From patchwork Mon Dec 20 14:27:38 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Trevor Gamblin X-Patchwork-Id: 1705 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EC3D5C433EF for ; Mon, 20 Dec 2021 14:28:01 +0000 (UTC) Received: from mx0a-0064b401.pphosted.com (mx0a-0064b401.pphosted.com [205.220.166.238]) by mx.groups.io with SMTP id smtpd.web08.5815.1640010477454145202 for ; Mon, 20 Dec 2021 06:27:57 -0800 Authentication-Results: mx.groups.io; dkim=fail reason="body hash did not verify" header.i=@windriver.com header.s=pps06212021 header.b=qm4WUGBf; spf=permerror, err=parse error for token &{10 18 %{ir}.%{v}.%{d}.spf.has.pphosted.com}: invalid domain name (domain: windriver.com, ip: 205.220.166.238, mailfrom: prvs=7988a2314e=trevor.gamblin@windriver.com) Received: from pps.filterd (m0250810.ppops.net [127.0.0.1]) by mx0a-0064b401.pphosted.com (8.16.1.2/8.16.1.2) with ESMTP id 1BKDn3Al022936 for ; Mon, 20 Dec 2021 06:27:57 -0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=windriver.com; h=from : to : subject : date : message-id : content-type : content-transfer-encoding : mime-version; s=PPS06212021; bh=S5g2SFsLd0qCwo357cKvpQJ53Hj9KQQEZRsg3lxYxX4=; b=qm4WUGBf/XFPyMGhqtgMpMzC74QQ/VOY1C0AZn3ALH5kRAqRSnu8mTsul3ZrPDGeQjDU 50V2FMi5oyUzyxIJ3OvTB+XQ7w91aQCyWloSSQvgPGGLulV+LQKvwLbx8kzBZ9OhWFJC VtMPurc4T6y2blXUNKlSyIU8jN+mDQhpnX7gn2WnHpb2yt7PNsaYKtlYA+ClAzYhNBqI VN+X1ytpQwbHpeAARhCmzthsfT2uwWuyKJ6QVX87q+k+RMMEs+mhhQdTlMcOXSXOh5lZ jVU7DLQ1J/VkrAVfLyedbj6lPgg8o0sg6cpA9YVRq6eqB3BUcUNhh1RyS9dkzeTAMh63 iw== Received: from nam10-dm6-obe.outbound.protection.outlook.com (mail-dm6nam10lp2103.outbound.protection.outlook.com [104.47.58.103]) by mx0a-0064b401.pphosted.com (PPS) with ESMTPS id 3d2pb6073t-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 20 Dec 2021 06:27:57 -0800 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=m4TTJNsakJOpVaSlAk7f0ASTULQnqwiqf1B3PmaEr1PT+jFgabUXNG8rfqNh+6/UArRqDlDF9rwfV1h6IAVnDWg8kmk2MksmWMrSZAYfRDyFVepk6sV3E5Pi04t55l4p3z3UVCLRSu41D8UVwO5KauBDaw7EdFXW5NsYhIX990r56qpBX4Jd/S6olbE7Vq1z9Grnnqwb8nRS10rddu53zwxe4BkAxfYh64L3LqFHr2bcWo4Yx/sCwBl2rrmws+M7b13oFwIT1jOpfMityi2dPBTIsfJglF8PUyEokWLbmGZzKhfnyohxgrskBk0p3xPZ3AxaXXSPZGsu7ZkLLN0d+A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=S5g2SFsLd0qCwo357cKvpQJ53Hj9KQQEZRsg3lxYxX4=; b=Oj3DJehuiUj33ahenLOgEaKMk9NG5qPMRsoJ6sejPBXW0JzI8S6fSw7jGJjvfkLEKP3aOonBNRO6HN/z42R52vFEIU7QB7aF0eEXhXeAsPLFoQ6dP48WNkU77t155MBxC1kd23fNeubsjD4L/kQ/Y/WbihOFvhZtGjV9VxhBRSm84FxdldX/TTeoCnZHeFk/VCRTwVqVux9jxL/6M6MkmdqLzro3ewh46flviYzFt0TEe+sptm/zEvCt4VvMcFgkiL0M9WIE+5WxfluslIcg17zSOFz/TiIPYuOfYJ/BM67qoKuGosYGXjXdPzwHDRGnSNOg5UKlZz5G6uldugDhyA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=windriver.com; dmarc=pass action=none header.from=windriver.com; dkim=pass header.d=windriver.com; arc=none