Commit Graph

  • 8b786ccb53 Update to 3.13.11 factory/devel Matěj Cepl 2025-12-19 18:36:21 +01:00
  • b020ec1b9b chore: remove files which should be deleted, but they were not factory/base Matěj Cepl 2025-11-23 02:11:04 +01:00
  • 6807e0fac4 Add pass-test_write_read_limited_history.patch: Fix readline history truncation when length is reduced Matěj Cepl 2025-11-20 00:40:25 +01:00
  • a8f3f2707f Add CVE-2025-6075-expandvars-perf-degrad.patch avoid simple quadratic complexity vulnerabilities of os.path.expandvars() (CVE-2025-6075, bsc#1252974). Matěj Cepl 2025-11-14 01:47:34 +01:00
  • 02c7c3ac57 Add CVE-2025-8291-consistency-zip64.patch Matěj Cepl 2025-11-04 17:47:42 +01:00
  • 1b4b152007 Merge remote-tracking branch 'suse/slfo-1.2' into factory Matěj Cepl 2025-11-20 22:58:40 +01:00
  • 6823a127f7 Merge branch 'main' into main_3139 Matěj Cepl 2025-11-04 17:04:03 +01:00
  • 8490c35b5e Accepting request 1311758 from devel:languages:python:Factory Ana Guerrero 2025-10-17 15:25:33 +00:00
  • 216aee44d2 Accepting request 1311480 from home:dgarcia:branches:devel:languages:python:Factory Matej Cepl 2025-10-16 16:27:11 +00:00
  • 5c7e077e05 Accepting request 1307951 from devel:languages:python:Factory Ana Guerrero 2025-10-01 16:55:40 +00:00
  • 6ccfd57cb6 Accepting request 1307678 from home:dgarcia:branches:devel:languages:python:Factory Matej Cepl 2025-09-29 16:57:25 +00:00
  • f26b5dd668 Accepting request 1306530 from devel:languages:python:Factory Ana Guerrero 2025-09-23 14:05:25 +00:00
  • 97f2e50954 Accepting request 1306454 from home:dimstar:Factory Markéta Machová 2025-09-22 12:45:38 +00:00
  • d782ad00ca - Require AppStream to validate appdata file instead of deprecated appstream-glib. - Update idle3.appdata.xml to pass the more pedantic appstreamcli. Matej Cepl 2025-09-18 14:05:23 +00:00
  • b40f1d6405 Accepting request 1304230 from devel:languages:python:Factory Ana Guerrero 2025-09-14 16:49:35 +00:00
  • 45ae9e0091 Accepting request 1303343 from home:dgarcia:branches:devel:languages:python:Factory Markéta Machová 2025-09-12 07:39:47 +00:00
  • 0f5697e310 Accepting request 1299833 from devel:languages:python:Factory Ana Guerrero 2025-08-21 14:47:12 +00:00
  • 3dc0e87868 Sync from SUSE:SLFO:Main python313 revision 1344033085c30612f3de7a4751d95c0c slfo-main slfo-1.2 Adrian Schröter 2025-08-19 16:39:27 +02:00
  • f819c56b57 - Update to 3.13.7: - gh-137583: Fix a deadlock introduced in 3.13.6 when a call to ssl.SSLSocket.recv was blocked in one thread, and then another method on the object (such as ssl.SSLSocket.send) was subsequently called in another thread. - gh-137044: Return large limit values as positive integers instead of negative integers in resource.getrlimit(). Accept large values and reject negative values (except RLIM_INFINITY) for limits in resource.setrlimit(). - gh-136914: Fix retrieval of doctest.DocTest.lineno for objects decorated with functools.cache() or functools.cached_property. - gh-131788: Make ResourceTracker.send from multiprocessing re-entrant safe - gh-136155: We are now checking for fatal errors in EPUB builds in CI. - gh-137400: Fix a crash in the free threading build when disabling profiling or tracing across all threads with PyEval_SetProfileAllThreads() or PyEval_SetTraceAllThreads() or their Python equivalents threading.settrace_all_threads() and threading.setprofile_all_threads(). - Remove upstreamed patch: - gh137583-only-lock-SSL-context.patch Matej Cepl 2025-08-15 12:33:36 +00:00
