summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2014-09-02[1.5.x] Bump version numbers for bugfix release.1.5.10James Bennett
2014-08-28[1.5.x] Fixed #23375 -- Added missing security issues to the archive.Simon Charette
Backport of c9c0be3 from master
2014-08-27Fixed #23329 -- Allowed inherited and m2m fields to be referenced in the admin.Simon Charette
Thanks to Trac alias Markush2010 and ross for the detailed reports. Backport of 3cbb759 from master
2014-08-26[1.5.x] Fixed spelling mistake in file docs.Tim Graham
Backport of a3e88e64a4 from master
2014-08-20[1.5.x] Bumped version number post-release.Tim Graham
2014-08-20[1.5.x] Added dates to release notes.Tim Graham
2014-08-20[1.5.x] Bump version numbers for security release.1.5.9James Bennett
2014-08-20[1.5.x] Prevented data leakage in contrib.admin via query string manipulation.Simon Charette
This is a security fix. Disclosure following shortly.
2014-08-20[1.5.x] Fixed #23066 -- Modified RemoteUserMiddleware to logout on ↵Preston Holmes
REMOTE_USE change. This is a security fix. Disclosure following shortly.
2014-08-20[1.5.x] Fixed #23157 -- Removed O(n) algorithm when uploading duplicate file ↵Tim Graham
names. This is a security fix. Disclosure following shortly.
2014-08-20[1.5.x] Prevented reverse() from generating URLs pointing to other hosts.Florian Apolloner
This is a security fix. Disclosure following shortly.
2014-08-20[1.5.x] Added release note stubs for 1.5.9 and 1.4.14.Tim Graham
2014-08-13[1.5.x] Corrected content_type parameter name in sitemap docs.Tim Graham
mimetype was deprecated in 1.5 per 11ec0253ab4cc926ab9e77619132cb398231ac33. Backport of a7443c24a3 from master
2014-08-11[1.5.x] Added a warning that remove_tags() output shouldn't be considered safe.Tim Graham
Backport of 7efce77de2 from master
2014-08-11[1.5.x] Fixed #23267 -- Fixed typo in Translation documentationOla Sitarska
Thanks to Tomin1 for the report. Backport of 2e7be92b4df29ac851d570e57da5dcf756c5ac52 from master.
2014-08-08[1.5.x] Noted that django-jython requires Django 1.7.Tim Graham
Backport of 72e98d5c16 from stable/1.6.x
2014-08-06[1.5.x] Removed a doc reference to the deprecated `mimetype` kwarg.Mohammed Attia
Backport of 61ed959235 from master
2014-08-06[1.5.x] Fixed #23239 -- Clarified a phrase in the contrib.markup docs.Tim Graham
2014-08-02[1.5.x] Fixed #23149 -- Clarified note on HTTPOnly in cookie-based session docsErik Romijn
Backport of e26366da44bb343e7a95d01ff0dd18b8026c2802 from master.
2014-07-14[1.5.x] Revert "Fixed #13794 -- Fixed to_field usage in BaseInlineFormSet."Ramiro Morales
This reverts commit 4ae68f677b3348765d8649d8b57beffa18fe8d3d. stable/1.5.x branch is in security-fixes-only mode.
2014-07-14[1.5.x] Fixed #13794 -- Fixed to_field usage in BaseInlineFormSet.Tim Graham
Thanks sebastien at clarisys.fr for the report and gautier for the patch. Backport of 5e2c4a4bd1 from master
2014-07-07[1.5.x] Fixed #22966 -- Clarified which release notes appear for each doc ↵Tim Graham
version. Thanks haimunt at yahoo.com for the suggestion. Backport of e6b3d6c22f from master
2014-06-18[1.5.x] Fixed #22859 -- Improved crossDomain technique in CSRF example.Tim Graham
Thanks flisky for the report. Backport of 0be4d64487 from master
2014-06-15[1.5.x] Fixed #22842vagrant
Backport of 7a1f8414c3b71b6af03e5be9f5f8db115551c410 from master.
