<feed xmlns='http://www.w3.org/2005/Atom'>
<title>chango.git, branch 3.1.12</title>
<subtitle>django
</subtitle>
<id>http://cgit.adnoto.dev/chango.git/atom?h=3.1.12</id>
<link rel='self' href='http://cgit.adnoto.dev/chango.git/atom?h=3.1.12'/>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/'/>
<updated>2021-06-02T08:39:54Z</updated>
<entry>
<title>[3.1.x] Bumped version for 3.1.12 release.</title>
<updated>2021-06-02T08:39:54Z</updated>
<author>
<name>Carlton Gibson</name>
<email>carlton.gibson@noumenal.es</email>
</author>
<published>2021-06-02T08:39:54Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=625d3c1c643b0eb5c84339415ca0ba9f1728efa2'/>
<id>urn:sha1:625d3c1c643b0eb5c84339415ca0ba9f1728efa2</id>
<content type='text'>
</content>
</entry>
<entry>
<title>[3.1.x] Fixed CVE-2021-33571 -- Prevented leading zeros in IPv4 addresses.</title>
<updated>2021-06-02T08:38:07Z</updated>
<author>
<name>Mariusz Felisiak</name>
<email>felisiak.mariusz@gmail.com</email>
</author>
<published>2021-05-24T07:55:14Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=203d4ab9ebcd72fc4d6eb7398e66ed9e474e118e'/>
<id>urn:sha1:203d4ab9ebcd72fc4d6eb7398e66ed9e474e118e</id>
<content type='text'>
validate_ipv4_address() was affected only on Python &lt; 3.9.5, see [1].
URLValidator() uses a regular expressions and it was affected on all
Python versions.

[1] https://bugs.python.org/issue36384
</content>
</entry>
<entry>
<title>[3.1.x] Fixed CVE-2021-33203 -- Fixed potential path-traversal via admindocs' TemplateDetailView.</title>
<updated>2021-06-02T08:38:07Z</updated>
<author>
<name>Florian Apolloner</name>
<email>florian@apolloner.eu</email>
</author>
<published>2021-05-17T09:26:36Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=20c67a0693c4ede2b09af02574823485e82e4c8f'/>
<id>urn:sha1:20c67a0693c4ede2b09af02574823485e82e4c8f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>[3.1.x] Confirmed release date for Django 3.1.12, and 2.2.24.</title>
<updated>2021-06-02T08:22:02Z</updated>
<author>
<name>Carlton Gibson</name>
<email>carlton.gibson@noumenal.es</email>
</author>
<published>2021-06-02T08:19:19Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=aa8781c0a671610d5327d0a14d45df3b1f29640d'/>
<id>urn:sha1:aa8781c0a671610d5327d0a14d45df3b1f29640d</id>
<content type='text'>
Backport of f66ae7a2d5558fe88ddfe639a610573872be6628 from main
</content>
</entry>
<entry>
<title>[3.1.x] Fixed typo in MiddlewareMixin deprecation note.</title>
<updated>2021-05-27T04:55:00Z</updated>
<author>
<name>Nick Pope</name>
<email>nick@nickpope.me.uk</email>
</author>
<published>2021-05-26T19:01:09Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=a4eb07ac06fa629f13fe757cda730f77dbf46074'/>
<id>urn:sha1:a4eb07ac06fa629f13fe757cda730f77dbf46074</id>
<content type='text'>
Backport of e513fb0e77baf2ebcbf2cbe366bdf0228d01119f from main.
</content>
</entry>
<entry>
<title>[3.1.x] Added stub release notes and date for Django 3.1.12 and 2.2.24.</title>
<updated>2021-05-26T08:19:28Z</updated>
<author>
<name>Carlton Gibson</name>
<email>carlton.gibson@noumenal.es</email>
</author>
<published>2021-05-25T08:38:20Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=c7fdc790cfebe52371e04c03164ac5ab93ac3e67'/>
<id>urn:sha1:c7fdc790cfebe52371e04c03164ac5ab93ac3e67</id>
<content type='text'>
Backport of b46dbd4e3e255223078ae0028934ea986e19ebc1 from main
</content>
</entry>
<entry>
<title>[3.1.x] Changed IRC references to Libera.Chat.</title>
<updated>2021-05-20T10:29:31Z</updated>
<author>
<name>Mariusz Felisiak</name>
<email>felisiak.mariusz@gmail.com</email>
</author>
<published>2021-05-20T10:23:36Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=024e969062d1b7772c48c5fe45b65fcde50dea67'/>
<id>urn:sha1:024e969062d1b7772c48c5fe45b65fcde50dea67</id>
<content type='text'>
Backport of 66491f08fe86629fa25977bb3dddda06959f65e7 from main.
</content>
</entry>
<entry>
<title>[3.1.x] Post-release version bump.</title>
<updated>2021-05-13T07:18:51Z</updated>
<author>
<name>Mariusz Felisiak</name>
<email>felisiak.mariusz@gmail.com</email>
</author>
<published>2021-05-13T07:18:51Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=c53a76bdbf9b88fac0820cac50ae42e43f9b803f'/>
<id>urn:sha1:c53a76bdbf9b88fac0820cac50ae42e43f9b803f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>[3.1.x] Bumped version for 3.1.11 release.</title>
<updated>2021-05-13T07:16:23Z</updated>
<author>
<name>Mariusz Felisiak</name>
<email>felisiak.mariusz@gmail.com</email>
</author>
<published>2021-05-13T07:16:23Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=6efdf1b7e9425c186f5ae1c5dd9a11629131fcbe'/>
<id>urn:sha1:6efdf1b7e9425c186f5ae1c5dd9a11629131fcbe</id>
<content type='text'>
</content>
</entry>
<entry>
<title>[3.1.x] Fixed #32718 -- Relaxed file name validation in FileField.</title>
<updated>2021-05-13T06:56:06Z</updated>
<author>
<name>Mariusz Felisiak</name>
<email>felisiak.mariusz@gmail.com</email>
</author>
<published>2021-05-13T06:53:44Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/chango.git/commit/?id=b7d4a6fa650f97982cf9ca246ddfa623d685487b'/>
<id>urn:sha1:b7d4a6fa650f97982cf9ca246ddfa623d685487b</id>
<content type='text'>
- Validate filename returned by FileField.upload_to() not a filename
  passed to the FileField.generate_filename() (upload_to() may
  completely ignored passed filename).
- Allow relative paths (without dot segments) in the generated filename.

Thanks to Jakub Kleň for the report and review.
Thanks to all folks for checking this patch on existing projects.
Thanks Florian Apolloner and Markus Holtermann for the discussion and
implementation idea.

Regression in 0b79eb36915d178aef5c6a7bbce71b1e76d376d3.

Backport of b55699968fc9ee985384c64e37f6cc74a0a23683 from main.
</content>
</entry>
</feed>
