Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Reserve your abuse for your true friends. -- Larry Wall in <199712041852.KAA19364@wall.org>


devel / comp.lang.python.announce / [Python-announce] [RELEASE] Python 3.11.5, 3.10.13, 3.9.18, and 3.8.18 is now available

SubjectAuthor
o [Python-announce] [RELEASE] Python 3.11.5, 3.10.13, 3.9.18, and 3.8.18 is now avŁukasz Langa

1
[Python-announce] [RELEASE] Python 3.11.5, 3.10.13, 3.9.18, and 3.8.18 is now available

<52D8805C-BD62-4301-9AC9-A6D1F1916729@langa.pl>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=10061&group=comp.lang.python.announce#10061

  copy link   Newsgroups: comp.lang.python.announce
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!not-for-mail
From: luk...@langa.pl (Łukasz Langa)
Newsgroups: comp.lang.python.announce
Subject: [Python-announce] [RELEASE] Python 3.11.5, 3.10.13, 3.9.18, and 3.8.18 is now available
Date: Thu, 24 Aug 2023 23:06:08 +0200
Lines: 113
Approved: python-announce-list@python.org
Message-ID: <52D8805C-BD62-4301-9AC9-A6D1F1916729@langa.pl>
Reply-To: python-list@python.org
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6\))
Content-Type: multipart/signed;
boundary="Apple-Mail=_5A1D3808-33A7-4A7F-A0C5-A0B578023CFB";
protocol="application/pgp-signature";
micalg=pgp-sha256
X-Trace: news.uni-berlin.de 6/S5zbEbdVUox1PdoBD7Bw5ocFhXTvuT3tsPxjgwY0NA==
Cancel-Lock: sha1:eNQ+z+dl1YHUG5wbmKpRpKLsjTI= sha256:ZRKT9503/PSqLHHLjrmJXEZJPYR36yNPPLPxkukdFjc=
Authentication-Results: mail.python.org; dkim=pass
reason="2048-bit key; unprotected key"
header.d=langa.pl header.i=@langa.pl header.b=iPsueFHw;
dkim-adsp=pass; dkim-atps=neutral
X-Spam-Status: OK 0.000
X-Spam-Evidence: '*H*': 1.00; '*S*': 0.00; 'url-ip:140.82/16': 0.03;
'content-type:multipart/signed': 0.05; 'to:name:python-dev': 0.05;
'volunteers': 0.05; 'url:downloads': 0.07; 'content-
type:application/pgp-signature': 0.09; 'filename:fname piece:asc':
0.09; 'filename:fname piece:signature': 0.09;
'filename:fname:signature.asc': 0.09; 'instances': 0.09; 'ned':
0.09; 'pablo': 0.09; 'upgrading': 0.09; 'url-ip:184.105/16': 0.09;
'url:discuss': 0.09; 'url:release': 0.09; 'subject:Python': 0.12;
'log': 0.12; 'url:github': 0.14; 'url-ip:140/8': 0.15; '<>:':
0.16; 'bypass': 0.16; 'deily': 0.16; 'encrypted': 0.16; 'fixes':
0.16; 'galindo': 0.16; 'possible!': 0.16; 'received:10.202': 0.16;
'received:10.202.2': 0.16; 'received:10.202.2.163': 0.16;
'received:internal': 0.16; 'received:messagingengine.com': 0.16;
'releases': 0.16; 'resolution': 0.16; 'salgado': 0.16; 'somewhat':
0.16; 'tls': 0.16; 'url:cgi': 0.16; 'url:cpython': 0.16;
'wouters': 0.16; '\xc5\x81ukasz': 0.16; 'python': 0.16; 'to:addr
:python-list': 0.20; 'issue': 0.21; 'subject:] ': 0.21; 'to:no
real name:2**1': 0.22; 'certificate': 0.26; 'notes': 0.26;
'foundation.': 0.28; 'dive': 0.32; 'downloads': 0.32; 'there':
0.33; 'release': 0.34; 'understood': 0.35; 'words': 0.35;
'received:66': 0.35; 'fix': 0.36; 'change': 0.36; 'subject:[':
0.37; 'thanks': 0.38; 'safe': 0.39; 'steve': 0.39; 'data.': 0.40;
'included': 0.61; 'url-ip:192/8': 0.61; 'url:u': 0.63; 'between':
0.63; 'from:charset:utf-8': 0.64; 'security': 0.64; 'our': 0.64;
'in.': 0.64; 'url:name': 0.64; 'your': 0.64; 'among': 0.65; 'url-
ip:198/8': 0.65; 'url:5': 0.67; 'right': 0.68; 'url-ip:lookup
error': 0.70; 'affected': 0.70; 'there!': 0.70; 'content': 0.72;
'url:t': 0.73; 'yourself': 0.75; 'details.': 0.76; 'highly': 0.78;
'(like': 0.84; 'importantly,': 0.84; 'smith.': 0.84; 'those,':
0.84; 'to:addr:python-announce': 0.97
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=langa.pl; h=cc
:content-type:content-type:date:date:from:from:in-reply-to
:message-id:mime-version:reply-to:sender:subject:subject:to:to;
s=fm3; t=1692911183; x=1692997583; bh=Ny4i9MbZBYNnYZO6717TOSlju
R8Hjwa0nHtCZhdTaNA=; b=iPsueFHwhUb/ZItjKaUnJCggXxV3wkciJpNcK4a1k
INuh03GU/2LaSai3Rn2a7sbbC2q4krNkh+NuoWrzAbki01nxFhc59tyS73+nwtah
4QN3FO9KS2FFTD66y0CmeyONYf6z5yQM1X1Do53j4GJmT3DVVisyK3cUxoq9u2Hb
DJJIpCYQt/dnt1g4J1UKB3xFaX4U9KogeN9R6TCMYm1GLj3fkYna3t+lbx1Dgfnb
5mP+sgsWwGaEt6lAwdWRITxc1Wm16WDscbQKqTY/Iy0ApFa/4kbGm4Lo1bqRKMFk
mpAirvMpKxKgh4CepcCq+UM2Kafk/z+Fchqw+hoYcnXwA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
messagingengine.com; h=cc:content-type:content-type:date:date
:feedback-id:feedback-id:from:from:in-reply-to:message-id
:mime-version:reply-to:sender:subject:subject:to:to:x-me-proxy
:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t=
1692911183; x=1692997583; bh=Ny4i9MbZBYNnYZO6717TOSljuR8Hjwa0nHt
CZhdTaNA=; b=sOm9oJ0yGpmFeyPrgqcQKKx9CEe8eXvlMhOdep4AzBW7e4jvygF
DA7oOebWPKVAarkW4GsmWfyisN1hUFmJg0sNY4MCGcnETC5fEDAVwximoFcR/OEa
+Wo1RQkovT9T/eUW+727nlyEsRbOJNiLKV4GUDqV7hb9KTwT9yfDIQ6qziehIH5V
UCXLHzhAxY7Xw82vlb4NyKGM1hZg3mmTVeKPcfRZClN3LflOZEKWSYTpOo4Ts00W
jXWTvUrSQIzvIujJmmbpGvzu9opGydwjr4K64kSNIAP8Iz/vfhiLlv5ASeDhpj6I
XxdzaEnk3h7ZS6BB978PZ6VeZ0DVuYqcnLQ==
X-ME-Sender: <xms:TsbnZC6_2dYv9EGV8gbraQSuxfe-UrLTweTqYJ0RYK1Wfd_rgMPTOg>
<xme:TsbnZL7W14bpqDC4zozVt5AP361nSKOudT5h9BLONyfP001pD2lBzLUO50wKUqkAi
w7kcl8b9svtDd0>
X-ME-Received: <xmr:TsbnZBd7XQeW-m9ty73ruxDu_rBtRjCociKaYXfFfWDkqR_jnxgPf5i0T__8BsZrKl0ubiCT3r4qd2SLJ3wJ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedviedruddviedgudehhecutefuodetggdotefrod
ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh
necuuegrihhlohhuthemuceftddtnecunecujfgurhephfgtggfukfffvffosehgtdhmre
hhtdejnecuhfhrohhmpefnuhhkrghsiicunfgrnhhgrgcuoehluhhkrghsiieslhgrnhhg
rgdrphhlqeenucggtffrrghtthgvrhhnpeevfeffvdfgvedugfdtueejffekfeehgeduud
evudettdefhffhueehfeegtdefudenucffohhmrghinhepghhithhhuhgsrdgtohhmpdhp
hihthhhonhdrohhrghdpmhhithhrvgdrohhrghenucevlhhushhtvghrufhiiigvpedtne
curfgrrhgrmhepmhgrihhlfhhrohhmpehluhhkrghsiieslhgrnhhgrgdrphhl
X-ME-Proxy: <xmx:TsbnZPJ-e88aBmbremJdvqpO39Y2pDL_10rp7pl_v1s7-SoHkbCnTA>
<xmx:TsbnZGI9_mp_TWNfhOW9vbB6JvgCsDmA7hML8Dj_Y304LCvxMozDYQ>
<xmx:TsbnZAzLpAyWeUOTFl4fpAt55194CptgX__nZgJWKU3YL6fjZzPH3g>
<xmx:T8bnZIi2FDWHDtGUTwd2YpSSRHKMgn6yZcSSQVfyXH3JnAwwz7LcgA>
Feedback-ID: i8e7440be:Fastmail
X-Mailer: Apple Mail (2.3731.700.6)
X-MailFrom: lukasz@langa.pl
X-Mailman-Rule-Hits: emergency
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved
Message-ID-Hash: 2VDJP6JU7DO7PKIVZQMVD6H3F2MDDQZQ
X-Message-ID-Hash: 2VDJP6JU7DO7PKIVZQMVD6H3F2MDDQZQ
X-Mailman-Approved-At: Thu, 24 Aug 2023 17:24:11 -0400
X-Content-Filtered-By: Mailman/MimeDel 3.3.9b1
X-Mailman-Version: 3.3.9b1
Precedence: list
List-Id: Announcement-only list for the Python programming language <python-announce-list.python.org>
Archived-At: <https://mail.python.org/archives/list/python-announce-list@python.org/message/2VDJP6JU7DO7PKIVZQMVD6H3F2MDDQZQ/>
List-Archive: <https://mail.python.org/archives/list/python-announce-list@python.org/>
List-Help: <mailto:python-announce-list-request@python.org?subject=help>
List-Owner: <mailto:python-announce-list-owner@python.org>
List-Post: <mailto:python-announce-list@python.org>
List-Subscribe: <mailto:python-announce-list-join@python.org>
List-Unsubscribe: <mailto:python-announce-list-leave@python.org>
 by: Łukasz Langa - Thu, 24 Aug 2023 21:06 UTC
Attachments: signature.asc (application/pgp-signature)

There’s security content in the releases, let’s dive right in.

gh-108310 <https://github.com/python/cpython/issues/108310>: Fixed an issue where instances of ssl.SSLSocket <https://docs.python.org/release/3.10.13/library/ssl.html#ssl.SSLSocket> were vulnerable to a bypass of the TLS handshake and included protections (like certificate verification) and treating sent unencrypted data as if it were post-handshake TLS encrypted data. Security issue reported as CVE-2023-40217 1 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40217> by Aapo Oksman. Patch by Gregory P. Smith.
Upgrading is highly recommended to all users of affected versions.

<https://discuss.python.org/t/python-3-11-5-3-10-13-3-9-18-and-3-8-18-is-now-available/32254/1#python-3115-1>Python 3.11.5

Get it here: https://www.python.org/downloads/release/python-3115/

This release was held up somewhat by the resolution of this CVE, which is why it includes a whopping 328 new commits since 3.11.4 (compared to 238 commits between 3.10.4 and 3.10.5). Among those, there is a fix for CVE-2023-41105 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41105>which affected Python 3.11.0 - 3.11.4. See gh-106242 <https://github.com/python/cpython/issues/106242> for details.

There are also some fixes for crashes, check out the change log <https://docs.python.org/release/3.11.5/whatsnew/changelog.html> to see all information.

Most importantly, the release notes on the downloads page <https://www.python.org/downloads/release/python-3115/> include a description of the Larmor precession. I understood some of the words there!

<https://discuss.python.org/t/python-3-11-5-3-10-13-3-9-18-and-3-8-18-is-now-available/32254/1#python-31013-2>Python 3.10.13

Get it here: https://www.python.org/downloads/release/python-31013/

16 commits.

<https://discuss.python.org/t/python-3-11-5-3-10-13-3-9-18-and-3-8-18-is-now-available/32254/1#python-3918-3>Python 3.9.18

Get it here: https://www.python.org/downloads/release/python-3918/

11 commits.

<https://discuss.python.org/t/python-3-11-5-3-10-13-3-9-18-and-3-8-18-is-now-available/32254/1#python-3818-4>Python 3.8.18

Get it here: https://www.python.org/downloads/release/python-3818/

9 commits.

<https://discuss.python.org/t/python-3-11-5-3-10-13-3-9-18-and-3-8-18-is-now-available/32254/1#stay-safe-and-upgrade-5>Stay safe and upgrade!

Thanks to all of the many volunteers who help make Python Development and these releases possible! Please consider supporting our efforts by volunteering yourself or through organization contributions to the Python Software Foundation.

--
Łukasz Langa @ambv <https://discuss.python.org/u/ambv>
on behalf of your friendly release team,

Ned Deily @nad <https://discuss.python.org/u/nad>
Steve Dower @steve.dower <https://discuss.python.org/u/steve.dower>
Pablo Galindo Salgado @pablogsal <https://discuss.python.org/u/pablogsal>
Łukasz Langa @ambv <https://discuss.python.org/u/ambv>
Thomas Wouters @thomas <https://discuss.python.org/u/thomas>

Attachments: signature.asc (application/pgp-signature)

devel / comp.lang.python.announce / [Python-announce] [RELEASE] Python 3.11.5, 3.10.13, 3.9.18, and 3.8.18 is now available

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor