Page MenuHomePhabricator

Toolforge bastion hosts need updated python
Closed, InvalidPublic

Description

login.toolforge.org and dev.toolforge.org are both running python 3.7.3. This is several bugfix/security releases behind 3.7.9, which is the final release of the 3.7 series which reached end-of-life 3-1/2 years ago.

Event Timeline

Actually, I said that wrong. 3.7.10 - 3.7.17 are all security releases that came out after 3.7.9. So we're behind 8 security releases.

taavi subscribed.

We rely on Debian for security updates, the last time python3.7 was updated was in October. Once https://wikitech.wikimedia.org/wiki/News/Toolforge_Grid_Engine_deprecation is complete the bastions can be upgraded to newer Debian and so newer Python 3.x releases.