-
-
Notifications
You must be signed in to change notification settings - Fork 29.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade macOS and Windows installers to use SQLite 3.37.2 #90083
Comments
SQLite 3.37.0 was released a couple of days ago: https://sqlite.org/releaselog/3_37_0.html Given that 3.11 feature freeze is approx. May 2022, and that it took approx. 5 months between SQLite 3.36.0 and 3.37.0, I'd say we aim for a field tested SQLite 3.37.0 instead of a possibly fresh-out-of-the-box 3.38.0 in 3.11. Let's wait a couple of weeks before changing the macOS/Windows installers. |
SQLite 3.37.1 appeared the day before New Years Eve. So let us wait until the end of January before upgrading the installers. |
SQLite 3.37.2 is fresh out now. Copying the release statement from the SQLite forum:
Link to the release page: https://www.sqlite.org/releaselog/3_37_2.html We should consider backporting to 3.10 and 3.9 due to the severity of the bug. |
Quoting the SQLite forum post, regarding backporting:
The Python 3.10 Windows and macOS installers ship with SQLite 3.36.0, so they are vulnerable to this bug. Ditto for the Python 3.9 Windows and macOS installers which ship with SQLite 3.35.5. |
Are we enabling the build option they mention on the release page? Or is We should obviously do the upgrade, but that will determine how |
As I understand the forum post, you're vulnerable if you use that specific build option (we don't), _or_ if you use the pragma (anyone may do that). So AFAICS, we should upgrade. |
We should definitely upgrade, but we probably don't have to trigger a |
No, I don’t think we need to rush a new release. The scheduled 3.10 and 3.9 releases should do fine. Can you update the sources repo in the mean time? |
Done |
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
The text was updated successfully, but these errors were encountered: