Re: Django security releases issued: 5.1.1, 5.0.9, and 4.2.16

2024-09-03 Thread אורי
Hi, I noticed that Django 4.2.16 release notes (and the other versions released today) are not updated: https://docs.djangoproject.com/en/5.1/releases/4.2.16/ This happens usually every time after a new release. Is it possible to fix it? Thanks, Uri Rodberg, Speedy Net. אורי u...@speedy.net On

Django security releases issued: 5.1.1, 5.0.9, and 4.2.16

2024-09-03 Thread Natalia Bidart
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2024/sep/03/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an ema

Re: Django security releases issued: 5.0.8 and 4.2.15

2024-08-19 Thread Montego King
Thanks On Tue, Aug 6, 2024, 3:35 PM Sarah Boyce wrote: > Details are available on the Django project weblog: > > https://www.djangoproject.com/weblog/2024/aug/06/security-releases/ > > -- > You received this message because you are subscribed to the Google Groups > "Django users" group. > To uns

Django security releases issued: 5.0.8 and 4.2.15

2024-08-06 Thread Sarah Boyce
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2024/aug/06/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 5.0.7 and 4.2.14

2024-07-09 Thread Natalia Bidart
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2024/jul/09/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Re: Django security releases issued: 5.0.3, 4.2.11, and 3.2.25

2024-03-04 Thread Ayoub ANSAIR
Thank you ! Le lun. 4 mars 2024 à 09:58, Mariusz Felisiak a écrit : > Details are available on the Django project weblog: > > https://www.djangoproject.com/weblog/2024/mar/04/security-releases/ > > -- > You received this message because you are subscribed to the Google Groups > "Django users" gr

Django security releases issued: 5.0.3, 4.2.11, and 3.2.25

2024-03-04 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2024/mar/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 5.0.2, 4.2.10, and 3.2.24

2024-02-06 Thread Natalia Bidart
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2024/feb/06/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an ema

Django security releases issued: 4.2.7, 4.1.13, and 3.2.23

2023-11-01 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/nov/01/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.2.6, 4.1.12, and 3.2.22

2023-10-04 Thread Natalia Bidart
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/oct/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.2.5, 4.1.11, and 3.2.21

2023-09-04 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/sep/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.2.3, 4.1.10, and 3.2.20

2023-07-03 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/jul/03/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.2.1, 4.1.9, and 3.2.19

2023-05-03 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/may/03/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.1.7, 4.0.10, and 3.2.18

2023-02-14 Thread Carlton Gibson
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/feb/14/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.1.6, 4.0.9, and 3.2.17

2023-02-01 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2023/feb/01/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.0.7 and 3.2.15.

2022-08-03 Thread Carlton Gibson
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2022/aug/03/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Re: Django security releases issued: 4.0.6 and 3.2.14.

2022-07-04 Thread אורי
Hi, Bugfixes are empty on https://docs.djangoproject.com/en/4.0/releases/4.0.6/ אורי u...@speedy.net On Mon, Jul 4, 2022 at 11:00 AM Mariusz Felisiak wrote: > Details are available on the Django project weblog: > > https://www.djangoproject.com/weblog/2022/jul/04/security-releases/ > > -- >

Django security releases issued: 4.0.6 and 3.2.14.

2022-07-04 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2022/jul/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.0.4, 3.2.13, and 2.2.28

2022-04-11 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2022/apr/11/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.0.2, 3.2.12, and 2.2.27

2022-01-31 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2022/feb/01/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 4.0.1, 3.2.11, and 2.2.26

2022-01-04 Thread Carlton Gibson
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2022/jan/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Re: Django security releases issued: 3.2.10, 3.1.14, and 2.2.25

2021-12-07 Thread kayhan
Okay, thank you. I really like open source technologies On Tue, Dec 7, 2021 at 11:12 AM Mariusz Felisiak wrote: > Details are available on the Django project weblog: > > https://www.djangoproject.com/weblog/2021/dec/07/security-releases/ > > -- > You received this message because you are subscri

Django security releases issued: 3.2.10, 3.1.14, and 2.2.25

2021-12-06 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/dec/07/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 3.2.5 and 3.1.13

2021-07-01 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/jul/01/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 3.2.4, 3.1.12, and 2.2.24

2021-06-02 Thread Carlton Gibson
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/jun/02/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To u

Re: [django-announce] Django security releases issued: 3.2.1, 3.1.9 and 2.2.21

2021-05-07 Thread Markus Holtermann
Hi all, We took an defense-in-depth approach which seemed fined with our test suite. But it turns out, there are cases that weren't covered by tests which caused a regression in a few specific cases. This is tracked in https://code.djangoproject.com/ticket/32718 Cheers, Markus On Fri, May 7,

Re: [django-announce] Django security releases issued: 3.2.1, 3.1.9 and 2.2.21

2021-05-07 Thread Ned Batchelder
It seems to me that the release note for 2.2.21 is incomplete. It says, "Specifically, empty file names and paths with dot segments will be rejected." But it's stricter than that: any path component causes the path to be rejected: > if name != os.path.basename(name): >     raise Suspiciou

Django security releases issued: 3.2.2, 3.1.10, and 2.2.22

2021-05-06 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/may/06/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 3.2.1, 3.1.9 and 2.2.21

2021-05-04 Thread Carlton Gibson
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/may/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To un

Django security releases issued: 3.1.8, 3.0.14, and 2.2.20

2021-04-06 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/apr/06/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 3.1.7, 3.0.13 and 2.2.19

2021-02-19 Thread Carlton Gibson
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/feb/19/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 3.1.6, 3.0.12, and 2.2.18

2021-02-01 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2021/feb/01/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Re: Django security releases issued: 3.1.1, 3.0.10 and 2.2.16

2020-09-02 Thread Annick Sakoua
Thanks :), didn't see that Le mardi 1 septembre 2020 à 10:20:39 UTC+1, carlton...@gmail.com a écrit : > Today the Django team issued 3.1.1, 3.0.10 and 2.2.16 as part of our > security process. These releases address two security issues, and we > encourage all users to upgrade as soon as possib

Django security releases issued: 3.1.1, 3.0.10 and 2.2.16

2020-09-01 Thread Carlton Gibson
Today the Django team issued 3.1.1, 3.0.10 and 2.2.16 as part of our security process. These releases address two security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2020/sep/01/security-releases/ -- You received this message becaus

Django security releases issued: 3.0.4, 2.2.11, and 1.11.29

2020-03-04 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2020/mar/04/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Django security releases issued: 3.0.3, 2.2.10 and 1.11.28

2020-02-03 Thread Carlton Gibson
Today the Django team issued 3.0.3, 2.2.10 and 1.11.28 as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2020/feb/03/security-releases/

Re: Django security releases issued: 3.0.1, 2.2.9, and 1.11.27

2019-12-18 Thread אורי
Django developers, We use Django 2.1 and anyway I saw that Django expects each user to have one email address, where on Speedy Net each user can have multiple email addresses. So I had to override *def save* in *class PasswordResetForm* on Speedy Net: https://github.com/speedy-net/speedy-net/blob

Django security releases issued: 3.0.1, 2.2.9, and 1.11.27

2019-12-18 Thread Mariusz Felisiak
Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an em

Re: Django security releases issued: 2.2.8 and 2.1.15.

2019-12-02 Thread Integr@te System
Many thanks Django Team and Carlton's informing. On Mon, Dec 2, 2019, 16:28 אורי wrote: > Bugfixes is empty on > https://docs.djangoproject.com/en/2.2/releases/2.1.15/ > אורי > u...@speedy.net > > > On Mon, Dec 2, 2019 at 11:12 AM Carlton Gibson > wrote: > >> Today the Django team issued 2.2.8

Re: Django security releases issued: 2.2.8 and 2.1.15.

2019-12-02 Thread אורי
Bugfixes is empty on https://docs.djangoproject.com/en/2.2/releases/2.1.15/ אורי u...@speedy.net On Mon, Dec 2, 2019 at 11:12 AM Carlton Gibson wrote: > Today the Django team issued 2.2.8 and 2.1.15 as part of our security > process. These releases address security issues, and we encourage al

Django security releases issued: 2.2.8 and 2.1.15.

2019-12-02 Thread Carlton Gibson
Today the Django team issued 2.2.8 and 2.1.15 as part of our security process. These releases address security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/dec/02/security-releases/

Django security releases issued: 2.2.4, 2.1.11, and 1.11.23.

