Skip to content

fix(deps): update dependency django to v4.2.1 [security]#133

Merged
descope[bot] merged 1 commit intomainfrom
renovate/pypi-Django-vulnerability
May 9, 2023
Merged

fix(deps): update dependency django to v4.2.1 [security]#133
descope[bot] merged 1 commit intomainfrom
renovate/pypi-Django-vulnerability

Conversation

@descope
Copy link
Contributor

@descope descope bot commented May 9, 2023

This PR contains the following updates:

Package Type Update Change
Django (source, changelog) dependencies patch ==4.2 -> ==4.2.1

GitHub Vulnerability Alerts

CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.


Release Notes

django/django

v4.2.1

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Jerusalem, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

@descope descope bot added the security label May 9, 2023
@descope descope bot enabled auto-merge (squash) May 9, 2023 22:03
@descope descope bot merged commit 691d81c into main May 9, 2023
@descope descope bot deleted the renovate/pypi-Django-vulnerability branch May 9, 2023 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants