Skip to content

fix(security): bump Django 5.0.14 -> 5.1.15, certifi, django-csp#154

Open
thomasrockhu-codecov wants to merge 1 commit intomasterfrom
security/bump-django-certifi
Open

fix(security): bump Django 5.0.14 -> 5.1.15, certifi, django-csp#154
thomasrockhu-codecov wants to merge 1 commit intomasterfrom
security/bump-django-certifi

Conversation

@thomasrockhu-codecov
Copy link
Contributor

@thomasrockhu-codecov thomasrockhu-codecov commented Feb 25, 2026

Summary

  • Django 5.0.14 -> 5.1.15: Django 5.0 is EOL; 5.1.15 fixes CVE-2025-64459 and CVE-2026-1207
  • certifi 2024.7.4 -> 2025.1.31: updated CA certificate bundle
  • django-csp 3.7 -> 3.8: required for Django 5.1 compatibility

Issues

Test plan

  • CI passes
  • Verify Slack app boots correctly with Django 5.1
  • Verify django-csp 3.8 is compatible with existing CSP config
  • Smoke-test Slack bot interactions

Made with Cursor

- Django 5.0.14 -> 5.1.15: 5.0 is EOL, fixes CVE-2025-64459 and CVE-2026-1207
- certifi 2024.7.4 -> 2025.1.31: updated CA certificate bundle
- django-csp 3.7 -> 3.8: required for Django 5.1 compatibility

Made-with: Cursor
@thomasrockhu-codecov thomasrockhu-codecov marked this pull request as ready for review February 25, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants