Post #813480
2025-06-03 21:48 UTC
Replies (4)
-
@sethmlarson@fosstodon.org 2025-06-03 21:51
The PSF Developers-in-Residence program makes this possible, check out how the @ThePSF supports the Python ecosystem with full-time staffing: https://www.python.org/psf/developersinresidence/
-
@samueloph@mastodon.social 2025-06-03 23:23
@sethmlarson I love that the people behind it were careful enough to explicitly mention the lower bound of the affected versions on the critical CVE: > Only Python versions 3.12 or later are affected by these vulnerabilities If the team would like to go one step further, they could do as curl does and pinpoint commits (breaking and fixing commit), from which version ranges can be inferred, but the level of details in the CVE is already great.
-
@ptmcg@fosstodon.org 2025-06-05 02:25
@sethmlarson Sadly, the releases for 3.12 and earlier are uninstallable on my Windows machine, nor on the vast majority of Windows machines whose owners don't know or don't care to maintain a Windows C build environment. (And why no binary for 3.12, btw, which is still in bugfix release?)
-
@lwflouisa@comics.town 2025-06-25 20:28
@sethmlarson Is CVE still happening? I got the impression they were on emergency funding.