Re: rdflib / CVE-2019-7653

2019-03-12 Thread Brian May
Chris Lamb writes: > I also still don't grok the move to Python 3 (nor the changes to > debian/gbp.conf as it happens). It seems to go against the > general theme of being as conservative as possible in stable/ > securoty updates. Again, likely one for recording for posterity in > debian/changelo

sqlalchemy security fix available for testing

2019-03-12 Thread Sylvain Beucler
Hi, I made a fix for sqlalchemy available for testing (CVE-2019-7164/7548): https://people.debian.org/~beuc/lts/sqlalchemy/ Upstream author Mike Bayer warns that this might break applications, hence if you are depend on sqlalchemy you are encouraged to test: https://gerrit.sqlalchemy.org/#/c/sqla

Re: rdflib / CVE-2019-7653

2019-03-12 Thread Chris Lamb
Hi Brian, > "Use easy_install provided scripts instead of our our custom scripts." > > Any better? Somewhat, although I believe truly helpful changelog entries typically have both the "what" and "why" component, of which yours is currently missing the latter. Best wishes, -- ,''`.