Received: from mail.netlandish.com (mail.netlandish.com [174.136.98.166]) by code.netlandish.com (Postfix) with ESMTP id C6559560D for <~petersanchez/public-inbox@lists.code.netlandish.com>; Fri, 14 Jun 2024 13:21:53 +0000 (UTC) Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=209.85.221.179; helo=mail-vk1-f179.google.com; envelope-from=peter@netlandish.com; receiver=lists.code.netlandish.com Authentication-Results: mail.netlandish.com; dkim=pass (1024-bit key; unprotected) header.d=netlandish.com header.i=@netlandish.com header.b=GBavplNJ Received: from mail-vk1-f179.google.com (mail-vk1-f179.google.com [209.85.221.179]) by mail.netlandish.com (Postfix) with ESMTP id B109D17A3C7 for <~petersanchez/public-inbox@lists.code.netlandish.com>; Fri, 14 Jun 2024 13:22:03 +0000 (UTC) Received: by mail-vk1-f179.google.com with SMTP id 71dfb90a1353d-4e7eadf3668so809597e0c.0 for <~petersanchez/public-inbox@lists.code.netlandish.com>; Fri, 14 Jun 2024 06:22:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=netlandish.com; s=google; t=1718371323; x=1718976123; darn=lists.code.netlandish.com; h=content-disposition:mime-version:message-id:subject:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=V3KBCkCcqjYHiE0OPVE5yy45OTOFb7JYnA7WaXtsJEI=; b=GBavplNJRiH+eHyz3r0KvFRcs5WZuRiHC8DuGSzCWQZPl1zw/lpNgIZZYh1vb1PCgv vvDtk6kNSHvRcmMnYYnDpGQlrId2hi4GFxq60Qd7zFQPgT9+SnLvuMuBdC8SaZwOmqg3 0JyDVct/I0R8EjzXoaHYmsjGdkW5Kr4bb1A+E= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1718371323; x=1718976123; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=V3KBCkCcqjYHiE0OPVE5yy45OTOFb7JYnA7WaXtsJEI=; b=nrT+Z+JRLNm5t19NC6SfiiH+mgOE+Wr2UDEuCcbPramB29gCGHJ4TuPdqUG84T/tYq yEPchpu/H1lk57c0PY6JyYuRTZ+yem/zDi1GTdhssEvCYPVhLuHZBNwQbdIWVny1Sul8 kUhHCuLfYq0xqqlRKftzJbrKjfKx7P4hV/N7U5vUrUCuIluxr+iypZzgC7x0B2wBP6iu YchFZ0jqvVRb4gYcnvfZkz7LJWagPEnSZxOwBFBkaagIEQdan8+EvdzBr9H2pWKh8cmL 2zcYJNkny/IPapkQ+0jgGjRIcn6ajJVWfIssHVB1d9//EOwSbYemIbSEepWbPBZbq44S Ofxg== X-Gm-Message-State: AOJu0YyJDZ5Ctw58PdjMlt56sCCn0wxUU63jmPyoKOMoqnka/nDmKCeI 0rfezdhRMOQ30D3sH1lLJJ6eoSCPZX5P9QUq9jlpidFOdanjLUzaLQfsTvyVqamQfdUocFPTBbA 95cWbag== X-Google-Smtp-Source: AGHT+IGmfBGpe4Kf1vQTooQeXRACXJBKSN51kFu117gs9me1sESdMJupcrQU7erQCfEyJKngL9p/Kw== X-Received: by 2002:a05:6122:1da2:b0:4eb:3aa:2d8f with SMTP id 71dfb90a1353d-4ee3df85d1dmr3019854e0c.6.1718371322651; Fri, 14 Jun 2024 06:22:02 -0700 (PDT) Received: from localhost ([186.77.204.38]) by smtp.gmail.com with ESMTPSA id 71dfb90a1353d-4ed3f1f71f4sm505080e0c.10.2024.06.14.06.22.01 for <~petersanchez/public-inbox@lists.code.netlandish.com> (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Jun 2024 06:22:01 -0700 (PDT) Date: Fri, 14 Jun 2024 07:22:00 -0600 From: Peter Sanchez To: ~petersanchez/public-inbox@lists.code.netlandish.com Subject: Security fix: django-impersonate 1.9.4 release Message-ID: X-PGP-Key: https://petersanchez.com/publickey.txt MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline I rushed out the 1.9.3 release and didn't realize I had made a mistake in forgetting to remove the `.format()` call when processing the `next` variable. Thank you, again, to Santos Gallegos for pointing this out. As a result I removed it and released version 1.9.4. Please update. https://pypi.org/project/django-impersonate/1.9.4/ https://hg.code.netlandish.com/~petersanchez/django-impersonate/rev/33cb8c77262a474869ab94bcb82c5446baf3c228 Apologies for this mix up. Honestly I just wasn't paying attention as I was slammed for time and trying to get this out asap. If anyone out there has any extra time to help support this project, it would be more than appreciated! Unfortunately my time for open source projects is very very limited. Thanks, Peter