From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Fri, 17 Apr 2026 12:28:10 +0200 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wDgQj-00DA0j-2l for lore@lore.pengutronix.de; Fri, 17 Apr 2026 12:28:10 +0200 Received: from [127.0.0.1] (helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1wDgQj-0003X9-Mv; Fri, 17 Apr 2026 12:28:09 +0200 Received: from mo4-p00-ob.smtp.rzone.de ([81.169.146.161]) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1wDgQU-0003Vv-4l for ptxdist@pengutronix.de; Fri, 17 Apr 2026 12:27:54 +0200 ARC-Seal: i=1; a=rsa-sha256; t=1776421673; cv=none; d=strato.com; s=strato-dkim-0002; b=rpsmP0ftUi7983qwnc6ecpkY+z/5ZTEMYy8St61xWEZMvtDTyHpaVGdQMfif11J6NA lv3POXuOPeetFXKDUtPKV3l5p1cRTmsF03mES3whFknhPalzlzAOy0X/s28RadBbq1Ei 2J8zYZDXaE5M2jjpZgXn9onKO3XFrxLswwCFQnRHEoYBLsWZwZExKXXmLzBWLibaOl6u Vo2FkCSIMpABus4upDc4TayFZAcqRS6itlO7SKMN5K2G19a2/uE/xcamssmnJlTxGmph 1MXD092s9ChDLFf+xw0loLq4VOP8Eqd0VY2flo2PehojURzO6Q0RKoSixS87aVWqheVy P/VQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; t=1776421673; s=strato-dkim-0002; d=strato.com; h=Message-ID:Date:Subject:To:From:Cc:Date:From:Subject:Sender; bh=0FxqWyU1dqCLjxXxrkoYv4doxL8Y2G1jiAyYAdX9f1g=; b=ooli1TQCvSSyaaC/0B1O2rWA8+vuEJSoSFtQYnZV9h4jKUsMbWJspCTy9VEfNEVsHo vC5plKjff+8WME+uzvD6FnD4VBuAziC4DBglzA8B0eeJ7LInJLhv9uJgY4YSMjdeO/Cb 6tsYXOFsPJdySYVRHTIQ51LoiS5a2l6xuL/AmM/MUTZZLZb0n3mFgN/tcvVvUoYTbHPk Smx3FF9fBG6OJOobNcKHf1swXtU/BGQyNJ2WwSbySLd3CKk9w4ClM+zUwyNFBIGuqJ64 qVlHP3iGjTrrgxAcu8KuElJXYPWtQGHij3YoTtvOexJI4DleTs9iJDQY0tkO3nF95E5g XwFQ== ARC-Authentication-Results: i=1; strato.com; arc=none; dkim=none X-RZG-CLASS-ID: mo00 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1776421673; s=strato-dkim-0002; d=4wiebe.de; h=Message-ID:Date:Subject:To:From:Cc:Date:From:Subject:Sender; bh=0FxqWyU1dqCLjxXxrkoYv4doxL8Y2G1jiAyYAdX9f1g=; b=AX7QF3JB0+QbBb6D7f1vzvpVmAVtLHOWCh5xxxBxL7IzNU9bSAyUAMR9XoOjAXacYD 4xOuyLlPNWPbotQkFI+3QZ5fHyKXTe/EPt4ckFK+3UcFiKN5HIDWoHGXJblaIoeubzZH i5ezdQUDmWRvqaeNoTstw0ksVPOL5RfA2K0A+SEPHv68Iyk7HZNBGbVrPsN/rUeVtHrs K/GaHwvWhWnnJMXA/q6xoqCUnWk4zRLuzizd0YmTowA+KFX6dzmrDh/7FQ6BtltE1Pg3 oFecNErMbVr6l3UX0qem+fkjF7Vvb45iDNeWYGaJ9uOCj3Z4zH/N9a8s0Acx5xLvVHnH EYLA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; t=1776421673; s=strato-dkim-0003; d=4wiebe.de; h=Message-ID:Date:Subject:To:From:Cc:Date:From:Subject:Sender; bh=0FxqWyU1dqCLjxXxrkoYv4doxL8Y2G1jiAyYAdX9f1g=; b=G63SU2AAPtinCDT13ow7zE+Wb/7qRCzdRWNDFkF8FiQXqO6NUVtLeBEBVhA8T002w7 bkXni56JCu1CkgnzxCDQ== X-RZG-AUTH: ":Km0JfEyhft8wzIIhFLJpRLyPODuSc5X4exbVQe+uavLthqzsfqAYbr4lR6AnJJS2/A==" Received: from home by smtp.strato.de (RZmta 55.0.1 DYNA|AUTH) with ESMTPSA id 478a7e23HARrPTm (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256 bits)) (Client did not present a certificate) for ; Fri, 17 Apr 2026 12:27:53 +0200 (CEST) Received: from home (cloud.local [127.0.0.1]) by home (Postfix) with ESMTP id C42F51A0A13 for ; Fri, 17 Apr 2026 12:27:52 +0200 (CEST) To: ptxdist@pengutronix.de Date: Fri, 17 Apr 2026 12:27:45 +0200 Message-ID: <20260417102745.86171-1-artur@4wiebe.de> X-Mailer: git-send-email 2.53.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="us-ascii" X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on metis.whiteo.stw.pengutronix.de X-Spam-Level: X-Spam-Status: No, score=-2.5 required=4.0 tests=AWL,BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED,SPF_HELO_PASS,SPF_NONE autolearn=ham autolearn_force=no version=3.4.2 Subject: [ptxdist] [PATCH] python3-tornado: version bump 6.5.1 -> 6.5.5 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Artur Wiebe via ptxdist Reply-To: ptxdist@pengutronix.de Cc: Artur Wiebe Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Changes between 6.5.1 and 6.5.5: - 6.5.2: WebSocket ping interval fix, improved Host header handling, restored deprecated host argument on HTTPServerRequest, misc fixes. - 6.5.3: Security fixes for CVE-2025-67724 (header injection/XSS in set_status reason), CVE-2025-67725 (DoS via repeated HTTP headers), CVE-2025-67726 (DoS via multipart/form-data parsing). - 6.5.4: Restore case-insensitive "in" operator on HTTPHeaders (regression in 6.5.3). - 6.5.5: Security fixes: limit multipart/form-data to 100 parts by default, validate cookie domain/path/samesite arguments, reject CR in multipart headers. License unchanged (Apache-2.0). Signed-off-by: Artur Wiebe --- rules/python3-tornado.make | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/python3-tornado.make b/rules/python3-tornado.make index b70b63654..d364ef668 100644 --- a/rules/python3-tornado.make +++ b/rules/python3-tornado.make @@ -11,8 +11,8 @@ # PACKAGES-$(PTXCONF_PYTHON3_TORNADO) += python3-tornado -PYTHON3_TORNADO_VERSION := 6.5.1 -PYTHON3_TORNADO_MD5 := e3e3d74e2fedffacdacd8626d0c17a37 +PYTHON3_TORNADO_VERSION := 6.5.5 +PYTHON3_TORNADO_MD5 := 765aacc9cb8931aa66c8f3a83050120c PYTHON3_TORNADO := tornado-$(PYTHON3_TORNADO_VERSION) PYTHON3_TORNADO_SUFFIX := tar.gz PYTHON3_TORNADO_URL := $(call ptx/mirror-pypi, tornado, $(PYTHON3_TORNADO).$(PYTHON3_TORNADO_SUFFIX)) -- 2.53.0