mirror of
https://github.com/pretix/pretix.git
synced 2026-05-14 16:44:06 +00:00
[SECURITY] Use defusedcsv for exports
This commit is contained in:
@@ -1,9 +1,9 @@
|
||||
import csv
|
||||
import io
|
||||
from collections import OrderedDict
|
||||
from decimal import Decimal
|
||||
|
||||
import pytz
|
||||
from defusedcsv import csv
|
||||
from django import forms
|
||||
from django.db.models import Sum
|
||||
from django.dispatch import receiver
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import csv
|
||||
import io
|
||||
|
||||
from defusedcsv import csv
|
||||
from django.conf import settings
|
||||
from django.contrib import messages
|
||||
from django.core.urlresolvers import resolve, reverse
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import csv
|
||||
import io
|
||||
from collections import OrderedDict
|
||||
|
||||
from defusedcsv import csv
|
||||
from django import forms
|
||||
from django.db.models.functions import Coalesce
|
||||
from django.utils.translation import ugettext as _, ugettext_lazy
|
||||
|
||||
@@ -39,3 +39,4 @@ chardet<3.1.0,>=3.0.2
|
||||
mt-940==3.2
|
||||
vobject==0.9.*
|
||||
pycountry
|
||||
defusedcsv>=1.0.1
|
||||
|
||||
@@ -100,7 +100,8 @@ setup(
|
||||
'mt-940==4.7',
|
||||
'django-i18nfield>=1.0.1',
|
||||
'vobject==0.9.*',
|
||||
'pycountry'
|
||||
'pycountry',
|
||||
'defusedcsv'
|
||||
],
|
||||
extras_require={
|
||||
'dev': [
|
||||
|
||||
Reference in New Issue
Block a user