• [Python-announce] [RELEASE] Python versions 3.10.8, 3.9.15, 3.8.15, 3.7.15 now available

    From =?utf-8?Q?=C5=81ukasz_Langa?=@lukasz@langa.pl to comp.lang.python.announce on Tue Oct 11 21:58:32 2022
    From Newsgroup: comp.lang.python.announce


    --Apple-Mail=_BBE68CB2-11E2-4B6B-8565-2BB3B64565A4
    Content-Transfer-Encoding: quoted-printable
    Content-Type: text/plain;
    charset=utf-8

    D=C3=A9j=C3=A0 vu? Right, a month after the expedited releases we are =
    doing the dance again. This coincides with the regular scheduled time =
    for 3.10.8 but since we accrued a few fixes in 3.7 - 3.9 as well, = we=E2=80=99re again releasing all four editions at the same time. = We=E2=80=99re not promising to continue at this pace =F0=9F=98=85

    =
    <https://discuss.python.org/t/python-versions-3-10-8-3-9-15-3-8-15-3-7-15-= now-available/19889#security-content-this-time-1>Security content this =
    time

    CVE-2022-40674: bundled libexpat was upgraded from 2.4.7 to 2.4.9 which =
    fixes a heap use-after-free vulnerability in function doContent
    gh-97616: a fix for a possible buffer overflow in list *=3D int
    gh-97612: a fix for possible shell injection in the example script = get-remote-certificate.py (this issue originally had a CVE assigned to =
    it, which its author withdrew)
    gh-96577: a fix for a potential buffer overrun in msilib
    =
    <https://discuss.python.org/t/python-versions-3-10-8-3-9-15-3-8-15-3-7-15-= now-available/19889#python-3108-2>Python 3.10.8

    Get it here: https://www.python.org/downloads/release/python-3108/ = <https://www.python.org/downloads/release/python-3108/>
    As a bugfix release coming a mere month after an out-of-schedule =
    security release, 3.10.8 is somewhat smaller compared to 3.9.8 released =
    at the same stage of the release cycle a year ago. There=E2=80=99s 151 = commits vs 204 in 3.9. It=E2=80=99s still a larger release than 3.10.7 =
    at 113 commits. One way or the other, it=E2=80=99s worth checking out =
    the change log = <https://docs.python.org/release/3.10.8/whatsnew/changelog.html>.

    =
    <https://discuss.python.org/t/python-versions-3-10-8-3-9-15-3-8-15-3-7-15-= now-available/19889#and-now-for-something-completely-different-3>And now =
    for something completely different

    Granular convection is a phenomenon where granular material subjected to = shaking or vibration will exhibit circulation patterns similar to types =
    of fluid convection.

    It is sometimes described as the Brazil nut effect when the largest =
    particles end up on the surface of a granular material containing a =
    mixture of variously sized objects; this derives from the example of a = typical container of mixed nuts, where the largest will be Brazil nuts.

    The phenomenon is also known as the muesli effect since it is seen in =
    packets of breakfast cereal containing particles of different sizes but = similar densities, such as muesli mix.

    Under experimental conditions, granular convection of variously sized = particles has been observed forming convection cells similar to fluid =
    motion.

    =
    <https://discuss.python.org/t/python-versions-3-10-8-3-9-15-3-8-15-3-7-15-= now-available/19889#we-hope-you-enjoy-the-new-releases-4>We hope you =
    enjoy the new releases!

    Thanks to all of the many volunteers who help make Python Development =
    and these releases possible! Please consider supporting our efforts by = volunteering yourself or through organization contributions to the =
    Python Software Foundation.

    Your friendly release team,

    Ned Deily @nad <https://discuss.python.org/u/nad>
    Steve Dower @steve.dower <https://discuss.python.org/u/steve.dower>
    Pablo Galindo Salgado @pablogsal =
    <https://discuss.python.org/u/pablogsal>
    =C5=81ukasz Langa @ambv <https://discuss.python.org/u/ambv>

    --Apple-Mail=_BBE68CB2-11E2-4B6B-8565-2BB3B64565A4
    Content-Transfer-Encoding: 7bit
    Content-Disposition: attachment;
    filename=signature.asc
    Content-Type: application/pgp-signature;
    name=signature.asc
    Content-Description: Message signed with OpenPGP

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCAAdFiEE4/8oOcBIslwITevpsmmV4xAlBWgFAmNFyugACgkQsmmV4xAl BWh4sg/8D7uYlWC0XW/Kh8ApRPEcd7L2A84NhoVMBkrMvwub567WEenjrFV2T45T +VpC833sufSbfAyYw/gEgrggkmEYMzwIJYiVnZ8vEtQcPJLYEcE4q+b119w/5oi8 TNXSxKfUwWB/EzXYj61fX035l00XO83YJIi5IAiumWax0MpvJz6mzcX5nK++VjW/ vpwkBkE55ZpO2L5wS451w+aqH4SQQpf/eeBozYvjC+CG+rhLUcLsijLLSj8OiZoq Kq8xYGj1i7wZFOiEG7JAv13XJIIuYyhIVBskROhPW0wgVnlXyZvg1J6amS1mK0ap s6aEYjC+3GBMyWQ4G00UubSB+4LG6ql+ijIRgTStIr3lFgTn65bWpbgzHlUL3kMH u29jEDufb5njJ0DavyT5olmhgxVwURKVPXIxdoiomKDt0o7rKunWwixZwEO8iVC2 UdHHrGTM3HpcW+AYF2RpXvihZJAldjv8vJ0byHyIPXTGLpWvPAH/7Co8C5LXhSUr a9r+x8qImzzWF9HrWN5RstatavU/PlS6PhpdJcJEmKhGuoaITeRpKJ8CFzhL6TtM slkwuJAZklbIsqMFYfwkvOa0kuTwaz7Wku7H6N8230/B7WXqdhjvjATJ+3ENlQXG +Nh51HRgJ7R8AiHnWjChaO9PDrLnSP5x8k1Y3dK1GK+wzpE5Ux4=
    =AMYN
    -----END PGP SIGNATURE-----

    --Apple-Mail=_BBE68CB2-11E2-4B6B-8565-2BB3B64565A4--
    --- Synchronet 3.19c-Linux NewsLink 1.113