From b269ed48ee8761649f1ef6796140737e745b0e13 Mon Sep 17 00:00:00 2001 From: John Westcott IV Date: Wed, 9 Nov 2022 10:24:16 -0500 Subject: [PATCH 1/2] Updating the patch release of django per dependabot alerts --- requirements/requirements.in | 2 +- requirements/requirements.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements/requirements.in b/requirements/requirements.in index 00779e760c..24d2abb7c8 100644 --- a/requirements/requirements.in +++ b/requirements/requirements.in @@ -10,7 +10,7 @@ cryptography>=36.0.2,<37.0.0 # Until paramiko fixes https://github.com/paramiko/ Cython<3 # Since the bump to PyYAML 5.4.1 this is now a mandatory dep daphne distro -django==3.2.13 # see UPGRADE BLOCKERs +django>=3.2.16,<4.0.0 # see UPGRADE BLOCKERs https://github.com/ansible/awx/security/dependabot/67 django-auth-ldap django-cors-headers>=3.5.0 django-crum diff --git a/requirements/requirements.txt b/requirements/requirements.txt index c407a3f5ee..d9599a6682 100644 --- a/requirements/requirements.txt +++ b/requirements/requirements.txt @@ -86,7 +86,7 @@ defusedxml==0.6.0 # social-auth-core distro==1.5.0 # via -r /awx_devel/requirements/requirements.in -django==3.2.13 +django==3.2.16 # via # -r /awx_devel/requirements/requirements.in # channels From 110636796235de21098362bdd30eaaf9f01fbb3d Mon Sep 17 00:00:00 2001 From: John Westcott IV Date: Fri, 11 Nov 2022 13:37:15 -0500 Subject: [PATCH 2/2] Doing a hard pin on django --- requirements/requirements.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements/requirements.in b/requirements/requirements.in index 24d2abb7c8..70bf2ca946 100644 --- a/requirements/requirements.in +++ b/requirements/requirements.in @@ -10,7 +10,7 @@ cryptography>=36.0.2,<37.0.0 # Until paramiko fixes https://github.com/paramiko/ Cython<3 # Since the bump to PyYAML 5.4.1 this is now a mandatory dep daphne distro -django>=3.2.16,<4.0.0 # see UPGRADE BLOCKERs https://github.com/ansible/awx/security/dependabot/67 +django==3.2.16 # see UPGRADE BLOCKERs https://github.com/ansible/awx/security/dependabot/67 django-auth-ldap django-cors-headers>=3.5.0 django-crum