3 ms·
Distros are backporting security patches into their releases, so no harm done. If you rely on the python.org releases and don't build from source, then yes, tha
by hexa- 6y ago
Distros are backporting security patches into their releases, so no harm done. If you rely on the python.org releases and don't build from source, then yes, that is a bit sad.
Case in point: The Debian security tracker, see their notes section referencing each commit.
https://security-tracker.debian.org/tracker/CVE-2021-3177 https://security-tracker.debian.org/tracker/CVE-2021-3177
- AaronFriel 6y agoThe python:3.8 and python:3.9 container images if used to build web services such as Django with GIS extensions may have an RCE until Python.org sources are updated.
- hexa- 6y agoWhy can't the base image receive those patches as well?
- AaronFriel 6y agoThose images pull from python.org sources, see: https://github.com/docker-library/python/blob/master/3.8/buster/Dockerfile https://github.com/docker-library/python/blob/master/3.8/bus...