This version includes fixes for: * CVE-2020-14422: Hash collisions in IPv4Interface and IPv6Interface * CVE-2020-15523: Python uses invalid DLL path after calling Py_SetPath on Windows This version also includes support for OpenSSL 1.1.x builds that use 'no-deprecated' and '--api=1.1.0'[1], and so this removes the previous OpenSSL-related patches. This also backports fixes for security issues, including: * CVE-2019-20907: Infinite loop in the tarfile module This also updates the setuptools and pip packages to 47.1.0 and 20.1.1, respectively. [1]: https://github.com/python/cpython/pull/20566 Signed-off-by: Jeffery To <jeffery.to@gmail.com>
16 lines
551 B
Diff
16 lines
551 B
Diff
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=804249
|
|
https://sources.debian.org/patches/python-setuptools/40.8.0-1/sorted-requires.diff/
|
|
|
|
Index: b/setuptools/command/egg_info.py
|
|
===================================================================
|
|
--- a/setuptools/command/egg_info.py
|
|
+++ b/setuptools/command/egg_info.py
|
|
@@ -641,7 +641,7 @@ def _write_requirements(stream, reqs):
|
|
|
|
def append_cr(line):
|
|
return line + '\n'
|
|
- lines = map(append_cr, lines)
|
|
+ lines = map(append_cr, sorted(lines))
|
|
stream.writelines(lines)
|
|
|
|
|