Skip to content

fix(deps): upgrade django to 6.0.8 for security fixes - #244

Merged
matrixise merged 1 commit into
masterfrom
security/upgrade-django
Sep 24, 2026
Merged

matrixise merged 1 commit into
masterfrom
security/upgrade-django

Conversation

@matrixise

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades django from 6.0.6 to 6.0.8, constrained to django<6.1 to keep this a security-only patch (not a minor version bump)
  • Resolves 2 open medium Dependabot alerts: the cache middleware potentially exposing private responses when unrelated request cookies are present, and DomainNameValidator permitting newline characters that could enable HTTP header injection. Also picks up the GDALRaster heap over-read fix (GHSA-crhf-3pfg-w68w)
  • Advisories: GHSA-3h9f-r86x-qvjx, GHSA-crhf-3pfg-w68w, GHSA-8qcx-xf44-272x

Test plan

  • python manage.py test pythonie --settings=pythonie.settings.tests (SQLite, 7/7 passed)
  • ruff check pythonie clean

@matrixise
matrixise force-pushed the security/upgrade-django branch 4 times, most recently from 4c13b72 to d73d90f Compare September 24, 2026 06:37
Resolves medium severity Dependabot alerts: the cache middleware
potentially exposing private responses when unrelated request cookies
are present, GDALRaster over-reading heap memory when constructed from
bytes, and DomainNameValidator permitting newline characters that
could enable HTTP header injection.

Pinned to the 6.0.x branch (django<6.1) to keep this a security-only
patch rather than a minor version upgrade.

GHSA-3h9f-r86x-qvjx, GHSA-crhf-3pfg-w68w, GHSA-8qcx-xf44-272x

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@matrixise
matrixise force-pushed the security/upgrade-django branch from d73d90f to c760b16 Compare September 24, 2026 06:37
@matrixise
matrixise merged commit 974d547 into master Sep 24, 2026
0 of 2 checks passed
@matrixise
matrixise deleted the security/upgrade-django branch September 24, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant