---
title: "Django 1.9.8 リリースノート"
version: 6.1
locale: ja
source: https://docs.djangoproject.com/ja/6.1/releases/1.9.8/
canonical: https://djangodocs.dev/ja/6.1/releases/1.9.8/
---
# Django 1.9.8 リリースノート

*July 18, 2016*

Django 1.9.8 では、1.9.7 にあったセキュリティの問題といくつかのバグを修正しました。

## XSS in admin's add/change related popup

Unsafe usage of JavaScript's `Element.innerHTML` could result in XSS in the
admin's add/change related popup. `Element.textContent` is now used to
prevent execution of the data.

The debug view also used `innerHTML`. Although a security issue wasn't
identified there, out of an abundance of caution it's also updated to use
`textContent`.

## バグ修正

- Fixed missing `varchar/text_pattern_ops` index on `CharField` and
  `TextField` respectively when using `AddField` on PostgreSQL
  ([#26889](https://code.djangoproject.com/ticket/26889)).
- Python 2 で非 ASCII 文字列のファイル名を使うと `makemessages` がクラッシュする問題を修正 ([#26897](https://code.djangoproject.com/ticket/26897))。