  • 6ca12749fe Accepting request 1299154 from home:mcepl:branches:devel:languages:python:Factory Matej Cepl 2025-08-12 22:07:14 +00:00
  • af83d0ea02 - Add gh137583-only-lock-SSL-context.patch fixing the regression in 3.13.6 by breaking non-blocking TLS connections (gh#python/cpython#137583). Matej Cepl 2025-08-12 09:37:56 +00:00
  • 588cd5ec7f declarations are automatically closed, tags are ignored (CVE-2025-6069, bsc#1244705). - Remove upstreamed patches: - CVE-2025-8194-tarfile-no-neg-offsets.patch - CVE-2025-6069-quad-complex-HTMLParser.patch Matej Cepl 2025-08-07 10:56:04 +00:00
  • 4a974dadae - Update to 3.13.6: Python 3.13.6 final Release date: 2025-08-06 - Tools/Demos - gh-135968: Stubs for strip are now provided as part of an iOS install. - Tests - gh-135966: The iOS testbed now handles the app_packages folder as a site directory. - gh-135494: Fix regrtest to support excluding tests from --pgo tests. Patch by Victor Stinner. - gh-135489: Show verbose output for failing tests during PGO profiling step with –enable-optimizations. - Security - gh-135661: Fix parsing start and end tags in html.parser.HTMLParser according to the HTML5 standard. - Whitespaces no longer accepted between </ and the tag name. E.g. </ script> does not end the script section. - Vertical tabulation (\v) and non-ASCII whitespaces no longer recognized as whitespaces. The only whitespaces are \t\n\r\f and space. - Null character (U+0000) no longer ends the tag name. - Attributes and slashes after the tag name in end tags are now ignored, instead of terminating after the first > in quoted attribute value. E.g. </script/foo=">"/>. - Multiple slashes and whitespaces between the last attribute and closing > are now ignored in both start and end tags. E.g. <a foo=bar/ //>. - Multiple = between attribute name and value are no longer collapsed. E.g. <a foo==bar> produces attribute Matej Cepl 2025-08-07 10:16:41 +00:00
  • 9a64481749 Accepting request 1297126 from devel:languages:python:Factory Dominique Leuenberger 2025-08-04 13:22:18 +00:00
  • c0f5d18c1e - Add CVE-2025-8194-tarfile-no-neg-offsets.patch which now validates archives to ensure member offsets are non-negative (gh#python/cpython#130577, CVE-2025-8194, bsc#1247249). Matej Cepl 2025-08-01 20:14:12 +00:00
  • 0c1f23a3d6 - Add CVE-2025-8194-tarfile-no-neg-offsets.patch which now validates archives to ensure member offsets are non-negative (gh#python/cpython#130577, CVE-2025-8194, bsc#1247249). Matej Cepl 2025-08-01 20:14:12 +00:00
  • 00d0af4ebb Accepting request 1294512 from devel:languages:python:Factory Ana Guerrero 2025-07-20 13:28:48 +00:00
  • 5ef0b0ecff Sync from SUSE:SLFO:Main python313 revision 13c51d6d24a5108bc9042a7d6fb5aeb4 Adrian Schröter 2025-07-18 11:40:31 +02:00
  • f1f4736355 - Fix gil/nogil package description, bsc#1246229 Daniel Garcia 2025-07-10 10:18:09 +00:00
  • 8fc89fce82 - Fix gil/nogil package description, bsc#1246229 Daniel Garcia 2025-07-10 10:18:09 +00:00
  • e51fa4e692 - Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705). Matej Cepl 2025-07-02 14:51:36 +00:00
  • 5584dde572 - Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705). Matej Cepl 2025-07-02 14:51:36 +00:00
  • da11e6e10a - Add bsc1243155-sphinx-non-determinism.patch (bsc#1243155) to generate ids for audit_events using docname (reproducible builds). Matej Cepl 2025-07-02 13:52:43 +00:00
  • b30cd19ff8 - Add bsc1243155-sphinx-non-determinism.patch (bsc#1243155) to generate ids for audit_events using docname (reproducible builds). Matej Cepl 2025-07-02 13:52:43 +00:00
  • a7efa91dcd - Use one core to build doc. This will make sphinx doc build reproducible. bsc#1243155 Matej Cepl 2025-07-02 11:27:27 +00:00
  • cb554c7d4c Accepting request 1289841 from home:dgarcia:branches:devel:languages:python:Factory Matej Cepl 2025-07-02 11:27:27 +00:00
  • 6fe6053eb5 Sync from SUSE:SLFO:Main python313 revision f3fded152e9ee7e3c3e8a86fe18815c2 Adrian Schröter 2025-06-27 16:00:14 +02:00
  • 92106b1aea Accepting request 1288597 from devel:languages:python:Factory Ana Guerrero 2025-06-26 09:38:02 +00:00
  • b58f975be7 Add link to bsc#1244061 to changelog. Matej Cepl 2025-06-25 19:43:42 +00:00
  • cf3b0e517c Add link to bsc#1244061 to changelog. Matej Cepl 2025-06-25 19:43:42 +00:00
  • f3df88065e Accepting request 1287762 from devel:languages:python:Factory Ana Guerrero 2025-06-24 18:45:07 +00:00
  • c7e438c2e0 - Substantially rewritten doc-py38-to-py36.patch patch to be more flexible and covering even unexpected changes. Matej Cepl 2025-06-22 19:29:14 +00:00
  • 7d8817d9bb - Substantially rewritten doc-py38-to-py36.patch patch to be more flexible and covering even unexpected changes. Matej Cepl 2025-06-22 19:29:14 +00:00
  • eb2298e3f2 - adjusted sofilename for "nogil" build correctly. Matej Cepl 2025-06-22 16:37:53 +00:00
  • 308dfaef9b Accepting request 1287576 from home:msmeissn:branches:devel:languages:python:Factory Matej Cepl 2025-06-22 16:37:53 +00:00
  • f9c64528f8 - Update to 3.13.5: - Tests - gh-135120: Add test.support.subTests(). - Library - gh-133967: Do not normalize locale name ‘C.UTF-8’ to ‘en_US.UTF-8’. - gh-135326: Restore support of integer-like objects with __index__() in random.getrandbits(). - gh-135321: Raise a correct exception for values greater than 0x7fffffff for the BINSTRING opcode in the C implementation of pickle. - gh-135276: Backported bugfixes in zipfile.Path from zipp 3.23. Fixed .name, .stem and other basename-based properties on Windows when working with a zipfile on disk. - gh-134151: email: Fix TypeError in email.utils.decode_params() when sorting RFC 2231 continuations that contain an unnumbered section. - gh-134152: email: Fix parsing of email message ID with invalid domain. - gh-127081: Fix libc thread safety issues with os by replacing getlogin with getlogin_r re-entrant version. - gh-131884: Fix formatting issues in json.dump() when both indent and skipkeys are used. - Core and Builtins - gh-135171: Roll back changes to generator and list comprehensions that went into 3.13.4 to fix gh-127682, but which involved semantic and bytecode changes not appropriate for a bugfix release. - C API - gh-134989: Fix Py_RETURN_NONE, Py_RETURN_TRUE and Matej Cepl 2025-06-11 22:06:33 +00:00
  • c2d30804e6 - Update to 3.13.5: - Tests - gh-135120: Add test.support.subTests(). - Library - gh-133967: Do not normalize locale name ‘C.UTF-8’ to ‘en_US.UTF-8’. - gh-135326: Restore support of integer-like objects with __index__() in random.getrandbits(). - gh-135321: Raise a correct exception for values greater than 0x7fffffff for the BINSTRING opcode in the C implementation of pickle. - gh-135276: Backported bugfixes in zipfile.Path from zipp 3.23. Fixed .name, .stem and other basename-based properties on Windows when working with a zipfile on disk. - gh-134151: email: Fix TypeError in email.utils.decode_params() when sorting RFC 2231 continuations that contain an unnumbered section. - gh-134152: email: Fix parsing of email message ID with invalid domain. - gh-127081: Fix libc thread safety issues with os by replacing getlogin with getlogin_r re-entrant version. - gh-131884: Fix formatting issues in json.dump() when both indent and skipkeys are used. - Core and Builtins - gh-135171: Roll back changes to generator and list comprehensions that went into 3.13.4 to fix gh-127682, but which involved semantic and bytecode changes not appropriate for a bugfix release. - C API - gh-134989: Fix Py_RETURN_NONE, Py_RETURN_TRUE and Matej Cepl 2025-06-11 22:06:33 +00:00
  • 3386fc12ed Add missing import Matej Cepl 2025-06-10 01:23:49 +00:00
  • 70558652fc Add missing import Matej Cepl 2025-06-10 01:23:49 +00:00
  • e8c68d65d4 - Update to 3.13.4: - Security - gh-135034: Fixes multiple issues that allowed tarfile extraction filters (filter="data" and filter="tar") to be bypassed using crafted symlinks and hard links. Addresses CVE-2024-12718 (bsc#1244056), CVE-2025-4138 (bsc#1244059), CVE-2025-4330 (bsc#1244060), and CVE-2025-4517 (bsc#1244032). - gh-133767: Fix use-after-free in the “unicode-escape” decoder with a non-“strict” error handler (CVE-2025-4516, bsc#1243273). - gh-128840: Short-circuit the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. - Library - gh-134718: ast.dump() now only omits None and [] values if they are default values. - gh-128840: Fix parsing long IPv6 addresses with embedded IPv4 address. - gh-134696: Built-in HACL* and OpenSSL implementations of hash function constructors now correctly accept the same documented named arguments. For instance, md5() could be previously invoked as md5(data=data) or md5(string=string) depending on the underlying implementation but these calls were not compatible. Patch by Bénédikt Tran. - gh-134210: curses.window.getch() now correctly handles signals. Patch by Bénédikt Tran. - gh-80334: multiprocessing.freeze_support() now checks for work on any “spawn” start method platform rather than only on Windows. Matej Cepl 2025-06-09 21:38:15 +00:00
  • 6072bbdbcd - Update to 3.13.4: - Security - gh-135034: Fixes multiple issues that allowed tarfile extraction filters (filter="data" and filter="tar") to be bypassed using crafted symlinks and hard links. Addresses CVE-2024-12718 (bsc#1244056), CVE-2025-4138 (bsc#1244059), CVE-2025-4330 (bsc#1244060), and CVE-2025-4517 (bsc#1244032). - gh-133767: Fix use-after-free in the “unicode-escape” decoder with a non-“strict” error handler (CVE-2025-4516, bsc#1243273). - gh-128840: Short-circuit the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. - Library - gh-134718: ast.dump() now only omits None and [] values if they are default values. - gh-128840: Fix parsing long IPv6 addresses with embedded IPv4 address. - gh-134696: Built-in HACL* and OpenSSL implementations of hash function constructors now correctly accept the same documented named arguments. For instance, md5() could be previously invoked as md5(data=data) or md5(string=string) depending on the underlying implementation but these calls were not compatible. Patch by Bénédikt Tran. - gh-134210: curses.window.getch() now correctly handles signals. Patch by Bénédikt Tran. - gh-80334: multiprocessing.freeze_support() now checks for work on any “spawn” start method platform rather than only on Windows. Matej Cepl 2025-06-09 21:38:15 +00:00
  • f5a88d357f Accepting request 1281135 from devel:languages:python:Factory Dominique Leuenberger 2025-06-01 19:36:01 +00:00
  • 96acb778b3 - Don't use %elif, it is supported only from rpm 4.15.0, which is not in SLE-15. Matej Cepl 2025-05-28 09:47:26 +00:00
  • 6d5d3f96b0 - Don't use %elif, it is supported only from rpm 4.15.0, which is not in SLE-15. Matej Cepl 2025-05-28 09:47:26 +00:00
  • b8ba5ea90c Sync from SUSE:SLFO:Main python313 revision 383b9a75c226d18ca6d663c7a0c8c962 Adrian Schröter 2025-05-23 20:41:08 +02:00
  • 820434f8e4 Accepting request 1278136 from devel:languages:python:Factory Ana Guerrero 2025-05-23 12:26:37 +00:00
  • 8d20edb449 - Add CVE-2025-4516-DecodeError-handler.patch fixing CVE-2025-4516 (bsc#1243273) blocking DecodeError handling vulnerability, which could lead to DoS. Matej Cepl 2025-05-17 07:34:05 +00:00
  • 487ae82f04 - Add CVE-2025-4516-DecodeError-handler.patch fixing CVE-2025-4516 (bsc#1243273) blocking DecodeError handling vulnerability, which could lead to DoS. Matej Cepl 2025-05-17 07:34:05 +00:00
  • 55fb9cd905 Accepting request 1276664 from devel:languages:python:Factory Ana Guerrero 2025-05-13 18:05:26 +00:00
  • 64bae1f84b - Remove python-3.3.0b1-test-posix_fadvise.patch (not needed since kernel 3.6-rc1) Matej Cepl 2025-05-10 11:43:36 +00:00
  • d8af743464 - Remove python-3.3.0b1-test-posix_fadvise.patch (not needed since kernel 3.6-rc1) Matej Cepl 2025-05-10 11:43:36 +00:00
  • c1d8c54913 Accepting request 1270150 from devel:languages:python:Factory Ana Guerrero 2025-04-25 20:17:50 +00:00
  • 82f875fb14 Sync from SUSE:SLFO:Main python313 revision 5d4062f27189f9d44beb46048ef6cfe5 Adrian Schröter 2025-04-25 01:03:29 +02:00
  • 201e349852 This Matej Cepl 2025-04-16 07:52:47 +00:00
  • bb17c93a2a This Matej Cepl 2025-04-16 07:52:47 +00:00
  • a90f4e560b Fix patches Matej Cepl 2025-04-16 07:17:38 +00:00
  • 55167f91bd Fix patches Matej Cepl 2025-04-16 07:17:38 +00:00
  • 0f47302d79 - Add gh-126500-test_ssl-no-stop-ThreadedEchoServer-OSError.patch and gh-127257-ssl-OSError-ERR_LIB_SYS.patch to make the interpreter compatible with OpenSSL 3.5 (bsc#1241067). Matej Cepl 2025-04-16 07:15:35 +00:00
  • b91bbdde1b - Add gh-126500-test_ssl-no-stop-ThreadedEchoServer-OSError.patch and gh-127257-ssl-OSError-ERR_LIB_SYS.patch to make the interpreter compatible with OpenSSL 3.5 (bsc#1241067). Matej Cepl 2025-04-16 07:15:35 +00:00
  • 24d06dc05c - Add gh-132535-rsrc-warn-test_timeout.patch to fix failing tests in the build system without network access (gh#python/cpython#132535). Matej Cepl 2025-04-15 22:19:57 +00:00
  • 384d0f4194 - Add gh-132535-rsrc-warn-test_timeout.patch to fix failing tests in the build system without network access (gh#python/cpython#132535). Matej Cepl 2025-04-15 22:19:57 +00:00
  • 3837884001 - Add gh126985-mv-pyvenv.cfg2getpath.patch to remove failing tests in test_sysconfig. Matej Cepl 2025-04-15 14:09:42 +00:00
  • 9e2287fa69 - Add gh126985-mv-pyvenv.cfg2getpath.patch to remove failing tests in test_sysconfig. Matej Cepl 2025-04-15 14:09:42 +00:00
  • a23dbf9cdf - Update to 3.13.3: - Tools/Demos - gh-131852: msgfmt no longer adds the POT-Creation-Date to generated .mo files for consistency with GNU msgfmt. - gh-85012: Correctly reset msgctxt when compiling messages in msgfmt. - gh-130025: The iOS testbed now correctly handles symlinks used as Python framework references. - Tests - gh-131050: test_ssl.test_dh_params is skipped if the underlying TLS library does not support finite-field ephemeral Diffie-Hellman. - gh-129200: Multiple iOS testbed runners can now be started at the same time without introducing an ambiguity over simulator ownership. - gh-130292: The iOS testbed will now run successfully on a machine that has not previously run Xcode tests (such as CI configurations). - gh-130293: The tests of terminal colorization are no longer sensitive to the value of the TERM variable in the testing environment. - gh-126332: Add unit tests for pyrepl. - Security - gh-131809: Update bundled libexpat to 2.7.1 - gh-131261: Upgrade to libexpat 2.7.0 - gh-127371: Avoid unbounded buffering for tempfile.SpooledTemporaryFile.writelines(). Previously, disk spillover was only checked after the lines iterator had been exhausted. This is now done after each line is written. Matej Cepl 2025-04-11 19:56:43 +00:00
