Skip to content

Commit 86aa42f

Browse files
build(deps): Bump django from 4.2.25 to 4.2.29 in /.kokoro (#457)
Bumps [django](https://github.com/django/django) from 4.2.25 to 4.2.29. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/django/django/commit/f2ec75efbcf4d1ed63f135e5f8ff5f0463175312"><code>f2ec75e</code></a> [4.2.x] Bumped version for 4.2.29 release.</li> <li><a href="https://github.com/django/django/commit/54b50bf7d6dcbf02d4c01f853627cc9299d4934d"><code>54b50bf</code></a> [4.2.x] Fixed CVE-2026-25674 -- Prevented potentially incorrect permissions o...</li> <li><a href="https://github.com/django/django/commit/b3e8ec8cc310489fe80174b14b11edb970d682ea"><code>b3e8ec8</code></a> [4.2.x] Fixed CVE-2026-25673 -- Simplified URLField scheme detection.</li> <li><a href="https://github.com/django/django/commit/e52ff00856cce3a2b05d244ee98dc2b8d9fcf3a9"><code>e52ff00</code></a> [4.2.x] Added stub release notes and release date for 4.2.29.</li> <li><a href="https://github.com/django/django/commit/e0896dfe83cce33b5cae3fcf0bbbef89e92b4bc6"><code>e0896df</code></a> [4.2.x] Added CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285, C...</li> <li><a href="https://github.com/django/django/commit/609d5526f0c4f8904ffabbce96cdb31953ffa92f"><code>609d552</code></a> [4.2.x] Post-release version bump.</li> <li><a href="https://github.com/django/django/commit/20c71f6b91324cf401056c72136c14e0ec2bf7bf"><code>20c71f6</code></a> [4.2.x] Bumped version for 4.2.28 release.</li> <li><a href="https://github.com/django/django/commit/881ff2c4830f95fa844d8de5977c06205d45368f"><code>881ff2c</code></a> [4.2.x] Refs CVE-2026-1312 -- Raised ValueError when FilteredRelation aliases...</li> <li><a href="https://github.com/django/django/commit/90f5b10784ba5bf369caed87640e2b4394ea3314"><code>90f5b10</code></a> [4.2.x] Fixed CVE-2026-1312 -- Protected order_by() from SQL injection via al...</li> <li><a href="https://github.com/django/django/commit/f75f8f3597e1ce351d5ac08b6ba7ebd9dadd9b5d"><code>f75f8f3</code></a> [4.2.x] Fixed CVE-2026-1287 -- Protected against SQL injection in column alia...</li> <li>Additional commits viewable in <a href="https://github.com/django/django/compare/4.2.25...4.2.29">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=django&package-manager=pip&previous-version=4.2.25&new-version=4.2.29)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/googleapis/sphinx-docfx-yaml/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Dan Lee <71398022+dandhlee@users.noreply.github.com>
1 parent 1c88f0c commit 86aa42f

2 files changed

Lines changed: 4 additions & 4 deletions

File tree

packages/gcp-sphinx-docfx-yaml/.kokoro/requirements.in

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# Library specific extra installations.
22
# Extra installations are required to ensure all documentation can be
33
# generated and not missed out with the generate-docs script.
4-
django==4.2.25
4+
django==4.2.29
55
google-cloud-aiplatform[prediction]
66
googleapis-common-protos==1.58.0 # pinned for conflict in range specifier.
77
grpcio-status==1.48.2 # must be pinned due to protobuf compatibility.

packages/gcp-sphinx-docfx-yaml/.kokoro/requirements.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -171,9 +171,9 @@ distlib==0.3.9 \
171171
--hash=sha256:47f8c22fd27c27e25a65601af709b38e4f0a45ea4fc2e710f65755fa8caaaf87 \
172172
--hash=sha256:a60f20dea646b8a33f3e7772f74dc0b2d0772d2837ee1342a00645c81edf9403
173173
# via virtualenv
174-
django==4.2.25 \
175-
--hash=sha256:2391ab3d78191caaae2c963c19fd70b99e9751008da22a0adcc667c5a4f8d311 \
176-
--hash=sha256:9584cf26b174b35620e53c2558b09d7eb180a655a3470474f513ff9acb494f8c
174+
django==4.2.29 \
175+
--hash=sha256:074d7c4d2808050e528388bda442bd491f06def4df4fe863f27066851bba010c \
176+
--hash=sha256:86d91bc8086569c8d08f9c55888b583a921ac1f95ed3bdc7d5659d4709542014
177177
# via -r requirements.in
178178
docker==6.0.0 \
179179
--hash=sha256:19e330470af40167d293b0352578c1fa22d74b34d3edf5d4ff90ebc203bbb2f1 \

0 commit comments

Comments
 (0)