summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2022-01-04[4.0.x] Bumped version for 4.0.1 release.4.0.1Carlton Gibson
2022-01-04[4.0.x] Fixed CVE-2021-45452 -- Fixed potential path traversal in storage ↵Florian Apolloner
subsystem. Thanks to Dennis Brinkrolf for the report.
2022-01-04[4.0.x] Fixed CVE-2021-45116 -- Fixed potential information disclosure in ↵Florian Apolloner
dictsort template filter. Thanks to Dennis Brinkrolf for the report. Co-authored-by: Adam Johnson <me@adamj.eu>
2022-01-04[4.0.x] Fixed CVE-2021-45115 -- Prevented DoS vector in ↵Florian Apolloner
UserAttributeSimilarityValidator. Thanks Chris Bailey for the report. Co-authored-by: Adam Johnson <me@adamj.eu>
2022-01-04[4.0.x] Avoided suggestion of plain text database password in sessions topic.Luke Plant
Backport of ccafad2e429468c518c80fb178f9e7a3f06e78e1 from main
2021-12-31[4.0.x] Fixed #33391 -- Clarified Aggregate.empty_result_set_value docs.Mariusz Felisiak
Backport of 4400d8568ad5695c46e8de45635a82a27a26b871 from main
2021-12-30[4.0.x] Improved @display(empty_value) example in ↵mangelozzi
ModelAdmin.empty_value_display docs. Backport of eb901681ab58c008f7bbbe555e5f43f8e0893bd3 from main
2021-12-30[4.0.x] Fixed #27936 -- Rewrote spanning multi-valued relationships docs.Jacob Walls
Backport of 6174814dbe04fb6668aa212a6cdbca765a8b0522 from main
2021-12-30[4.0.x] Added default values to Entry's fields in making queries docs.Mariusz Felisiak
This makes it easier to create a data in examples. Backport of 1283458baae482c2bbb22c842b1db6c832c953f3 from main
2021-12-28[4.0.x] Updated example of YAML serialization format in docs.Sergey Fursov
Backport of feeb0685c62a793c55a058584ba1de45e74f80f7 from main
2021-12-28[4.0.x] Added stub release notes for 4.0.1, 3.2.11, and 2.2.26 releases.Carlton Gibson
Backport of b13d920b7b56d3e088e35311f5ee54f25d2779af from main.
2021-12-22[4.0.x] Refs #32355 -- Bumped required psycopg2 version to 2.8.4.Mariusz Felisiak
psycopg2 2.8.4 is the first release to support Python 3.8. Backport of ca04659b4b3f042c1bc7e557c25ed91e3c56c745 from main
2021-12-22[4.0.x] Refs #31026 -- Updated TemplatesSetting docs to refer to forms.David Smith
Backport of 78f062f63e7dea09c219fd1310d43950817f4c78 from main
2021-12-22[4.0.x] Added TemplatesSetting to list of built-in renderers in ↵Adam Johnson
FORM_RENDERER docs. Backport of fde425051c31b240e8eca48a8eb54daa6d372c9f from main
2021-12-21[4.0.x] Fixed #32600 -- Fixed Geometry collections and Polygon segmentation ↵Brenton Partridge
fault on macOS ARM64. Backport of 19fb838803f63eef0726a370050443b693f109be from main
2021-12-17[4.0.x] Fixed #33366 -- Fixed case handling with swappable setting detection ↵Simon Charette
in migrations autodetector. The migration framework uniquely identifies models by case insensitive labels composed of their app label and model names and so does the app registry in most of its methods (e.g. AppConfig.get_model) but it wasn't the case for get_swappable_settings_name() until this change. This likely slipped under the radar for so long and only regressed in b9df2b74b98b4d63933e8061d3cfc1f6f39eb747 because prior to the changes related to the usage of model states instead of rendered models in the auto-detector the exact value settings value was never going through a case folding hoop. Thanks Andrew Chen Wang for the report and Keryn Knight for the investigation. Backport of 43289707809c814a70f0db38ca4f82f35f43dbfd from main
2021-12-16[4.0.x] Fixed #33350 -- Reallowed using cache decorators with duck-typed ↵Mariusz Felisiak
HttpRequest. Regression in 3fd82a62415e748002435e7bad06b5017507777c. Thanks Terence Honles for the report. Backport of 40165eecc40f9e223702a41a0cb0958515bb1f82 from main
2021-12-15[4.0.x] Refs #33365, Refs #30530 -- Doc'd re_path() behavior change in ↵Mariusz Felisiak
Django 2.2.25, 3.1.14, and 3.2.10. Follow up to d4dcd5b9dd9e462fec8220e33e3e6c822b7e88a6. Backport of 5de12a369a7b2231e668e0460c551c504718dbf6 from main
2021-12-14[4.0.x] Fixed #33361 -- Fixed Redis cache backend crash on booleans.Jeremy Lainé
Backport of 2f33217ea2cad688040dd6044cdda946c62e5b65 from main
2021-12-13[4.0.x] Fixed #33338 -- Doc'd that never_cache() decorator set Expires header.mgaligniana
Backport of 669dcefc04837c35fc2ec5ce906d84397005965d from main
2021-12-13[4.0.x] Corrected example in models.DecimalField docs.Beomsoo Kim
Backport of 7e4a9a9f696574a18f5c98f34d5a88e254b2d394 from main
2021-12-13[4.0.x] Updated link to Microsoft SQL Server backend.Wayne Lambert
Backport of 8a8c8797e81b338f3c93a5a4e2483916e68e4a54 from main
2021-12-08[4.0.x] Refs #33319 -- Added note about commutation of QuerySet's | operator.Ömer Faruk Abacı
Backport of f04b44bad40369ec2df74b16adb4d3f09350e4b2 from main
2021-12-08[4.0.x] Fixed #33346 -- Fixed SimpleTestCase.assertFormsetError() crash on a ↵Baptiste Mispelon
formset named "form". Thanks OutOfFocus4 for the report. Regression in 456466d932830b096d39806e291fe23ec5ed38d5. Backport of cb383753c0e0eb52306e1024d32a782549c27e61 from main.
2021-12-07[4.0.x] Improved release notes wording for template-based form rendering.Nick Pope
Backport of dfdf1c68645627f54259dbe25f5b42329ee83b5d from main
2021-12-07[4.0.x] Added stub release notes for 4.0.1.Mariusz Felisiak
Backport of adef3d975e55c55b020c2f357d82c2db11e58450 from main
2021-12-07[4.0.x] Post-release version bump.Mariusz Felisiak
2021-12-07[4.0.x] Bumped version for 4.0 release.4.0Mariusz Felisiak
2021-12-07[4.0.x] Finalized release notes for Django 4.0.Mariusz Felisiak
Backport of d7bd9eb6cda0aff4634cbb453622b24a98933463 from main
2021-12-07[4.0.x] Updated asgiref dependency for 4.0 release series.Mariusz Felisiak
Backport of 513441240f874dd0b6187c0c6aaa3e8eccd8ddbe from main
2021-12-07[4.0.x] Added CVE-2021-44420 to security archive.Mariusz Felisiak
Backport of 8747052411275d290b2152ffcb8dee11afbb82cd from main
2021-12-07[4.0.x] Fixed #30530, CVE-2021-44420 -- Fixed potential bypass of an ↵Florian Apolloner
upstream access control based on URL paths. Thanks Sjoerd Job Postmus and TengMA(@te3t123) for reports. Backport of d4dcd5b9dd9e462fec8220e33e3e6c822b7e88a6 from main.
2021-12-06[4.0.x] Updated translations from Transifex.Mariusz Felisiak
This also fixes related i18n tests. Co-authored-by: Claude Paroz <claude@2xlibre.net>
2021-12-06[4.0.x] Fixed #33335 -- Made model validation ignore functional unique ↵Hannes Ljungberg
constraints. Regression in 3aa545281e0c0f9fac93753e3769df9e0334dbaa. Thanks Hervé Le Roy for the report. Backport of 1eaf38fa87384fe26d1abf6e389d6df1600d4d8c from main
2021-12-04[4.0.x] Refs #33333 -- Fixed ↵Mariusz Felisiak
PickleabilityTestCase.test_annotation_with_callable_default() crash on Oracle. Grouping by LOBs is not allowed on Oracle. This moves a binary field to a separate model. Backport of d3a64bea51676fcf8a0ae593cf7b103939e12c87 from main
2021-12-03[4.0.x] Fixed #33333 -- Fixed setUpTestData() crash with models.BinaryField ↵Mariusz Felisiak
on PostgreSQL. This makes models.BinaryField pickleable on PostgreSQL. Regression in 3cf80d3fcf7446afdde16a2be515c423f720e54d. Thanks Adam Zimmerman for the report. Backport of 2c7846d992ca512d36a73f518205015c88ed088c from main.
2021-12-02[4.0.x] Fixed #33334 -- Alphabetized form and model fields in reference docs.Shivam Durgbuns
Backport of d75c387f46c55459a2daf071e5463bad0ad7dcbd from main
2021-11-30[4.0.x] Added stub release notes and release date for 3.2.10, 3.1.14 and 2.2.25.Mariusz Felisiak
Backport of ae4077e13ea2e4c460c3f21b9aab93a696590851 from main
2021-11-26[4.0.x] Fixed #33301 -- Clarified the type of arguments required by custom ↵Baptiste Mispelon
assertions. Backport of 528691d1b66b4ecf7bbb55f783fc919d40d4a235 from main
2021-11-26[4.0.x] Refs #33163 -- Corrected example of connection signal handlers in ↵Mariusz Felisiak
AppConfig.ready(). Backport of 75ee7057e98dd9725fabb98cabe42966fa4c8222 from main
2021-11-24[4.0.x] Fixed typo in docs/releases/4.0.txt.Ryuji Tsutsui
Backport of b8c0b22f2f0f8ce664642332d6d872f300c662b4 from main
2021-11-23[4.0.x] Corrected signatures of QuerySet's methods.Mariusz Felisiak
Backport of a17becf4c7f4e4057e8c94990e4b4999be0aea95 from main
2021-11-22[4.0.x] Corrected isort example in coding style docs.Mariusz Felisiak
Follow up to e74b3d724e5ddfef96d1d66bd1c58e7aae26fc85. Backport of 8b020f2e64f1cbf2b06205a389a13af6623f90ce from main
2021-11-22[4.0.x] Corrected "pip install" call in coding style docs.Paolo Melchiorre
Backport of dd528cb2cefc0db8b91a7ff0a2bc87305b976597 from main
2021-11-22[4.0.x] Bumped version for 4.0 release candidate 1.4.0rc1Mariusz Felisiak
2021-11-18[4.0.x] Added Malay language.jhisham
Backport of 5e218cc0b704ebf64c460050a97b5fafe63e92b0 from main
2021-11-18[4.0.x] Configured Read The Docs to build all formats.Adam Johnson
`all` acts as an alias for all formats ([docs](https://docs.readthedocs.io/en/stable/config-file/v2.html#formats)). Whilst there are only three formats right now, this would auto expand to other formats in the future, which seems desirable? Backport of 1fe23bdd29a8f2f6802c2038702ff7a5d0e21a0d from main
2021-11-17[4.0.x] Fixed crash building HTML docs since Sphinx 4.3.Mariusz Felisiak
See https://github.com/sphinx-doc/sphinx/commit/dd2ff3e911c751c06c81f494128fba56d8ecbafd. Backport of f0480ddd2d3cb04b784cf7ea697f792b45c689cc from main
2021-11-17[4.0.x] Fixed #33163 -- Added example of connection signal handlers in ↵Roxane
AppConfig.ready() to docs. Backport of 2d124f6a1c45afdde8be90c01043e0b14455d41e from main
2021-11-12[4.0.x] Fixed #33279 -- Fixed handling time zones with "-" sign in names.Can Sarigol
Thanks yakimka for the report. Regression in fde9b7d35e4e185903cc14aa587ca870037941b1. Backport of 661316b066923493ff91d6d2aa92e463f595a6b1 from main.