Release notes
*Sourced from [django-anymail's releases](https://github.com/anymail/django-anymail/releases).*
> ## v1.2.1
> #### Security fix
>
> This release fixes a moderate severity security issue affecting Anymail v0.2–v1.2:
> Prevent timing attack on WEBHOOK_AUTHORIZATION secret ([CVE-2018-6596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6596))
>
> If you are using Anymail's tracking webhooks, you should upgrade to this release, and you may want to rotate to a new WEBHOOK_AUTHORIZATION shared secret (see [docs](http://anymail.readthedocs.io/en/stable/tips/securing_webhooks/#use-a-shared-authorization-secret)). You should definitely change your webhook auth if your logs indicate attempted exploit.
>
> (If you are only sending email using an Anymail EmailBackend, and have not set up Anymail's event tracking webhooks, this issue does not affect you.)
>
> *More information*
>
> Anymail's webhook validation was vulnerable to a timing attack. A remote attacker could use this to obtain your WEBHOOK_AUTHORIZATION shared secret, potentially allowing them to post fabricated or malicious email tracking events to your app.
>
> There have not been any reports of attempted exploit. (The vulnerability was discovered through code review.) Attempts would be visible in HTTP logs as a very large number of 400 responses on Anymail's webhook urls (by default "/anymail/*esp_name*/tracking/"), and in Python error monitoring as a very large number of AnymailWebhookValidationFailure exceptions.
>
> ## v1.2
> #### New features
>
> * **Postmark:** Support new click webhook in normalized tracking events
>
> ## v1.1
> #### Bug fixes
>
> * **Mailgun:** Support metadata in opened/clicked/unsubscribed tracking webhooks, and fix potential problems if metadata keys collided with Mailgun event parameter names. (See [#76](https://github-redirect.dependabot.com/anymail/django-anymail/issues/76), [#77](https://github-redirect.dependabot.com/anymail/django-anymail/issues/77))
>
> #### Other changes
>
> * **Internal:** Rework Anymail's ParsedEmail class and rename to EmailAddress to align it with similar functionality in the Python 3.6 email package, in preparation for future inbound support. ParsedEmail was not documented for use outside Anymail's internals (so this change does not bump the semver major version), but if you were using it in an undocumented way you will need to update your code.
Changelog
*Sourced from [django-anymail's changelog](https://github.com/anymail/django-anymail/blob/master/CHANGELOG.rst).*
> v1.2.1
> ------
>
> *2018-02-02*
>
> Security
> ~~~~~~~~
>
> * Fix a **moderate severity** security issue affecting Anymail v0.2–v1.2:
> prevent timing attack on WEBHOOK_AUTHORIZATION secret.
> (`CVE-2018-6596 `__)
>
> *More information*
>
> If you are using Anymail's tracking webhooks, you should upgrade to this release,
> and you may want to rotate to a new WEBHOOK_AUTHORIZATION shared secret (see
> `docs `__).
> You should definitely change your webhook auth if your logs indicate attempted exploit.
>
> (If you are only sending email using an Anymail EmailBackend, and have not set up
> Anymail's event tracking webhooks, this issue does not affect you.)
>
> Anymail's webhook validation was vulnerable to a timing attack. A remote attacker
> could use this to obtain your WEBHOOK_AUTHORIZATION shared secret, potentially allowing
> them to post fabricated or malicious email tracking events to your app.
>
> There have not been any reports of attempted exploit. (The vulnerability was discovered
> through code review.) Attempts would be visible in HTTP logs as a very large number of
> 400 responses on Anymail's webhook urls (by default "/anymail/*esp_name*/tracking/"),
> and in Python error monitoring as a very large number of
> AnymailWebhookValidationFailure exceptions.
>
>
> v1.2
> ----
>
> *2017-11-02*
>
> Features
> ~~~~~~~~
>
> * **Postmark:** Support new click webhook in normalized tracking events
>
>
> v1.1
> ----
>
> *2017-10-28*
>
> Fixes
> ... (truncated)
Commits
- [`194b42f`](https://github.com/anymail/django-anymail/commit/194b42fe45f8f3b804abf0ba4a75cefdcddc2638) Release 1.2.1
- [`c079983`](https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d3607a04691b) Security: prevent timing attack on WEBHOOK_AUTHORIZATION secret
- [`7029298`](https://github.com/anymail/django-anymail/commit/7029298b930620b1655dab2548f72d6640a5905e) Release 1.2
- [`7e90818`](https://github.com/anymail/django-anymail/commit/7e908184ed5e4e29ece9cd08968a8bbfa66b4350) Postmark: support "clicked" tracking events
- [`930753e`](https://github.com/anymail/django-anymail/commit/930753e4b6437c65921b99ae2e1e92f82c5b57bc) Release 1.1
- [`9acf650`](https://github.com/anymail/django-anymail/commit/9acf6501b583fa490efb6af38558663e257c6f4a) Utils: Finish ParsedEmail --> EmailAddress conversion
- [`bb68f3d`](https://github.com/anymail/django-anymail/commit/bb68f3dd6defc3e58a9d9c52661f4f4eb9a5e10e) Mailgun: fix event/metadata param extraction in tracking webhook
- [`636c8a5`](https://github.com/anymail/django-anymail/commit/636c8a5d80a93add9595f9670d633be62b415d66) Tests: move sample files into separate subdir
- [`3866689`](https://github.com/anymail/django-anymail/commit/386668908423d1d4eade90cf7a21a546a1e96514) Utils: convert internal ParsedEmail to documented EmailAddress
- [`fe097ce`](https://github.com/anymail/django-anymail/commit/fe097ce4b4979643721d9b8b0439c0cada923d6b) Utils: add parse_rfc2822date
- Additional commits viewable in [compare view](https://github.com/anymail/django-anymail/compare/v1.0...v1.2.1)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/OLC-Bioinformatics/olc_genomics_portal/network/alerts).
Bumps django-anymail from 1.0 to 1.2.1.
Release notes
*Sourced from [django-anymail's releases](https://github.com/anymail/django-anymail/releases).* > ## v1.2.1 > #### Security fix > > This release fixes a moderate severity security issue affecting Anymail v0.2–v1.2: > Prevent timing attack on WEBHOOK_AUTHORIZATION secret ([CVE-2018-6596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6596)) > > If you are using Anymail's tracking webhooks, you should upgrade to this release, and you may want to rotate to a new WEBHOOK_AUTHORIZATION shared secret (see [docs](http://anymail.readthedocs.io/en/stable/tips/securing_webhooks/#use-a-shared-authorization-secret)). You should definitely change your webhook auth if your logs indicate attempted exploit. > > (If you are only sending email using an Anymail EmailBackend, and have not set up Anymail's event tracking webhooks, this issue does not affect you.) > > *More information* > > Anymail's webhook validation was vulnerable to a timing attack. A remote attacker could use this to obtain your WEBHOOK_AUTHORIZATION shared secret, potentially allowing them to post fabricated or malicious email tracking events to your app. > > There have not been any reports of attempted exploit. (The vulnerability was discovered through code review.) Attempts would be visible in HTTP logs as a very large number of 400 responses on Anymail's webhook urls (by default "/anymail/*esp_name*/tracking/"), and in Python error monitoring as a very large number of AnymailWebhookValidationFailure exceptions. > > ## v1.2 > #### New features > > * **Postmark:** Support new click webhook in normalized tracking events > > ## v1.1 > #### Bug fixes > > * **Mailgun:** Support metadata in opened/clicked/unsubscribed tracking webhooks, and fix potential problems if metadata keys collided with Mailgun event parameter names. (See [#76](https://github-redirect.dependabot.com/anymail/django-anymail/issues/76), [#77](https://github-redirect.dependabot.com/anymail/django-anymail/issues/77)) > > #### Other changes > > * **Internal:** Rework Anymail's ParsedEmail class and rename to EmailAddress to align it with similar functionality in the Python 3.6 email package, in preparation for future inbound support. ParsedEmail was not documented for use outside Anymail's internals (so this change does not bump the semver major version), but if you were using it in an undocumented way you will need to update your code.Changelog
*Sourced from [django-anymail's changelog](https://github.com/anymail/django-anymail/blob/master/CHANGELOG.rst).* > v1.2.1 > ------ > > *2018-02-02* > > Security > ~~~~~~~~ > > * Fix a **moderate severity** security issue affecting Anymail v0.2–v1.2: > prevent timing attack on WEBHOOK_AUTHORIZATION secret. > (`CVE-2018-6596Commits
- [`194b42f`](https://github.com/anymail/django-anymail/commit/194b42fe45f8f3b804abf0ba4a75cefdcddc2638) Release 1.2.1 - [`c079983`](https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d3607a04691b) Security: prevent timing attack on WEBHOOK_AUTHORIZATION secret - [`7029298`](https://github.com/anymail/django-anymail/commit/7029298b930620b1655dab2548f72d6640a5905e) Release 1.2 - [`7e90818`](https://github.com/anymail/django-anymail/commit/7e908184ed5e4e29ece9cd08968a8bbfa66b4350) Postmark: support "clicked" tracking events - [`930753e`](https://github.com/anymail/django-anymail/commit/930753e4b6437c65921b99ae2e1e92f82c5b57bc) Release 1.1 - [`9acf650`](https://github.com/anymail/django-anymail/commit/9acf6501b583fa490efb6af38558663e257c6f4a) Utils: Finish ParsedEmail --> EmailAddress conversion - [`bb68f3d`](https://github.com/anymail/django-anymail/commit/bb68f3dd6defc3e58a9d9c52661f4f4eb9a5e10e) Mailgun: fix event/metadata param extraction in tracking webhook - [`636c8a5`](https://github.com/anymail/django-anymail/commit/636c8a5d80a93add9595f9670d633be62b415d66) Tests: move sample files into separate subdir - [`3866689`](https://github.com/anymail/django-anymail/commit/386668908423d1d4eade90cf7a21a546a1e96514) Utils: convert internal ParsedEmail to documented EmailAddress - [`fe097ce`](https://github.com/anymail/django-anymail/commit/fe097ce4b4979643721d9b8b0439c0cada923d6b) Utils: add parse_rfc2822date - Additional commits viewable in [compare view](https://github.com/anymail/django-anymail/compare/v1.0...v1.2.1)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/OLC-Bioinformatics/olc_genomics_portal/network/alerts).