hackariens / django

Templates pour la crΓ©ation d'un nouveau projet django
2 stars 0 forks source link

chore(deps): update dependency django to v3.1.10 [security] - autoclosed #60

Closed renovate[bot] closed 3 years ago

renovate[bot] commented 3 years ago

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
Django (source, changelog) ==3.1.7 -> ==3.1.10 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-28658

In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

CVE-2021-31542

In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.


Release Notes

django/django ### [`v3.1.10`](https://togithub.com/django/django/compare/3.1.9...3.1.10) [Compare Source](https://togithub.com/django/django/compare/3.1.9...3.1.10) ### [`v3.1.9`](https://togithub.com/django/django/compare/3.1.8...3.1.9) [Compare Source](https://togithub.com/django/django/compare/3.1.8...3.1.9) ### [`v3.1.8`](https://togithub.com/django/django/compare/3.1.7...3.1.8) [Compare Source](https://togithub.com/django/django/compare/3.1.7...3.1.8)

Configuration

πŸ“… Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by WhiteSource Renovate. View repository job log here.

guardrails[bot] commented 3 years ago

All previously detected findings have been fixed. Good job! πŸ‘πŸŽ‰

We will keep this comment up-to-date as you go along and notify you of any security issues that we identify.


πŸ‘‰ Go to the dashboard for detailed results.

πŸ“₯ Happy? Share your feedback with us.