2014-05-29[1.5.x] Improved deprecation plan links in release notes.Tim Graham
Backport of 7ff326928a08d4c51141768bd305a44ca5ecb2e7 from master
2014-05-17[1.5.x] Fixed #22644 -- Clarified documentation for NamedUrlWizardViewErik Romijn
Backport of 727d048f0991ccbd1564c6fb225ffbfd2f1a2102 from master.
2014-05-16[1.5.x] Fixed case in form widgets docsClaude Paroz
Backport of 9494f29d from master
2014-05-16[1.5.x] Fixed #22167 -- Improved documentation on context processorsMoritz
Backport of e7ffba8f78849fbf60b98fb8d67ef4577b585e3b from master.
2014-05-15[1.5.x] Minor edits to latest release notes.Tim Graham
Backport of 860d31ac7a3bdd4b27db8b34b110b3d801ddaf8a from master
2014-05-14Bumped version number post release.Jacob Kaplan-Moss
2014-05-14Bumped version numbers for release.1.5.8Jacob Kaplan-Moss
2014-05-14Added release notes for 1.4.13, 1.5.8.Jacob Kaplan-Moss
2014-05-12[1.5.x] Added additional checks in is_safe_url to account for flexible parsing.Erik Romijn
This is a security fix. Disclosure following shortly.
2014-05-12[1.5.x] Dropped fix_IE_for_vary/attach.Aymeric Augustin
This is a security fix. Disclosure following shortly.
2014-05-05[1.5.x] Fixed #22575 -- Fixed typo in ↵Tim Graham
docs/topics/class-based-views/generic-editing.txt. Thanks adminq80 at gmail.com. Backport of 87776859af from master
2014-04-28[1.5.x] Added dates to release notes of today's release.Tim Graham
Backport of 68d264059abb21b96c4fe68bf4d99520268a451c from master
2014-04-28[1.5.x] Post release version bump.Tim Graham
2014-04-28[1.5.x] Update version numbers for 1.5.7 bugfix release.1.5.7James Bennett
2014-04-23[1.5.x] Removed bad import in last commit.Tim Graham
2014-04-23[1.5.x] Fixed #22486 -- Restored the ability to reverse views created using ↵Tim Graham
functools.partial. Regression in 8b93b31487d6d3b0fcbbd0498991ea0db9088054. Thanks rcoup for the report. Backport of 3c06b2f2a3 from master
2014-04-22[1.5.x] Updated grammar in description of django.contrib.auth.Ray Ashman
Backport of 9853779805 from master
2014-04-22[1.5.x] Post release version bump.Tim Graham
2014-04-21[1.5.x] Add missing disclosure information to security archive.James Bennett
2014-04-21[1.5.x] Update for 1.5.6 security release.1.5.6James Bennett
2014-04-21[1.5.x] Added information on resolved security issues to release notes.Erik Romijn
Backport of c07f3e60c2d455e36ba4ac339d4283d32bbc3814 from master
2014-04-21[1.5.x] Fixed queries that may return unexpected results on MySQL due to ↵Erik Romijn
typecasting. This is a security fix. Disclosure will follow shortly. Backport of 75c0d4ea3ae48970f788c482ee0bd6b29a7f1307 from master
2014-04-21[1.5.x] Prevented leaking the CSRF token through caching.Aymeric Augustin
This is a security fix. Disclosure will follow shortly. Backport of c083e3815aec23b99833da710eea574e6f2e8566 from master
2014-04-21[1.5.x] Fixed a remote code execution vulnerabilty in URL reversing.Tim Graham
Thanks Benjamin Bach for the report and initial patch. This is a security fix; disclosure to follow shortly. Backport of 8b93b31487d6d3b0fcbbd0498991ea0db9088054 from master
2014-04-21[1.5.x] Corrected the section identifier for MySQL unicode reference.Matt Lauber
Backport of b2514c02e1 from master
2014-04-18[1.5.x] Fixed #22471 -- Corrected misprint in i18n docsErik Romijn
Backport of 54d5c37de6572eae57a66339bb38719e681cee82 from master.