Go to file
Peter Korsgaard f25ad2f317 package/python-django: security bump to version 3.0.10
Fixes the following security issues:

CVE-2020-24583: Incorrect permissions on intermediate-level directories on Python 3.7+
On Python 3.7+, FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to
intermediate-level directories created in the process of uploading files and
to intermediate-level collected static directories when using the
collectstatic management command.

You should review and manually fix permissions on existing
intermediate-level directories.

CVE-2020-24584: Permission escalation in intermediate-level directories of
the file system cache on Python 3.7+
On Python 3.7+, the intermediate-level directories of the file system cache
had the system’s standard umask rather than 0o077 (no group or others
permissions).

https://docs.djangoproject.com/en/dev/releases/3.0.10/

In addition, 3.0.8..10 contains a number of bugfixes.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit eaefa775ed)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2020-09-05 09:40:26 +02:00
arch arch/x86: adds BR2_X86_CPU_HAS_3DNOW flag 2020-07-16 18:19:11 +02:00
board board/raspberrypi: fix rpi4/rpi4-64 genimage config files 2020-07-22 09:06:20 +02:00
boot boot/uboot: Fix kconfig to use $(BR2_MAKE) 2020-08-28 16:54:20 +02:00
configs configs/raspberrypi{3, 4}_64: enabling BR2_LINUX_KERNEL_DTB_OVERLAY_SUPPORT no longer needed 2020-05-16 21:41:16 +02:00
docs docs/manual/adding-packages-cargo.txt: drop debug profile 2020-08-28 19:07:38 +02:00
fs fs/cpio/init: unbreak ttyname_r() on glibc after dropping /dev/console exec 2020-08-29 19:40:45 +02:00
linux linux: run depmod only if modules directory exists 2020-08-29 19:42:17 +02:00
package package/python-django: security bump to version 3.0.10 2020-09-05 09:40:26 +02:00
support support/scripts/pkg-stats: drop erroneous "break" in CVE.affects() 2020-08-28 19:29:42 +02:00
system package/systemd: make sure init choice and package have same dependencies 2020-04-05 20:33:36 +02:00
toolchain toolchain/toolchain-wrapper: let recent GCC handle SOURCE_DATE_EPOCH 2020-07-16 18:32:17 +02:00
utils utils/scanpypi: use raw strings in re.compile/re.sub 2020-08-28 18:34:34 +02:00
.defconfig
.flake8 .flake8: fix check for 80/132 columns 2019-04-10 12:31:33 +02:00
.gitignore
.gitlab-ci.yml gitlab-ci: convert only/except to rules 2020-08-13 11:44:11 +02:00
.gitlab-ci.yml.in gitlab-ci: convert only/except to rules 2020-08-13 11:44:11 +02:00
CHANGES Update for 2020.05.2 2020-08-29 20:22:09 +02:00
Config.in Config.in: update BR2_OPTIMIZE_FAST prompt and help text 2020-07-22 13:38:46 +02:00
Config.in.legacy package/wiringpi: remove 2020-05-25 22:48:44 +02:00
COPYING
DEVELOPERS DEVELOPERS: drop Maxime Ripard from kmsxx maintainers 2020-08-28 18:38:32 +02:00
Makefile Update for 2020.05.2 2020-08-29 20:22:09 +02:00
Makefile.legacy Remove BR2_DEPRECATED 2016-10-15 23:14:45 +02:00
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches