Bumps django from 1.5.4 to 1.11.20. This update includes security fixes.
Vulnerabilities fixed
*Sourced from The GitHub Security Advisory Database.*
> **Low severity vulnerability that affects django**
> In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
>
> Affected versions: < 1.11.18
*Sourced from The GitHub Security Advisory Database.*
> **Moderate severity vulnerability that affects django**
> Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
>
> Affected versions: < 1.11.19
Commits
- [`1c9cb94`](https://github.com/django/django/commit/1c9cb948d7b0c264d244763b6682ab790a6b90a0) [1.11.x] Bumped version for 1.11.20 release.
- [`f2c5f66`](https://github.com/django/django/commit/f2c5f66c7c7212721ce2de6a44dfd828c7268c16) [1.11.x] Refs [#30175](https://github-redirect.dependabot.com/django/django/issues/30175) -- Added release notes for 1.11.20 release.
- [`1cdba62`](https://github.com/django/django/commit/1cdba624d55d5c2fe3c74fff1fb5fb17b126821d) [1.11.x] Bumped version for 1.11.19 release.
- [`0bbb560`](https://github.com/django/django/commit/0bbb560183fabf0533289700845dafa94951f227) [1.11.x] Fixed CVE-2019-6975 -- Fixed memory exhaustion in utils.numberformat...
- [`11cb395`](https://github.com/django/django/commit/11cb39514dcb6de197ce22f8fa0cf011d53162e7) [1.11.x] Removed extra characters in docs header underlines.
- [`fc858ab`](https://github.com/django/django/commit/fc858abe51675843407debbd613c2be627a1209f) Added stub release notes for security releases.
- [`f245cec`](https://github.com/django/django/commit/f245cecc6f887d181bfa2400f60283ad5037c485) [1.11.x] Used extlinks for GitHub commits.
- [`5a50ef9`](https://github.com/django/django/commit/5a50ef90852be2723e97b0bd4537fc8faa5f263f) [1.11.x] Replaced CVE/ticket roles with extlinks.
- [`951ee0b`](https://github.com/django/django/commit/951ee0b118eb640e6484189117be3308417d87bd) [1.11.x] Refs [#30150](https://github-redirect.dependabot.com/django/django/issues/30150) -- Doc'd that MySQL 8 isn't supported.
- [`cea425e`](https://github.com/django/django/commit/cea425e6eb7db9ae56e835577415267e95a56e26) [1.11.x] Fixed E117 and F405 flake8 warnings.
- Additional commits viewable in [compare view](https://github.com/django/django/compare/1.5.4...1.11.20)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)
Finally, you can contact us by mentioning @dependabot.
Bumps django from 1.5.4 to 1.11.20. This update includes security fixes.
Vulnerabilities fixed
*Sourced from The GitHub Security Advisory Database.* > **Low severity vulnerability that affects django** > In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content. > > Affected versions: < 1.11.18 *Sourced from The GitHub Security Advisory Database.* > **Moderate severity vulnerability that affects django** > Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function. > > Affected versions: < 1.11.19Commits
- [`1c9cb94`](https://github.com/django/django/commit/1c9cb948d7b0c264d244763b6682ab790a6b90a0) [1.11.x] Bumped version for 1.11.20 release. - [`f2c5f66`](https://github.com/django/django/commit/f2c5f66c7c7212721ce2de6a44dfd828c7268c16) [1.11.x] Refs [#30175](https://github-redirect.dependabot.com/django/django/issues/30175) -- Added release notes for 1.11.20 release. - [`1cdba62`](https://github.com/django/django/commit/1cdba624d55d5c2fe3c74fff1fb5fb17b126821d) [1.11.x] Bumped version for 1.11.19 release. - [`0bbb560`](https://github.com/django/django/commit/0bbb560183fabf0533289700845dafa94951f227) [1.11.x] Fixed CVE-2019-6975 -- Fixed memory exhaustion in utils.numberformat... - [`11cb395`](https://github.com/django/django/commit/11cb39514dcb6de197ce22f8fa0cf011d53162e7) [1.11.x] Removed extra characters in docs header underlines. - [`fc858ab`](https://github.com/django/django/commit/fc858abe51675843407debbd613c2be627a1209f) Added stub release notes for security releases. - [`f245cec`](https://github.com/django/django/commit/f245cecc6f887d181bfa2400f60283ad5037c485) [1.11.x] Used extlinks for GitHub commits. - [`5a50ef9`](https://github.com/django/django/commit/5a50ef90852be2723e97b0bd4537fc8faa5f263f) [1.11.x] Replaced CVE/ticket roles with extlinks. - [`951ee0b`](https://github.com/django/django/commit/951ee0b118eb640e6484189117be3308417d87bd) [1.11.x] Refs [#30150](https://github-redirect.dependabot.com/django/django/issues/30150) -- Doc'd that MySQL 8 isn't supported. - [`cea425e`](https://github.com/django/django/commit/cea425e6eb7db9ae56e835577415267e95a56e26) [1.11.x] Fixed E117 and F405 flake8 warnings. - Additional commits viewable in [compare view](https://github.com/django/django/compare/1.5.4...1.11.20)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.