Skip to content

Releases: moggers87/django-sendfile2

v0.7.0

08 Aug 21:40
v0.7.0
Compare
Choose a tag to compare
  • Fix reflected file download vulnerability
  • Add support for spaces in filenames

v0.6.1

18 Jan 22:11
v0.6.1
Compare
Choose a tag to compare
  • Fixed Django 4.0 compatibility
  • Add support for Python 3.10
  • Remove support for Python 3.5 and 3.6
  • Remove support for Django 3.1

v0.6.0

17 Jun 21:16
v0.6.0
Compare
Choose a tag to compare

This release contains a fix for GHSA-6r3c-8xf3-ggrr. Thanks to Gianluca Pacchiella for reporting this issue and for providing the initial patch.

  • Fixed issue where django-sendfile could serve any file, even if it was
    outside SENDFILE_ROOT. SEDNFILE_ROOT is now required for all
    backends.

0.5.1

30 Dec 03:58
v0.5.1
Compare
Choose a tag to compare
  • Fix issue with versioneer not being updated about the package name change
    • tox now does a proper sdist and install to avoid this in future

The following is from version 0.5.0 which was tagged but not released:

  • Rename Python package from sendfile to django_sendfile
    • This will require changing SENDFILE_BACKEND, INSTALLED_APPS, and
      any imports
  • Remove code used to support Python 2.7
  • Add support for the latest versions of Django and Python