embassynetwork / modernomad

manage multi-use community houses: members, guests, events.
https://embassynetwork.com/
GNU Affero General Public License v3.0
133 stars 59 forks source link

Bump django-debug-toolbar from 1.11 to 3.2.3 #872

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps django-debug-toolbar from 1.11 to 3.2.3.

Release notes

Sourced from django-debug-toolbar's releases.

3.2.3

What's Changed

New Contributors

Full Changelog: https://github.com/jazzband/django-debug-toolbar/compare/3.2.2...3.2.3

3.2.2

What's Changed

... (truncated)

Changelog

Sourced from django-debug-toolbar's changelog.

3.2.3 (2021-12-12)

  • Changed cache monkey-patching for Django 3.2+ to iterate over existing caches and patch them individually rather than attempting to patch django.core.caches as a whole. The middleware.cache is still being patched as a whole in order to attempt to catch any cache usages before enable_instrumentation is called.
  • Add check W006 to warn that the toolbar is incompatible with TEMPLATES settings configurations with APP_DIRS set to False.
  • Create urls module and update documentation to no longer require importing the toolbar package.

3.2.2 (2021-08-14)

  • Ensured that the handle stays within bounds when resizing the window.
  • Disabled HistoryPanel when RENDER_PANELS is True or if RENDER_PANELS is None and the WSGI container is running with multiple processes.
  • Fixed RENDER_PANELS functionality so that when True panels are rendered during the request and not loaded asynchronously.
  • HistoryPanel now shows status codes of responses.
  • Support request.urlconf override when checking for toolbar requests.

3.2.1 (2021-04-14)

  • Fixed SQL Injection vulnerability, CVE-2021-30459. The toolbar now calculates a signature on all fields for the SQL select, explain, and analyze forms.
  • Changed djdt.cookie.set() to set sameSite=Lax by default if callers do not provide a value.
  • Added PRETTIFY_SQL configuration option to support controlling SQL token grouping. By default it's set to True. When set to False, a performance improvement can be seen by the SQL panel.
  • Added a JavaScript event when a panel loads of the format djdt.panel.[PanelId] where PanelId is the panel_id property of the panel's Python class. Listening for this event corrects the bug in the Timer Panel in which it didn't insert the browser timings after switching requests in the History Panel.
  • Fixed issue with the toolbar expecting URL paths to start with /__debug__/ while the documentation indicates it's not required.

3.2 (2020-12-03)

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 years ago

Superseded by #878.