[RFC] Security policy for dev-lang/python and dev-lang/pypy

Michał Górny <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Organization Gentoo
Message-ID <[email protected]>
Hello, everyone.

TL;DR: Python team will only be backporting important security fixes,
and only to current default + next default (3.13 + 3.14).


In the past, I've been quite aggressively backporting security fixes to
all Python versions in ::gentoo, including these we do not support via
PYTHON_TARGETS.  Alas, I don't have the energy for that anymore.

CPython upstream is quite problematic here.  As of today, Python 3.10
through 3.12 is still "security" supported upstream [1].  However,
upstream security support is quite problematic, as:

1. They rarely make releases of these versions, so issues quickly pile
up.  They have this "releases are costly" attitude [2], which is quite
unfair to all the downstreams having to independently backport
everything.

2. They are quite inconsistent about actually performing backports. 
Sometimes security fixes are backported immediately, at other times
there are backported just before the release -- so using snapshots
doesn't really solve the problem.  Even when backports are actually
filed, PRs for some branches are merged fast while others wait.

3. They are quite inconsistent about actually marking security issues as
such.  Sometimes they are documented as library changes (especially when
there were no CVE at the time of fixing), so you end up having to
literally read through the whole changelog and figure out what is what.

As many other projects, Python is getting a lot of security issues
reported with various levels of significance.  There's basically a lot
to sieve through, and I don't think any of us has the energy to do that,
especially that it's essentially upstream's constant neglect we're
fixing.


All that said, I'd like to propose that from now on:

- Python team will backport important security fixes to the current
default Python version and the newer Python versions that aren't in
alpha/beta phase (i.e. 3.13 + 3.14 now, 3.14 from June).

- Older versions and dev-lang/pypy will receive security fixes as they
are released upstream (unless something really important comes up).

- Secfixes that don't seem important will be delivered as upstream
releases them.

WDYT?


[1] https://devguide.python.org/versions/
[2] https://github.com/python/cpython/issues/148031#issuecomment-4183874361

-- 
Best regards,
Michał Górny
signature.asc (application/pgp-signature, 293 B)
-----BEGIN PGP SIGNATURE-----

iKQEABYKAEwWIQQcFD0bEK7NPNmWHtiOMjR69AVa6AUCad5SkxsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDISHG1nb3JueUBnZW50b28ub3JnAAoJEI4yNHr0BVro
oxYBAIYCCqZ1gc56w3h5quoKM9oRKkT6N+KGNT/xzZjn2z8dAQCWnPaFFNaFAw7r
SzR6aK8CzUciNp+Ht2XBjrlxBIU5BQ==
=1stJ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.