Skip to content

Commit

Permalink
Version 6.3.2
Browse files Browse the repository at this point in the history
  • Loading branch information
bdarnell committed May 14, 2023
1 parent 89aacf1 commit f41d78d
Show file tree
Hide file tree
Showing 2 changed files with 12 additions and 0 deletions.
1 change: 1 addition & 0 deletions docs/releases.rst
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ Release notes
.. toctree::
:maxdepth: 2

releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
Expand Down
11 changes: 11 additions & 0 deletions docs/releases/v6.3.2.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
What's new in Tornado 6.3.2
===========================

May 13, 2023
------------

Security improvements
~~~~~~~~~~~~~~~~~~~~~

- Fixed an open redirect vulnerability in StaticFileHandler under certain
configurations.

3 comments on commit f41d78d

@kloczek
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it possible to make giuthub releases on release new version? 🤔
https://github.com/tornadoweb/tornado/tags is empty and only on GH releases is spread notification to those who have st watch->releases.

Thx.

@bdarnell
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our distribution mechanism is PyPI, not github releases, and this will always remain the authoritative source as the standard for the python ecosystem. I do not want to set up another non-authoritative distribution system just to support different notification workflows. I recommend you use one of the services that can send notifications based on updates to PyPI packages.

@kloczek
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This requrest is not about diostribution but spreading notyfications.

Please sign in to comment.