Re: Security support for pypy and jython

2024-09-04 Thread Roberto C . Sánchez
On Thu, Aug 29, 2024 at 05:06:51PM -0300, Santiago Ruano Rincón wrote: > > Following a discussion on IRC, it seems that for bullseye, it would make > more sense to explicitly declare the python 2 ecosystem (python2.7, > pypy, jython) as non supported. This is actually the current status, > since p

Re: Security support for pypy and jython

2024-08-29 Thread Santiago Ruano Rincón
> > track the associated CVEs. > > > > > > > > > > > > Do we want to mark pypy and jython as EOL, or limited-support, in > > > > debian-security-support? > > > > > > For pypy and jython/bullseye, I would included them in > &g

Re: Security support for pypy and jython

2024-08-13 Thread Sylvain Beucler
dists) include the python2 stdlib. Unlike pypy3, neither package currently track the associated CVEs. Do we want to mark pypy and jython as EOL, or limited-support, in debian-security-support? For pypy and jython/bullseye, I would included them in security-support-limited.deb11, with the same

Re: Security support for pypy and jython

2024-08-13 Thread Moritz Mühlenhoff
ncluded up to bullseye) and jython (all > > dists) include the python2 stdlib. Unlike pypy3, neither package currently > > track the associated CVEs. > > > > > > Do we want to mark pypy and jython as EOL, or limited-support, in > > debian-security-support? >

Re: Security support for pypy and jython

2024-08-12 Thread Santiago Ruano Rincón
rently > track the associated CVEs. > > > Do we want to mark pypy and jython as EOL, or limited-support, in > debian-security-support? For pypy and jython/bullseye, I would included them in security-support-limited.deb11, with the same rationale than for python2.7. Any objection?

Security support for pypy and jython

2024-08-08 Thread Sylvain Beucler
Hello Security Team, python2.7 was marked unsupported in bullseye. We recently noted that pypy[v2] (included up to bullseye) and jython (all dists) include the python2 stdlib. Unlike pypy3, neither package currently track the associated CVEs. Do we want to mark pypy and jython as EOL, or l