Hello community, here is the log from the commit of package python-Django for openSUSE:Leap:15.2 checked in at 2020-02-21 23:48:31 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Leap:15.2/python-Django (Old) and /work/SRC/openSUSE:Leap:15.2/.python-Django.new.26092 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-Django" Fri Feb 21 23:48:31 2020 rev:40 rq:776291 version:2.2.10 Changes: -------- --- /work/SRC/openSUSE:Leap:15.2/python-Django/python-Django.changes 2020-01-15 15:45:56.387340406 +0100 +++ /work/SRC/openSUSE:Leap:15.2/.python-Django.new.26092/python-Django.changes 2020-02-21 23:48:33.816472516 +0100 @@ -1,0 +2,20 @@ +Tue Feb 4 09:42:08 UTC 2020 - Ondřej Súkup <[email protected]> + +- update to 2.2.10 +- drop pyyaml53.patch + * fix boo#1161919 (CVE-2020 7471) Potential SQL injection via ``StringAgg(delimiter)`` + + +------------------------------------------------------------------- +Wed Jan 15 15:08:32 UTC 2020 - Ondřej Súkup <[email protected]> + +- add pyyaml53.patch - fix tests with PyYAML 5.3 + +------------------------------------------------------------------- +Sun Dec 29 11:00:47 UTC 2019 - Ondřej Súkup <[email protected]> + +- Update to 2.2.9 + * CVE-2019-19844: Potential account hijack via password reset form (bsc#1159447) + * Fixed a data loss possibility in SplitArrayField. + +------------------------------------------------------------------- Old: ---- Django-2.2.8.tar.gz Django-2.2.8.tar.gz.asc New: ---- Django-2.2.10.tar.gz Django-2.2.10.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-Django.spec ++++++ --- /var/tmp/diff_new_pack.AkyOTS/_old 2020-02-21 23:48:34.444473764 +0100 +++ /var/tmp/diff_new_pack.AkyOTS/_new 2020-02-21 23:48:34.448473771 +0100 @@ -1,7 +1,7 @@ # # spec file for package python-Django # -# Copyright (c) 2019 SUSE LLC +# Copyright (c) 2020 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -22,8 +22,8 @@ %bcond_with selenium %bcond_with memcached Name: python-Django -# We want support LTS versions of Django - odd numbered 2.2 -> 2.4 -> 2.6 -> 3.0 etc -Version: 2.2.8 +# We want support LTS versions of Django - numbered 2.2 -> 3.2 -> 4.2 etc +Version: 2.2.10 Release: 0 Summary: A high-level Python Web framework License: BSD-3-Clause ++++++ Django-2.2.8.tar.gz -> Django-2.2.10.tar.gz ++++++ /work/SRC/openSUSE:Leap:15.2/python-Django/Django-2.2.8.tar.gz /work/SRC/openSUSE:Leap:15.2/.python-Django.new.26092/Django-2.2.10.tar.gz differ: char 5, line 1 ++++++ Django-2.2.8.tar.gz.asc -> Django-2.2.10.tar.gz.asc ++++++ --- /work/SRC/openSUSE:Leap:15.2/python-Django/Django-2.2.8.tar.gz.asc 2020-01-15 15:45:56.267340338 +0100 +++ /work/SRC/openSUSE:Leap:15.2/.python-Django.new.26092/Django-2.2.10.tar.gz.asc 2020-02-21 23:48:33.788472460 +0100 @@ -2,7 +2,7 @@ Hash: SHA256 This file contains MD5, SHA1, and SHA256 checksums for the source-code -tarball and wheel files of Django 2.2.8, released December 2, 2019. +tarball and wheel files of Django 2.2.10, released February 3, 2020. To use this file, you will need a working