python311 py311-html-docs: updated to 3.11.17
3.11.17
Security
gh-158446: Fix a crash or incorrect output that could occur when formatting a float or complex with a precision close to the platform’s INT_MAX. PyOS_double_to_string() now raises ValueError for any precision of that magnitude, regardless of presentation type or value, as the format string parsers already did for precisions above INT_MAX.
gh-156793: asyncio: loop.start_tls() and loop.create_connection() now validate the server_hostname argument if an ssl.SSLContext is passed with check_hostname set to True, emitting DeprecationWarning if server_hostname is missing. (This will raise ValueError in Python 3.13 and later.)
gh-156793: ssl.SSLContext.wrap_bio() now validates its server_side, server_hostname and session arguments similar to ssl.SSLContext.wrap_socket(), but for backward compatiblity reasons emits DeprecationWarning instead of ValueError.
In particular, a context with check_hostname enabled and no server_hostname passed to wrap_bio() now emits DeprecationWarning to indicate the hostname wasn’t checked. (In Python 3.13 and later, this raises ValueError.)
gh-157265: In tarfile, when extracting a link falls back to extracting a member of the archive, skip the member when the filter function returns None when called with the extracted member’s name replaced with the link’s.
gh-157190: Fixed a vulnerability in the tarfile data and tar extraction filters where a crafted archive using a hard link to a symbolic link could change the permissions and modification time of a file outside the destination directory, and expose its contents inside the extracted tree. This addresses CVE 2026-82049.
gh-157953: Update bundled libexpat to version 2.8.5.
[14 lines not shown]
python312 py312-html-docs: updated to 3.12.15
3.12.15
Security
gh-158446: Fix a crash or incorrect output that could occur when formatting a float or complex with a precision close to the platform’s INT_MAX. PyOS_double_to_string() now raises ValueError for any precision of that magnitude, regardless of presentation type or value, as the format string parsers already did for precisions above INT_MAX.
gh-156793: asyncio: loop.start_tls() and loop.create_connection() now validate the server_hostname argument if an ssl.SSLContext is passed with check_hostname set to True, emitting DeprecationWarning if server_hostname is missing. (This will raise ValueError in Python 3.13 and later.)
gh-156793: ssl.SSLContext.wrap_bio() now validates its server_side, server_hostname and session arguments similar to ssl.SSLContext.wrap_socket(), but for backward compatiblity reasons emits DeprecationWarning instead of ValueError.
In particular, a context with check_hostname enabled and no server_hostname passed to wrap_bio() now emits DeprecationWarning to indicate the hostname wasn’t checked. (In Python 3.13 and later, this raises ValueError.)
gh-157265: In tarfile, when extracting a link falls back to extracting a member of the archive, skip the member when the filter function returns None when called with the extracted member’s name replaced with the link’s.
gh-157190: Fixed a vulnerability in the tarfile data and tar extraction filters where a crafted archive using a hard link to a symbolic link could change the permissions and modification time of a file outside the destination directory, and expose its contents inside the extracted tree. This addresses CVE 2026-82049.
gh-157953: Update bundled libexpat to version 2.8.5.
[14 lines not shown]
Add various Intel models (Lakefield, Granite Rapids, Arrow Lake, Panther Lake,
WildCat, Clearwater Forest, Sierra Forest, Lunar Lake).
Fix Yonah name (missing comma between Pentium and Core Duo).
Add few more AMD K8 models (Lima, Sherman, Windsor FX, Tyler, Richmond).
python313 py313-html-docs: updated to 3.13.16
3.13.16
macOS
gh-158010: Updated macOS installer to use OpenSSL 3.5.9, jumping from the 3.0 series to 3.5 after 3.0’s end of public support in September 2026.
Windows
gh-158010: Updated Windows builds to use OpenSSL 3.5.9, jumping from the 3.0 series to 3.5 after 3.0’s end of public support in September 2026.
gh-72353: Reading from the console on Windows now continues if the read was cancelled by Ctrl+C, but the SIGINT handler did not raise an exception. Previously the read ended as if at end of file.
gh-86427: Fix the encoding of the standard streams in the legacy Windows stdio mode (PYTHONLEGACYWINDOWSSTDIO). It is now the code page of the console, as in Python 3.7, not the ANSI code page.
gh-87587: os.device_encoding() on Windows now returns the code page of any console file descriptor, not only 0, 1 and 2, and returns None for other character devices like NUL. The UTF-8 code page is now reported as "utf-8" instead of "cp65001".
Tools/Demos
gh-113318: Fix Argument Clinic for @getter and @setter in a preprocessor conditional block. It failed with an internal error. Argument Clinic now also rejects the accessors of the same attribute with different C basenames, and the same accessor defined twice, which silently generated invalid or duplicated entries of PyGetSetDef.
Tests
gh-158051: The iOS testbed has been updated for compatibilty with Xcode 27.
gh-155997: Fix test.support.interpreters.list_all(). It failed if an interpreter was destroyed during the call, in particular by a garbage collection which finalized the object owning the last reference to it.
gh-75876: A test decorated with bigmemtest() now runs in a subprocess if it really allocates the memory it asks for (that is, if the -M option is used), so that the memory it uses and the address space it fragments are released when it ends. A dummy run stays in the process. The separate memory watchdog process is no longer used.
gh-155411: Fix test.support.subTests() for asynchronous test methods. They were wrapped in a synchronous function, which discarded the coroutine without awaiting it, so the test silently did not run at all.
gh-132581: The list of tests which altered the execution environment now includes the reasons why the environment was considered altered, for example an unraisable exception or a modified sys.path. The final result no longer repeats the same state twice (like ENV CHANGED then ENV CHANGED).