  • 9624a1ae7e - Update to 3.13.3: - Tools/Demos - gh-131852: msgfmt no longer adds the POT-Creation-Date to generated .mo files for consistency with GNU msgfmt. - gh-85012: Correctly reset msgctxt when compiling messages in msgfmt. - gh-130025: The iOS testbed now correctly handles symlinks used as Python framework references. - Tests - gh-131050: test_ssl.test_dh_params is skipped if the underlying TLS library does not support finite-field ephemeral Diffie-Hellman. - gh-129200: Multiple iOS testbed runners can now be started at the same time without introducing an ambiguity over simulator ownership. - gh-130292: The iOS testbed will now run successfully on a machine that has not previously run Xcode tests (such as CI configurations). - gh-130293: The tests of terminal colorization are no longer sensitive to the value of the TERM variable in the testing environment. - gh-126332: Add unit tests for pyrepl. - Security - gh-131809: Update bundled libexpat to 2.7.1 - gh-131261: Upgrade to libexpat 2.7.0 - gh-127371: Avoid unbounded buffering for tempfile.SpooledTemporaryFile.writelines(). Previously, disk spillover was only checked after the lines iterator had been exhausted. This is now done after each line is written. Matej Cepl 2025-04-11 19:56:43 +00:00
  • 208ac0bda6 revert Matej Cepl 2025-04-11 06:10:15 +00:00
  • 415df5f3cd Accepting request 1268534 from devel:languages:python:Factory Matej Cepl 2025-04-11 06:10:15 +00:00
  • 1a9b96ab31 Sync from SUSE:SLFO:Main python313 revision d0dfd4215089a37af0ae2e0812cb62c5 Adrian Schröter 2025-03-21 10:53:19 +01:00
  • 88b70a09e9 - don't require rpm-build-python for base to fix bootstrap issue after primary_python change - replace rpm-build-python alias with python-rpm-packaging package name Matej Cepl 2025-03-14 22:57:44 +00:00
  • 3467717953 Accepting request 1253127 from devel:LoongArch:Factory Matej Cepl 2025-03-14 22:57:44 +00:00
  • 1ea8708b8d Accepting request 1251953 from devel:languages:python:Factory Ana Guerrero 2025-03-12 14:19:55 +00:00
  • 3bce06d06a Fix bug reference in the changelog Matej Cepl 2025-03-11 06:50:29 +00:00
  • 1e079c98aa Fix bug reference in the changelog Matej Cepl 2025-03-11 06:15:52 +00:00
  • 347e286045 - Skip PGO with %want_reproducible_builds (boo#1040589) Matej Cepl 2025-03-10 18:35:58 +00:00
  • 279fe75cee Accepting request 1250305 from devel:languages:python:Factory Ana Guerrero 2025-03-06 13:47:53 +00:00
  • d6f4df3c91 Accepting request 1250070 from home:dgarcia:branches:devel:languages:python:Factory Markéta Machová 2025-03-05 06:27:41 +00:00
  • d4d0782687 Sync from SUSE:SLFO:Main python313 revision 3a4e5c994aa27bd66e968be481da9eb4 Adrian Schröter 2025-02-25 19:38:36 +01:00
  • 7d140c532a Accepting request 1243939 from devel:languages:python:Factory Dominique Leuenberger 2025-02-09 18:58:56 +00:00
  • 875a6f6235 - Add doc-py38-to-py36.patch to make documentation buildable on SLE with older Sphinx. Matej Cepl 2025-02-05 16:42:08 +00:00
