Skip to content

Bump django-filter from 2.0.0 to 2.4.0#25

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/dev/django-filter-2.4.0
Closed

Bump django-filter from 2.0.0 to 2.4.0#25
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/dev/django-filter-2.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Dec 7, 2020

Copy link
Copy Markdown

Bumps django-filter from 2.0.0 to 2.4.0.

Release notes

Sourced from django-filter's releases.

Version 2.4.0

  • SECURITY: Added a MaxValueValidator to the form field for NumberFilter. This prevents a potential DoS attack if numbers with very large exponents were subsequently converted to integers.

    The default limit value for the validator is 1e50.

    The new NumberFilter.get_max_validator() allows customising the used validator, and may return None to disable the validation entirely.

  • Added testing against Django 3.1 and Python 3.9.

    In addition tests against Django main development branch are now required to pass.

Version 2.3.0

https://github.com/carltongibson/django-filter/blob/master/CHANGES.rst#version-230-2020-6-5

Version 2.2

Highlights:

  • Added DjangoFilterBackend.get_schema_operation_parameters() for DRF 3.10+ OpenAPI schema generation. (#1086)
  • Added lookup_expr to MultipleChoiceFilter (#1054)
  • Dropped support for EOL Python 3.4

Version 2.1.0

  • Fixed a regression in FilterView introduced in 2.0. An empty QuerySet was incorrectly used whenever the FilterSet was unbound (i.e. when there were no GET parameters). The correct, pre-2.0 behaviour is now restored.

    A workaround was to set strict=False on the FilterSet. This is no longer necessary, so you may restore strict behaviour as desired.

  • Added IsoDateTimeFromToRangeFilter. Allows From-To filtering using ISO-8601 formatted dates.

Changelog

Sourced from django-filter's changelog.

Version 2.4.0 (2020-9-27)

  • SECURITY: Added a MaxValueValidator to the form field for NumberFilter. This prevents a potential DoS attack if numbers with very large exponents were subsequently converted to integers.

    The default limit value for the validator is 1e50.

    The new NumberFilter.get_max_validator() allows customising the used validator, and may return None to disable the validation entirely.

  • Added testing against Django 3.1 and Python 3.9.

    In addition tests against Django main development branch are now required to pass.

Version 2.3.0 (2020-6-5)

  • Fixed import of FieldDoesNotExist. (#1127)
  • Added testing against Django 3.0. (#1125)
  • Declared support for, and added testing against, Python 3.8. (#1138)
  • Fix filterset multiple inheritance bug (#1131)
  • Allowed customising default lookup expression. (#1129)
  • Drop Django 2.1 and below (#1180)
  • Fixed IsoDateTimeRangeFieldTests for Django 3.1
  • Require tests to pass against Django master.

Version 2.2 (2019-7-16)

  • Added DjangoFilterBackend.get_schema_operation_parameters() for DRF 3.10+ OpenAPI schema generation. (#1086)
  • Added lookup_expr to MultipleChoiceFilter (#1054)
  • Dropped support for EOL Python 3.4

Version 2.1 (2019-1-20)

  • Fixed a regression in FilterView introduced in 2.0. An empty QuerySet was incorrectly used whenever the FilterSet was unbound (i.e. when there were no GET parameters). The correct, pre-2.0 behaviour is now restored.

    A workaround was to set strict=False on the FilterSet. This is no longer necessary, so you may restore strict behaviour as desired.

  • Added IsoDateTimeFromToRangeFilter. Allows From-To filtering using ISO-8601 formatted dates.

... (truncated)

Commits
  • 7821072 Postpone move to CalVer.
  • fd5824e Restore version declaration in setup.py.
  • c9daa68 Version 20.9.0.
  • c045bbe Droped using bumpversion.
  • b1f56ed Use single version reference from main module.
  • 451d372 Update docs copyright year.
  • 82c9a42 Added MaxValueValidator to NumberFilter.
  • 2ebce74 Confirmed compatibility with Python 3.9. (#1270)
  • 85c9572 Run tests with GitHub Actions
  • d9f389f Update Jinja test dependency.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Dec 7, 2020
@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2021

Copy link
Copy Markdown
Author

Superseded by #116.

@dependabot dependabot Bot closed this Sep 27, 2021
@dependabot dependabot Bot deleted the dependabot/pip/dev/django-filter-2.4.0 branch September 27, 2021 03:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants