Security updates have been issued by Fedora (firefox, libopenmpt, matrix-synapse, vim, and xen), Mageia (gmp, heimdal, libsndfile, nginx/vsftpd, openjdk, sharpziplib/mono-tools, and vim), Red Hat (java-1.8.0-ibm), Scientific Linux (firefox), SUS…
[$] Python discusses deprecations
Feature deprecations are often controversial, but many projects find it
necessary, or desirable, to lose some of the baggage that has accreted over
time. A mid-November request to get rid of three Python standard library
modules provides a case…
[$] FIPS-compliant random numbers for the kernel
The Linux random-number generator (RNG) seems to attract an outsized amount
of attention (and work) for what is, or seemingly should be, a fairly small
component of the kernel. In part that is because random numbers, and
their quality, are ext…
Introducing CentOS Stream 9
The CentOS blog has announced the release of CentOS Stream 9:
CentOS Stream is a continuous-delivery distribution providing each point-release of Red Hat Enterprise Linux (RHEL). Before a package is formally introduced to CentOS Stream, it…
Security updates for Friday
Security updates have been issued by CentOS (krb5 and mailman), Debian (gmp and librecad), Fedora (php-symfony4 and wireshark), Mageia (bluez, busybox, docker-containerd, gfbgraph, hivex, nss, perl/perl-Encode, and udisks2/libblockdev), openSUSE…
This shouldn’t have happened: A vulnerability postmortem (Project Zero blog)
Over on the Project Zero blog, Tavis Ormandy has a lengthy postmortem on a vulnerability that he found in the Network Security Services (NSS) cryptography library. The vulnerability is a bog-standard buffer overflow that has existed in the libr…
Security updates for Thursday
Security updates have been issued by CentOS (kernel, openssh, and rpm), Debian (nss), Fedora (seamonkey), Mageia (glibc), openSUSE (go1.16, go1.17, kernel, mariadb, netcdf, openexr, poppler, python-Pygments, python-sqlparse, ruby2.5, speex, and …
[$] Fedora revisits the Git-forge debate
A seemingly straightforward question aimed at candidates for the in-progress
Fedora
elections led to a discussion on the Fedora devel mailing list that
branched into a few different directions. The question was related to a
struggle that the di…
[$] Python identifiers, PEP 8, and consistency
While there are few rules on the names of variables, classes, functions,
and so on (i.e. identifiers) in the Python language, there are some
guidelines on how those things should be named. But, of course, those
guidelines were not always follo…
Six more stable kernels
Greg Kroah-Hartman has announced the release of six new stable kernels: 5.10.82, 5.4.162, 4.19.218, 4.14.256, 4.9.291, and 4.4.293. These kernels contain lots of
important fixes throughout the tree; users of those series should upgrade.
…