Received: from BY5PR11MB3909.namprd11.prod.outlook.com (2603:10b6:a03:191::13) by BYAPR11MB3061.namprd11.prod.outlook.com (2603:10b6:a03:83::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4801.20; Mon, 20 Dec 2021 14:27:53 +0000 Received: from BY5PR11MB3909.namprd11.prod.outlook.com ([fe80::381c:4755:45c6:141]) by BY5PR11MB3909.namprd11.prod.outlook.com ([fe80::381c:4755:45c6:141%7]) with mapi id 15.20.4801.020; Mon, 20 Dec 2021 14:27:53 +0000 From: Trevor Gamblin To: openembedded-devel@lists.openembedded.org Subject: [meta-python][PATCH] python3-django: upgrade 3.2.5 -> 3.2.10 Date: Mon, 20 Dec 2021 09:27:38 -0500 Message-Id: <20211220142738.31148-1-trevor.gamblin@windriver.com> X-Mailer: git-send-email 2.33.0 X-ClientProxiedBy: YTXPR0101CA0035.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b00::48) To BY5PR11MB3909.namprd11.prod.outlook.com (2603:10b6:a03:191::13) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: f2da7371-fa4f-43c4-4dd5-08d9c3c4e89d X-MS-TrafficTypeDiagnostic: BYAPR11MB3061:EE_ X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:7691; X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: eC69gSi/XcFyk65Inq4ameEWJgbPEFBJ7bmY67ffEpDB40GrRsK9/VO+OvRHRdY6ybcXIIGQbCSkKnnDUJ15t7BOjEZk4rZiQRVlpDE67bTvES14nvaM2A6dELQZA2OeNb0JrAamdfltUijqifNwwCUrAb5+O8Z0qKfyrRJgbAHNtwJg+29UnyTEL8OQaQzfDRQF5oGrQVY6agfAzmXvkiELcamBG6UK3559u0VAWORNPCIlc+1B7rs+TQcO5vs83LuXGB17Jd7kY//P5Y7se+79BkXAcWO+TY5K6BEsgDKlYsNrjzEuJhM35cwe8Ra34RLGz/Z3N6LtvaDjpar0/MJrB41rIci8rKuo7l3Rgqt2W+SjOHBmAaW4RjDK+YlbnfmtBNcPd3xfxNao5/Jd4NXLH+mCHC3nbZw7uobGYn84wi+O0luJ1vyOVjXKvZQv4lJRTKH8PjqezyuJB+xkZLgmb2tWWlNTlObWCoO2nXfIms3x4znR6ivx/IesCH2Ue9heHFJxW6Yy84GdNQxWrAdQuMUAKulRhKATEkRtCgNZKLQwaR2spgHlMKWQi7IPAU4rPEXN4Tgh4hLoRpzO6RDtf594iR0NhCIn5VSP3PTbtrkQZ2bXkaOG8IYU+L6gbCKBl9IZeneVmzxw3zICQlFLClZL74KIbDv/R+2QCr53T5MSZ676uLEU6Vs5o1AiSRqc+dUus+BpyjQ9dkzRaNwq95sPifcgTsBVPdE7vFS7oZNNgn+zDiQOnavmBHLGz5BQxA3cNsKYFHMgMWQWPiIJsn+p7//W5g1a9WY8GhwEVt9RilUykJtm3qJSBVFPbD84PbIIWYLmdu26gEpdTA== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BY5PR11MB3909.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(4636009)(366004)(38100700002)(1076003)(38350700002)(316002)(508600001)(26005)(2906002)(5660300002)(6506007)(44832011)(6512007)(6666004)(8676002)(186003)(36756003)(86362001)(6916009)(6486002)(8936002)(52116002)(66476007)(2616005)(66556008)(83380400001)(66946007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?q?vVFfcgsxH6Q+NkqJBbXEvBJKtiDb?= =?utf-8?q?t8JQrC/NLnK7ETJNxttBJQHtDpWETRRkkMleQvnMW6NkduLkmvFfj+Hs96WoIT8OU?= =?utf-8?q?qTa6UxOpL5rT8akvcmDGb2htBDtYvoCX96Oh4TER+0w8X5iaCHr/V+IJHETxoAXlU?= =?utf-8?q?MUFWCeoG8rnosXJz6owBDooHA+eggZB1YTY81JmaCMjtKBkoLdZKyJS2b93eKQzbf?= =?utf-8?q?k7RMNxtWHONOT1SS5GfFdNjeHNv9Cp1Fcc1xsauSpjBgd/rV3faEXoo9waqOanMmf?= =?utf-8?q?N9y6nwxqQ3j19DxzB//1xotxYpPYy2x0F8t7Cdtd1t1DL86PenTv6+gGY9+78nfMz?= =?utf-8?q?kAC7KREu1OBhBhnOh9kMimQwdkLkEu6vsvNWEftj6X/DU/mN5kEyOPpsOrZdqEd1A?= =?utf-8?q?fPY7lg8xaWag4CFp/jfLI2U5NdVR/pwMNwseAOHguv1ofCMIUc9O3uw+dHyuiiNHj?= =?utf-8?q?3eLBvHxFRMipebxNbKh6z5KJ/SlQz82XwExQtoeN209/bC4do5phaCewnUXrmIXzJ?= =?utf-8?q?o04OY7LWeeG7d74eWhYjg+H/N6lJBHvTr1XSTLnxu2Gnaf7sWgtDuMyIoOLrdcQam?= =?utf-8?q?uvGj1ePuZ6OgiKn9IqDWVL5XM7Gmdaucfeu+MN4OkY4av/ml2wyieyaTpUqX5ASrO?= =?utf-8?q?DmSwLSQf9HQkweWNsMbQJYDry4JmEAkqTDJnuwCWGf5uGb5fZKOX6fk0IKIqppPzf?= =?utf-8?q?titmLwCS9G49e3Y6JE3Uzp4LmFp/nSZwWybGjV4mwNFWhCZaNt8ZSq2g/031T95+w?= =?utf-8?q?PAdywv1i+G/jM9P2EVzkRDLxAP4VWA++6ql7sh9V3Env0CWy0BJb+qNgN1p7hZXRN?= =?utf-8?q?P+KN4pqYRC6tuBgrjK/V1mMmb55LZnpd2c5gKwHA3IlYDSYey0hD/Bn6nTyMbEJ7Q?= =?utf-8?q?f+iZLahQU/3ivvu+LKx0gpulE9IKyzANyyfKayO3jCZCBlQqtJg+LDjo07AuW4Vx0?= =?utf-8?q?G7q/gwuDWR3OCMy01q1J+YDDzwX/nRIgb9EblqZ5vdikr+OOvs+V1iDK9VIaMxBIJ?= =?utf-8?q?YsB875tqo/4eu5XGCDmuB7nPC3dtvuIsZXha/Oxd3O4bFGOeCGLWrG3oWOkrTDD9N?= =?utf-8?q?5hhy/nrwNbgXZGTZNGbCvvGY3/osKV43otNLQpGZlpVT5XJycHqpDcgHlRQKBpqZZ?= =?utf-8?q?x/QUi1dAW8GId1FVgBzosHFYhLW0OVMcYmCERoWqVt+TrUTYn6kSjtRp7SqFvg0hT?= =?utf-8?q?vK/FVm1WKKKjoYfr1fgFAUOZ84ub28ANOwiVbEnKnzyl7bk6YYYHIx5anHw22hfzs?= =?utf-8?q?ybzaB4lpSgpX9iMA3AKJgKbGqr1cV7a0IRe+7/K9pO3jE8tQ5lDmU/JGKy/V0Pu+z?= =?utf-8?q?HV0ke5EmUN892M4ikmxOmCbfr20wj0Bg9BcKApcsJNC27/n3QI2eABUGLt/oRatYI?= =?utf-8?q?lJTWHBRrk3AfgCGOYJHxpPzFoLrIpSTy0ruj5yfVWVFTGghwg69zOQvGQI9MZoGoH?= =?utf-8?q?fizuso2Ft83cA/aeFe7u79CpQ0XJDw4fytvVvfRL6R/dbzfE/QyBBGcNBDfWwX7zj?= =?utf-8?q?md5ssfKaSIJEVNehiSvkCvIA2BwbfnVv99QYn7VS6kRHzWujrS/CViV0H4c/e+GKd?= =?utf-8?q?pofWYCTv3n3qPIZ31PznaBGVjyUPpbhXA=3D=3D?= X-OriginatorOrg: windriver.com X-MS-Exchange-CrossTenant-Network-Message-Id: f2da7371-fa4f-43c4-4dd5-08d9c3c4e89d X-MS-Exchange-CrossTenant-AuthSource: BY5PR11MB3909.namprd11.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Dec 2021 14:27:53.5296 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 8ddb2873-a1ad-4a18-ae4e-4644631433be X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: JlrRQTa70ieEoF+NOSkxZ3ULjTWLK1DRLn50pvkCdjyaOY24MQAgmRnzy5zS4LvIxgKVeM8JIKVCsSZubcdKJ62wsu/WmLj1e85JxDcfnIk= X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB3061 X-Proofpoint-ORIG-GUID: qhw-1l0htwjaoYSTpV1qx7iBdK4wSMwG X-Proofpoint-GUID: qhw-1l0htwjaoYSTpV1qx7iBdK4wSMwG X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.790,Hydra:6.0.425,FMLib:17.11.62.513 definitions=2021-12-20_06,2021-12-20_01,2021-12-02_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 priorityscore=1501 mlxscore=0 adultscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 mlxlogscore=999 malwarescore=0 bulkscore=0 suspectscore=0 impostorscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2110150000 definitions=main-2112200083 