Stimulus Tutorial: Moving & Animating Todos
https://onrails.blog/2024/03/18/stimulus-moving-and-animating-todos/
Howdy!
Those are the boring security releases that aren’t supposed to bring
anything new. But not this time! We do have a bit of news, actually. But
first things first: go update your systems!
Get it here: Python Release Python 3.10.14
26 commits since the last release.
Get it here: Python Release Python 3.9.19
26 commits since the last release.
Get it here: Python Release Python 3.8.19
28 commits since the last release.
zipfile is now protected from the “quoted-overlap” zipbomb to address CVE-2024-0450. It now raises BadZipFile when attempting to read an entry that overlaps with another entry or central directorytempfile.TemporaryDirectory cleanup no longer dereferences symlinks when working around file system permission errors to address CVE-2023-6597urllib.request no longer resolves the hostname before checking it against the system’s proxy bypass list on macOS and Windowssocket.if_indextoname() with a specific value (UINT_MAX) was fixed. Relatedly, an integer overflow in socket.if_indextoname() on 64-bit non-Windows platforms was fixed.pth files with names starting with a dot or containing the hidden file attribute are now skippediso2022_jp_3 and iso2022_jp_2004 codecs no longer read out of boundsssl.SSLContext.cert_store_stats() and ssl.SSLContext.get_ca_certs() now correctly lock access to the certificate store, when the ssl.SSLContext is shared across multiple threadsUpgrading is highly recommended to all users of affected versions.
It’s not something you will notice when downloading, but 3.10.14 here is the first release we’ve done where the source artifacts were built on GHA and not on a local computer of one of the release managers. We have the Security Developer in Residence @sethmlarson to thank for that!
It’s a big deal since public builds allow for easier auditing and
repeatability. It also helps with the so-called bus factor. In fact, to
test this out, this build of 3.10.14 was triggered by me and not Pablo,
who would usually release Python 3.10.
The artifacts are later still signed by the respective release manager, ensuring integrity when put on the downloads server.
The security releases you’re looking at are the first after the PSF became a CVE Numbering Authority. That’s also thanks to @sethmlarson.
What being our own CNA allows us is to ensure the quality of the
vulnerability reports is high, and that the severity estimates are accurate.
Seth summarized it best in his announcement here.
What this also allows us to do is to combine announcement of CVEs
with the release of patched versions of Python. This is in fact the case
with two of the CVEs listed above (CVE-2023-6597 and CVE-2024-0450). And since Seth is now traveling, this announcement duty was fulfilled by the PSF’s Director of Infrastructure @EWDurbin. Thanks!
I’m happy to see us successfully testing bus factor resilience on multiple fronts with this round of releases.
Thanks to all of the many volunteers who help make Python Development
and these releases possible! Please consider supporting our efforts by
volunteering yourself or through organization contributions to the
Python Software Foundation.
–
Łukasz Langa @ambv
on behalf of your friendly release team,
Ned Deily @nad
Steve Dower @steve.dower
Pablo Galindo Salgado @pablogsal
Łukasz Langa @ambv
Thomas Wouters @thomas
The rise of Artificial Intelligence (AI) is here, and it’s bringing a new era of technology that is already creating and impacting the world. It was the story of 2023, and its emphasis isn’t going anywhere anytime soon. While the creative growth of AI occurring so rapidly is a fascinating development for our society, it’s […]
The post How AI is unfairly targeting and discriminating against Black people appeared first on The Mozilla Blog.
REMEMBER THOSE COMMENTS BILLY RAY CYRUS MADE TO GQ THIS WEEK, ABOUT HOW SCARED HE IS FOR MILEY, AND HOW HE WISHED THEY’D NEVER DONE HANNAH MONTANA… WELL DID HE REALLY EXPECT MILEY NOT TO BE PISSED?
YEP, MILEY IS FUMING THAT DADDY BILLY RAY OPENED HIS MOUTH…A FRIEND TELLS POPEATER.COM, “To say Miley is angry is an understatement. She’s furious that her own flesh and blood would make a private matter so public. Who does he think he is, Michael Lohan?”
IN THE GQ INTERVIEW, BILLY RAY SAID THAT THEIR DISNEY SHOW “DESTROYED” HIS FAMILY.
THE SOURCE SAYS, “This isn’t what a father does. He never said a bad world about ‘Hannah Montana’ all those years it made millions for the family, and now that Miley has turned 18 and is making her own decisions, he does this. Unforgivable.”
THE INSIDER ADDS, “Miley has told him that if he wants to talk with her he has her number. It’s been the same number she always has had.”