From 59e479a405a95e5c54f712cecc1ecaa8318bead4035de6fe41a6cb2334979a37 Mon Sep 17 00:00:00 2001 From: Matej Cepl Date: Tue, 10 Aug 2021 04:45:47 +0000 Subject: [PATCH] Accepting request 911124 from home:fusionfuture:branches:devel:languages:python:Factory - Update to 3.8.11 * Security - bpo-44022 (boo#1189241): mod:http.client now avoids infinitely reading potential HTTP headers after a 100 Continue status response from the server. - bpo-43882: The presence of newline or tab characters in parts of a URL could allow some forms of attacks. Following the controlling specification for URLs defined by WHATWG urllib.parse() now removes ASCII newlines and tabs from URLs, preventing such attacks. - bpo-42800: Audit hooks are now fired for frame.f_code, traceback.tb_frame, and generator code/frame attribute access. * Core and Builtins - bpo-44070: No longer eagerly makes import filenames absolute, except for extension modules, which was introduced in 3.8.10. * Library - bpo-44061: Fix regression in previous release when calling pkgutil.iter_modules() with a list of pathlib.Path objects OBS-URL: https://build.opensuse.org/request/show/911124 OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:Factory/python38?expand=0&rev=77 --- Python-3.8.10.tar.xz | 3 --- Python-3.8.10.tar.xz.asc | 16 ---------------- Python-3.8.11.tar.xz | 3 +++ Python-3.8.11.tar.xz.asc | 16 ++++++++++++++++ python38.changes | 23 +++++++++++++++++++++++ python38.spec | 2 +- 6 files changed, 43 insertions(+), 20 deletions(-) delete mode 100644 Python-3.8.10.tar.xz delete mode 100644 Python-3.8.10.tar.xz.asc create mode 100644 Python-3.8.11.tar.xz create mode 100644 Python-3.8.11.tar.xz.asc diff --git a/Python-3.8.10.tar.xz b/Python-3.8.10.tar.xz deleted file mode 100644 index f2e1148..0000000 --- a/Python-3.8.10.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:6af24a66093dd840bcccf371d4044a3027e655cf24591ce26e48022bc79219d9 -size 18433456 diff --git a/Python-3.8.10.tar.xz.asc b/Python-3.8.10.tar.xz.asc deleted file mode 100644 index 41a4e29..0000000 --- a/Python-3.8.10.tar.xz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCgAdFiEE4/8oOcBIslwITevpsmmV4xAlBWgFAmCP0ScACgkQsmmV4xAl -BWgroBAAjg5MXDN3BHjiwrG2yj3VuF4sFaDIbls7V69bmatfADEFDIWpF1YrcS/m -xlgmzUe0VztLpnU+TnpZt6xMuaSjHwv8Gbh/0cN1jLJg8P0Ssv2FS4P7pcct/JG9 -OqhW8E0cm8Th3a+dGsDLatlppDrk/1RGl6ZXfdKHLVWANXXiJtN2BJdS6gVEATsq -PL0QB1dgwQ/AVlBuXwLTQNwV8UM/yFXuKNgNyZ/icLKCDjqZszc62552Zu2hoZ/0 -KiZDAQG3rIvYJdrn0TXDITaoUPmb5FQmLWh7kcdk6R7Gmks3YJzolfzFFlwpPBfs -ePgP741p11of9TlId/fVHgMtoV54JLznrcrSlBfOvxxK7Oid9g0WeuqM/IKa7IBy -n/a4mNZivESYHuLbt3O2rpVZfvfS4ao8JBPnWXWqF2sNmmciNJCMnUGqOKuDVWV2 -LiE/6v0vkDHw4GIwRvYXPwnguSzv4O5ltHhE6YKGaLDX+J7q2oYZX4kbUYY4Tbxy -8ANtf/WesIZN53TNjUn/62JvXpJe9UqxOC1Kzl2XSToTr0hll9K5TiS2VXch1Jgx -LVyqzNkORzTmvftooOw4SFLgJnBbwVMRP9r7qkmpKB1ATyGc1t7WliHW6vBfp18C -O337fYnSRXyxwJTt+Km3fER+al3XeJsC7eIGEk0iJDQfoq4xhEI= -=A5fV ------END PGP SIGNATURE----- diff --git a/Python-3.8.11.tar.xz b/Python-3.8.11.tar.xz new file mode 100644 index 0000000..9d1aa80 --- /dev/null +++ b/Python-3.8.11.