Hello community, here is the log from the commit of package python-Django1 for openSUSE:Factory checked in at 2020-02-06 13:19:24 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-Django1 (Old) and /work/SRC/openSUSE:Factory/.python-Django1.new.26092 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-Django1" Thu Feb 6 13:19:24 2020 rev:20 rq:769934 version:1.11.28 Changes: -------- --- /work/SRC/openSUSE:Factory/python-Django1/python-Django1.changes 2020-01-16 18:16:57.056829216 +0100 +++ /work/SRC/openSUSE:Factory/.python-Django1.new.26092/python-Django1.changes 2020-02-06 13:19:31.252680937 +0100 @@ -1,0 +2,7 @@ +Tue Feb 4 10:00:42 UTC 2020 - Ondřej Súkup <[email protected]> + +- update to 1.11.28 +- drop pyyaml53.patch + * fix boo#1161919 (CVE-2020-7471) Potential SQL injection via StringAgg(delimiter) + +------------------------------------------------------------------- Old: ---- Django-1.11.27.tar.gz Django-1.11.27.tar.gz.asc pyyaml53.patch New: ---- Django-1.11.28.tar.gz Django-1.11.28.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-Django1.spec ++++++ --- /var/tmp/diff_new_pack.gh4eX2/_old 2020-02-06 13:19:32.180681393 +0100 +++ /var/tmp/diff_new_pack.gh4eX2/_new 2020-02-06 13:19:32.184681394 +0100 @@ -22,7 +22,7 @@ %define skip_python3 1 %endif Name: python-Django1 -Version: 1.11.27 +Version: 1.11.28 Release: 0 Summary: A high-level Python Web framework License: BSD-3-Clause @@ -35,7 +35,6 @@ Patch0: django-sqlite-326.patch # PATCH-FIX-OPENSUSE bmwiedemann -- fix tests after 2028 - merged in Django master only Patch2: fix2028.patch -Patch3: pyyaml53.patch BuildRequires: %{python_module Jinja2 >= 2.9.2} BuildRequires: %{python_module Pillow} BuildRequires: %{python_module PyYAML} @@ -94,7 +93,6 @@ %setup -q -n Django-%{version} %patch0 -p1 %patch2 -p1 -%patch3 -p1 %build %python_build ++++++ Django-1.11.27.tar.gz -> Django-1.11.28.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-Django1/Django-1.11.27.tar.gz /work/SRC/openSUSE:Factory/.python-Django1.new.26092/Django-1.11.28.tar.gz differ: char 5, line 1 ++++++ Django-1.11.27.tar.gz.asc -> Django-1.11.28.tar.gz.asc ++++++ --- /work/SRC/openSUSE:Factory/python-Django1/Django-1.11.27.tar.gz.asc 2019-12-30 12:34:11.915784130 +0100 +++ /work/SRC/openSUSE:Factory/.python-Django1.new.26092/Django-1.11.28.tar.gz.asc 2020-02-06 13:19:30.844680737 +0100 @@ -2,16 +2,16 @@ Hash: SHA256 This file contains MD5, SHA1, and SHA256 checksums for the source-code -tarball and wheel files of Django 1.11.27, released December 18, 2019. +tarball and wheel files of Django 1.11.28, released February 3, 2020. To use this file, you will need a working install of PGP or other compatible public-key encryption software. You will also need to have the Django release manager's public key in your keyring; this key has -the ID ``2EF56372BA48CD1B`` and can be imported from the MIT +the ID ``E17DF5C82B4F9D00`` and can be imported from the MIT keyserver. For example, if using the open-source GNU Privacy Guard implementation of PGP: - gpg --keyserver pgp.mit.edu --recv-key 2EF56372BA48CD1B + gpg --keyserver pgp.mit.edu --recv-key E17DF5C82B4F9D00 Once the key is imported, verify this file:: @@ -24,40 +24,39 @@ Release packages: ================= -https://www.djangoproject.com/m/releases/1.11/Django-1.11.27-py2.py3-none-any.whl -https://www.djangoproject.com/m/releases/1.11/Django-1.11.27.tar.gz +https://www.djangoproject.com/m/releases/1.11/Django-1.11.28-py2.py3-none-any.whl +https://www.djangoproject.com/m/releases/1.11/Django-1.11.28.tar.gz MD5 checksums ============= -f18cd55578581166080cc7e04dd626cc Django-1.11.27-py2.py3-none-any.whl -e75626654c7d92ff8bafa2a36d137372 Django-1.11.27.tar.gz +103fe7af9f88d6c621026b8f9d284d1b Django-1.11.28-py2.py3-none-any.whl +8a21a5148aece7f6110d6ff3a9f57652 Django-1.11.28.tar.gz SHA1 checksums ============== -9df8b56e56bd2c29cd5f13b92b5a0b3aabacda1b Django-1.11.27-py2.py3-none-any.whl -8f0ad184cbae6e69dbe2a1f4d7ec32d842657001 Django-1.11.27.tar.gz +5a6260681cbd4c0493637fb04e3d3aeaf27c2429 Django-1.11.28-py2.py3-none-any.whl +1537a67692f9f724d005631cc035d9a58648934a Django-1.11.28.tar.gz SHA256 checksums ================ -372faee5b93c92f19e9d65f52b278a1b689d3e3b4a7d9d30db73a78ebc729770 Django-1.11.27-py2.py3-none-any.whl -20111383869ad1b11400c94b0c19d4ab12975316cd058eabd17452e0546169b8 Django-1.11.27.tar.gz +a3b01cdff845a43830d7ccacff55e0b8ff08305a4cbf894517a686e53ba3ad2d Django-1.11.28-py2.py3-none-any.whl +b33ce35f47f745fea6b5aa3cf3f4241069803a3712d423ac748bd673a39741eb Django-1.11.28.tar.gz -----BEGIN PGP SIGNATURE----- -iQJPBAEBCAA5FiEEq7LCqM0B8WE2GLcNLvVjcrpIzRsFAl355HEbHGZlbGlzaWFr -Lm1hcml1c3pAZ21haWwuY29tAAoJEC71Y3K6SM0bPCQP/3djeAG9eRP9/wOukhKz -K/fAzs2ZBjZSfx9eEZOA72aC1VtHC+rAHnrU9PL+hzGQjAAZaGVSnsi3zzzbd/yT -mF4LuV3QC+1ea4c5Z6O/xf3g7p8z6G/GJ02uJ3MbBCRDEXCcMMYET3c42zGSQ2/V -J6pK2tBPBSNCPUi21xksv1xgggX9+sUyTMKJyi7ozlaNc/U0K0+PaExIYJn4fNtB -Y8bhfiUB35P2FIDq0Pt8dQK6MQW8lxe3ojW4IGnWphama5K6hT29sWNvOgG9AKzF -srGVM5pVtgrXBzw8MgQicWc5qudnmzWQfk+O9VAGj+gtMNXsfoMqEx4C9Er3q0LH -z25uNP0OaKOJP3xEskwYC2On35aNtWS+Cq0kr1XlB1q7pLyUR84IzcuLt7q8Bekx -LpveFb4fyDiiy3U0uON+EfiTHT1uTnOJZzZLzTa6RJCRca3uruJMIihpqn/oo4FD -xSF5aeAZcX1oGkTxKeVUe2PByYZDyAPJTRnrnUBjmT0TQHrQEyD2hjX838cndZyR -is2HdFEoYr+/3mzN3g2LKpVALF7gCtStAcmF/pwxCn+toimKug1QahabNQyWNS2o -9zeuHQKoYR81yv84IaiOvfPrvLDENbdY43C7c7tynnoK4g3umZioPtCcfnO9xP5H -uRhVpcqhHfp+TnhOxKfeYpc2 -=7vFP +iQIzBAEBCAAdFiEE/l+2OHah1xioxnVW4X31yCtPnQAFAl4313kACgkQ4X31yCtP +nQApghAAwJVtvmmGChbVI5YkyLMqaitECRelw2voshJD2Jq2dIMzqkXzmjSYps8M +DWGxvJWsImy7zP6LfKZLg3VP13DBM9H25jzqUHuwUssXtRNtPzWexibajrdSbdhE +qmPVwvdpeXqGs1gNu6evX2X56cOH28antf7f1tZLFCizEP/xUOtmFOqHCLp3hcMB +WjVuiTq6LrETdzEzVjlQv592nz1EWo5fnAhOiYAEJvPWSUVMWIdYhgDLlMA6hfFF +Wl/IxLsZ2fGq80mXo8RC27YX0JAjwCaKydfhFLM/j+gEsC6V8jv+bttx8awX11W5 +BO0fjyG+pOA8VrxHrB7PWeOD9cAe1QrX4QnvySfH/Y3Zs6lJY7cSUuzjBHP3TdKg +wpQEPPO7OooSfJRBCtcPSJeby+Ky29AI2VnypAasDPEY9qjX7yPNmlRR8oW5ZnB7 +1NztJ95xpfU6zmt95ndIXCU843f/2uZrRMnFdv34XCbqxBP/93S5PT2A7026GPeg +Nis+R7WqDno3PvtIzNgQatj3TjXszAJq0j2YqDSB6QhaSiK+KsKBqF4acTOM5lBl +/5ChW+/fftWyERi9/cD6WKLdBKw3oZHaUWbvWcZCl6Wm1PlMpbCRA4bv7/QlmtC2 +CVNvlx0zhug5e4SR2PVO9mgvzfrz8krbWmFODWoX93pyIA9e28w= +=re0T -----END PGP SIGNATURE-----