[125 lines not shown]
python314 py314-html-docs: updated to 3.14.8
3.14.8
Security
gh-158446: Fix a crash or incorrect output that could occur when formatting a float or complex with a precision close to the platform’s INT_MAX. PyOS_double_to_string() now raises ValueError for any precision of that magnitude, regardless of presentation type or value, as the format string parsers already did for precisions above INT_MAX.
gh-156793: asyncio: loop.start_tls() and loop.create_connection() now validate the server_hostname argument if an ssl.SSLContext is passed with check_hostname set to True.
gh-156793: ssl.SSLContext.wrap_bio() now validates its server_side, server_hostname and session arguments similar to ssl.SSLContext.wrap_socket().
In particular, a context with check_hostname enabled and no server_hostname passed to wrap_bio() now raises ValueError instead of completing a handshake that verified the certificate chain without verifying the peer’s identity, with no indication that the check had been skipped.
gh-157953: Update bundled libexpat to version 2.8.5.
gh-156002: Bound the amount of data zipfile decompresses per read for members compressed with bzip2, LZMA, or Zstandard, matching the existing limit for deflate. A small archive member could previously expand into an unbounded allocation even when read in small chunks.
gh-155999: Fix the tarfile tar and data extraction filters creating directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.
[125 lines not shown]
py-uvloop: updated to 0.23.0
0.23.0
Changes
Add Python 3.15 and 3.15t wheel builds and CI coverage
Add support for the eager_start keyword argument in create_task()
Add thread name prefix to the default thread pool executor
Add support for special hostname <broadcast>
Upgrade libuv to v1.52.1
Improve performance by using Python C API to enter/exit context
Improve performance/latency of Transport.write
Replace some SSL vectorcall with direct methods
Optimize SSL buffered reads using C values
Fixes
Detach socket on create_connection cancellation to prevent fd double-close
[14 lines not shown]
harfbuzz: updated to 14.5.1
Overview of changes leading to 14.5.1
- Map the `fonupa` (Uralic Phonetic Alphabet) BCP 47 variant to the `UPPH`
OpenType language system tag.
- Produce smaller `cmap` subtables and drop no-op variation device tables when
subsetting.
- Fix possible deadlock in `hb_font_destroy()` after `hb_ft_font_set_funcs()`,
a regression from 14.5.0.
- Fix signed integer overflows when scaling glyph extents and applying
synthetic slant and emboldening.
- Fix float-to-int overflow in `VARC` component axis coordinates with
malformed fonts.
- Fix a memory leak in the experimental WebAssembly shaper when shaping with
features.
- Fix accumulator overflows in the experimental raster library when rendering
glyphs with very many overlapping edges.
- Fix heap buffer overflow in the experimental GPU library with malicious
[2 lines not shown]
Fix overly aggressive rejection of valid servers.
Patch taken from https://bugs.ntp.org/3877 . This patch is likely to be
included in the next release.
Fixes PR bin/60831
rumdl: update to 0.2.78.
Added
MD013: add cjk-soft-break option to join CJK line breaks without a space (5b5a744)
MD013: reflow definition list definitions (f07ddc8)
Fixed
MD013: keep CJK sentences on separate lines in semantic-line-breaks mode (ea2798d)
MD013: join soft breaks in MkDocs admonitions and tabs with one space (962f1ee)
code-block-tools: invalidate cached results when a lint tool changes (5ff393b)
code-block-tools: treat empty formatter output as a tool failure (8e1a0e7)
code-block-tools: report lint tool failures at their block and honor on-error in check (9f3ea71)
playground: build the playground engine from the repository at deploy time (e342590)
keep each line's ending when fixing a file with mixed line endings (6491db8)
lsp: apply every content change in a didChange notification (499d132)
output: map rule severity onto GitLab Code Quality severity (9e795b9)
MD032: withhold blank lines that would change how the lists parse (0db96d9)
[64 lines not shown]
dnscontrol: Update to 5.3.0
Changelog
Breaking changes:
9710715: feat(M365_BUILDER)!: rewrite in Go and update the records to Microsoft's current requirements (#4936) (@jonathan8devs)
Provider-specific changes:
b719bca: feat(p/AZURE_PRIVATE_DNS): Add OIDC support / support same auth methods as AZURE_DNS (#4929) (@TomOnTime)
c65a9c4: feat(p/BUNNYDNS): add GeoDNS metadata support (#4941) (@xddxdd)
03db6d3: feat(p/BUNNYDNS): manage health monitoring features via dnsconfig.js (#4951) (@xddxdd)
794895e: feat(p/GCORE): add "golden file" tests (#4942) (@xddxdd)
5ea9471: feat(p/OPENPROVIDER): add Openprovider as a new provider (#4891) (@nvanlaerebeke)
333b7b1: fix(p/FORTIGATE): ask the TLS and HTTP debug settings as yes/no questions in init (#4878) (@cafferata)
e7e452f: fix(p/OPENPROVIDER): retry transient API failures with diagnostics (#4937) (@nvanlaerebeke)
c5fabaa: fix(p/REALTIMEREGISTER): ensure proper quoting of txt records (#4945) (@BigDataJohan)
New features:
7935ffd: feat: Add new PROVIDER()/REGISTRAR()/DNS_SERVICE() syntax (#4955) (@TomOnTime)
966e4cf: feat: NEW PROVIDER: MITTWALD (Mittwald mStudio provider) (#4933) (@twiesing)
9091ae9: feat: NEW PROVIDER: SPACESHIP (DNS provider and registrar) (#4921) (@rootful)
94a262d: feat: Normalize all "targethost" and hex-encoded fields (#4944) (@TomOnTime)
[14 lines not shown]