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fb1a1114ebfe9e97199603c6083e20b236a0e007a2c51f29283ffb50c1420fb2 +size 18437648 diff --git a/Python-3.8.11.tar.xz.asc b/Python-3.8.11.tar.xz.asc new file mode 100644 index 0000000..3a69223 --- /dev/null +++ b/Python-3.8.11.tar.xz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEE4/8oOcBIslwITevpsmmV4xAlBWgFAmDZq2IACgkQsmmV4xAl +BWi57w/+NQXLn1ZoFPuESty4LEIc6Oa7WQrfzMUazzglfocM/0SK248LdIpMYA15 +tMgcI3H/YCuftg1Q9Zbij4bhY1SrwEH6mh8/l1M9RUFSQRjDB5TzibX9I1Qix1Tc +hCEl/dt1D6HwN/U8W8qv71lwz3gcSAT85zU8UTG8GdbPnrZRyjHq6vj1T5Os/N9u +pAfMob+pn8EkW8bxYldV3+514vlR2vYJUH/ZV3t+UzwiVGRJuh9cWEoH31hy4XQF +pJJX43Qh6aGQwwi1a4IFv3MhlKBT6G7SDgfaAd1LrkCAtFNOS/0CqLesItJHsdGQ +jTLVsAo9XQ5tRN3CpDZ10/UqMpFrtzRvdG0kB7cL29szqeVm1sqUlW7WyNKZJwia +8Q/8J+Od/Z30SAaGb7rVmW46ijAJr4QeXimanYZeiHEprQMOKhPz61mNYXtPHBV/ +G9J5OEIk5GIUrIumh2btAwzx5/L8NI+RJdTV8RD7z0TLHuDt7ExxcREfLMUY3dqf +0wul7/tQQLqvTZXYgQb0zyKpatGw+q89xYe7Eh0h4rkPO7WRJ0/pCaHP3DQZf3fy +D14pEVeUlK4+A6S31wKwE0wpZfK8p1m7Kl/l+tKSFhNl6sslo993wZCaBCbHjSnx +Jw0TuVLeoxR6smL/W/EEHPQ0dgG6IaEU8HC+iXFG6b3uuJdG/1Q= +=sO6f +-----END PGP SIGNATURE----- diff --git a/python38.changes b/python38.changes index 18b8bb5..e49f0de 100644 --- a/python38.changes +++ b/python38.changes @@ -1,3 +1,26 @@ +------------------------------------------------------------------- +Tue Aug 10 00:25:26 UTC 2021 - Fusion Future + +- Update to 3.8.11 + * Security + - bpo-44022 (boo#1189241): mod:http.client now avoids + infinitely reading potential HTTP headers after a 100 + Continue status response from the server. + - bpo-43882: The presence of newline or tab characters in parts + of a URL could allow some forms of attacks. + Following the controlling specification for URLs defined by + WHATWG urllib.parse() now removes ASCII newlines and tabs + from URLs, preventing such attacks. + - bpo-42800: Audit hooks are now fired for frame.f_code, + traceback.tb_frame, and generator code/frame attribute + access. + * Core and Builtins + - bpo-44070: No longer eagerly makes import filenames absolute, + except for extension modules, which was introduced in 3.8.10. + * Library + - bpo-44061: Fix regression in previous release when calling + pkgutil.iter_modules() with a list of pathlib.Path objects + ------------------------------------------------------------------- Mon Aug 2 12:35:43 UTC 2021 - Matej Cepl diff --git a/python38.spec b/python38.spec index 3870ad5..f297d45 100644 --- a/python38.spec +++ b/python38.spec @@ -87,7 +87,7 @@ %bcond_without profileopt %endif Name: %{python_pkg_name}%{psuffix} -Version: 3.8.10 +Version: 3.8.11 Release: 0 Summary: Python 3 Interpreter License: Python-2.0