[RFC] Security policy for dev-lang/python and dev-lang/pypy
Michał Górny <[email protected]>
| Newsgroups | gmane.linux.gentoo.devel |
|---|---|
| Organization | Gentoo |
| Message-ID | <[email protected]> |
Hello, everyone. TL;DR: Python team will only be backporting important security fixes, and only to current default + next default (3.13 + 3.14). In the past, I've been quite aggressively backporting security fixes to all Python versions in ::gentoo, including these we do not support via PYTHON_TARGETS. Alas, I don't have the energy for that anymore. CPython upstream is quite problematic here. As of today, Python 3.10 through 3.12 is still "security" supported upstream [1]. However, upstream security support is quite problematic, as: 1. They rarely make releases of these versions, so issues quickly pile up. They have this "releases are costly" attitude [2], which is quite unfair to all the downstreams having to independently backport everything. 2. They are quite inconsistent about actually performing backports. Sometimes security fixes are backported immediately, at other times there are backported just before the release -- so using snapshots doesn't really solve the problem. Even when backports are actually filed, PRs for some branches are merged fast while others wait. 3. They are quite inconsistent about actually marking security issues as such. Sometimes they are documented as library changes (especially when there were no CVE at the time of fixing), so you end up having to literally read through the whole changelog and figure out what is what. As many other projects, Python is getting a lot of security issues reported with various levels of significance. There's basically a lot to sieve through, and I don't think any of us has the energy to do that, especially that it's essentially upstream's constant neglect we're fixing. All that said, I'd like to propose that from now on: - Python team will backport important security fixes to the current default Python version and the newer Python versions that aren't in alpha/beta phase (i.e. 3.13 + 3.14 now, 3.14 from June). - Older versions and dev-lang/pypy will receive security fixes as they are released upstream (unless something really important comes up). - Secfixes that don't seem important will be delivered as upstream releases them. WDYT? [1] https://devguide.python.org/versions/ [2] https://github.com/python/cpython/issues/148031#issuecomment-4183874361 -- Best regards, Michał Górny
signature.asc
(application/pgp-signature, 293 B)
-----BEGIN PGP SIGNATURE----- iKQEABYKAEwWIQQcFD0bEK7NPNmWHtiOMjR69AVa6AUCad5SkxsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDISHG1nb3JueUBnZW50b28ub3JnAAoJEI4yNHr0BVro oxYBAIYCCqZ1gc56w3h5quoKM9oRKkT6N+KGNT/xzZjn2z8dAQCWnPaFFNaFAw7r SzR6aK8CzUciNp+Ht2XBjrlxBIU5BQ== =1stJ -----END PGP SIGNATURE-----