Re: CVE: Python-twisted a.o. needs update for F37 due to matrix-synapse security issue

2023-08-31 Thread Marius Schwarz
Am 30.08.23 um 20:44 schrieb Jonathan Steffan: On Sat, May 27, 2023 at 3:45 AM Vitaly Zaitsev via devel wrote: On 26/05/2023 16:22, Marius Schwarz wrote: > This brings me to the question: whats the main issue for twisted here? 1. Contact python-twisted maintainers. Marius,

Re: CVE: Python-twisted a.o. needs update for F37 due to matrix-synapse security issue

2023-08-30 Thread Jonathan Steffan
On Sat, May 27, 2023 at 3:45 AM Vitaly Zaitsev via devel < devel@lists.fedoraproject.org> wrote: > On 26/05/2023 16:22, Marius Schwarz wrote: > > This brings me to the question: whats the main issue for twisted here? > > 1. Contact python-twisted maintainers. Marius, According to the upstream m

Re: CVE: Python-twisted a.o. needs update for F37 due to matrix-synapse security issue

2023-05-27 Thread Vitaly Zaitsev via devel
On 26/05/2023 16:22, Marius Schwarz wrote: This brings me to the question: whats the main issue for twisted here? 1. Contact python-twisted maintainers. 2. Check if all dependent packages are compatible with the updated python-binding package. 3. If this is a major update, you or the package m

CVE: Python-twisted a.o. needs update for F37 due to matrix-synapse security issue

2023-05-26 Thread Marius Schwarz
Hi, due to an outdated(afaik) python-twisted version, it's not possible to build matrix-synapse in version 1.8x . Unlucky for all F37 users, matrix-synpase has 3 embargoed CVEs coming, which need fixing asap. As "releng" has shipped the last twisted update, I have no clue who could help here