  • c596c85ff5 - Update to 3.13.2: - Tools/Demos - gh-128152: Fix a bug where Argument Clinic’s C pre-processor parser tried to parse pre-processor directives inside C comments. Patch by Erlend Aasland. - Tests - gh-127906: Test the limited C API in test_cppext. Patch by Victor Stinner. - gh-127637: Add tests for the dis command-line interface. Patch by Bénédikt Tran. - gh-126925: iOS test results are now streamed during test execution, and the deprecated xcresulttool is no longer used. - Security - gh-105704: When using urllib.parse.urlsplit() and urllib.parse.urlparse() host parsing would not reject domain names containing square brackets ([ and ]). Square brackets are only valid for IPv6 and IPvFuture hosts according to RFC 3986 Section 3.2.2. (CVE-2025-0938, bsc#1236705) - gh-127655: Fixed the asyncio.selector_events._SelectorSocketTransport transport not pausing writes for the protocol when the buffer reaches the high water mark when using asyncio.WriteTransport.writelines() (CVE-2024-12254, bsc#1234290). - gh-126108: Fix a possible NULL pointer dereference in PySys_AddWarnOptionUnicode(). - gh-80222: Fix bug in the folding of quoted strings when flattening an email message using a modern email Matej Cepl 2025-02-05 09:57:45 +00:00
  • 5c3c7cecd2 Accepting request 1241509 from devel:languages:python:Factory Ana Guerrero 2025-02-03 20:40:34 +00:00
  • dfcfb5ce90 Accepting request 1240511 from home:dgarcia:branches:devel:languages:python:Factory Matej Cepl 2025-01-30 17:35:22 +00:00
  • 528339bd34 Accepting request 1228971 from devel:languages:python:Factory Ana Guerrero 2025-01-23 16:57:00 +00:00
  • 1faa76760c Sync from SUSE:SLFO:Main python313 revision 3939dadd6bf1a800644b15d384da5806 Adrian Schröter 2024-12-20 16:09:47 +01:00
  • d4f884437e - Add CVE-2024-12254-unbound-mem-buffering-SelectorSocketTransport.writelines.patch preventing exhaustion of memory (gh#python/cpython#127655, bsc#1234290, CVE-2024-12254). Matej Cepl 2024-12-06 20:46:56 +00:00
  • ecf4d377f8 Update patches Matej Cepl 2024-12-06 13:01:45 +00:00
  • d6003ec835 - Update to 3.13.1: - Tools/Demos - gh-126807: Fix extraction warnings in pygettext.py caused by mistaking function definitions for function calls. - gh-126167: The iOS testbed was modified so that it can be used by third-party projects for testing purposes. - Tests - gh-126909: Fix test_os extended attribute tests to work on filesystems with 1 KiB xattr size limit. - gh-125041: Re-enable skipped tests for zlib on the s390x architecture: only skip checks of the compressed bytes, which can be different between zlib’s software implementation and the hardware-accelerated implementation. - gh-124295: Add translation tests to the argparse module. - Security - gh-126623: Upgrade libexpat to 2.6.4 - gh-125140: Remove the current directory from sys.path when using PyREPL. - gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and is_unspecified. - Library - gh-127321: pdb.set_trace() will not stop at an opcode that does not have an associated line number anymore. - gh-127303: Publicly expose EXACT_TOKEN_TYPES in token.__all__. - gh-123967: Fix faulthandler for trampoline frames. If the top-most frame is a trampoline frame, skip it. Patch by Matej Cepl 2024-12-04 22:01:51 +00:00
  • b7339fbd1a Sync from SUSE:SLFO:Main python313 revision 8e47fdd964e0cf538aa6655838a42add Adrian Schröter 2024-12-04 09:25:36 +01:00
  • adc199414a Accepting request 1227320 from devel:languages:python:Factory Ana Guerrero 2024-11-30 12:27:29 +00:00
  • 64423e0ba5 Accepting request 1227315 from home:dgarcia:branches:devel:languages:python:Factory Daniel Garcia 2024-11-29 12:38:51 +00:00