Commit graph

339046 commits

Author SHA1 Message Date
nia
a8a66212fe xsqlmenu: fix installation, set LICENSE 2021-05-15 07:14:49 +00:00
nia
10c371c0e1 miredo: ensure translations are consistently installed 2021-05-15 07:01:31 +00:00
nia
def8a76616 spectrwm: uses pkg-config 2021-05-15 06:58:19 +00:00
nia
1cb5df58ae yorick: set LICENSE 2021-05-15 06:53:50 +00:00
nia
c15b610784 rp-pppoe: create OPSYS PLISTs 2021-05-15 06:51:16 +00:00
nia
ed7ff19260 dvdbackup: ensure locale files are reproducibly built 2021-05-15 06:48:04 +00:00
wiz
f41d7835d4 protobuf: add upstream bug report URL 2021-05-14 20:52:09 +00:00
wiz
bccf1ed4ab protobuf: add an upstream pull request that reports the same problem 2021-05-14 20:46:20 +00:00
wiz
9517c8e2c1 protobuf: fix build on NetBSD 2021-05-14 19:36:47 +00:00
adam
7e778bf6fe Updated www/py-django2, www/py-django3, www/py-django-extensions, www/py-django-countries 2021-05-14 18:58:37 +00:00
adam
4068d46c1d py-django-countries: updated to 7.2.1
7.2.1 (11 May 2021)
- Fix Latin translations.
2021-05-14 18:58:14 +00:00
adam
951f2004e9 py-django-extensions: updated to 3.1.3
3.1.3

Changes:

Fix: Django 3.2, Run tests against Django 3.2
Fix: Django 3.2, Handle warnings for default_app_config
Fix: sqldiff, Fix for missing field/index in model case
2021-05-14 18:56:52 +00:00
adam
7c0402c0e8 py-django3: updated to 3.2.3
Django 3.2.3 fixes several bugs in 3.2.2.

Bugfixes

Prepared for mysqlclient > 2.0.3 support.
Fixed a regression in Django 3.2 that caused the incorrect filtering of querysets combined with the | operator.
Fixed a regression in Django 3.2.1 where saving FileField would raise a SuspiciousFileOperation even when a custom upload_to returns a valid file path.


Django 3.2.2 fixes a security issue and a bug in 3.2.1.

CVE-2021-32052: Header injection possibility since URLValidator accepted newlines in input on Python 3.9.5+

On Python 3.9.5+, URLValidator didn’t prohibit newlines and tabs. If you used values with newlines in HTTP response, you could suffer from header injection attacks. Django itself wasn’t vulnerable because HttpResponse prohibits newlines in HTTP headers.

Moreover, the URLField form field which uses URLValidator silently removes newlines and tabs on Python 3.9.5+, so the possibility of newlines entering your data only existed if you are using this validator outside of the form fields.

This issue was introduced by the bpo-43882 fix.
2021-05-14 18:54:38 +00:00
adam
ab315ec0a5 py-django2: updated to 2.2.23
Django 2.2.23 fixes a regression in 2.2.21.

Bugfixes

Fixed a regression in Django 2.2.21 where saving FileField would raise a SuspiciousFileOperation even when a custom upload_to returns a valid file path


Django 2.2.22 fixes a security issue in 2.2.21.

CVE-2021-32052: Header injection possibility since URLValidator accepted newlines in input on Python 3.9.5+

On Python 3.9.5+, URLValidator didn’t prohibit newlines and tabs. If you used values with newlines in HTTP response, you could suffer from header injection attacks. Django itself wasn’t vulnerable because HttpResponse prohibits newlines in HTTP headers.

Moreover, the URLField form field which uses URLValidator silently removes newlines and tabs on Python 3.9.5+, so the possibility of newlines entering your data only existed if you are using this validator outside of the form fields.

This issue was introduced by the bpo-43882 fix.
2021-05-14 18:53:07 +00:00
nia
ec36d0e3e7 lua-sqlite3: needs m4 2021-05-14 14:52:58 +00:00
nia
7201eaee9a capnproto: needs openssl 2021-05-14 14:50:11 +00:00
nia
19690d9758 ddd: needs termcap 2021-05-14 14:48:36 +00:00
nia
43a3f43f27 diffbreaker: needds libcurses 2021-05-14 14:47:55 +00:00
nia
e92c720dd7 gnustep-makee: installs bash scripts, needs bash at runtime 2021-05-14 14:46:40 +00:00
nia
fc2526247d libfreefare: needs openssl 2021-05-14 14:44:27 +00:00
nia
b0dafbcf80 nsis: needs zlib 2021-05-14 14:43:00 +00:00
nia
f0ace72091 py-tortoisehg: needs pax tool 2021-05-14 14:41:16 +00:00
nia
f1f7e20d51 le: point at correct curses 2021-05-14 14:37:56 +00:00
nia
a440a52e14 mflteco: honor CFLAGS/LDFLAGS 2021-05-14 14:31:24 +00:00
nia
0da66c5f23 pico: honor LDFLAGS 2021-05-14 14:27:31 +00:00
nia
5f38efe199 tweak: honor CFLAGS/LDFLAGS 2021-05-14 14:22:04 +00:00
nia
2cff17e674 vim-lang: needs termcap 2021-05-14 14:19:44 +00:00
nia
a7f1f50e90 fuse-lzofs: needs zlib 2021-05-14 14:17:41 +00:00
nia
7b0c9a8b54 viking: needs docbook-xsl 2021-05-14 14:15:36 +00:00
nia
e2eeb9cb52 epeg: honor LDFLAGS 2021-05-14 14:13:22 +00:00
nia
472b9acbd2 gimp-ufraw: needs jasper 2021-05-14 14:09:05 +00:00
nia
ddc2ad1d68 libggimisc: create PLIST.Linux 2021-05-14 14:08:30 +00:00
nia
86d910bcdd uhd: do not use lib64 2021-05-14 14:05:06 +00:00
nia
4d430f57d5 mopher: needs bdb 2021-05-14 13:54:01 +00:00
nia
b6e2b958f9 squeak-vm: needs libuuid 2021-05-14 13:52:37 +00:00
nia
3129074835 fetchmailconf: needs openssl 2021-05-14 13:50:02 +00:00
nia
08f12d969a imp: use exact path to pax 2021-05-14 13:49:28 +00:00
nia
54b3449a12 ingo: use exact path to pax 2021-05-14 13:49:13 +00:00
nia
78d0e54bbb roundcube-plugin-carddav: needs pax tool 2021-05-14 13:44:31 +00:00
nia
36bbddf0df turba: use exact path for pax 2021-05-14 13:42:40 +00:00
nia
82ab925c0f thunderbird68: add PLIST.Linux 2021-05-14 13:41:49 +00:00
nia
76c9691360 eukleides: honor environment flags 2021-05-14 13:35:47 +00:00
nia
158bf8e5b2 kalk: needs m4 2021-05-14 13:30:56 +00:00
nia
7c1da800fb fd: honor CFLAGS/LDFLAGS 2021-05-14 13:26:27 +00:00
nia
274851088c iwatch: needs wide curses 2021-05-14 13:23:22 +00:00
nia
7e22fc07c1 avidemux: subst noop is ok 2021-05-14 13:20:16 +00:00
nia
b2dd266ee3 gst-plugins1-transcoder: needs Python as tool 2021-05-14 13:18:52 +00:00
nia
98a0900b3a bftpd: honor LDFLAGS 2021-05-14 13:16:53 +00:00
nia
068cb6299b gift-fasttrack: needs zlib 2021-05-14 13:13:21 +00:00
nia
21e2d44883 gupnp12: needs vala 2021-05-14 13:12:29 +00:00