Message284485
This code hasn't changed in years. So while I believe it's a security bug and should be fixed, I don't know if I agree it's a bad enough security bug to stop Python 3.5.3rc1, which is literally in the middle of the release process.
I'm guessing this is easily fixed (if not os.path.isfile(tixlib): return), so how about we release 3.5.3rc1 with this bug and I'll cherry-pick this fix for 3.5.3 final. |
|
Date |
User |
Action |
Args |
2017-01-02 15:43:20 | larry | set | recipients:
+ larry, christian.heimes, benjamin.peterson, ned.deily, serhiy.storchaka, symphorien |
2017-01-02 15:43:20 | larry | set | messageid: <1483371800.28.0.77011807675.issue29125@psf.upfronthosting.co.za> |
2017-01-02 15:43:20 | larry | link | issue29125 messages |
2017-01-02 15:43:20 | larry | create | |
|