a5f8f1daf0- Update to 3.1.4 * Fixed setting the Content-Length HTTP header in AsyncRequestFactory * Fixed passing extra HTTP headers to AsyncRequestFactory request methods * Fixed crash of key transforms for JSONField on PostgreSQL when usingi on a Subquery() annotation * Fixed a regression in Django 3.1 that caused the incorrect grouping by a Q object annotation * Fixed a regression in Django 3.1 that caused suppressing connection errors when JSONField is used on SQLite * Fixed a crash on SQLite, when QuerySet.values()/values_list() contained key transforms for JSONField returning non-string primitive valuesOndřej Súkup2020-12-09 12:32:02 +00:00
fb993450a7- Update to 3.1.3 * Fixed a regression in Django 3.1.2 that caused the incorrect height of the admin changelist search bar * Fixed a regression in Django 3.1.2 that caused the incorrect width of the admin changelist search bar on a filtered page * Fixed displaying Unicode characters in forms.JSONField and read-only models.JSONField values in the admin * Fixed a regression in Django 3.1 that caused a crash of ArrayAgg and StringAgg with ordering on key transforms for JSONField * Fixed a regression in Django 3.1 that caused a crash of __in lookup when using key transforms for JSONField in the lookup value * Fixed a regression in Django 3.1 that caused a crash of ExpressionWrapper with key transforms for JSONField * Fixed a regression in Django 3.1 that caused a migrations crash on PostgreSQL when adding an ExclusionConstraint with key transforms for JSONField in expressions * Fixed a regression in Django 3.1 where ProtectedError.protected_objects and RestrictedError.restricted_objects attributes returned iterators instead of set of objects * Fixed a regression in Django 3.1.2 that caused incorrect form input layout on small screens in the admin change form view * Fixed a regression in Django 3.1 that invalidated pre-Django 3.1 password reset tokens * Added support for asgiref 3.3 * Fixed a regression in Django 3.1 that caused incorrect textarea layout on medium-sized screens in the admin change form view with the sidebar open * Fixed a regression in Django 3.0.7 that didn’t use Subquery() aliases in the GROUP BY clause * Fixed a bug in Django 3.1 where FileField instances with a callable storage were not correctly deconstructed * Fixed a regression in Django 3.1 where the QuerySet.ordered attribute returned incorrectly True for GROUP BY queries (e.g. .annotate().values()) on models withOndřej Súkup2020-11-02 15:18:09 +00:00
5a89231331Accepting request 825714 from home:aplanas:branches:devel:languages:python:djangoDominique Leuenberger2020-08-12 07:29:18 +00:00
a713776f6e- update to 3.0.9 * Allowed setting the SameSite cookie flag in HttpResponse.delete_cookie() * Fixed crash when sending emails to addresses with display names longer than 75 chars on Python 3.6.11+, 3.7.8+, and 3.8.4+Ondřej Súkup2020-08-06 11:37:58 +00:00
a836e40a12- update to 3.0.8 * Fixed messages of InvalidCacheKey exceptions and CacheKeyWarning warnings raised by cache key validation * Fixed a regression in Django 3.0.7 that caused a queryset crash when grouping by a many-to-one relationship * Reallowed, following a regression in Django 3.0, non-expressions having a filterable attribute to be used as the right-hand side in queryset filters * Fixed a regression in Django 3.0.2 that caused a migration crash on PostgreSQL when adding a foreign key to a model with a namespaced db_table * Added compatibility for cx_Oracle 8Ondřej Súkup2020-07-08 12:24:10 +00:00
5f98db44a7* boo#1172167 - CVE-2020-13596: Possible XSS via adminOndřej Súkup2020-06-04 14:58:55 +00:00
8127a47a63- update to 3.0.7 - drop 32bit.patch * boo#1172167 - CVE-2020-13254: Potential data leakage via malformed memcached keys * boo#1172164 - CVE-2020-13596: Possible XSS via admin ForeignKeyRawIdWidget * many other bugfixesOndřej Súkup2020-06-04 14:39:41 +00:00
0349257ef9- Update to 2.2.12: * Added the ability to handle .po files containing different plural equations for the same language (#30439).
Tomáš Chvátal
2020-04-03 06:59:04 +00:00
5824a53f04- Update to 2.2.7: * Fixed a crash when using a contains, contained_by, has_key, has_keys, or has_any_keys lookup on JSONField, if the right or left hand side of an expression is a key transform (#30826). * Prevented migrate --plan from showing that RunPython operations are irreversible when reverse_code callables don’t have docstrings or when showing a forward migration plan (#30870). * Fixed migrations crash on PostgreSQL when adding an Index with fields ordering and opclasses (#30903). * Restored the ability to override get_FOO_display() (#30931).
Tomáš Chvátal
2019-11-15 11:01:10 +00:00
a242516680- Require full python interpreter on build and runtime
Tomáš Chvátal
2019-11-15 07:49:29 +00:00
568656c2c8- Update to 2.2.6: * Fixed migrations crash on SQLite when altering a model containing partial indexes (#30754). * Fixed a regression in Django 2.2.4 that caused a crash when filtering with a Subquery() annotation of a queryset containing JSONField or HStoreField (#30769).
Tomáš Chvátal
2019-10-07 13:20:58 +00:00
4185b17123- Update to 2.2.5: * Relaxed the system check added in Django 2.2 for models to reallow use of the same db_table by multiple models when database routers are installed (#30673). * Fixed crash of KeyTransform() for JSONField and HStoreField when using on expressions with params (#30672). * Fixed a regression in Django 2.2 where ModelAdmin.list_filter choices to foreign objects don’t respect a model’s Meta.ordering (#30449). * Fixed a race condition in loading URLconf module that could cause a crash of auto-reloader on Python 3.5 and below (#30500).
Tomáš Chvátal
2019-09-16 10:28:49 +00:00
9b9fc4bf15bsc#1142883 bsc#1142885 bsc#1142882 bsc#1142880
Tomáš Chvátal
2019-08-01 11:43:41 +00:00
e6d42316c4- Update to 2.2.4: * CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235 * Fixed a regression in Django 2.2 when ordering a QuerySet.union(), intersection(), or difference() by a field type present more than once results in the wrong ordering being used (#30628). * Fixed a migration crash on PostgreSQL when adding a check constraint with a contains lookup on DateRangeField or DateTimeRangeField, if the right hand side of an expression is the same type (#30621). * Fixed a regression in Django 2.2 where auto-reloader crashes if a file path contains nulls characters ('\x00') (#30506). * Fixed a regression in Django 2.2 where auto-reloader crashes if a translation directory cannot be resolved (#30647).
Tomáš Chvátal
2019-08-01 11:30:44 +00:00
1975509111- Update to 2.2.3: * CVE-2019-12781 (bsc#1139945): Incorrect HTTP detection with reverse-proxy connecting via HTTPS¶
Tomáš Chvátal
2019-07-18 17:26:36 +00:00
a2706e4981- update to 2.1.7 (CVE-2019-6975, bsc#1124991): * Corrected packaging error from 2.1.6 * Memory exhaustion in django.utils.numberformat.format() If django.utils.numberformat.format() – used by contrib.admin as well as the the floatformat, filesizeformat, and intcomma templates filters – received a Decimal with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to '{:f}'.format(). To avoid this, decimals with more than 200 digits are now formatted using scientific notation. * Made the obj argument of InlineModelAdmin.has_add_permission() optional to restore backwards compatibility with third-party code that doesn’t provide it
Thomas Bechtold
2019-02-12 09:33:11 +00:00
64adc52e6e- update to 2.1.5 (CVE-2019-3498, bsc#1120932): * CVE-2019-3498: Content spoofing possibility in the default 404 page * Fixed compatibility with mysqlclient 1.3.14 (#30013). * Fixed a schema corruption issue on SQLite 3.26+. You might have to drop and rebuild your SQLite database if you applied a migration while using an older version of Django with SQLite 3.26 or later (#29182). * Prevented SQLite schema alterations while foreign key checks are enabled to avoid the possibility of schema corruption (#30023). * Fixed a regression in Django 2.1.4 (which enabled keep-alive connections) where request body data isn’t properly consumed for such connections (#30015). * Fixed a regression in Django 2.1.4 where InlineModelAdmin.has_change_permission() is incorrectly called with a non-None obj argument during an object add (#30050).
Thomas Bechtold
2019-01-10 12:17:53 +00:00