summaryrefslogtreecommitdiffstats
path: root/package/python-django/python-django.mk
diff options
context:
space:
mode:
authorPeter Korsgaard <peter@korsgaard.com>2019-02-15 14:32:01 +0100
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>2019-02-15 21:48:38 +0100
commit653f86c0e91847dd8841837b650e2e966b59dd78 (patch)
tree8c2d18643b1dee2852d9fcdd141ec396e7bd9591 /package/python-django/python-django.mk
parent92f34e8fe297b740709a32aa49de58985783e95d (diff)
downloadbuildroot-653f86c0e91847dd8841837b650e2e966b59dd78.tar.gz
buildroot-653f86c0e91847dd8841837b650e2e966b59dd78.zip
package/python-django: security bump to version 2.1.7
Fixes the following security issues: CVE-2019-6975: Memory exhaustion in django.utils.numberformat.format() If django.utils.numberformat.format() – used by contrib.admin as well as the the floatformat, filesizeformat, and intcomma templates filters – received a Decimal with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to '{:f}'.format(). To avoid this, decimals with more than 200 digits are now formatted using scientific notation. https://docs.djangoproject.com/en/2.1/releases/2.1.6/ 2.1.6 contained a packaging error, fixed by 2.1.7: https://docs.djangoproject.com/en/2.1/releases/2.1.7/ Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Diffstat (limited to 'package/python-django/python-django.mk')
-rw-r--r--package/python-django/python-django.mk4
1 files changed, 2 insertions, 2 deletions
diff --git a/package/python-django/python-django.mk b/package/python-django/python-django.mk
index 53e8f20e87..5922a6c07c 100644
--- a/package/python-django/python-django.mk
+++ b/package/python-django/python-django.mk
@@ -4,10 +4,10 @@
#
################################################################################
-PYTHON_DJANGO_VERSION = 2.1.5
+PYTHON_DJANGO_VERSION = 2.1.7
PYTHON_DJANGO_SOURCE = Django-$(PYTHON_DJANGO_VERSION).tar.gz
# The official Django site has an unpractical URL
-PYTHON_DJANGO_SITE = https://files.pythonhosted.org/packages/5c/7f/4c750e09b246621e5e90fa08f93dec1b991f5c203b0ff615d62a891c8f41
+PYTHON_DJANGO_SITE = https://files.pythonhosted.org/packages/7e/ae/29c28f6afddae0e305326078f31372f03d7f2e6d6210c9963843196ce67e
PYTHON_DJANGO_LICENSE = BSD-3-Clause
PYTHON_DJANGO_LICENSE_FILES = LICENSE
PYTHON_DJANGO_SETUP_TYPE = setuptools
OpenPOWER on IntegriCloud