UW-GAC / primed-django

PRIMED Consortium Django application website
MIT License
0 stars 0 forks source link

Bump django from 4.2.15 to 4.2.16 #732

Closed dependabot[bot] closed 2 months ago

dependabot[bot] commented 2 months ago

Bumps django from 4.2.15 to 4.2.16.

Commits
  • 6f9fea3 [4.2.x] Bumped version for 4.2.16 release.
  • bf4888d [4.2.x] Fixed CVE-2024-45231 -- Avoided server error on password reset when e...
  • d147a8e [4.2.x] Fixed CVE-2024-45230 -- Mitigated potential DoS in urlize and urlizet...
  • 705066d [4.2.x] Fixed grammatical error in stub release notes for upcoming security r...
  • b07d4f2 [4.2.x] Added stub release notes and release date for 4.2.16.
  • e0579ce [4.2.x] Added CVE-2024-41989, CVE-2024-41990, CVE-2024-41991, and CVE-2024-42...
  • ae0ca83 [4.2.x] Post-release version bump.
  • See full diff in compare view


Most Recent Ignore Conditions Applied to This Pull Request | Dependency Name | Ignore Conditions | | --- | --- | | django | [>= 4.1.a, < 4.2] | | django | [>= 5.0.a, < 5.1] | | django | [>= 5.1.a, < 5.2] |

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
codecov[bot] commented 2 months ago

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 99.01%. Comparing base (7935be7) to head (b79ac3a). Report is 14 commits behind head on main.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## main #732 +/- ## ======================================= Coverage 99.01% 99.01% ======================================= Files 325 325 Lines 30708 30708 ======================================= Hits 30406 30406 Misses 302 302 ```

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.