Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-tornado6 for openSUSE:Factory 
checked in at 2026-09-23 14:33:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-tornado6 (Old)
 and      /work/SRC/openSUSE:Factory/.python-tornado6.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-tornado6"

Wed Sep 23 14:33:58 2026 rev:28 rq:1379400 version:6.5.10

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-tornado6/python-tornado6.changes  
2026-09-04 12:36:43.021802165 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-tornado6.new.383539/python-tornado6.changes  
    2026-09-23 14:35:19.640280910 +0200
@@ -1,0 +2,38 @@
+Mon Sep 21 06:37:36 UTC 2026 - Daniel Garcia <[email protected]>
+
+- update to 6.5.10:
+  - tornado.web: The allowed_symlink_directory argument of
+    StaticFileHandler may now be a list of directories instead of just
+    a single directory. This feature has been adjusted to improve
+    compatibility with Jupyter, which would fail to load with Tornado
+    6.5.9.
+- 6.5.9:
+  # Security fixes
+  - .StaticFileHandler no longer follows symlinks outside of the
+    static root directory. Applications that wish to continue the
+    previous behavior may set the new argument
+    allowed_symlink_directory to the directory (an ancestor of the
+    static root) that should be used for symlink validation. Thanks to
+    Yasha-ops and iaohkut-from-NightWolf-Team for reporting this
+    issue.
+  - curl_httpclient has a new max_body_size argument (default 100MB,
+    same as for simple_httpclient). This limit is enforced on all
+    requests, whether or not streaming_callback is used.
+    curl_httpclient now also controls its memory usage when
+    decompressing response bodies. Thanks to afldl,
+    iaohkut-from-NightWolf-Team, and aoto-tech for reporting this
+    issue.
+  - simple_httpclient now correctly applies the max_body_size limit to
+    responses using HTTP/1.0 format (no Content-Length or
+    Transfer-Encoding). Previously it silently truncated such
+    responses at max_buffer_size instead. Thanks to afldl for
+    reporting this issue.
+  - simple_httpclient now rejects responses that use more than 10 100
+    Continue responses, which could previously cause stack overflow
+    errors. Thanks to afldl for reporting this issue.
+  - The limit ParseBodyConfig.urlencoded.max_argument is now applied
+    to URL arguments in addition to POST bodies. Thanks to
+    iaohkut-from-NightWolf-Team, afldl, and manus-pi for reporting
+    this issue.
+
+-------------------------------------------------------------------

Old:
----
  tornado-6.5.8.tar.gz

New:
----
  tornado-6.5.10.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-tornado6.spec ++++++
--- /var/tmp/diff_new_pack.XGaEOX/_old  2026-09-23 14:35:20.292307870 +0200
+++ /var/tmp/diff_new_pack.XGaEOX/_new  2026-09-23 14:35:20.294307953 +0200
@@ -18,7 +18,7 @@
 
 %{?sle15_python_module_pythons}
 Name:           python-tornado6
-Version:        6.5.8
+Version:        6.5.10
 Release:        0
 Summary:        Open source version of scalable, non-blocking web server that 
power FriendFeed
 License:        Apache-2.0

++++++ tornado-6.5.8.tar.gz -> tornado-6.5.10.tar.gz ++++++
++++ 2209 lines of diff (skipped)

Reply via email to