Bumps django from 2.1.5 to 2.2. This update includes security fixes.
Vulnerabilities fixed
*Sourced from The GitHub Security Advisory Database.*
> **Memory exhaustion in django.utils.numberformat.format()**
> If django.utils.numberformat.format() -- used by contrib.admin as well as the the floatformat, filesizeformat, and intcomma templates filters -- received a Decimal with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to '{:f}'.format().
>
> Affected versions: >= 1.11.0, < 1.11.19; >= 2.0.0, < 2.0.11; >= 2.1.0, < 2.1.6
*Sourced from The GitHub Security Advisory Database.*
> **Moderate severity vulnerability that affects django**
> Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
>
> Affected versions: >= 2.1.0, < 2.1.6
Commits
- [`635d53a`](https://github.com/django/django/commit/635d53a86a36cde7866b9caefeb64d809e6bfcd9) [2.2.x] Bumped version number for 2.2 release.
- [`bc6f1da`](https://github.com/django/django/commit/bc6f1da6e9930db89df249b5a8c06bd261d0e9d8) [2.2.x] Set release date in v2.2 release notes.
- [`5427148`](https://github.com/django/django/commit/54271486871c071260d9b89a304d7b6fdd06dd0e) [2.2.x] Updated man page for 2.2 final.
- [`7090cbf`](https://github.com/django/django/commit/7090cbf54202c21978a93bdb76ba006780e1865c) [2.2.x] Updated contrib translations from Transifex
- [`98f526e`](https://github.com/django/django/commit/98f526e67c2899b9d44ba7cdbab5d70b1baa0060) [2.2.x] Updated core translations from Transifex
- [`917aa55`](https://github.com/django/django/commit/917aa556a9a64e6bdab9206a33a361549d7d31d9) [2.2.x] Fixed [#30289](https://github-redirect.dependabot.com/django/django/issues/30289) -- Prevented admin inlines for a ManyToManyField's impli...
- [`de62ba9`](https://github.com/django/django/commit/de62ba965fb7fdf44da03af3c31ced77cb09b744) [2.2.x] Added stub 2.1.8 release notes.
- [`fc708f3`](https://github.com/django/django/commit/fc708f32f50b2c5ef35ffc0fccae362ded5f93f1) [2.2.x] Refs [#30278](https://github-redirect.dependabot.com/django/django/issues/30278) -- Fixed link in cached_property docs.
- [`f141704`](https://github.com/django/django/commit/f14170406c8a1f97eacbc38830a7af62a17a31dd) [2.2.x] Refs [#30278](https://github-redirect.dependabot.com/django/django/issues/30278) -- Doc'd behavior of del on an unaccessed cached_property.
- [`4a7bbac`](https://github.com/django/django/commit/4a7bbace6bdfc3a4083df83bca3c456efbd66a53) [2.2.x] Fixed [#30265](https://github-redirect.dependabot.com/django/django/issues/30265) -- Fixed a tutorial number in Reusable App tutorial.
- Additional commits viewable in [compare view](https://github.com/django/django/compare/2.1.5...2.2)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)
Finally, you can contact us by mentioning @dependabot.
Bumps django from 2.1.5 to 2.2. This update includes security fixes.
Vulnerabilities fixed
*Sourced from The GitHub Security Advisory Database.* > **Memory exhaustion in django.utils.numberformat.format()** > If django.utils.numberformat.format() -- used by contrib.admin as well as the the floatformat, filesizeformat, and intcomma templates filters -- received a Decimal with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to '{:f}'.format(). > > Affected versions: >= 1.11.0, < 1.11.19; >= 2.0.0, < 2.0.11; >= 2.1.0, < 2.1.6 *Sourced from The GitHub Security Advisory Database.* > **Moderate severity vulnerability that affects django** > Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function. > > Affected versions: >= 2.1.0, < 2.1.6Commits
- [`635d53a`](https://github.com/django/django/commit/635d53a86a36cde7866b9caefeb64d809e6bfcd9) [2.2.x] Bumped version number for 2.2 release. - [`bc6f1da`](https://github.com/django/django/commit/bc6f1da6e9930db89df249b5a8c06bd261d0e9d8) [2.2.x] Set release date in v2.2 release notes. - [`5427148`](https://github.com/django/django/commit/54271486871c071260d9b89a304d7b6fdd06dd0e) [2.2.x] Updated man page for 2.2 final. - [`7090cbf`](https://github.com/django/django/commit/7090cbf54202c21978a93bdb76ba006780e1865c) [2.2.x] Updated contrib translations from Transifex - [`98f526e`](https://github.com/django/django/commit/98f526e67c2899b9d44ba7cdbab5d70b1baa0060) [2.2.x] Updated core translations from Transifex - [`917aa55`](https://github.com/django/django/commit/917aa556a9a64e6bdab9206a33a361549d7d31d9) [2.2.x] Fixed [#30289](https://github-redirect.dependabot.com/django/django/issues/30289) -- Prevented admin inlines for a ManyToManyField's impli... - [`de62ba9`](https://github.com/django/django/commit/de62ba965fb7fdf44da03af3c31ced77cb09b744) [2.2.x] Added stub 2.1.8 release notes. - [`fc708f3`](https://github.com/django/django/commit/fc708f32f50b2c5ef35ffc0fccae362ded5f93f1) [2.2.x] Refs [#30278](https://github-redirect.dependabot.com/django/django/issues/30278) -- Fixed link in cached_property docs. - [`f141704`](https://github.com/django/django/commit/f14170406c8a1f97eacbc38830a7af62a17a31dd) [2.2.x] Refs [#30278](https://github-redirect.dependabot.com/django/django/issues/30278) -- Doc'd behavior of del on an unaccessed cached_property. - [`4a7bbac`](https://github.com/django/django/commit/4a7bbace6bdfc3a4083df83bca3c456efbd66a53) [2.2.x] Fixed [#30265](https://github-redirect.dependabot.com/django/django/issues/30265) -- Fixed a tutorial number in Reusable App tutorial. - Additional commits viewable in [compare view](https://github.com/django/django/compare/2.1.5...2.2)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.