From 2dc12f9e904942f8f5ef9baf5263caddf40f347a Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Thu, 4 Jun 2026 01:05:02 +0200 Subject: [PATCH 1/3] python3Packages.django_6: 6.0.5 -> 6.0.6 https://docs.djangoproject.com/en/6.0/releases/6.0.6/ https://www.djangoproject.com/weblog/2026/jun/03/security-releases/ Fixes: CVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193, CVE-2026-48587 --- pkgs/development/python-modules/django/6.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix index 38c746fb5718..c223a4ac8594 100644 --- a/pkgs/development/python-modules/django/6.nix +++ b/pkgs/development/python-modules/django/6.nix @@ -42,7 +42,7 @@ buildPythonPackage (finalAttrs: { pname = "django"; - version = "6.0.5"; + version = "6.0.6"; pyproject = true; disabled = pythonOlder "3.12"; @@ -51,7 +51,7 @@ buildPythonPackage (finalAttrs: { owner = "django"; repo = "django"; tag = finalAttrs.version; - hash = "sha256-jII/aoJ75sS+ig4iVZmTcsEE76aC8Om/k2J+LnRj+cE="; + hash = "sha256-hLnTqY64PfaGJ1JJccrxYms41Jp4E4pVq6rmrtFpESE="; }; patches = [ From d8bfa3584308fe5579c14bba2e9e8335bff667b8 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Thu, 4 Jun 2026 13:53:49 +0200 Subject: [PATCH 2/3] python3Packages.django-formtools: disable failing test --- pkgs/development/python-modules/django-formtools/default.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/python-modules/django-formtools/default.nix b/pkgs/development/python-modules/django-formtools/default.nix index 3b38956a7fd6..c4b1afd38033 100644 --- a/pkgs/development/python-modules/django-formtools/default.nix +++ b/pkgs/development/python-modules/django-formtools/default.nix @@ -40,6 +40,9 @@ buildPythonPackage (finalAttrs: { disabledTests = [ # mismatch between test collection of django and pytest-django "TestStorage" + # Django 6.0.6/5.2.15 compat issue + # https://github.com/jazzband/django-formtools/issues/298 + "test_reset_cookie" ]; pythonImportsCheck = [ "formtools" ]; From 83f160689f4ba180768712599743d64d0ec2554a Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Thu, 4 Jun 2026 14:29:33 +0200 Subject: [PATCH 3/3] python3Packages.django_6: fix flaky test on aarch64-linux --- pkgs/development/python-modules/django/6.nix | 3 ++ .../6.x/invalidate-importlib-cache.patch | 54 +++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 pkgs/development/python-modules/django/6.x/invalidate-importlib-cache.patch diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix index c223a4ac8594..4b6e54569b85 100644 --- a/pkgs/development/python-modules/django/6.nix +++ b/pkgs/development/python-modules/django/6.nix @@ -62,6 +62,9 @@ buildPythonPackage (finalAttrs: { ./6.x/pythonpath.patch # test_incorrect_timezone should raise but doesn't ./6.x/disable-failing-test.patch + # https://code.djangoproject.com/ticket/36997 + # https://github.com/django/django/pull/21019 + ./6.x/invalidate-importlib-cache.patch ] ++ lib.optionals withGdal [ (replaceVars ./6.x/gdal.patch { diff --git a/pkgs/development/python-modules/django/6.x/invalidate-importlib-cache.patch b/pkgs/development/python-modules/django/6.x/invalidate-importlib-cache.patch new file mode 100644 index 000000000000..910b6477cd32 --- /dev/null +++ b/pkgs/development/python-modules/django/6.x/invalidate-importlib-cache.patch @@ -0,0 +1,54 @@ +From 130ccbf51a5ad4810dcef46584661a818b7964d3 Mon Sep 17 00:00:00 2001 +From: gghezext +Date: Sun, 29 Mar 2026 03:46:48 +0200 +Subject: [PATCH 1/2] Fixed #36997 -- Invalidated importlib caches after + writing migration files. + +--- + django/core/management/commands/makemigrations.py | 3 +++ + django/core/management/commands/squashmigrations.py | 2 ++ + docs/releases/6.1.txt | 5 ++++- + 3 files changed, 9 insertions(+), 1 deletion(-) + +diff --git a/django/core/management/commands/makemigrations.py b/django/core/management/commands/makemigrations.py +index 7f711ed7aec4..355d626ce2c4 100644 +--- a/django/core/management/commands/makemigrations.py ++++ b/django/core/management/commands/makemigrations.py +@@ -1,3 +1,4 @@ ++import importlib + import os + import sys + import warnings +@@ -395,6 +396,7 @@ def write_migration_files(self, changes, update_previous_migration_paths=None): + ) + self.log(writer.as_string()) + run_formatters(self.written_files, stderr=self.stderr) ++ importlib.invalidate_caches() + + @staticmethod + def get_relative_path(path): +@@ -502,6 +504,7 @@ def all_items_equal(seq): + with open(writer.path, "w", encoding="utf-8") as fh: + fh.write(writer.as_string()) + run_formatters([writer.path], stderr=self.stderr) ++ importlib.invalidate_caches() + if self.verbosity > 0: + self.log("\nCreated new merge migration %s" % writer.path) + if self.scriptable: +diff --git a/django/core/management/commands/squashmigrations.py b/django/core/management/commands/squashmigrations.py +index 9845b4d4567b..abc87717b66b 100644 +--- a/django/core/management/commands/squashmigrations.py ++++ b/django/core/management/commands/squashmigrations.py +@@ -1,3 +1,4 @@ ++import importlib + import os + import shutil + +@@ -208,6 +209,7 @@ def handle(self, **options): + with open(writer.path, "w", encoding="utf-8") as fh: + fh.write(writer.as_string()) + run_formatters([writer.path], stderr=self.stderr) ++ importlib.invalidate_caches() + + if self.verbosity > 0: + self.stdout.write(