| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2014-09-02 | [1.5.x] Bump version numbers for bugfix release.1.5.10 | James Bennett | |
| 2014-08-28 | [1.5.x] Fixed #23375 -- Added missing security issues to the archive. | Simon Charette | |
| Backport of c9c0be3 from master | |||
| 2014-08-27 | Fixed #23329 -- Allowed inherited and m2m fields to be referenced in the admin. | Simon Charette | |
| Thanks to Trac alias Markush2010 and ross for the detailed reports. Backport of 3cbb759 from master | |||
| 2014-08-26 | [1.5.x] Fixed spelling mistake in file docs. | Tim Graham | |
| Backport of a3e88e64a4 from master | |||
| 2014-08-20 | [1.5.x] Bumped version number post-release. | Tim Graham | |
| 2014-08-20 | [1.5.x] Added dates to release notes. | Tim Graham | |
| 2014-08-20 | [1.5.x] Bump version numbers for security release.1.5.9 | James Bennett | |
| 2014-08-20 | [1.5.x] Prevented data leakage in contrib.admin via query string manipulation. | Simon Charette | |
| This is a security fix. Disclosure following shortly. | |||
| 2014-08-20 | [1.5.x] Fixed #23066 -- Modified RemoteUserMiddleware to logout on ↵ | Preston Holmes | |
| REMOTE_USE change. This is a security fix. Disclosure following shortly. | |||
| 2014-08-20 | [1.5.x] Fixed #23157 -- Removed O(n) algorithm when uploading duplicate file ↵ | Tim Graham | |
| names. This is a security fix. Disclosure following shortly. | |||
| 2014-08-20 | [1.5.x] Prevented reverse() from generating URLs pointing to other hosts. | Florian Apolloner | |
| This is a security fix. Disclosure following shortly. | |||
| 2014-08-20 | [1.5.x] Added release note stubs for 1.5.9 and 1.4.14. | Tim Graham | |
| 2014-08-13 | [1.5.x] Corrected content_type parameter name in sitemap docs. | Tim Graham | |
| mimetype was deprecated in 1.5 per 11ec0253ab4cc926ab9e77619132cb398231ac33. Backport of a7443c24a3 from master | |||
| 2014-08-11 | [1.5.x] Added a warning that remove_tags() output shouldn't be considered safe. | Tim Graham | |
| Backport of 7efce77de2 from master | |||
| 2014-08-11 | [1.5.x] Fixed #23267 -- Fixed typo in Translation documentation | Ola Sitarska | |
| Thanks to Tomin1 for the report. Backport of 2e7be92b4df29ac851d570e57da5dcf756c5ac52 from master. | |||
| 2014-08-08 | [1.5.x] Noted that django-jython requires Django 1.7. | Tim Graham | |
| Backport of 72e98d5c16 from stable/1.6.x | |||
| 2014-08-06 | [1.5.x] Removed a doc reference to the deprecated `mimetype` kwarg. | Mohammed Attia | |
| Backport of 61ed959235 from master | |||
| 2014-08-06 | [1.5.x] Fixed #23239 -- Clarified a phrase in the contrib.markup docs. | Tim Graham | |
| 2014-08-02 | [1.5.x] Fixed #23149 -- Clarified note on HTTPOnly in cookie-based session docs | Erik Romijn | |
| Backport of e26366da44bb343e7a95d01ff0dd18b8026c2802 from master. | |||
| 2014-07-14 | [1.5.x] Revert "Fixed #13794 -- Fixed to_field usage in BaseInlineFormSet." | Ramiro Morales | |
| This reverts commit 4ae68f677b3348765d8649d8b57beffa18fe8d3d. stable/1.5.x branch is in security-fixes-only mode. | |||
| 2014-07-14 | [1.5.x] Fixed #13794 -- Fixed to_field usage in BaseInlineFormSet. | Tim Graham | |
| Thanks sebastien at clarisys.fr for the report and gautier for the patch. Backport of 5e2c4a4bd1 from master | |||
| 2014-07-07 | [1.5.x] Fixed #22966 -- Clarified which release notes appear for each doc ↵ | Tim Graham | |
| version. Thanks haimunt at yahoo.com for the suggestion. Backport of e6b3d6c22f from master | |||
| 2014-06-18 | [1.5.x] Fixed #22859 -- Improved crossDomain technique in CSRF example. | Tim Graham | |
| Thanks flisky for the report. Backport of 0be4d64487 from master | |||
| 2014-06-15 | [1.5.x] Fixed #22842 | vagrant | |
| Backport of 7a1f8414c3b71b6af03e5be9f5f8db115551c410 from master. | |||
| 2014-05-29 | [1.5.x] Improved deprecation plan links in release notes. | Tim Graham | |
| Backport of 7ff326928a08d4c51141768bd305a44ca5ecb2e7 from master | |||
| 2014-05-17 | [1.5.x] Fixed #22644 -- Clarified documentation for NamedUrlWizardView | Erik Romijn | |
| Backport of 727d048f0991ccbd1564c6fb225ffbfd2f1a2102 from master. | |||
| 2014-05-16 | [1.5.x] Fixed case in form widgets docs | Claude Paroz | |
| Backport of 9494f29d from master | |||
| 2014-05-16 | [1.5.x] Fixed #22167 -- Improved documentation on context processors | Moritz | |
| Backport of e7ffba8f78849fbf60b98fb8d67ef4577b585e3b from master. | |||
| 2014-05-15 | [1.5.x] Minor edits to latest release notes. | Tim Graham | |
| Backport of 860d31ac7a3bdd4b27db8b34b110b3d801ddaf8a from master | |||
| 2014-05-14 | Bumped version number post release. | Jacob Kaplan-Moss | |
| 2014-05-14 | Bumped version numbers for release.1.5.8 | Jacob Kaplan-Moss | |
| 2014-05-14 | Added release notes for 1.4.13, 1.5.8. | Jacob Kaplan-Moss | |
| 2014-05-12 | [1.5.x] Added additional checks in is_safe_url to account for flexible parsing. | Erik Romijn | |
| This is a security fix. Disclosure following shortly. | |||
| 2014-05-12 | [1.5.x] Dropped fix_IE_for_vary/attach. | Aymeric Augustin | |
| This is a security fix. Disclosure following shortly. | |||
| 2014-05-05 | [1.5.x] Fixed #22575 -- Fixed typo in ↵ | Tim Graham | |
| docs/topics/class-based-views/generic-editing.txt. Thanks adminq80 at gmail.com. Backport of 87776859af from master | |||
| 2014-04-28 | [1.5.x] Added dates to release notes of today's release. | Tim Graham | |
| Backport of 68d264059abb21b96c4fe68bf4d99520268a451c from master | |||
| 2014-04-28 | [1.5.x] Post release version bump. | Tim Graham | |
| 2014-04-28 | [1.5.x] Update version numbers for 1.5.7 bugfix release.1.5.7 | James Bennett | |
| 2014-04-23 | [1.5.x] Removed bad import in last commit. | Tim Graham | |
| 2014-04-23 | [1.5.x] Fixed #22486 -- Restored the ability to reverse views created using ↵ | Tim Graham | |
| functools.partial. Regression in 8b93b31487d6d3b0fcbbd0498991ea0db9088054. Thanks rcoup for the report. Backport of 3c06b2f2a3 from master | |||
| 2014-04-22 | [1.5.x] Updated grammar in description of django.contrib.auth. | Ray Ashman | |
| Backport of 9853779805 from master | |||
| 2014-04-22 | [1.5.x] Post release version bump. | Tim Graham | |
| 2014-04-21 | [1.5.x] Add missing disclosure information to security archive. | James Bennett | |
| 2014-04-21 | [1.5.x] Update for 1.5.6 security release.1.5.6 | James Bennett | |
| 2014-04-21 | [1.5.x] Added information on resolved security issues to release notes. | Erik Romijn | |
| Backport of c07f3e60c2d455e36ba4ac339d4283d32bbc3814 from master | |||
| 2014-04-21 | [1.5.x] Fixed queries that may return unexpected results on MySQL due to ↵ | Erik Romijn | |
| typecasting. This is a security fix. Disclosure will follow shortly. Backport of 75c0d4ea3ae48970f788c482ee0bd6b29a7f1307 from master | |||
| 2014-04-21 | [1.5.x] Prevented leaking the CSRF token through caching. | Aymeric Augustin | |
| This is a security fix. Disclosure will follow shortly. Backport of c083e3815aec23b99833da710eea574e6f2e8566 from master | |||
| 2014-04-21 | [1.5.x] Fixed a remote code execution vulnerabilty in URL reversing. | Tim Graham | |
| Thanks Benjamin Bach for the report and initial patch. This is a security fix; disclosure to follow shortly. Backport of 8b93b31487d6d3b0fcbbd0498991ea0db9088054 from master | |||
| 2014-04-21 | [1.5.x] Corrected the section identifier for MySQL unicode reference. | Matt Lauber | |
| Backport of b2514c02e1 from master | |||
| 2014-04-18 | [1.5.x] Fixed #22471 -- Corrected misprint in i18n docs | Erik Romijn | |
| Backport of 54d5c37de6572eae57a66339bb38719e681cee82 from master. | |||
