Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove vendored is_safe_url; drop Django 1.7 support #3

Merged

Conversation

moggers87
Copy link
Collaborator

Fixes #2

Also drop support for Django 1.7. Technically this package will still work with Django 1.7, but as pointed out in #2 Django 1.7 still has some security issues that have been since fixed in 1.8+

The vendored copy was from Django 1.9 and has been backported to 1.8.
Also 1.8+ have a fix for CVE-2017-7233, which our copy did not.

Fixes justinmayer#2
@coveralls
Copy link

Coverage Status

Coverage remained the same at 100.0% when pulling ca59e0d on moggers87:2-remove-vendored-is_safe_url into 8b233e6 on justinmayer:master.

4 similar comments
@coveralls
Copy link

Coverage Status

Coverage remained the same at 100.0% when pulling ca59e0d on moggers87:2-remove-vendored-is_safe_url into 8b233e6 on justinmayer:master.

@coveralls
Copy link

Coverage Status

Coverage remained the same at 100.0% when pulling ca59e0d on moggers87:2-remove-vendored-is_safe_url into 8b233e6 on justinmayer:master.

@coveralls
Copy link

coveralls commented Mar 12, 2018

Coverage Status

Coverage remained the same at 100.0% when pulling ca59e0d on moggers87:2-remove-vendored-is_safe_url into 8b233e6 on justinmayer:master.

@coveralls
Copy link

Coverage Status

Coverage remained the same at 100.0% when pulling ca59e0d on moggers87:2-remove-vendored-is_safe_url into 8b233e6 on justinmayer:master.

@moggers87 moggers87 mentioned this pull request Mar 12, 2018
@justinmayer
Copy link
Owner

Fantastic. Thanks, Matt!

@justinmayer justinmayer changed the title Remove vendored is_safe_url Remove vendored is_safe_url; drop Django 1.7 support Mar 17, 2018
@justinmayer justinmayer merged commit 7c4c232 into justinmayer:master Mar 17, 2018
@moggers87 moggers87 deleted the 2-remove-vendored-is_safe_url branch December 6, 2019 20:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Remove or update is_safe_url?
3 participants