test_all.txt | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/homeassistant/components/netatmo/manifest.json b/homeassistant/components/netatmo/manifest.json index aecd119454a..34307f2311d 100644 --- a/homeassistant/components/netatmo/manifest.json +++ b/homeassistant/components/netatmo/manifest.json @@ -3,7 +3,7 @@ "name": "Netatmo", "documentation": "https://www.home-assistant.io/integrations/netatmo", "requirements": [ - "pyatmo==4.2.1" + "pyatmo==4.2.2" ], "after_dependencies": [ "cloud", diff --git a/requirements_all.txt b/requirements_all.txt index d19ac5a4d0c..8a5d1a61828 100644 --- a/requirements_all.txt +++ b/requirements_all.txt @@ -1271,7 +1271,7 @@ pyarlo==0.2.4 pyatag==0.3.4.4 # homeassistant.components.netatmo -pyatmo==4.2.1 +pyatmo==4.2.2 # homeassistant.components.atome pyatome==0.1.1 diff --git a/requirements_test_all.txt b/requirements_test_all.txt index dffc55f56af..5bbfd1e5d1e 100644 --- a/requirements_test_all.txt +++ b/requirements_test_all.txt @@ -646,7 +646,7 @@ pyarlo==0.2.4 pyatag==0.3.4.4 # homeassistant.components.netatmo -pyatmo==4.2.1 +pyatmo==4.2.2 # homeassistant.components.apple_tv pyatv==0.7.5 From 7abdad4a991a6ebd1f2b5edc42cb4484307defb9 Mon Sep 17 00:00:00 2001 From: Paulus Schoutsen Date: Sat, 23 Jan 2021 18:28:57 +0100 Subject: [PATCH 4/5] Avoid misuse sanitize_path, clarify docs (#45469) --- homeassistant/util/__init__.py | 28 ++++++++++++++++++++++++---- tests/util/test_init.py | 12 ++++++------ 2 files changed, 30 insertions(+), 10 deletions(-) diff --git a/homeassistant/util/__init__.py b/homeassistant/util/__init__.py index db1bbaa9993..d3178cb5ddd 100644 --- a/homeassistant/util/__init__.py +++ b/homeassistant/util/__init__.py @@ -33,13 +33,33 @@ RE_SANITIZE_PATH = re.compile(r"(~|\.(\.)+)") def sanitize_filename(filename: str) -> str: - r"""Sanitize a filename by removing .. / and \\.""" - return RE_SANITIZE_FILENAME.sub("", filename) + """Check if a filename is safe. + + Only to be used to compare to original filename to check if changed. + If result changed, the given path is not safe and should not be used, + raise an error. + + DEPRECATED. + """ + # Backwards compatible fix for misuse of method + if RE_SANITIZE_FILENAME.sub("", filename) != filename: + return "" + return filename def sanitize_path(path: str) -> str: - """Sanitize a path by removing ~ and ..""" - return RE_SANITIZE_PATH.sub("", path) + """Check if a path is safe. + + Only to be used to compare to original path to check if changed. + If result changed, the given path is not safe and should not be used, + raise an error. + + DEPRECATED. + """ + # Backwards compatible fix for misuse of method + if RE_SANITIZE_PATH.sub("", path) != path: + return "" + return path def slugify(text: str, *, separator: str = "_") -> str: diff --git a/tests/util/test_init.py b/tests/util/test_init.py index ef5ecd898d7..d3f45b968bc 100644 --- a/tests/util/test_init.py +++ b/tests/util/test_init.py @@ -12,17 +12,17 @@ from tests.async_mock import MagicMock, patch def test_sanitize_filename(): """Test sanitize_filename.""" assert util.sanitize_filename("test") == "test" - assert util.sanitize_filename("/test") == "test" - assert util.sanitize_filename("..test") == "test" - assert util.sanitize_filename("\\test") == "test" - assert util.sanitize_filename("\\../test") == "test" + assert util.sanitize_filename("/test") == "" + assert util.sanitize_filename("..test") == "" + assert util.sanitize_filename("\\test") == "" + assert util.sanitize_filename("\\../test") == "" def test_sanitize_path(): """Test sanitize_path.""" assert util.sanitize_path("test/path") == "test/path" - assert util.sanitize_path("~test/path") == "test/path" - assert util.sanitize_path("~/../test/path") == "//test/path" + assert util.sanitize_path("~test/path") == "" + assert util.sanitize_path("~/../test/path") == "" def test_slugify(): From db7c260ffbd7239656c88edcf61fb72cdff67822 Mon Sep 17 00:00:00 2001 From: Paulus Schoutsen Date: Sat, 23 Jan 2021 18:37:07 +0100 Subject: [PATCH 5/5] Bumped version to 2021.1.5 --- homeassistant/const.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/homeassistant/const.py b/homeassistant/const.py index cda54d78b21..f7e795a281e 100644 --- a/homeassistant/const.py +++ b/homeassistant/const.py @@ -1,7 +1,7 @@ """Constants used by Home Assistant components.""" MAJOR_VERSION = 2021 MINOR_VERSION = 1 -PATCH_VERSION = "4" +PATCH_VERSION = "5" __short_version__ = f"{MAJOR_VERSION}.{MINOR_VERSION}" __version__ = f"{__short_version__}.{PATCH_VERSION}" REQUIRED_PYTHON_VER = (3, 7, 1)