[Security] Bump django from 2.2.4 to 2.2.10#279
[Security] Bump django from 2.2.4 to 2.2.10#279dependabot-preview[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps [django](https://github.com/django/django) from 2.2.4 to 2.2.10. **This update includes security fixes.** - [Release notes](https://github.com/django/django/releases) - [Commits](django/django@2.2.4...2.2.10) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
Code Climate has analyzed commit 2f649d6 and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 99.4%. View more on Code Climate. |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
1 similar comment
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps django from 2.2.4 to 2.2.10. This update includes security fixes.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Sourced from The GitHub Security Advisory Database.
Commits
b2c33a5[2.2.x] Bumped version for 2.2.10 release.c67a368[2.2.x] Fixed CVE-2020-7471 -- Properly escaped StringAgg(delimiter) parameter.96d6443[2.2.x] Fixed timezones tests for PyYAML 5.3+.813b33e[2.2.x] Added CVE-2019-19844 to the security archive.e728612[2.2.x] Post-release version bump.c494d90[2.2.x] Bumped version for 2.2.9 release.4d334be[2.2.x] Fixed CVE-2019-19844 -- Used verified user email for password reset r...86befcc[2.2.x] Refs #31073 -- Added release notes for 02eff7ef60466da108b1a33f1e4dc0...f33be1e[2.2.x] Fixed #31073 -- Prevented CheckboxInput.get_context() from mutating a...e8b0903[2.2.x] Fixed #31006 -- Doc'd backslash escaping in date/time template filters.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard: