Patchwork v2.0.4 Available
dja at axtens.net
Fri Jul 5 16:17:02 AEST 2019
We're pleased to announce the release of Patchwork v2.0.4. This release
is part of the "Dazzle" release series:
This release is a PATCH release that focuses on bugfixes, in particular
CVE-2019-13122. For more details, please see below.
In general we would encourage installations to upgrade to v2.1.4,
however in light of CVE-2019-13122 we thought it worthwhile to ship a
new version in the 2.0 series for those who cannot upgrade just yet.
Changes in Patchwork v2.0.3..v2.0.4
6ead7215f198 Release 2.0.4
0d91b9fbc003 docs: Add a release note for CVE-2019-13122
5c735f49677d filters: Escape State names when generating selector HTML
1a5aad5e0395 tests: Add test for unescaped values in patch detail page
5cda060535b1 templatetags: Do not mark output of msgid tag as safe
a2a51cb7777e Revert "models: Use 'base_manager_name'"
75564e93e151 Revert "models: Only set 'base_manager_name' for Django >= 1.10"
1cb63755c988 Revert "models: Series plural name is Series"
16c2052cc604 Post-release version bump
More information about the Patchwork