2019-08-01 Thread Carlton Gibson
Today the Django team issued 2.2.4, 2.1.11, and 1.11.23 as part of our security process. These releases address security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/aug/01/security-releases/ -- You received this message because y

Django security releases issued: 2.2.3, 2.1.10 and 1.11.22

2019-07-01 Thread Mariusz Felisiak
Today the Django team issued 2.2.3, 2.1.10, and 1.11.22 as part of our security process. These releases address security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/jul/01/security-releases/ -- You received this message because y

Django security releases issued: 2.2.3, 2.1.10 and 1.11.22

2019-07-01 Thread Mariusz Felisiak
Today the Django team issued 2.2.3, 2.1.10, and 1.11.22 as part of our security process. These releases address security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/jul/01/security-releases/ -- You received this message because y

Re: Django security releases issued: 2.2.2, 2.1.9 and 1.11.21

2019-06-03 Thread wanbao jin
Oh, i missed that link, thanks. 😀 ‪On Mon, Jun 3, 2019 at 9:45 PM ‫אורי‬‎ wrote:‬ > wanbao Did you read > https://www.djangoproject.com/weblog/2019/jun/03/security-releases/ ? > אורי > u...@speedy.net > > > On Mon, Jun 3, 2019 at 4:42 PM wanbao jin wrote: > >> What were those security issues? C

Re: Django security releases issued: 2.2.2, 2.1.9 and 1.11.21

2019-06-03 Thread אורי
wanbao Did you read https://www.djangoproject.com/weblog/2019/jun/03/security-releases/ ? אורי u...@speedy.net On Mon, Jun 3, 2019 at 4:42 PM wanbao jin wrote: > What were those security issues? Could you briefly explain about it? > > Thanks > > On Mon, Jun 3, 2019 at 7:17 PM Carlton Gibson >

Re: Django security releases issued: 2.2.2, 2.1.9 and 1.11.21

2019-06-03 Thread Michal Petrucha
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Mon, Jun 03, 2019 at 09:41:59PM +0800, wanbao jin wrote: > What were those security issues? Could you briefly explain about it? > > Thanks They are described in the blog post that Carlton linked to in the first email: https://www.djangoproject.c

Re: Django security releases issued: 2.2.2, 2.1.9 and 1.11.21

2019-06-03 Thread wanbao jin
What were those security issues? Could you briefly explain about it? Thanks On Mon, Jun 3, 2019 at 7:17 PM Carlton Gibson wrote: > Today the Django team issued 2.2.2, 2.1.9, and 1.11.21 as part of our > security process. These releases address security issues, and we encourage > all users to up

Django security releases issued: 2.2.2, 2.1.9 and 1.11.21

2019-06-03 Thread Carlton Gibson
Today the Django team issued 2.2.2, 2.1.9, and 1.11.21 as part of our security process. These releases address security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/jun/03/security-releases/ -- You received this message because y

Django security releases issued: 2.1.6, 2.0.11, and 1.11.19

2019-02-11 Thread Carlton Gibson
Today the Django team issued 2.1.6, 2.0.11, and 1.11.19 as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/feb/11/security-releases/ -- You received this message because

Django security releases issued: 2.1.5, 2.0.10, and 1.11.18

2019-01-04 Thread Tim Graham
Today the Django team issued 2.1.5, 2.0.10, and 1.11.18 as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2019/jan/04/security-releases/ The issue was publicly reported through

Django security release issued: 2.1.2

2018-10-01 Thread Carlton Gibson
Today the Django team issued 2.1.2 as part of our security process. This release address a security issue, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2018/oct/01/security-release/

Django security releases issued: 1.11.15 and 2.0.8

2018-08-01 Thread Tim Graham
Today the Django team issued 1.11.15 and 2.0.8 as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2018/aug/01/security-releases/ As a reminder, we ask that potential security iss

Django security releases issued: 2.0.3, 1.11.11, and 1.8.19

2018-03-06 Thread Tim Graham
Today the Django team issued Django 2.0.3, 1.11.11, and 1.8.19 as part of our security process. These releases address two security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2018/mar/06/security-releases/ As a reminder, we ask that pot

Django security releases issued: 1.11.5 and 1.10.8

2017-09-05 Thread Tim Graham
Today the Django team issued 1.11.5 and 1.10.8 as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2017/sep/05/security-releases/ As a reminder, we ask that potential security i

Django security releases issued: 1.10.7, 1.9.13, and 1.8.18

2017-04-04 Thread Tim Graham
Today the Django team issued 1.10.7, 1.9.13, and 1.8.18 as part of our security process. These releases address two security issues, and we encourage all users to upgrade as soon as possible: https://www.djangoproject.com/weblog/2017/apr/04/security-releases/ As a reminder, we ask that potentia

Re: Django Security issue

2016-12-05 Thread 'Aaron C. de Bruyn' via Django users
It's a little un-clear how you are setting up your Django deployment, but the 'dev server' shouldn't be exposed directly to the internet. Have you read through the deployment guides? https://docs.djangoproject.com/en/1.10/howto/deployment/ -A On Sun, Dec 4, 2016 at 11:43 PM, deepak gupta wrote

Django Security issue

2016-12-04 Thread deepak gupta
Hi All, When ever we are opening a public IP on our server (CentOS and our application developed on Django 1.9.7, Angular 1.5). Inbound port is enabled on 8080, there is no port configuration for outbound traffic. We found once we enable public IP, it start generating huge outbound HTTP traffic, e

Re: [ANNOUNCE] Django security advisory: Vulnerability in password reset (master branch only)

2016-11-23 Thread William Hakizimana
While we are at it, could we implement these NIST new password guidelines into django? Just On Monday, November 21, 2016 at 3:13:21 PM UTC-6, Tim Graham wrote: > > We don't normally give security advis

[ANNOUNCE] Django security advisory: Vulnerability in password reset (master branch only)

2016-11-21 Thread Tim Graham
We don't normally give security advisories for issues that affect only the master branch, but in this case we've made an exception as the issue could be high impact. Please see the blog post for details: https://www.djangoproject.com/weblog/2016/nov/21/passwordresetconfirmview-security-advisory/

[ANNOUNCE] Django security releases issued: 1.10.3, 1.9.11, and 1.8.16

2016-11-01 Thread Tim Graham
Today the Django team issued 1.10.3, 1.9.11, and 1.8.16 as part of our security process. These releases address two security issues, and we encourage all users to upgrade as soon as possible. Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2016/nov/01/se

[ANNOUNCE] Django security releases issued: 1.9.10 and 1.8.15

2016-09-26 Thread Tim Graham
Today the Django team issued 1.9.10 and 1.8.15 as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible. Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2016/sep/26/security-relea

[ANNOUNCE] Django security releases issued: 1.10 release candidate 1, 1.9.8, and 1.8.14

2016-07-18 Thread Tim Graham
Today the Django team issued 1.10 release candidate 1, 1.9.8, and 1.8.14 as part of our security process. This releases address a security issue, and we encourage all users to upgrade as soon as possible. Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2

Re: [ANNOUNCE] Django security releases issued: 1.9.3 and 1.8.10

2016-03-02 Thread Tim Graham
Please create a separate thread with some details such as a sample project with steps to reproduce the issue so we can determine if it's a problem in Django or in your application. Thanks! On Wednesday, March 2, 2016 at 8:49:03 PM UTC-5, José David Ordoñez wrote: > > After upgrading django 1.8.9

Re: [ANNOUNCE] Django security releases issued: 1.9.3 and 1.8.10

2016-03-02 Thread José David Ordoñez
After upgrading django 1.8.9 to 1.8.10 my i18n/setlang/ went crazy "TypeError: must be unicode not str" when using {% url 'set_language' %} by going back to 1.8.9 solved the issue. El martes, 1 de marzo de 2016, 12:50:27 (UTC-4:30), Tim Graham escribió: > > Today the Django team issued 1.9.3 and

[ANNOUNCE] Django security releases issued: 1.9.3 and 1.8.10

2016-03-01 Thread Tim Graham
Today the Django team issued 1.9.3 and 1.8.10 as part of our security process. This releases address two security issues, and we encourage all users to upgrade as soon as possible. Details are available on the Django project weblog: https://www.djangoproject.com/weblog/2016/mar/01/security-rele

[ANNOUNCE] Django security releases issued (1.7.11, 1.8.7, and 1.9rc2)

2015-11-24 Thread Tim Graham
Today the Django team issued multiple releases -- Django 1.7.11, 1.8.7, and 1.9rc2 -- as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible. More details can be found on our blog: https://www.djangoproject.com/weblog/

[ANNOUNCE] Django security releases issued (1.4.22, 1.7.10, and 1.8.4)

2015-08-18 Thread Tim Graham
Today the Django team issued multiple releases -- Django 1.4.22, 1.7.10, and 1.8.4 -- as part of our security process. These releases address a security issue, and we encourage all users to upgrade as soon as possible. More details can be found on our blog: https://www.djangoproject.com/weblog/

[ANNOUNCE] Django security releases issued (1.4.21, 1.7.9, and 1.8.3)

2015-07-08 Thread Tim Graham
Today the Django team issued multiple releases -- Django 1.4.21, 1.7.9, and 1.8.3 -- as part of our security process. These releases address a couple security issues, and we encourage all users to upgrade as soon as possible. More details can be found on our blog: https://www.djangoproject.com/

[ANNOUNCE] Django Security advisory: simple_tag does not do auto-escaping

2015-06-29 Thread Tim Graham
The Django team has just published a short security advisory about usage of the simple_tag template tag helper. You should audit your own code. https://www.djangoproject.com/weblog/2015/jun/29/simple_tag-security-advisory/ -- You received this message because you are subscribed to the Google Gr

[ANNOUNCE] Django security release issued (1.8.2)

2015-05-20 Thread Tim Graham
Today the Django team issued Django 1.8.2 as part of our security process. This releases address a security issue, and we encourage all users to upgrade as soon as possible. More details can be found on our blog: https://www.djangoproject.com/weblog/2015/may/20/security-release/ As a reminder,

[ANNOUNCE] Django security releases issued

2014-08-20 Thread James Bennett
Today we've issued releases to address four security issues reported to us. Full disclosure is on the djangoproject.com weblog: https://www.djangoproject.com/weblog/2014/aug/20/security/ All users are encouraged to upgrade. Additionally, for anyone who missed it, last week we published an adviso

[Announce] Django security releases issued

2014-05-14 Thread Jacob Kaplan-Moss
Today we've issued releases to remedy three security issues reported to us. Affected versions are Django 1.4, Django 1.5, Django 1.6 and the Django 1.7 beta. Full details and download information are on the Django project weblog: https://www.djangoproject.com/weblog/2014/may/14/security-releases

[ANNOUNCE] Django security releases issued

2014-04-21 Thread James Bennett
Today we've issued releases to remedy three security issues reported to us. Affected versions are Django 1.4, Django 1.5, Django 1.6 and the Django 1.7 beta. Full details and download information are on the Django project weblog: https://www.djangoproject.com/weblog/2014/apr/21/security/ -- Yo

Re: django security

2013-09-08 Thread Mike Dewhirst
On 8/09/2013 3:23am, Natko Perko wrote: I browsed through books like Pro Django, Two scoops, Effective Django etc. and I pretty much found the same things as in the documentation. I was hoping to find, as I said before, a version for dummies with things explained from the basics or sowhat, like

Re: django security

2013-09-07 Thread Natko Perko
I browsed through books like Pro Django, Two scoops, Effective Django etc. and I pretty much found the same things as in the documentation. I was hoping to find, as I said before, a version for dummies with things explained from the basics or sowhat, like how does an attack works and how to pr

Re: django security

2013-09-06 Thread Stefano Probst
Hi! Do you mean something like the documentation ? Best regards -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an email

Re: django security

2013-09-06 Thread Tom Lockhart
On 2013-09-06, at 4:04 PM, Natko Perko wrote: > > Obviously not and obviously I couldnt google it. Ah, of course. What is obviously not obvious to you is not obvious to the rest of us either. Please be specific on what you did find and what you feel you are missing. Even if it is obvious. O

Re: django security

2013-09-06 Thread Natko Perko
Obviously not and obviously I couldnt google it. Best Regards. -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from it, send an email to django-users+unsubscr...@googlegroups.com. To po

django security

2013-09-06 Thread Natko Perko
hello, anyone got some links for in depth django security an built in django security thats explained for dummies? :) -- You received this message because you are subscribed to the Google Groups "Django users" group. To unsubscribe from this group and stop receiving emails from i

Re: django security

2008-04-03 Thread Daniel Hepper
Hi Andy, a good start is to have a look at chapter 19 in the django book, available online under http://djangobook.com/en/1.0/chapter19/ Additionally, chapter 14 covers Cross-site request forgery http://djangobook.com/en/1.0/chapter14/ Daniel On Thu, Apr 3, 2008 at 9:41 AM, andy baxter <[EMA

django security

2008-04-03 Thread andy baxter
hello, Is there any documentation online about security issues when using django? I'm assuming when writing code for my django app that I don't have to worry about things like quoting strings sent to the database because the django db api will already do that, but other things I'm not so sure

Django Security

2006-09-21 Thread Tyson Tate
t Django has a great track-record with security, I still need more concrete evidence to show to non-web-app people to convince them that Django is easily secured. Listing the major websites that run Django is one way to convince them of this, but I still need more. Are there any Django secur