
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
A package that allows you to utilize 12factor inspired environment variables to configure your Django application.
django-environ
is the Python package that allows you to use
Twelve-factor methodology <https://www.12factor.net/>
_ to configure your
Django application with environment variables.
.. -teaser-end-
For that, it gives you an easy way to configure Django application using environment variables obtained from an environment file and provided by the OS:
.. -code-begin-
.. code-block:: python
import environ import os
env = environ.Env( # set casting, default value DEBUG=(bool, False) )
BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(file)))
environ.Env.read_env(os.path.join(BASE_DIR, '.env'))
DEBUG = env('DEBUG')
SECRET_KEY = env('SECRET_KEY')
DATABASES = { # read os.environ['DATABASE_URL'] and raises # ImproperlyConfigured exception if not found # # The db() method is an alias for db_url(). 'default': env.db(),
# read os.environ['SQLITE_URL']
'extra': env.db_url(
'SQLITE_URL',
default='sqlite:////tmp/my-tmp-sqlite.db'
)
}
CACHES = { # Read os.environ['CACHE_URL'] and raises # ImproperlyConfigured exception if not found. # # The cache() method is an alias for cache_url(). 'default': env.cache(),
# read os.environ['REDIS_URL']
'redis': env.cache_url('REDIS_URL')
}
.. -overview-
The idea of this package is to unify a lot of packages that make the same stuff:
Take a string from os.environ
, parse and cast it to some of useful python
typed variables. To do that and to use the 12factor <https://www.12factor.net/>
_
approach, some connection strings are expressed as url, so this package can parse
it and return a urllib.parse.ParseResult
. These strings from os.environ
are loaded from a .env
file and filled in os.environ
with setdefault
method, to avoid to overwrite the real environ.
A similar approach is used in Two Scoops of Django <https://www.feldroy.com/books/two-scoops-of-django-3-x>
_
book and explained in 12factor-django <https://wellfire.co/learn/easier-12-factor-django>
_
article.
Using django-environ
you can stop to make a lot of unversioned
settings_*.py
to configure your app.
See cookiecutter-django <https://github.com/cookiecutter/cookiecutter-django>
_
for a concrete example on using with a django project.
Feature Support
os.environ
with .env file variablesenviron.FileAwareEnv
instead of environ.Env
).. -project-information-
django-environ
is released under the MIT / X11 License <https://choosealicense.com/licenses/mit/>
__,
its documentation lives at Read the Docs <https://django-environ.readthedocs.io/en/latest/>
,
the code on GitHub <https://github.com/joke2k/django-environ>
,
and the latest release on PyPI <https://pypi.org/project/django-environ/>
_.
It’s rigorously tested on Python 3.5+, and officially supports Django 1.11, 2.2, 3.0, 3.1, 3.2 and 4.0.
If you'd like to contribute to django-environ
you're most welcome!
.. -support-
Should you have any question, any remark, or if you find a bug, or if there is
something you can't do with the django-environ
, please
open an issue <https://github.com/joke2k/django-environ>
_.
If you would like to contribute to django-environ
, please take a look at the
current issues <https://github.com/joke2k/django-environ/issues>
_. If there is
a bug or feature that you want but it isn't listed, make an issue and work on it.
the repository <https://github.com/joke2k/django-environ>
_ on GitHub
to start making your changes to the develop branch (or branch off of it).Added +++++
#355 <https://github.com/joke2k/django-environ/pull/355>
_.#371 <https://github.com/joke2k/django-environ/issues/371>
_.#362 <https://github.com/joke2k/django-environ/issues/362>
_.Deprecated ++++++++++
Env.unicode()
is deprecated and will be removed in the next
major release. Use Env.str()
instead.Changed +++++++
ImproperlyConfigured
exception
#360 <https://github.com/joke2k/django-environ/issues/360>
_.Fixed +++++
_cast_urlstr
unquoting
#357 <https://github.com/joke2k/django-environ/issues/357>
_.#220 <https://github.com/joke2k/django-environ/issues/220>
_.environ.Path.__eq__()
to compare paths correctly
#86 <https://github.com/joke2k/django-environ/issues/86>
,
#197 <https://github.com/joke2k/django-environ/issues/197>
.Full changelog <https://django-environ.readthedocs.org/en/latest/changelog.html>
_.
If you discover a security vulnerability within django-environ
, please
send an e-mail to Serghei Iakovlev via egrep@protonmail.ch. All security
vulnerabilities will be promptly addressed.
django-environ
was initially created by Daniele Faraglia <https://github.com/joke2k>
_
and currently maintained by Serghei Iakovlev <https://github.com/sergeyklay/>
_.
A full list of contributors can be found in GitHub <https://github.com/joke2k/django-environ/graphs/contributors>
__.
The existence of django-environ
would have been impossible without these
projects:
rconradharris/envparse <https://github.com/rconradharris/envparse>
_jazzband/dj-database-url <https://github.com/jazzband/dj-database-url>
_migonzalvar/dj-email-url <https://github.com/migonzalvar/dj-email-url>
_ghickman/django-cache-url <https://github.com/ghickman/django-cache-url>
_dstufft/dj-search-url <https://github.com/dstufft/dj-search-url>
_julianwachholz/dj-config-url <https://github.com/julianwachholz/dj-config-url>
_nickstenning/honcho <https://github.com/nickstenning/honcho>
_rconradharris/envparse <https://github.com/rconradharris/envparse>
_FAQs
A package that allows you to utilize 12factor inspired environment variables to configure your Django application.
We found that django-environ-plus demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.