Mailing List Archive

Upcoming 3.7.10 and 3.6.13 Security Releases
We are planning to produce the next security-fix rollup releases for Python 3.7.x and 3.6.x on 2021-01-15. The most recent releases for these versions were on 2020-08-17. There has not been a lot of activity for either branch since then.

Core developers: if you know of any additional security issues that should be addressed in these releases, please mark the relevant bpo issues as "release blocker" and, if possible, submit PRs for review prior to the end of 2021-01-14 AOE.

Thanks!

--
Ned Deily
nad@python.org -- []
Re: Upcoming 3.7.10 and 3.6.13 Security Releases [ In reply to ]
On 10. 01. 21 21:15, Ned Deily wrote:
> We are planning to produce the next security-fix rollup releases for Python 3.7.x and 3.6.x on 2021-01-15. The most recent releases for these versions were on 2020-08-17. There has not been a lot of activity for either branch since then.
>
> Core developers: if you know of any additional security issues that should be addressed in these releases, please mark the relevant bpo issues as "release blocker" and, if possible, submit PRs for review prior to the end of 2021-01-14 AOE.

Hi Ned. I am not a core developer, but can https://bugs.python.org/issue42938
please be included? I know it is past the deadline, but I have not seen the
releases.

Thanks,
--
Miro Hron?ok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
Python-Dev mailing list -- python-dev@python.org
To unsubscribe send an email to python-dev-leave@python.org
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at https://mail.python.org/archives/list/python-dev@python.org/message/JUJAS2O2DY3TUPITDY7VQYEZXDVVMV7N/
Code of Conduct: http://python.org/psf/codeofconduct/
Re: Upcoming 3.7.10 and 3.6.13 Security Releases [ In reply to ]
On 20/01/2021 13.06, Miro Hron?ok wrote:
> On 10. 01. 21 21:15, Ned Deily wrote:
>> We are planning to produce the next security-fix rollup releases for
>> Python 3.7.x and 3.6.x on 2021-01-15. The most recent releases for
>> these versions were on 2020-08-17.  There has not been a lot of
>> activity for either branch since then.
>>
>> Core developers: if you know of any additional security issues that
>> should be addressed in these releases, please mark the relevant bpo
>> issues as "release blocker" and, if possible, submit PRs for review
>> prior to the end of 2021-01-14 AOE.
>
> Hi Ned. I am not a core developer, but can
> https://bugs.python.org/issue42938 please be included? I know it is past
> the deadline, but I have not seen the releases.

Ned has postponed the upcoming security releases for the issue.
Benjamin's fix has landed two days ago. The fixes will be included in
3.7.10 and 3.6.13.

Christian
_______________________________________________
Python-Dev mailing list -- python-dev@python.org
To unsubscribe send an email to python-dev-leave@python.org
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at https://mail.python.org/archives/list/python-dev@python.org/message/EMSDC5PS5EU2W77SRJAON4BOHNCD7N76/
Code of Conduct: http://python.org/psf/codeofconduct/
Re: Upcoming 3.7.10 and 3.6.13 Security Releases [ In reply to ]
On 20. 01. 21 13:43, Christian Heimes wrote:
> On 20/01/2021 13.06, Miro Hron?ok wrote:
>> On 10. 01. 21 21:15, Ned Deily wrote:
>>> We are planning to produce the next security-fix rollup releases for
>>> Python 3.7.x and 3.6.x on 2021-01-15. The most recent releases for
>>> these versions were on 2020-08-17.  There has not been a lot of
>>> activity for either branch since then.
>>>
>>> Core developers: if you know of any additional security issues that
>>> should be addressed in these releases, please mark the relevant bpo
>>> issues as "release blocker" and, if possible, submit PRs for review
>>> prior to the end of 2021-01-14 AOE.
>>
>> Hi Ned. I am not a core developer, but can
>> https://bugs.python.org/issue42938 please be included? I know it is past
>> the deadline, but I have not seen the releases.
>
> Ned has postponed the upcoming security releases for the issue.
> Benjamin's fix has landed two days ago. The fixes will be included in
> 3.7.10 and 3.6.13.

Thanks!

--
Miro Hron?ok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
Python-Dev mailing list -- python-dev@python.org
To unsubscribe send an email to python-dev-leave@python.org
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at https://mail.python.org/archives/list/python-dev@python.org/message/T544X74NME4BP2OFROK6UXQGRBPJVSL5/
Code of Conduct: http://python.org/psf/codeofconduct/
Re: Upcoming 3.7.10 and 3.6.13 Security Releases [ In reply to ]
On Jan 20, 2021, at 08:17, Miro Hron?ok <mhroncok@redhat.com> wrote:
> On 20. 01. 21 13:43, Christian Heimes wrote:
>> On 20/01/2021 13.06, Miro Hron?ok wrote:
>>> On 10. 01. 21 21:15, Ned Deily wrote:
>>>> We are planning to produce the next security-fix rollup releases for
>>>> Python 3.7.x and 3.6.x on 2021-01-15. The most recent releases for
>>>> these versions were on 2020-08-17. There has not been a lot of
>>>> activity for either branch since then.
>>>>
>>>> Core developers: if you know of any additional security issues that
>>>> should be addressed in these releases, please mark the relevant bpo
>>>> issues as "release blocker" and, if possible, submit PRs for review
>>>> prior to the end of 2021-01-14 AOE.
>>>
>>> Hi Ned. I am not a core developer, but can
>>> https://bugs.python.org/issue42938 please be included? I know it is past
>>> the deadline, but I have not seen the releases.
>> Ned has postponed the upcoming security releases for the issue.
>> Benjamin's fix has landed two days ago. The fixes will be included in
>> 3.7.10 and 3.6.13.

Thanks, Christian, that's correct.

In the meantime, another potential security issue has arisen that might impact 3.7 and 3.6 so I'm going to continue to hold off on the releases until we have a resolution of that.

https://bugs.python.org/issue42967

--
Ned Deily
nad@python.org -- []
_______________________________________________
Python-Dev mailing list -- python-dev@python.org
To unsubscribe send an email to python-dev-leave@python.org
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at https://mail.python.org/archives/list/python-dev@python.org/message/D47G5BO6B6SRPZ3QPTP6ZCUZRCQSRPBC/
Code of Conduct: http://python.org/psf/codeofconduct/
Re: Upcoming 3.7.10 and 3.6.13 Security Releases [ In reply to ]
On Wed, Jan 20, 2021 at 7:22 PM Ned Deily <nad@python.org> wrote:

>
>
> In the meantime, another potential security issue has arisen that might
> impact 3.7 and 3.6 so I'm going to continue to hold off on the releases
> until we have a resolution of that.
>
> https://bugs.python.org/issue42967
>
>
And another security issue was brought up to our attention here (today):

https://bugs.python.org/issue42987
Re: Upcoming 3.7.10 and 3.6.13 Security Releases [ In reply to ]
On Thu, Jan 21, 2021 at 5:09 AM Senthil Kumaran <senthil@uthcode.com> wrote:
> And another security issue was brought up to our attention here (today):
> https://bugs.python.org/issue42987

This one was already fixed (the issue is closed).

Victor
--
Night gathers, and now my watch begins. It shall not end until my death.
_______________________________________________
Python-Dev mailing list -- python-dev@python.org
To unsubscribe send an email to python-dev-leave@python.org
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at https://mail.python.org/archives/list/python-dev@python.org/message/SYPPDTQESDXOFS6OB27QONBJSPUOX4YX/
Code of Conduct: http://python.org/psf/codeofconduct/