On 14 Jul 2023, at 19:14, Bob Kline via Python-list <python-list@python.org> wrote:
Can someone point me to the official catalog of security vulnerabilities in
Python (by which I mean cpython and the standard libraries)? I found https://www.cvedetails.com/vulnerability-list/vendor_id-10210/product_id-18230/Python-Python.html
but that isn't maintained by python.org. I also found security-announce@python.org, but there hasn't been anything posted there
in over a year as far as I can tell, and even before that it's pretty thin.
If there's a better place to ask, please advise.
Thanks.
--
Bob Kline
https://www.rksystems.com
mailto:bkline@rksystems.com
--
https://mail.python.org/mailman/listinfo/python-list
Can someone point me to the official catalog of security vulnerabilities
in Python ....
Where do you get your python from?
You may find that the organisation that packages python that you use has such a list.
Can someone point me to the official catalog of security vulnerabilities in >Python (by which I mean cpython and the standard libraries)? I found >https://www.cvedetails.com/vulnerability-list/vendor_id-10210/product_id-18230/Python-Python.html
but that isn't maintained by python.org.
I am active in the `Zope` community (a web application server
based on Python). This community has a security mailing list
for security related reports
and issues public CVE (= "Commun Vulnerabilities and Exposures") reports
(via a "GitHUB" service) as soon as a security risk has been resolved.
I expect that security risks for Python itself are handled in
a similar way (as, Python too, maintains its code on "GitHUB").
...
For details about CVE, read "https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures".
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (0 / 16) |
Uptime: | 168:01:57 |
Calls: | 10,385 |
Calls today: | 2 |
Files: | 14,057 |
Messages: | 6,416,544 |