turian / audio-discrimination-crowdsource

Web service to crowd-source audio discrimination data
2 stars 3 forks source link

Bump django-allauth from 0.53.1 to 0.54.0 #187

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps django-allauth from 0.53.1 to 0.54.0.

Changelog

Sourced from django-allauth's changelog.

0.54.0 (2023-03-31)


Note worthy changes

  • Dropped support for EOL Python versions (3.5, 3.6).

Security notice

  • Even when account enumeration prevention was turned on, it was possible for an attacker to infer whether or not a given account exists based upon the response time of an authentication attempt. Fixed.
Commits
  • 77368a8 chore: Preparing release 0.54.0
  • 6acb0dc fix(account): Account enumeration timing attack
  • 367865f docs: Remove ACCOUNT_PREVENT_ENUMERATION warning
  • 64d2477 chore: Run extra CI on Python 3.11
  • da299f8 chore: Run CI on Ubuntu 22
  • 632f37d chore!: Drop support for EOL Python 3.5 and 3.6, test on Python 3.11 too
  • afa3ea9 docs(README): Reworded inspite
  • 54d7280 chore(socialaccount): Remove hard-coded redirect URL
  • 0655cdf feat(accounts): add key to password reset template
  • See full diff in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)