pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/www/py-django3 py-django3: updated to 3.2.1



details:   https://anonhg.NetBSD.org/pkgsrc/rev/cce200753fb3
branches:  trunk
changeset: 452042:cce200753fb3
user:      adam <adam%pkgsrc.org@localhost>
date:      Wed May 05 07:06:29 2021 +0000

description:
py-django3: updated to 3.2.1

Django 3.2.1

CVE-2021-31542: Potential directory-traversal via uploaded files
MultiPartParser, UploadedFile, and FieldFile allowed directory-traversal via uploaded files with suitably crafted file names.
In order to mitigate this risk, stricter basename and path sanitation is now applied. Specifically, empty file names and paths with dot segments will be rejected.

Bugfixes

Corrected detection of GDAL 3.2 on Windows.
Fixed a bug in Django 3.2 where subclasses of BigAutoField and SmallAutoField were not allowed for the DEFAULT_AUTO_FIELD setting.
Fixed a regression in Django 3.2 that caused a crash of QuerySet.values()/values_list() after QuerySet.union(), intersection(), and difference() when it was ordered by an unannotated field.
Restored, following a regression in Django 3.2, displaying an exception message on the technical 404 debug page.
Fixed a bug in Django 3.2 where a system check would crash on a reverse one-to-one relationships in CheckConstraint.check or UniqueConstraint.condition.
Fixed a regression in Django 3.2 that caused a crash of ModelAdmin.search_fields when searching against phrases with unbalanced quotes.
Fixed a bug in Django 3.2 where variable lookup errors were logged rendering the sitemap template if alternates were not defined.
Fixed a regression in Django 3.2 that caused a crash when combining Q() objects which contains boolean expressions.
Fixed a regression in Django 3.2 that caused a crash of QuerySet.update() on a queryset ordered by inherited or joined fields on MySQL and MariaDB.
Fixed a regression in Django 3.2 that caused a crash when decoding a cookie value, used by django.contrib.messages.storage.cookie.CookieStorage, in the pre-Django 3.2 format.
Fixed a regression in Django 3.2 that stopped the shift-key modifier selecting multiple rows in the admin changelist.
Fixed a bug in Django 3.2 where a system check would crash on the STATICFILES_DIRS setting with a list of 2-tuples of (prefix, path).
Fixed a long standing bug involving queryset bitwise combination when used with subqueries that began manifesting in Django 3.2, due to a separate fix using Exists to exclude() multi-valued 
relationships.
Fixed a bug in Django 3.2 where variable lookup errors were logged when rendering some admin templates.
Fixed a bug in Django 3.2 where an admin changelist would crash when deleting objects filtered against multi-valued relationships. The admin changelist now uses Exists() instead QuerySet.distinct() 
because calling delete() after distinct() is not allowed in Django 3.2 to address a data loss possibility.
Fixed a regression in Django 3.2 where the calling process environment would not be passed to the dbshell command on PostgreSQL.
Fixed a performance regression in Django 3.2 when building complex filters with subqueries. As a side-effect the private API to check django.db.sql.query.Query equality is removed.

Django 3.2.0:
Automatic AppConfig discovery simplifies configuration of pluggable applications.
Customizing the type of auto-created primary keys begins a process of migrating to BigAutoField primary key fields by default.
Functional indexes can now be created on expressions and database functions.

diffstat:

 www/py-django3/Makefile |   6 ++--
 www/py-django3/PLIST    |  57 ++++++++++++++++++++++++++++++++++++++++++++----
 www/py-django3/distinfo |  10 ++++----
 3 files changed, 60 insertions(+), 13 deletions(-)

diffs (211 lines):

diff -r d7dd4c2e276a -r cce200753fb3 www/py-django3/Makefile
--- a/www/py-django3/Makefile   Wed May 05 07:04:18 2021 +0000
+++ b/www/py-django3/Makefile   Wed May 05 07:06:29 2021 +0000
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.13 2021/03/01 12:43:26 adam Exp $
+# $NetBSD: Makefile,v 1.14 2021/05/05 07:06:29 adam Exp $
 
-DISTNAME=      Django-3.1.7
+DISTNAME=      Django-3.2.1
 PKGNAME=       ${PYPKGPREFIX}-${DISTNAME:tl}
 CATEGORIES=    www python
 MASTER_SITES=  https://www.djangoproject.com/m/releases/${PKGVERSION_NOREV:R}/
@@ -11,7 +11,7 @@
 COMMENT=       Django, a high-level Python Web framework
 LICENSE=       modified-bsd
 
-DEPENDS+=      ${PYPKGPREFIX}-asgiref>=3.2:../../www/py-asgiref
+DEPENDS+=      ${PYPKGPREFIX}-asgiref>=3.3.2:../../www/py-asgiref
 DEPENDS+=      ${PYPKGPREFIX}-pytz-[0-9]*:../../time/py-pytz
 DEPENDS+=      ${PYPKGPREFIX}-sqlparse>=0.2.2:../../databases/py-sqlparse
 
diff -r d7dd4c2e276a -r cce200753fb3 www/py-django3/PLIST
--- a/www/py-django3/PLIST      Wed May 05 07:04:18 2021 +0000
+++ b/www/py-django3/PLIST      Wed May 05 07:06:29 2021 +0000
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.2 2020/09/10 09:37:17 adam Exp $
+@comment $NetBSD: PLIST,v 1.3 2021/05/05 07:06:29 adam Exp $
 bin/django-admin-${PYVERSSUFFIX}
 bin/django-admin-${PYVERSSUFFIX}.py
 ${PYSITELIB}/${EGG_INFODIR}/PKG-INFO
@@ -1173,7 +1173,6 @@
 ${PYSITELIB}/django/contrib/admin/static/admin/js/SelectBox.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/SelectFilter2.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/actions.js
-${PYSITELIB}/django/contrib/admin/static/admin/js/actions.min.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/admin/DateTimeShortcuts.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/admin/RelatedObjectLookups.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/autocomplete.js
@@ -1181,15 +1180,12 @@
 ${PYSITELIB}/django/contrib/admin/static/admin/js/cancel.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/change_form.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/collapse.js
-${PYSITELIB}/django/contrib/admin/static/admin/js/collapse.min.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/core.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/inlines.js
-${PYSITELIB}/django/contrib/admin/static/admin/js/inlines.min.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/jquery.init.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/nav_sidebar.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/popup_response.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/prepopulate.js
-${PYSITELIB}/django/contrib/admin/static/admin/js/prepopulate.min.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/prepopulate_init.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/urlify.js
 ${PYSITELIB}/django/contrib/admin/static/admin/js/vendor/jquery/LICENSE.txt
@@ -1784,6 +1780,9 @@
 ${PYSITELIB}/django/contrib/auth/management/__init__.py
 ${PYSITELIB}/django/contrib/auth/management/__init__.pyc
 ${PYSITELIB}/django/contrib/auth/management/__init__.pyo
+${PYSITELIB}/django/contrib/auth/management/commands/__init__.py
+${PYSITELIB}/django/contrib/auth/management/commands/__init__.pyc
+${PYSITELIB}/django/contrib/auth/management/commands/__init__.pyo
 ${PYSITELIB}/django/contrib/auth/management/commands/changepassword.py
 ${PYSITELIB}/django/contrib/auth/management/commands/changepassword.pyc
 ${PYSITELIB}/django/contrib/auth/management/commands/changepassword.pyo
@@ -2063,6 +2062,9 @@
 ${PYSITELIB}/django/contrib/contenttypes/management/__init__.py
 ${PYSITELIB}/django/contrib/contenttypes/management/__init__.pyc
 ${PYSITELIB}/django/contrib/contenttypes/management/__init__.pyo
+${PYSITELIB}/django/contrib/contenttypes/management/commands/__init__.py
+${PYSITELIB}/django/contrib/contenttypes/management/commands/__init__.pyc
+${PYSITELIB}/django/contrib/contenttypes/management/commands/__init__.pyo
 ${PYSITELIB}/django/contrib/contenttypes/management/commands/remove_stale_contenttypes.py
 ${PYSITELIB}/django/contrib/contenttypes/management/commands/remove_stale_contenttypes.pyc
 ${PYSITELIB}/django/contrib/contenttypes/management/commands/remove_stale_contenttypes.pyo
@@ -2821,6 +2823,12 @@
 ${PYSITELIB}/django/contrib/gis/locale/zh_Hans/LC_MESSAGES/django.po
 ${PYSITELIB}/django/contrib/gis/locale/zh_Hant/LC_MESSAGES/django.mo
 ${PYSITELIB}/django/contrib/gis/locale/zh_Hant/LC_MESSAGES/django.po
+${PYSITELIB}/django/contrib/gis/management/__init__.py
+${PYSITELIB}/django/contrib/gis/management/__init__.pyc
+${PYSITELIB}/django/contrib/gis/management/__init__.pyo
+${PYSITELIB}/django/contrib/gis/management/commands/__init__.py
+${PYSITELIB}/django/contrib/gis/management/commands/__init__.pyc
+${PYSITELIB}/django/contrib/gis/management/commands/__init__.pyo
 ${PYSITELIB}/django/contrib/gis/management/commands/inspectdb.py
 ${PYSITELIB}/django/contrib/gis/management/commands/inspectdb.pyc
 ${PYSITELIB}/django/contrib/gis/management/commands/inspectdb.pyo
@@ -3541,6 +3549,9 @@
 ${PYSITELIB}/django/contrib/redirects/migrations/0001_initial.py
 ${PYSITELIB}/django/contrib/redirects/migrations/0001_initial.pyc
 ${PYSITELIB}/django/contrib/redirects/migrations/0001_initial.pyo
+${PYSITELIB}/django/contrib/redirects/migrations/0002_alter_redirect_new_path_help_text.py
+${PYSITELIB}/django/contrib/redirects/migrations/0002_alter_redirect_new_path_help_text.pyc
+${PYSITELIB}/django/contrib/redirects/migrations/0002_alter_redirect_new_path_help_text.pyo
 ${PYSITELIB}/django/contrib/redirects/migrations/__init__.py
 ${PYSITELIB}/django/contrib/redirects/migrations/__init__.pyc
 ${PYSITELIB}/django/contrib/redirects/migrations/__init__.pyo
@@ -3768,6 +3779,12 @@
 ${PYSITELIB}/django/contrib/sessions/locale/zh_Hans/LC_MESSAGES/django.po
 ${PYSITELIB}/django/contrib/sessions/locale/zh_Hant/LC_MESSAGES/django.mo
 ${PYSITELIB}/django/contrib/sessions/locale/zh_Hant/LC_MESSAGES/django.po
+${PYSITELIB}/django/contrib/sessions/management/__init__.py
+${PYSITELIB}/django/contrib/sessions/management/__init__.pyc
+${PYSITELIB}/django/contrib/sessions/management/__init__.pyo
+${PYSITELIB}/django/contrib/sessions/management/commands/__init__.py
+${PYSITELIB}/django/contrib/sessions/management/commands/__init__.pyc
+${PYSITELIB}/django/contrib/sessions/management/commands/__init__.pyo
 ${PYSITELIB}/django/contrib/sessions/management/commands/clearsessions.py
 ${PYSITELIB}/django/contrib/sessions/management/commands/clearsessions.pyc
 ${PYSITELIB}/django/contrib/sessions/management/commands/clearsessions.pyo
@@ -3792,6 +3809,12 @@
 ${PYSITELIB}/django/contrib/sitemaps/apps.py
 ${PYSITELIB}/django/contrib/sitemaps/apps.pyc
 ${PYSITELIB}/django/contrib/sitemaps/apps.pyo
+${PYSITELIB}/django/contrib/sitemaps/management/__init__.py
+${PYSITELIB}/django/contrib/sitemaps/management/__init__.pyc
+${PYSITELIB}/django/contrib/sitemaps/management/__init__.pyo
+${PYSITELIB}/django/contrib/sitemaps/management/commands/__init__.py
+${PYSITELIB}/django/contrib/sitemaps/management/commands/__init__.pyc
+${PYSITELIB}/django/contrib/sitemaps/management/commands/__init__.pyo
 ${PYSITELIB}/django/contrib/sitemaps/management/commands/ping_google.py
 ${PYSITELIB}/django/contrib/sitemaps/management/commands/ping_google.pyc
 ${PYSITELIB}/django/contrib/sitemaps/management/commands/ping_google.pyo
@@ -3809,6 +3832,9 @@
 ${PYSITELIB}/django/contrib/sites/apps.py
 ${PYSITELIB}/django/contrib/sites/apps.pyc
 ${PYSITELIB}/django/contrib/sites/apps.pyo
+${PYSITELIB}/django/contrib/sites/checks.py
+${PYSITELIB}/django/contrib/sites/checks.pyc
+${PYSITELIB}/django/contrib/sites/checks.pyo
 ${PYSITELIB}/django/contrib/sites/locale/af/LC_MESSAGES/django.mo
 ${PYSITELIB}/django/contrib/sites/locale/af/LC_MESSAGES/django.po
 ${PYSITELIB}/django/contrib/sites/locale/ar/LC_MESSAGES/django.mo
@@ -4039,6 +4065,12 @@
 ${PYSITELIB}/django/contrib/staticfiles/handlers.py
 ${PYSITELIB}/django/contrib/staticfiles/handlers.pyc
 ${PYSITELIB}/django/contrib/staticfiles/handlers.pyo
+${PYSITELIB}/django/contrib/staticfiles/management/__init__.py
+${PYSITELIB}/django/contrib/staticfiles/management/__init__.pyc
+${PYSITELIB}/django/contrib/staticfiles/management/__init__.pyo
+${PYSITELIB}/django/contrib/staticfiles/management/commands/__init__.py
+${PYSITELIB}/django/contrib/staticfiles/management/commands/__init__.pyc
+${PYSITELIB}/django/contrib/staticfiles/management/commands/__init__.pyo
 ${PYSITELIB}/django/contrib/staticfiles/management/commands/collectstatic.py
 ${PYSITELIB}/django/contrib/staticfiles/management/commands/collectstatic.pyc
 ${PYSITELIB}/django/contrib/staticfiles/management/commands/collectstatic.pyo
@@ -4237,6 +4269,9 @@
 ${PYSITELIB}/django/core/management/color.py
 ${PYSITELIB}/django/core/management/color.pyc
 ${PYSITELIB}/django/core/management/color.pyo
+${PYSITELIB}/django/core/management/commands/__init__.py
+${PYSITELIB}/django/core/management/commands/__init__.pyc
+${PYSITELIB}/django/core/management/commands/__init__.pyo
 ${PYSITELIB}/django/core/management/commands/check.py
 ${PYSITELIB}/django/core/management/commands/check.pyc
 ${PYSITELIB}/django/core/management/commands/check.pyo
@@ -4330,6 +4365,9 @@
 ${PYSITELIB}/django/core/serializers/json.py
 ${PYSITELIB}/django/core/serializers/json.pyc
 ${PYSITELIB}/django/core/serializers/json.pyo
+${PYSITELIB}/django/core/serializers/jsonl.py
+${PYSITELIB}/django/core/serializers/jsonl.pyc
+${PYSITELIB}/django/core/serializers/jsonl.pyo
 ${PYSITELIB}/django/core/serializers/python.py
 ${PYSITELIB}/django/core/serializers/python.pyc
 ${PYSITELIB}/django/core/serializers/python.pyo
@@ -4840,6 +4878,9 @@
 ${PYSITELIB}/django/template/__init__.py
 ${PYSITELIB}/django/template/__init__.pyc
 ${PYSITELIB}/django/template/__init__.pyo
+${PYSITELIB}/django/template/autoreload.py
+${PYSITELIB}/django/template/autoreload.pyc
+${PYSITELIB}/django/template/autoreload.pyo
 ${PYSITELIB}/django/template/backends/__init__.py
 ${PYSITELIB}/django/template/backends/__init__.pyc
 ${PYSITELIB}/django/template/backends/__init__.pyo
@@ -4999,6 +5040,9 @@
 ${PYSITELIB}/django/utils/cache.py
 ${PYSITELIB}/django/utils/cache.pyc
 ${PYSITELIB}/django/utils/cache.pyo
+${PYSITELIB}/django/utils/connection.py
+${PYSITELIB}/django/utils/connection.pyc
+${PYSITELIB}/django/utils/connection.pyo
 ${PYSITELIB}/django/utils/crypto.py
 ${PYSITELIB}/django/utils/crypto.pyc
 ${PYSITELIB}/django/utils/crypto.pyo
@@ -5137,6 +5181,9 @@
 ${PYSITELIB}/django/views/decorators/clickjacking.py
 ${PYSITELIB}/django/views/decorators/clickjacking.pyc
 ${PYSITELIB}/django/views/decorators/clickjacking.pyo
+${PYSITELIB}/django/views/decorators/common.py
+${PYSITELIB}/django/views/decorators/common.pyc
+${PYSITELIB}/django/views/decorators/common.pyo
 ${PYSITELIB}/django/views/decorators/csrf.py
 ${PYSITELIB}/django/views/decorators/csrf.pyc
 ${PYSITELIB}/django/views/decorators/csrf.pyo
diff -r d7dd4c2e276a -r cce200753fb3 www/py-django3/distinfo
--- a/www/py-django3/distinfo   Wed May 05 07:04:18 2021 +0000
+++ b/www/py-django3/distinfo   Wed May 05 07:06:29 2021 +0000
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.13 2021/03/01 12:43:26 adam Exp $
+$NetBSD: distinfo,v 1.14 2021/05/05 07:06:29 adam Exp $
 
-SHA1 (Django-3.1.7.tar.gz) = 7f08108d90fac2862f8db9344def74229830bc88
-RMD160 (Django-3.1.7.tar.gz) = 3f4a7e32347b3e81ee1a8856c5c03772653d0ca3
-SHA512 (Django-3.1.7.tar.gz) = a8a24f7f25ff2f3a7b5ebe4cef08c7f1303c78bd33f9a53c10630159d6895a738e863dc1034ad0817ad89275c202b4319aa5949ce89f36ca0b537c8a5c0c407c
-Size (Django-3.1.7.tar.gz) = 9673009 bytes
+SHA1 (Django-3.2.1.tar.gz) = cd6f18967e13a6e67dbee4713116aab9cb348865
+RMD160 (Django-3.2.1.tar.gz) = 669c38006c87e1776aa86611b51f0738a0b809b0
+SHA512 (Django-3.2.1.tar.gz) = 5f3f80047cdcb6c9a07ca0dc9d6d83d190c8c0215311f39e6e441384659c92e4fa42bf4677d297a4ba8520a0bfbd78c4b2ca13cf467c1e1220c0c6a3131ba444
+Size (Django-3.2.1.tar.gz) = 9820723 bytes



Home | Main Index | Thread Index | Old Index