Skip to content

deps(backend): bump django from 5.1.4 to 6.0.5 in /backend in the django group across 1 directory#5

Merged
e-scheer merged 1 commit into
mainfrom
dependabot/pip/backend/django-5d083ea891
May 16, 2026
Merged

deps(backend): bump django from 5.1.4 to 6.0.5 in /backend in the django group across 1 directory#5
e-scheer merged 1 commit into
mainfrom
dependabot/pip/backend/django-5d083ea891

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 16, 2026

Bumps the django group with 1 update in the /backend directory: django.

Updates django from 5.1.4 to 6.0.5

Commits
  • 8f8ad09 [6.0.x] Bumped version for 6.0.5 release.
  • 44ad76e [6.0.x] Fixed CVE-2026-6907 -- Prevented caching of requests when Vary header...
  • 1b0184a [6.0.x] Fixed CVE-2026-35192 -- Ensured Vary header is sent when setting sess...
  • ad8f9e1 [6.0.x] Fixed CVE-2026-5766 -- Enforced DATA_UPLOAD_MAX_MEMORY_SIZE in Memory...
  • 990ab01 [6.0.x] Fixed #37039 -- Removed outdated note from QuerySet.iterator() docs.
  • f0c269f [6.0.x] Fixed typo in stub release notes for 5.2.14.
  • 8bcd15b [6.0.x] Fixed #37067 -- Added trailing slash in django_file_prefixes().
  • 3cdec64 [6.0.x] Refs CVE-2026-25674 -- Clarified role of umask in upload permissions.
  • 5dd5c70 [6.0.x] Added stub release notes and release date for 6.0.5 and 5.2.14.
  • 8ee7341 [6.0.x] Refs #373, #34122 -- Removed warning that ForeignObject is an interna...
  • Additional commits viewable in compare view

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 16, 2026

Labels

The following labels could not be found: backend, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps the django group with 1 update in the /backend directory: [django](https://github.com/django/django).


Updates `django` from 5.1.4 to 6.0.5
- [Commits](django/django@5.1.4...6.0.5)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 6.0.5
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: django
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps(backend): bump django from 5.1.4 to 6.0.5 in /backend in the django group deps(backend): bump django from 5.1.4 to 6.0.5 in /backend in the django group across 1 directory May 16, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/backend/django-5d083ea891 branch from 25d0e94 to a0f6ad9 Compare May 16, 2026 23:00
@e-scheer e-scheer merged commit bb95b6f into main May 16, 2026
4 checks passed
@e-scheer e-scheer deleted the dependabot/pip/backend/django-5d083ea891 branch May 16, 2026 23:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant