Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-Django4 for openSUSE:Factory checked in at 2025-11-06 18:15:18 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-Django4 (Old) and /work/SRC/openSUSE:Factory/.python-Django4.new.1980 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-Django4" Thu Nov 6 18:15:18 2025 rev:17 rq:1315975 version:4.2.26 Changes: -------- --- /work/SRC/openSUSE:Factory/python-Django4/python-Django4.changes 2025-10-02 19:23:05.473715150 +0200 +++ /work/SRC/openSUSE:Factory/.python-Django4.new.1980/python-Django4.changes 2025-11-06 18:18:34.465064150 +0100 @@ -1,0 +2,6 @@ +Thu Nov 6 07:27:42 UTC 2025 - Markéta Machová <[email protected]> + +- Update to 4.2.26 (bsc#1252926) + * CVE-2025-64459: Potential SQL injection via _connector keyword argument + +------------------------------------------------------------------- Old: ---- Django-4.2.25.checksum.txt django-4.2.25.tar.gz New: ---- Django-4.2.26.checksum.txt django-4.2.26.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-Django4.spec ++++++ --- /var/tmp/diff_new_pack.q4kWr4/_old 2025-11-06 18:18:35.141092735 +0100 +++ /var/tmp/diff_new_pack.q4kWr4/_new 2025-11-06 18:18:35.141092735 +0100 @@ -29,7 +29,7 @@ %{?sle15_python_module_pythons} Name: python-Django4 # We want support LTS versions of Django - numbered 2.2 -> 3.2 -> 4.2 etc -Version: 4.2.25 +Version: 4.2.26 Release: 0 Summary: A high-level Python Web framework License: BSD-3-Clause ++++++ Django-4.2.25.checksum.txt -> Django-4.2.26.checksum.txt ++++++ --- /work/SRC/openSUSE:Factory/python-Django4/Django-4.2.25.checksum.txt 2025-10-02 19:23:05.357710297 +0200 +++ /work/SRC/openSUSE:Factory/.python-Django4.new.1980/Django-4.2.26.checksum.txt 2025-11-06 18:18:34.381060598 +0100 @@ -2,24 +2,24 @@ Hash: SHA256 This file contains MD5, SHA1, and SHA256 checksums for the -source-code tarball and wheel files of Django 4.2.25, released October 1, 2025. +source-code tarball and wheel files of Django 4.2.26, released November 5, 2025. To use this file, you will need a working install of PGP or other compatible public-key encryption software. You will also need to have the Django release manager's public key in your keyring. This key has -the ID ``131403F4D16D8DC7`` and can be imported from the MIT +the ID ``2EE82A8D9470983E`` and can be imported from the MIT keyserver, for example, if using the open-source GNU Privacy Guard implementation of PGP: - gpg --keyserver pgp.mit.edu --recv-key 131403F4D16D8DC7 + gpg --keyserver pgp.mit.edu --recv-key 2EE82A8D9470983E or via the GitHub API: - curl https://github.com/jacobtylerwalls.gpg | gpg --import - + curl https://github.com/nessita.gpg | gpg --import - Once the key is imported, verify this file: - gpg --verify Django-4.2.25.checksum.txt + gpg --verify Django-4.2.26.checksum.txt Once you have verified this file, you can use normal MD5, SHA1, or SHA256 checksumming applications to generate the checksums of the Django @@ -28,40 +28,41 @@ Release packages ================ -https://www.djangoproject.com/download/4.2.25/tarball/ -https://www.djangoproject.com/download/4.2.25/wheel/ +https://www.djangoproject.com/download/4.2.26/tarball/ +https://www.djangoproject.com/download/4.2.26/wheel/ MD5 checksums ============= -ce41aa87dfd60ccc571c29b45af92239 django-4.2.25.tar.gz -d1c93783460faef1eed82835c02f2d5c django-4.2.25-py3-none-any.whl +7a756599abea23cd9208e1c736739bdb django-4.2.26.tar.gz +93c99abba363de24d55bf1ca45ca7216 django-4.2.26-py3-none-any.whl SHA1 checksums ============== -48139ef1b0b54d03568d5ef0e465bb8b45a2e52f django-4.2.25.tar.gz -cac688484dc2cb601fa099e39a26efb4b7aca719 django-4.2.25-py3-none-any.whl +879a7dd2f0d2db3ba7c9618e84dc267e5aa362db django-4.2.26.tar.gz +8f6c2d8a0aaec238c47be7ccdec34053013a87ed django-4.2.26-py3-none-any.whl SHA256 checksums ================ -2391ab3d78191caaae2c963c19fd70b99e9751008da22a0adcc667c5a4f8d311 django-4.2.25.tar.gz -9584cf26b174b35620e53c2558b09d7eb180a655a3470474f513ff9acb494f8c django-4.2.25-py3-none-any.whl +9398e487bcb55e3f142cb56d19fbd9a83e15bb03a97edc31f408361ee76d9d7a django-4.2.26.tar.gz +c96e64fc3c359d051a6306871bd26243db1bd02317472a62ffdbe6c3cae14280 django-4.2.26-py3-none-any.whl -----BEGIN PGP SIGNATURE----- -iQIzBAEBCAAdFiEEU9RpQuAGoqPu3IvIExQD9NFtjccFAmjdKHIACgkQExQD9NFt -jcfgsBAAhTLE5Cek0S+8d6TYT24pBc1gF9D934/Iv2pvgiQk9Hlu2aNma0/veJDr -4A1rEbMGlGaFar2yel6y9YnLEAV8v6/qQnXfHgQrt8gWVj0Lp8Fxm83irhrSor3j -sqr3vt9GmVRFujosdyhfioPwn36mWHOzkuJtT0Ul86gaJM4b2mK10OrEaAXPIE22 -kDbAFphA3qCVubVWSe1E7R4nRPkhelEmDAnnwCY8wWzLSgsU9m2H12Nyt63LK1Ba -0ebHbxiMNbiua1NM6mzWE56homk/VGPUcwM1nOBNR5i8zN/MyM5DM3VQi3r2JB92 -E8kYwgI12ahpGYDLs+cnkxGUoqC/BaWJ3uqm7Rzbe6oqe1O1lVaK2EArjTbp5vz1 -4dMYC1P1Zil7cHc0b4BctmiKlUwjR8aJ3ktEgdQvwOtLJ0eFJOd1tdCilMmw8IFW -zwpisCFjKVydrk65BEz7r/JBqvp1OwbFIcd2g2tNCpEPiZTvye6+5DG0rIugroej -MG0z2wyBWGemCeFGZN9zxnePGIk+mav2S2HIVjZnxyC8zs3XNGOsd13ZNaZdC2eI -2Wl/j0hGOTFBfY/kCsv549k8kjazpRfD7JWJH49BjBu9b1VkwzEyoItXyrlxRKYA -097SCoaED6NqOe8vwEiBEh+ZBnNJzB6LjOytsLbeZPAYVHgygOI= -=wotO +iQJcBAEBCABGFiEEW1sboQ2FrHxcduOPLugqjZRwmD4FAmkLSZEoHDEyNDMwNCtu +ZXNzaXRhQHVzZXJzLm5vcmVwbHkuZ2l0aHViLmNvbQAKCRAu6CqNlHCYPuPVD/0e +GbxD+pq6P3AgHsQb40ZgGfTmSScXKO6ndMFBFTqdGIyqAcy1wufHhPq4q3Lpdq1P +GvDYBWp9iecxr5YYmELc/42EMhN8BclaEG9SvQSIUF2uLik+6P0AUp3f1g+zlf0u +cwqrY2AGlsOS8geHImqoo24f3pmyzqf5URg1IgABKRiM4XW3a1yS1HWq0YFyRPei +uzAmq7PUPA5C+lCsUuJ1GkhNwrmeU/lwCCXmZxwSIAD6i7/yod7Uwz+TpC3MzQoy +InB999H1/orwRR/zCMfQsCIsWI2omcwirAnwYn/8FK03zW/SHZOFxlpWWkRQNOXq +vdFOFAO7KTRKPnIyceaOxItyNrlxDFWCvSuvviyIvsvilGCYtcqPUCNP4SaAZMvn +GWEMKATkB487rv2R2lisWc/3wqc9vtyzDrVQTprkvdLv4OJCmyfFJcMwB3/j+cbp +P7ML+pqlu2J3uPFAibtYaGODeVi1QSMI/he+ayFU84Ak/RMzKQFc5UaoPj4nVeUi +M7poZG0d8+N6erUaMFIh0WJlVvw22Y8OB2obRE0R1rj3uiMHx7F699tE+uAI2Rzc +nDW4EJHGugkC4OAPbjiRdYWLFu9VH1qiSM0Ui+mZpC8HFL273enkXY9oYQYBimTz +07zJBw+Oa3Bq3vhDvY1P2HbifWR8d+j7FKniVyijGw== +=c5nG -----END PGP SIGNATURE----- ++++++ django-4.2.25.tar.gz -> django-4.2.26.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-Django4/django-4.2.25.tar.gz /work/SRC/openSUSE:Factory/.python-Django4.new.1980/django-4.2.26.tar.gz differ: char 5, line 1
