summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2025-05-06[5.2.x] Bumped version for 5.2.1 release.5.2.1Natalia
2025-05-06[5.2.x] Fixed CVE-2025-32873 -- Mitigated potential DoS in strip_tags().Sarah Boyce
Thanks to Elias Myllymäki for the report, and Shai Berger and Jake Howard for the reviews. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 9f3419b519799d69f2aba70b9d25abe2e70d03e0 from main.
2025-05-06[5.2.x] Simplified artifact building steps in ↵Natalia
docs/internals/howto-release-django.txt. With the recent merge of artifact build updates from https://github.com/django/django/pull/19436, there is no need to have different build instructions for 4.2. Backport of f7d97dd11819be8996798a7197c5695a317334a0 from main.
2025-05-06[5.2.x] Refs #36052, #32234 -- Fixed inspectdb tests for CompositePrimaryKey ↵Mariusz Felisiak
on Oracle. Tests regression in 4c75858135589f3a00e32eb4d476074536371a32. Backport of dd133054cb98f77577c06d7ef1f2391a865784bc from main
2025-05-02[5.2.x] Fixed #17461 -- Doc'd the presumed order of foreign keys on the ↵Clifford Gama
intermediary model of a self-referential m2m. Thanks Giannis Terzopoulos and Sarah Boyce for the reviews. Backport of 9d93e35c207a001de1aa9ca9165bdec824da9021 from main.
2025-04-30[5.2.x] Made cosmetic edits and added upcoming security release to release ↵Natalia
notes. Backport of 0f5dd0dff3049189a3fe71a62670b746543335d5 from main.
2025-04-30[5.2.x] Fixed #36357 -- Skipped unique_together in inspectdb output for ↵Baptiste Mispelon
composite primary keys. Thanks to Baptiste Mispelon for the report and quick fix, and to Simon Charette and Jacob Walls for the reviews. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 66f9eb0ff1e7147406318c5ba609729678e4e6f6 from main.
2025-04-30[5.2.x] Fixed #36358 -- Corrected introspection of composite primary keys on ↵Simon Charette
SQLite. Previously, any first field of a composite primary key with type `INTEGER` was incorrectly introspected as an `AutoField` due to SQLite treating `INTEGER PRIMARY KEY` as an alias for the `ROWID`. This change ensures that integer fields in composite PKs are not mistaken for auto-incrementing fields. Thanks Jacob Walls and Sarah Boyce for the reviews. Backport of 07100db6f46255ec6ef70b860495f977473684d6 from main.
2025-04-30[5.2.x] Refs #36052, #32234 -- Removed ↵Simon Charette
create_test_table_with_composite_primary_key flag in favor of using CompositePrimaryKey. Now that Django properly supports creating models with composite primary keys, the tests should use a `CompositePrimaryKey` field instead of a feature flag to inline backend specific SQL for creating a composite PK. Specifcially, the inspectdb's test_composite_primary_key was adjusted to use schema editor instead of per-backend raw SQL. Backport of 4c75858135589f3a00e32eb4d476074536371a32 from main.
2025-04-30[5.2.x] Fixed #36360 -- Fixed QuerySet.update() crash when referring ↵Simon Charette
annotations through values(). The issue was only manifesting itself when also filtering againt a related model as that forces the usage of a subquery because SQLUpdateCompiler doesn't support the UPDATE FROM syntax yet. Regression in 65ad4ade74dc9208b9d686a451cd6045df0c9c3a. Refs #28900. Thanks Gav O'Connor for the detailed report. Backport of 8ef4e0bd423ac3764004c73c3d1098e7a51a2945 from main.
2025-04-29[5.2.x] Used addCleanup() instead of try-finally blocks in inspectdb tests.Baptiste Mispelon
Backport of 2722cb61ccae84f593e6d2c28814e3c628743994 from main.
2025-04-27[5.2.x] Fixed #35931 -- Documented fields and methods of the FlatPage model.koresi
Co-authored-by: Clifford Gama <53076065+cliff688@users.noreply.github.com> Backport of 0ee06c04e0256094270db3ffe8b5dafa6a8457a3 from main.
2025-04-27[5.2.x] Fixed #36335 -- Fixed typo in docs/topics/db/managers.txt.dbogar89
Backport of 7b394b9988b986429a4da4e60416e0f08ff649e5 from main
2025-04-24[5.2.x] Fixed #36309 -- Made email alternatives and attachments pickleable.nessita
Regression in aba0e541caaa086f183197eaaca0ac20a730bbe4 and in d5bebc1c26d4c0ec9eaa057aefc5b38649c0ba3b. Thanks Florent Messa for the report, and Jake Howard and Claude Paroz for the review. Backport of 0596263c3136bc26cffa670e5322bd0aa56c4d34 from main.
2025-04-23[5.2.x] Refs #36341 -- Added release notes for 5.1.9 and 4.2.21 for fix in ↵nessita
wordwrap template filter. Revision 1e9db35836d42a3c72f3d1015c2f302eb6fee046 fixed a regression in 55d89e25f4115c5674cdd9b9bcba2bb2bb6d820b, which also needs to be backported to the stable branches in extended support (5.1.x and 4.2.x). Backport of c86242d61ff81bddbead115c458c1eb532d43b43 from main.
2025-04-23[5.2.x] Fixed #36341 -- Preserved whitespaces in wordwrap template filter.Matti Pohjanvirta
Regression in 55d89e25f4115c5674cdd9b9bcba2bb2bb6d820b. This work improves the django.utils.text.wrap() function to ensure that empty lines and lines with whitespace only are kept instead of being dropped. Thanks Matti Pohjanvirta for the report and fix. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 1e9db35836d42a3c72f3d1015c2f302eb6fee046 from main.
2025-04-22[5.2.x] Fixed #36331 -- Reverted "Fixed #36055 -- Prevented overlap of ↵antoliny0919
object-tools buttons and page header in the admin." This reverts commits b1324a680add78de24c763911d0eefa19b9263bc and 02a5cbfe76382da2a0414df17017185be5bd47f9. The former caused a regression in admin sites that relied on the `object-tools` block being inside the `content` block. Thank you to Fabian Braun for the report. Backport of 1bc805e23b73a580b82a1d416ab0fb59a1073047 from main.
2025-04-17[5.2.x] Fixed #36314 -- Fixed MinimumLengthValidator error message translation.Ahmed Nassar
Regression in ec7d69035a408b357f1803ca05a7c991cc358cfa. Thank you Gabriel Trouvé for the report and Claude Paroz for the review. Backport of d469db978ea6a705549b9519313d9adc198e4232 from main.
2025-04-15[5.2.x] Fixed #36269 -- Documented how to test callable storage in FileField.Ahmed Nassar
Backport of 8bca33f68acc4fc881146c4b9cf4101a8bfab437 from main.
2025-04-15[5.2.x] Fixed #35993 -- Documented gettext f-string support limitations.Ahmed Nassar
Thank you to Claude Paroz and Athena Wolfskämpf for the review. Backport of 2c2f09055579cc6068cae6c6fd3135011d6df4f1 from main.
2025-04-12[5.2.x] Fixed #36320 -- Ignored "duplicated_toc_entry" for ePub docs build.Baptiste Mispelon
Backport of ac16d2876da296d8e50450bf7d776f92d1e16b0d from main
2025-04-11[5.2.x] Fixed #36288 -- Addressed improper handling of duplicates in ↵Simon Charette
values_list(). Now that selected aliases are stored in sql.Query.selected: dict[str, Any] the values_list() method must ensures that duplicate field name references are assigned unique aliases. Refs #28900. Regression in 65ad4ade74dc9208b9d686a451cd6045df0c9c3a. Thanks Claude for the report. Backport of 21f8be76d43aa1ee5ae41c1e0a428cfea1f231c1 from main.
2025-04-08[5.2.x] Clarified `url` and `name` arguments in flatpages URLconf ref docs.Clifford Gama
Backport of a2f7b3a6a04c8c46c38040c9d9d5bdc6298bd714 from main.
2025-04-08[5.2.x] Added missing closing parenthesis in docs/ref/contrib/flatpages.txt.Natalia
Backport of f9f0a183273724046710efbb3e6646d9fe3fd08e from main.
2025-04-07[5.2.x] Fixed #36301 -- Fixed select_for_update(of) crash when using ↵Simon Charette
values()/values_list(). Regression in 65ad4ade74dc9208b9d686a451cd6045df0c9c3a which allowed for annotations to be SELECT'ed before model field references through values()/values_list() and broke assumptions the select_for_update(of) table infererence logic had about model fields always being first. Refs #28900. Thanks OutOfFocus4 for the report and Sarah for the test. Backport of 71a19a0e475165dbc14c1fe02f552013ee670e4c from main
2025-04-07[5.2.x] Fixed #36298 -- Truncated the overwritten file content in ↵Sarah Boyce
file_move_safe(). Regression in 58cd4902a71a3695dd6c21dc957f59c333db364c. Thanks Baptiste Mispelon for the report. Backport of 8ad3e80e88201f4c557f6fa79fcfc0f8a0961830 from main.
2025-04-05[5.2.x] Fixed #36299 -- Prevented field selection on QuerySet.alias() after ↵Simon Charette
values(). Regression in 65ad4ade74dc9208b9d686a451cd6045df0c9c3a. Refs #28900. Thanks Jeff Iadarola for the report and tests. Co-Authored-By: OutOfFocus4 <jeff.iadarola@gmail.com> Backport of 12b771a1ec4bbfe82405176f5601e6441855a303 from main
2025-04-04[5.2.x] Fixed #36289 -- Fixed bulk_create() crash with nullable geometry ↵Simon Charette
fields on PostGIS. Swapped to an allow list instead of a deny list for field types to determine if the UNNEST optimization can be enabled to avoid further surprises with other types that would require further specialization to adapt. Regression in a16eedcf9c69d8a11d94cac1811018c5b996d491. Thanks Joshua Goodwin for the report and Sarah Boyce for the test. Backport of 764af7a3d6c0b543dcf659a2c327f214da768fe4 from main
2025-04-03[5.2.x] Fixed #36290 -- Made TupleIn() lookup discard tuples containing None.Simon Charette
Just like the In() lookup discards of None members TupleIn() should discard tuples containing any None as NULL != NULL in SQL and the framework expects such queries to be elided under some circumstances. Refs #31667, #36116. Thanks Basptise Mispelon for bisecting the regression to 626d77e. Backport of f7f38f3a0b44d8c6d14344dae66b6ce52cd77b55 from main
2025-04-03[5.2.x] Fixed #36292 -- Fixed crash when aggregating over a group mixing ↵Simon Charette
transforms and references. Regression in 65ad4ade74dc9208b9d686a451cd6045df0c9c3a. Refs #28900 Thanks Patrick Altman for the report. Backport of 543e17c4405dfdac4f18759fc78b190406d14239 from main
2025-04-03[5.2.x] Fixed #35980 -- Updated setuptools to normalize package names in ↵Nick Pope
built artifacts. Backport of 3ae049b26b995c650c41ef918d5f60beed52b4ba from main.
2025-04-02[5.2.x] Added stub release notes for 5.2.1.Sarah Boyce
Backport of c7ff347c641f2f97fa9f2f7d182982f789a211b4 from main.
2025-04-02[5.2.x] Post-release version bump.Sarah Boyce
2025-04-02[5.2.x] Bumped version for 5.2 release.5.2Sarah Boyce
2025-04-02[5.2.x] Updated man page for Django 5.2 final.Sarah Boyce
2025-04-02[5.2.x] Finalized release notes for Django 5.2.Sarah Boyce
Backport of 345ba995c0df114288909040ff2bcecbad50a35d from main.
2025-04-02[5.2.x] Added CVE-2025-27556 to security archive.Sarah Boyce
Backport of b83dab7d8da8d1dd888164de5ed79e88cedcb19b from main.
2025-04-02[5.2.x] Fixed CVE-2025-27556 -- Mitigated potential DoS in ↵Sarah Boyce
url_has_allowed_host_and_scheme() on Windows. Thank you sw0rd1ight for the report. Backport of 39e2297210d9d2938c75fc911d45f0e863dc4821 from main.
2025-04-02[5.2.x] Fixed #36213 -- Doc'd MySQL's handling of self-select updates in ↵Babak Mahmoudy
QuerySet.update(). Co-authored-by: Andro Ranogajec <ranogaet@gmail.com> Backport of be1b776ad8d6f9bccfbdf63f84b16fb81a13119e from main.
2025-04-01[5.2.x] Fixed #36284, Refs #31170 -- Ensured related lookup popups are ↵nessita
closed properly. In the admin, when selecting related objects via the helpers defined in `RelatedObjectLookups.js`, the `dismissRelatedLookupPopup` function was attempting to access `window.relatedWindows`, which does not exist in real execution, causing related lookup popups to remain open. This change ensures that this code correctly accesses the module-local `relatedWindows` by explicitly assigning it to `window.relatedWindows`. Regression in 91bebf1adb43561b54bac18e76224759dc70acb3. Thanks Matthias Kestenholz for the report, the fix ideas, and testing. Co-authored-by: Matthias Kestenholz <mk@feinheit.ch> Backport of a245604277eb9edeba234dacf199890766462709 from main.
2025-04-01[5.2.x] Fixed #36283 -- Reverted "Fixed #35798, Refs #31641 -- Prevented ↵Mariusz Felisiak
admin navigation sidebar loading flicker." This reverts commit 747b417a220b0412ed806001a383959449aac6da that caused a visual regression when both navigation and filter sidebars are visible. Backport of 12385b4fa7059aab8e4f671853cc09ae8509501f from main.
2025-03-31[5.2.x] Fixes #36215 -- Included unpacking generalization notes in coding ↵Aarni Koskela
style guide (PEP-448). Backport of 6b3250673937b105af44f2f14247e56876f8dbe1 from main.
2025-03-31[5.2.x] Clarified pre_delete and post_delete's origin attributes.Clifford Gama
Backport of 9d5d0e8135a9654aa289cf922fcd00ad5e2a7fe5 from main.
2025-03-31[5.2.x] Updated translations from Transifex.Sarah Boyce
2025-03-31[5.2.x] Refs #36055 -- Prevented overlap of object-tools buttons and page ↵Mariusz Felisiak
header in the admin on small screens. Visual regression in b1324a680add78de24c763911d0eefa19b9263bc. Backport of 02a5cbfe76382da2a0414df17017185be5bd47f9 from main.
2025-03-30[5.2.x] Fixed warnings per flake8 7.2.0.Mariusz Felisiak
https://github.com/PyCQA/flake8/releases/tag/7.2.0 Backport of 281910ff8e9ae98fa78ee5d26ae3f0b713ccf418 from main
2025-03-28[5.2.x] Refs #34619 -- Fixed labels width in FilteredSelectMultiple in the ↵Mariusz Felisiak
admin. Visual regression in 857b1048d53ebf5fc5581c110e85c212b81ca83a. Backport of a0f50c2a483678d31bd1ad6f08fd3a0b8399e27b from main.
2025-03-28[5.2.x] Simplified Intersphinx configuration example.Carlton Gibson
docs.djangoproject.com had been updated to serve the object.inv file from the default location, so the second tuple element can be None (the "default" value). Backport of 5df512e53ab12fd8a0c92421a45aa1b664adb166 from main.
2025-03-27[5.2.x] Doc'd how to use Intersphinx in the reusable apps tutorial.Carlton Gibson
Backport of 6e54e20cc3908d4eb103678db14e1e02e05069dd from main.
2025-03-26[5.2.x] Refs #34619 -- Corrected selector description in the admin.Mariusz Felisiak
Backport of 0d92428d77fafff373e05dd5a6cdb62bd1dfbda0 from main