Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update from Python 3.10.11 to 3.10.13.
Python 3.10.12
Released June 6, 2023. Security release, no more binary installers.
urllib.parse.urlsplit()
now strips leading C0 control and space characters following the specification for URLs defined by WHATWG in response to CVE-2023-24329.uu.decode()
that could allow for directory traversal based on the input if noout_file
was specified.http.client.SimpleHTTPRequestHandler
.trace.__main__
now usesio.open_code()
for files to be executed instead of rawopen()
.tarfil
e, andshutil.unpack_archive()
, have a newfilter
argument that allows limitingtar
features than may be surprising or dangerous, such as creating files outside the destination directory. See Extraction filters for details.Python 3.10.13
Released Aug. 24, 2023. Security release, no more binary installers.