Python policy about /usr/lib/pythonXY.zip

2022-11-04 Thread Julien Palard
The Python Policy document [1] states: > For all supported Debian releases, sys.path does not include a > /usr/lib/pythonXY.zip entry. I may not understand the sentence, or something, because it looks wrong to me as pythonXY looks to be in sys.path, at least on my Debian bookworm: $ /usr/b

Re: review for gtg/0.6-1

2022-11-04 Thread François Mazen
Hello Jeroen, thanks for this important package review! I've fixed most of your remarks. Here are the ones that I don't know what to do: > * copyright: >  + public domain without explanation detailing exactly what exemption >    the files in question have from default copyright restrictions. I

Re: rdflib: URLInputSource can be abused to retrieve arbitrary documents if used naïvely

2022-11-04 Thread Étienne Mollier
Control: tags -1 help Hi all, Apparently, help is needed from upstream rdflib development team on the critical security bug #1023399[0] and their respective entry on their bug tracker[1]. I tried to have a look some time ago, but didn't make sense of the issue. I tag the bug appropriately to ra