pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/www/py-django py-django: updated to 1.11.21



details:   https://anonhg.NetBSD.org/pkgsrc/rev/18a17423f19a
branches:  trunk
changeset: 334718:18a17423f19a
user:      adam <adam%pkgsrc.org@localhost>
date:      Mon Jun 03 12:33:00 2019 +0000

description:
py-django: updated to 1.11.21

Django 1.11.21 release notes

CVE-2019-12308: AdminURLFieldWidget XSS

The clickable ?Current URL? link generated by AdminURLFieldWidget displayed the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value 
provided as a URL query parameter payload, could result in an clickable JavaScript link.

AdminURLFieldWidget now validates the provided value using URLValidator before displaying the clickable link. You may customise the validator by passing a validator_class kwarg to 
AdminURLFieldWidget.__init__(), e.g. when using formfield_overrides.

diffstat:

 www/py-django/Makefile |   8 ++++----
 www/py-django/distinfo |  10 +++++-----
 2 files changed, 9 insertions(+), 9 deletions(-)

diffs (38 lines):

diff -r 5d81a4ee476d -r 18a17423f19a www/py-django/Makefile
--- a/www/py-django/Makefile    Mon Jun 03 12:29:50 2019 +0000
+++ b/www/py-django/Makefile    Mon Jun 03 12:33:00 2019 +0000
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.105 2019/02/12 13:11:56 adam Exp $
+# $NetBSD: Makefile,v 1.106 2019/06/03 12:33:00 adam Exp $
 
-DISTNAME=      Django-1.11.20
+DISTNAME=      Django-1.11.21
 PKGNAME=       ${PYPKGPREFIX}-${DISTNAME:tl}
 CATEGORIES=    www python
 MASTER_SITES=  https://www.djangoproject.com/m/releases/${PKGVERSION_NOREV:R}/
@@ -19,8 +19,8 @@
 
 post-install:
        cd ${DESTDIR}${PREFIX}/bin && \
-               ${MV} django-admin django-admin-${PYVERSSUFFIX} && \
-               ${MV} django-admin.py django-admin-${PYVERSSUFFIX}.py || ${TRUE}
+       ${MV} django-admin django-admin-${PYVERSSUFFIX} && \
+       ${MV} django-admin.py django-admin-${PYVERSSUFFIX}.py || ${TRUE}
 
 .include "../../lang/python/application.mk"
 .include "../../lang/python/egg.mk"
diff -r 5d81a4ee476d -r 18a17423f19a www/py-django/distinfo
--- a/www/py-django/distinfo    Mon Jun 03 12:29:50 2019 +0000
+++ b/www/py-django/distinfo    Mon Jun 03 12:33:00 2019 +0000
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.84 2019/02/12 13:11:56 adam Exp $
+$NetBSD: distinfo,v 1.85 2019/06/03 12:33:00 adam Exp $
 
-SHA1 (Django-1.11.20.tar.gz) = bad59a5672e6abe394ed03b9fd6d592d874bd750
-RMD160 (Django-1.11.20.tar.gz) = 73acd2b9dd8896f1abeb32ef01aef38c7e394875
-SHA512 (Django-1.11.20.tar.gz) = 5a0fff6c9b90a08e98dee6d4d090047adb900a8f6a061f98e685e8998bfe3d97fe7a90aa7d4d2feae67026fb6e4441393d50cb5ab295604ed362a080b987f062
-Size (Django-1.11.20.tar.gz) = 7846576 bytes
+SHA1 (Django-1.11.21.tar.gz) = 2b2f2c26835c641ccc313bd5330418237e587741
+RMD160 (Django-1.11.21.tar.gz) = 6dde2ec05193955a09d3717bc5bc033816a87354
+SHA512 (Django-1.11.21.tar.gz) = c91a1189b6b8fbbb1470f870b09c1c553e860d3b8c0977240399524a830d5403929f14b4e4b689354080748aab1c70587ad56e265f4ac0b3bdc2714d01adbbc4
+Size (Django-1.11.21.tar.gz) = 7847136 bytes



Home | Main Index | Thread Index | Old Index