X-MIME-Autoconverted: from 8bit to quoted-printable by mx0a-0064b401.pphosted.com id 1BKDn3Al022936 List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 20 Dec 2021 14:28:01 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/94444 From the release notes page (https://docs.djangoproject.com/en/4.0/releases/3.2.10/): Django 3.2.10 fixes a security issue with severity “low” and a bug in 3.2.9. CVE-2021-44420: Potential bypass of an upstream access control based on URL paths HTTP requests for URLs with trailing newlines could bypass an upstream access control based on URL paths. Bugfixes Fixed a regression in Django 3.2 that caused a crash of setUpTestData() with BinaryField on PostgreSQL, which is memoryview-backed (#33333). Django 3.2.9 fixes a bug in 3.2.8 and adds compatibility with Python 3.10. Bugfixes Fixed a bug in Django 3.2 that caused a migration crash on SQLite when altering a field with a functional index (#33194). Django 3.2.8 fixes two bugs in 3.2.7. Bugfixes Fixed a bug in Django 3.2 that caused incorrect links on read-only fields in the admin (#33077). Fixed a regression in Django 3.2 that caused incorrect selection of items across all pages when actions were placed both on the top and bottom of the admin change-list view (#33083). Django 3.2.7 fixes a bug in 3.2.6. Bugfixes Fixed a regression in Django 3.2 that caused the incorrect offset extraction from fixed offset timezones (#32992). Django 3.2.6 fixes several bugs in 3.2.5. Bugfixes Fixed a regression in Django 3.2 that caused a crash validating "NaN" input with a forms.DecimalField when additional constraints, e.g. max_value, were specified (#32949). Fixed a bug in Django 3.2 where a system check would crash on a model with a reverse many-to-many relation inherited from a parent class (#32947). Signed-off-by: Trevor Gamblin --- .../{python3-django_3.2.5.bb => python3-django_3.2.10.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta-python/recipes-devtools/python/{python3-django_3.2.5.bb => python3-django_3.2.10.bb} (77%) diff --git a/meta-python/recipes-devtools/python/python3-django_3.2.5.bb b/meta-python/recipes-devtools/python/python3-django_3.2.10.bb similarity index 77% rename from meta-python/recipes-devtools/python/python3-django_3.2.5.bb rename to meta-python/recipes-devtools/python/python3-django_3.2.10.bb index c10212c4c..0c5fbb8c8 100644 --- a/meta-python/recipes-devtools/python/python3-django_3.2.5.bb +++ b/meta-python/recipes-devtools/python/python3-django_3.2.10.bb @@ -1,7 +1,7 @@ require python-django.inc inherit setuptools3 -SRC_URI[sha256sum] = "3da05fea54fdec2315b54a563d5b59f3b4e2b1e69c3a5841dda35019c01855cd" +SRC_URI[sha256sum] = "074e8818b4b40acdc2369e67dcd6555d558329785408dcd25340ee98f1f1d5c4" RDEPENDS:${PN} += "\ ${PYTHON_PN}-sqlparse \