deps(py)(deps): bump django from 5.1.4 to 5.2.14 in /backend in the python-non-major group#28
Conversation
Bumps the python-non-major group in /backend with 1 update: [django](https://github.com/django/django). Updates `django` from 5.1.4 to 5.2.14 - [Commits](django/django@5.1.4...5.2.14) --- updated-dependencies: - dependency-name: django dependency-version: 5.2.14 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-non-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Fechando: Estendendo o |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
…t-level) PR #28 do Dependabot propos django 5.1.4 -> 5.2.14 e foi classificado como minor (semver), entrando no group python-non-major com CI verde. Mas 5.1 -> 5.2 e a transicao LTS-para-LTS em Django, que o item B16 do Improvement-system.md marca como decisao sprint-level: exige validacao manual alem do CI (settings deprecadas, middlewares customizados, auth backend, testes E2E reais). Antes deste fix, o ignore cobria so 'version-update:semver-major' (django 5.x -> 6.x). Agora cobre minor tambem, evitando que upgrades LTS escapem como minor inocente. Patches (5.1.5, 5.1.6, ...) continuam abertos — eles trazem fixes de CVE que importam para producao. Quando subir django em Sprint dedicada, remover este ignore inteiro (volta a aceitar minor + major). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…t-level) PR #28 do Dependabot propos django 5.1.4 -> 5.2.14 e foi classificado como minor (semver), entrando no group python-non-major com CI verde. Mas 5.1 -> 5.2 e a transicao LTS-para-LTS em Django, que o item B16 do Improvement-system.md marca como decisao sprint-level: exige validacao manual alem do CI (settings deprecadas, middlewares customizados, auth backend, testes E2E reais). Antes deste fix, o ignore cobria so 'version-update:semver-major' (django 5.x -> 6.x). Agora cobre minor tambem, evitando que upgrades LTS escapem como minor inocente. Patches (5.1.5, 5.1.6, ...) continuam abertos — eles trazem fixes de CVE que importam para producao. Quando subir django em Sprint dedicada, remover este ignore inteiro (volta a aceitar minor + major). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…t-level) (#30) PR #28 do Dependabot propos django 5.1.4 -> 5.2.14 e foi classificado como minor (semver), entrando no group python-non-major com CI verde. Mas 5.1 -> 5.2 e a transicao LTS-para-LTS em Django, que o item B16 do Improvement-system.md marca como decisao sprint-level: exige validacao manual alem do CI (settings deprecadas, middlewares customizados, auth backend, testes E2E reais). Antes deste fix, o ignore cobria so 'version-update:semver-major' (django 5.x -> 6.x). Agora cobre minor tambem, evitando que upgrades LTS escapem como minor inocente. Patches (5.1.5, 5.1.6, ...) continuam abertos — eles trazem fixes de CVE que importam para producao. Quando subir django em Sprint dedicada, remover este ignore inteiro (volta a aceitar minor + major). Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Bumps the python-non-major group in /backend with 1 update: django.
Updates
djangofrom 5.1.4 to 5.2.14Commits
024c26b[5.2.x] Bumped version for 5.2.14 release.2115d4e[5.2.x] Fixed CVE-2026-6907 -- Prevented caching of requests when Vary header...47cf968[5.2.x] Fixed CVE-2026-35192 -- Ensured Vary header is sent when setting sess...2ec27ed[5.2.x] Fixed CVE-2026-5766 -- Enforced DATA_UPLOAD_MAX_MEMORY_SIZE in Memory...ed18840[5.2.x] Fixed typo in stub release notes for 5.2.14.de3f622[5.2.x] Added stub release notes and release date for 5.2.14.fb61c8a[5.2.x] Refs CVE-2026-4292 -- Isolated new test in AdminViewListEditable.bd1a758[5.2.x] Fixed two issues in release helper scripts/verify_release.sh.da57aaa[5.2.x] Added CVE-2026-3902, CVE-2026-4277, CVE-2026-4292, CVE-2026-33033, an...c9a8bdb[5.2.x] Post-release version bump.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions