Hi there,
we have some security content that built up to a need to release all versions of Python pretty soon. The Release Managers decided to perform all of them in one go on March 14th. We have a few things to ask you.
-
Please keep buildbots green this week across the board. There’s quite a few people involved in the releases on Mar 14th. We’d like to avoid last-minute fixes or deadline slippage.
-
A few of the security-related updates are still in flight, please help if you can:
- Issue 44549: Update Windows installer to use bzip2 1.0.8 - Python tracker bzip2 1.0.8 for Windows
- Issue 46932: Please update bundled libexpat to 2.4.7 with an important fix - Python tracker expat 2.4.7
- Issue 46948: [CVE-2022-26488] Escalation of privilege via Windows Installer - Python tracker [CVE-2022-26488] Escalation of privilege via Windows Installer
-
If you have any other security-related changes you’d like to see released next week, the time is now to land them in the relevant branches.
Cheers,
Your Friendly RMs