[Python-modules-team] Bug#619096: python-qscintilla2: the PyQt4.QtCore module is version 1 but the PyQt4.Qsci module requires version -1

2011-11-01 Thread Astromaximum developer
Looks like qscintilla bindings are broken again. Please use exactly the same script earlier in this bug report. Here's the minimal repro script: import sys from PyQt4.QtCore import * from PyQt4.QtGui import * from PyQt4.Qsci import QsciScintilla app = QApplication(sys.argv) w = QWidget() sci =

[Python-modules-team] Bug#646517: Insecure use of pickle when deserializing POST/PUT input

2011-11-01 Thread David Black
Hi, upstream already has the pickle 'loader' (they have commented out the pickle.load line) why hasn't debian already done this? ___ Python-modules-team mailing list Python-modules-team@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mai

[Python-modules-team] Bug#643873: Bug#643873: Making Numpy transition less painful

2011-11-01 Thread Jakub Wilk
* Sandro Tosi , 2011-11-01, 12:52: Dependencies generated by dh_numpy == dh_numpy would generate dependency either on "python-numpy-abi$N" (by default) or on "python-numpy-api$N" (if a special option, say, --strict, is used). I just realized that, in order to m

[Python-modules-team] Bug#647315: Security issue (no CVE yet)

2011-11-01 Thread Moritz Muehlenhoff
Package: python-django-piston Severity: grave Tags: security Please see https://www.djangoproject.com/weblog/2011/nov/01/piston-and-tastypie-security-releases/ Cheers, Moritz -- System Information: Debian Release: wheezy/sid APT prefers unstable APT policy: (500, 'unstable') Architec

[Python-modules-team] Bug#646517: Insecure use of pickle when deserializing POST/PUT input

2011-11-01 Thread Michael Ziegler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, I'm not quite sure how to fix this issue. From what I can tell from a few quick tests, your fix seems to work, but the pickle documentation itself states: > Never unpickle data received from an untrusted or unauthenticated source. So maybe th

[Python-modules-team] Processed: your mail

2011-11-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 646517 + pending Bug #646517 [python-django-piston] Insecure use of pickle when deserializing POST/PUT input Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 646517: http://bugs.debian.or

[Python-modules-team] Processed: reassign 647260 to python-qt4, forcibly merging 647210 647260

2011-11-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 647260 python-qt4 python-qt4/4.8.6-1 Bug #647260 [python-kde4] [python-kde4] Version mismatch between PyKDE4.plasma and PyQt4.QtCore Bug reassigned from package 'python-kde4' to 'python-qt4'. Bug No longer marked as found in versions pyk

[Python-modules-team] Bug#643873: Bug#643873: Making Numpy transition less painful

2011-11-01 Thread Sandro Tosi
On Mon, Oct 31, 2011 at 22:07, Jakub Wilk wrote: > * Sandro Tosi , 2011-10-31, 19:57: >>> >>> Dependencies generated by dh_numpy >>> == >>> dh_numpy would generate dependency either on "python-numpy-abi$N" (by >>> default) or on "python-numpy-api$N" (if a special op

[Python-modules-team] package sympy

2011-11-01 Thread Georges Khaznadar
Hello, I have fixed the file debian/watch for the package sympy, so it can detect now the version change in google's repositories, thanks to debian's proxying. The last version of the updated package is now sympy_0.7.1.rc1, I uploaded it to mentors.debian.net. I tried to retrieve our SNV, input