Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-tornado6 for openSUSE:Factory
checked in at 2026-09-23 14:33:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-tornado6 (Old)
and /work/SRC/openSUSE:Factory/.python-tornado6.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-tornado6"
Wed Sep 23 14:33:58 2026 rev:28 rq:1379400 version:6.5.10
Changes:
--------
--- /work/SRC/openSUSE:Factory/python-tornado6/python-tornado6.changes
2026-09-04 12:36:43.021802165 +0200
+++
/work/SRC/openSUSE:Factory/.python-tornado6.new.383539/python-tornado6.changes
2026-09-23 14:35:19.640280910 +0200
@@ -1,0 +2,38 @@
+Mon Sep 21 06:37:36 UTC 2026 - Daniel Garcia <[email protected]>
+
+- update to 6.5.10:
+ - tornado.web: The allowed_symlink_directory argument of
+ StaticFileHandler may now be a list of directories instead of just
+ a single directory. This feature has been adjusted to improve
+ compatibility with Jupyter, which would fail to load with Tornado
+ 6.5.9.
+- 6.5.9:
+ # Security fixes
+ - .StaticFileHandler no longer follows symlinks outside of the
+ static root directory. Applications that wish to continue the
+ previous behavior may set the new argument
+ allowed_symlink_directory to the directory (an ancestor of the
+ static root) that should be used for symlink validation. Thanks to
+ Yasha-ops and iaohkut-from-NightWolf-Team for reporting this
+ issue.
+ - curl_httpclient has a new max_body_size argument (default 100MB,
+ same as for simple_httpclient). This limit is enforced on all
+ requests, whether or not streaming_callback is used.
+ curl_httpclient now also controls its memory usage when
+ decompressing response bodies. Thanks to afldl,
+ iaohkut-from-NightWolf-Team, and aoto-tech for reporting this
+ issue.
+ - simple_httpclient now correctly applies the max_body_size limit to
+ responses using HTTP/1.0 format (no Content-Length or
+ Transfer-Encoding). Previously it silently truncated such
+ responses at max_buffer_size instead. Thanks to afldl for
+ reporting this issue.
+ - simple_httpclient now rejects responses that use more than 10 100
+ Continue responses, which could previously cause stack overflow
+ errors. Thanks to afldl for reporting this issue.
+ - The limit ParseBodyConfig.urlencoded.max_argument is now applied
+ to URL arguments in addition to POST bodies. Thanks to
+ iaohkut-from-NightWolf-Team, afldl, and manus-pi for reporting
+ this issue.
+
+-------------------------------------------------------------------
Old:
----
tornado-6.5.8.tar.gz
New:
----
tornado-6.5.10.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-tornado6.spec ++++++
--- /var/tmp/diff_new_pack.XGaEOX/_old 2026-09-23 14:35:20.292307870 +0200
+++ /var/tmp/diff_new_pack.XGaEOX/_new 2026-09-23 14:35:20.294307953 +0200
@@ -18,7 +18,7 @@
%{?sle15_python_module_pythons}
Name: python-tornado6
-Version: 6.5.8
+Version: 6.5.10
Release: 0
Summary: Open source version of scalable, non-blocking web server that
power FriendFeed
License: Apache-2.0
++++++ tornado-6.5.8.tar.gz -> tornado-6.5.10.tar.gz ++++++
++++ 2209 lines of diff (skipped)