Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <B3DBB52A-914E-40AB-973C-D06A6A320723@stufft.io>
Date: Sat, 27 Jul 2013 03:29:06 -0400
From: Donald Stufft <donald@...fft.io>
To: oss-security@...ts.openwall.com
Cc: kseifried@...hat.com
Subject: Re: CVE Request: Insecure Software Download in pip


If it helps at all this is the commit that introduced initial support for it (where it explicitly calls out PEP381)

https://github.com/pypa/pip/commit/e80c387a26858c4d7ff43c5f030b04b03fd43dfe

-----------------
Donald Stufft
PGP: 0x6E3CBCE93372DCFA // 7C6B 7C5D 5E2B 6356 A926 F04F 6E3C BCE9 3372 DCFA


Download attachment "signature.asc" of type "application/pgp-signature" (842 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.