install of PGP or other compatible public-key encryption software. You will also need to have @@ -24,39 +24,39 @@ Release packages: ================= -https://www.djangoproject.com/m/releases/2.2/Django-2.2.8-py3-none-any.whl -https://www.djangoproject.com/m/releases/2.2/Django-2.2.8.tar.gz +https://www.djangoproject.com/m/releases/2.2/Django-2.2.10-py3-none-any.whl +https://www.djangoproject.com/m/releases/2.2/Django-2.2.10.tar.gz MD5 checksums ============= -2dd61e8dfadc3754e35f927d4142fc0f Django-2.2.8-py3-none-any.whl -57d965818410a4e00e2267eef66aa9c9 Django-2.2.8.tar.gz +d24676ee3a4e112abc46f5363a608cd6 Django-2.2.10-py3-none-any.whl +10f192f8565ab137aea2dda4a4cb3d26 Django-2.2.10.tar.gz SHA1 checksums ============== -ad9d4b417d4b99ec19548d7339b345d807de5000 Django-2.2.8-py3-none-any.whl -0a631fe2237fea6a60cdd5d02b618632b6e49a1b Django-2.2.8.tar.gz +084cdc5c5e2041b0d202cd9cfc2d272f978a244b Django-2.2.10-py3-none-any.whl +86b0f5160b52cc4330d17cd69090f7f240c9fb47 Django-2.2.10.tar.gz SHA256 checksums ================ -fa98ec9cc9bf5d72a08ebf3654a9452e761fbb8566e3f80de199cbc15477e891 Django-2.2.8-py3-none-any.whl -a4ad4f6f9c6a4b7af7e2deec8d0cbff28501852e5010d6c2dc695d3d1fae7ca0 Django-2.2.8.tar.gz +9a4635813e2d498a3c01b10c701fe4a515d76dd290aaa792ccb65ca4ccb6b038 Django-2.2.10-py3-none-any.whl +1226168be1b1c7efd0e66ee79b0e0b58b2caa7ed87717909cd8a57bb13a7079a Django-2.2.10.tar.gz -----BEGIN PGP SIGNATURE----- -iQIzBAEBCAAdFiEE/l+2OHah1xioxnVW4X31yCtPnQAFAl3ky/QACgkQ4X31yCtP -nQBi8w//S+ZVGHyo35gekAy3j11PmUuiD2nhGlrmfZgiBsAepcxIpXH/ZYS+OWUY -ZYdyUYb9308YGiKzkOxOMmsqrZeEwzImQcf844MCbQcFkPe0NWc9FZ/RphCaStVN -pxoGHZOfV6bOyLVJO8jV4YqDl/MBWdvtFDMhrrJlZSmgmVDAfpSV+BFUmoFaiC2i -vd1fKKVLxTVZrr6L6ov0h8JM2gMPVoGp4P/WDofk1LuWRKLZmwtrp7PRdBeyf5jO -itoQD00qAt2IsdaXYuPkaCMdQWzCJDGiFFUjcRkzdZtLaKugTnuHMol9/lCcXkW1 -NL//xq+rh8YfyTkNk4rDHuu98urPz46z1kgvNOSJlgpTf4RWjk/va1s+/Cc28QSa -KVA4CcD+2+we781USYJG0B10+OsgzWbPV+50IOejVqrhj5QCSa6LRG37hp6iJThp -+2ZqM8DthouFdjliT1W3pEzcyII/nWqIibyWo7zMrQQk5N9f5E628KHIFlOeB7+8 -pinSTmfUpTS5leVBRIzc2LhdE9WYoPaFdQOm2AD7vHDIwYxy5l9uStyN25xi+Jp1 -EvsFmIKj9COc21L4nDujpgKdLJ0eiGAL6fJ6UQydvMaBsdbPXO8kTk/lXooQx1X/ -LhbnxqLG1Yzh9bxNHCGOGPDnWswGeTFNpAhRwtryCBASeItQzAE= -=xo2Q +iQIzBAEBCAAdFiEE/l+2OHah1xioxnVW4X31yCtPnQAFAl432l4ACgkQ4X31yCtP +nQDn1BAAn6zw5gnrDYDq1l3EOu5msL93pTt4vlRQP398taGwmytUdlpiDBtzRwUC +wDRqOIwAoExhoxRbg5vn4oYkb+V5mYBr3ExWQpDvVRS3j4Pt+sldOUUF66JpfUEV +iyo982VN0x91Ddx1Q+KGiEd3i+p5w2VFMDh+FDM+ySBzv86t0g0errCxb6+9Je4P +MxtLgVzeGhAigoiQzJcGjr3uYxOZSNwNuxYiw/3vHpi8KmET3Bst+zLhYtr3LiAz +3+K1qWek/Wwbv/Ycj4S+6TaVjaUkeNN3LlU7JCS8HFh2FkqmBGkmw5lZKM8RO9BK +hIu8ZK8c5gzJ2I/Ez9bU1aAE2GFXBKMdvixmDMJ7NrMGATjrGOhI3mfGkG01QDKq +jcLK89d/faeb2qsNRaSFlroI4F4tEVPkvehKAeazByynpZZ30kSmr2PMQwJezAK8 +LSjOfGSpF4cQJe4d/oyQm+JfqZA0NTby+6JjFgN1Ar0DjouXsUa96m5iQgwBbNwJ +x6NqRk9fWyC73nr+MyQ2h+WaWwsW5sT2T6V6ZVaNLu3jdt9ijfhjKTsrvEIhe+Ri +7sMz57PBaSNETZgwT86aLvDE6BMP5FjJ4MKB5MGFK3q3FHTtsogj5a3WZ1lyWyt0 +WiWQzCjdIyQnrmSOLTXV6EdlThziXZor81ilDiFcMeIUr/HF8tk= +=IWbV -----END PGP SIGNATURE-----
