Skip to content

fix(deps): upgrade djangorestframework to 3.18.1 for security fixes - #243

Merged
matrixise merged 1 commit into
masterfrom
security/upgrade-djangorestframework
Sep 24, 2026
Merged

matrixise merged 1 commit into
masterfrom
security/upgrade-djangorestframework

Conversation

@matrixise

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades djangorestframework from 3.17.1 to 3.18.1
  • Resolves 2 open medium Dependabot alerts: a potential bypass of Django's DATA_UPLOAD_MAX_MEMORY_SIZE when parsing oversized JSON/urlencoded bodies via DRF request.data, and disclosure of GET-protected data by AdminRenderer when rendering invalid write requests
  • Advisories: GHSA-2m8g-3cmr-wg3w, GHSA-g47c-3xmw-q6m2

Test plan

  • python manage.py test pythonie --settings=pythonie.settings.tests (SQLite, 7/7 passed)
  • ruff check pythonie clean

@matrixise
matrixise force-pushed the security/upgrade-djangorestframework branch 3 times, most recently from 6ea314e to 21bdd06 Compare September 24, 2026 06:37
Resolves medium severity Dependabot alerts: a potential bypass of
Django's DATA_UPLOAD_MAX_MEMORY_SIZE when parsing oversized JSON and
urlencoded bodies via DRF request.data, and disclosure of
GET-protected data by AdminRenderer when rendering invalid write
requests.

GHSA-2m8g-3cmr-wg3w, GHSA-g47c-3xmw-q6m2

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@matrixise
matrixise force-pushed the security/upgrade-djangorestframework branch from 21bdd06 to 2a8de63 Compare September 24, 2026 06:37
@matrixise
matrixise merged commit 05c27d1 into master Sep 24, 2026
0 of 2 checks passed
@matrixise
matrixise deleted the security/upgrade-djangorestframework branch September 24, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant