From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id d05YCtj1AWDJQwAA0tVLHw (envelope-from ) for ; Fri, 15 Jan 2021 20:06:48 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id 4MTDBdj1AWA2WwAA1q6Kng (envelope-from ) for ; Fri, 15 Jan 2021 20:06:48 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 6D8D89404C9 for ; Fri, 15 Jan 2021 20:06:47 +0000 (UTC) Received: from localhost ([::1]:46876 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1l0VMq-0004fT-Pp for larch@yhetil.org; Fri, 15 Jan 2021 15:06:44 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:46214) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1l0VMU-0004UD-KE for help-guix@gnu.org; Fri, 15 Jan 2021 15:06:22 -0500 Received: from mail-qk1-x734.google.com ([2607:f8b0:4864:20::734]:36173) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1l0VMQ-0005Fm-HJ for help-guix@gnu.org; Fri, 15 Jan 2021 15:06:22 -0500 Received: by mail-qk1-x734.google.com with SMTP id 186so12911614qkj.3 for ; Fri, 15 Jan 2021 12:06:17 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=5tEKbefdKDkWe8ichQTEbY1mbTUJt9UM5F5Q9fDF5lw=; b=rd4wbtDd2Gm5ziMxPR6jjIYF0mNn1hqmckOvGp+WYAAD45Ic+KQ5MYcc7c1PB3B9Sl PlhlRTjzfKrhIIEEs8EyccAUWMQXJo1e1rk30hlmBE6+2Ho67yi07KDkluNItFpoNxKm /7jTaYyFENp4NAHR/dti17eVJlKEfwNHn5ZgPuxgcM6ZTk3Ri2hqgDeL2eEEW99mXrF4 dgyflb0bxXj82JA6aTgup7DVlWYZw7UDzi4BFsXABARwnJIAtRcExlGNqfbKlTg3yUu7 aNoPWQZBLG9s5wKXvICf/VkQBVvl1WVqg+JjBXSMrb/JPHGGEzPJhBa3wgZ0ERE7Nxrp Drfw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=5tEKbefdKDkWe8ichQTEbY1mbTUJt9UM5F5Q9fDF5lw=; b=QQt21z5vC3QixpiA5W6QtgKbFAEPb5pZfYB9iWFQyWOfM1V7jA7b6vwkfDDIicf6A9 1QUgnjKjaKRELB8dcVc3AP285dqzh7hyIxh+pCeDgulohUFaf2jh+IwHWhhz/aYG0sE7 KgZ6LTvJgx70sg9ilOtd0pS5hZT2eoKOx8W73S+D9C/iUd5PepF66//LC/hgDIaMBc9J UoOWSQ8B8awGSi36GZ0ZDF7y3dsILQ2toIuhDFmpHapIgz7ks20zGVeq/BIODnCJdkSb a38X11cf470XyDDrwX+51pC9F/WS4raIMB6ZgXp2eJY3V3L1T0q3fGX8w7nL9h9fmZ4C QJMw== X-Gm-Message-State: AOAM530Odx9N+2DanYFJotKVTFiB6J6prKpiI6Glbs5DWOHGfJz144Dc fjcARz2bjBiOAleFvf/kgEiRRMQuDCbn7QGgWGk= X-Google-Smtp-Source: ABdhPJy5DygRAOsUFmNStDQbvBVtKgwx6CqHJCDoMVoDLYKuGKSQx1ZazJQiYc7BDc+VWANtAuawVrHSDjG8BbhzI+0= X-Received: by 2002:a37:a64b:: with SMTP id p72mr14469154qke.304.1610741176598; Fri, 15 Jan 2021 12:06:16 -0800 (PST) MIME-Version: 1.0 References: <87ft325gws.fsf@disroot.org> <87czy65dbi.fsf@disroot.org> In-Reply-To: <87czy65dbi.fsf@disroot.org> From: zimoun Date: Fri, 15 Jan 2021 21:06:05 +0100 Message-ID: Subject: Re: Does Guix provide security support for Python2? For how long? To: zimoun , help-guix Content-Type: text/plain; charset="UTF-8" Received-SPF: pass client-ip=2607:f8b0:4864:20::734; envelope-from=zimon.toutoune@gmail.com; helo=mail-qk1-x734.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: help-guix@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: help-guix-bounces+larch=yhetil.org@gnu.org Sender: "Help-Guix" X-Migadu-Flow: FLOW_IN X-Migadu-Spam-Score: -2.06 Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=gmail.com header.s=20161025 header.b=rd4wbtDd; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (aspmx1.migadu.com: domain of help-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=help-guix-bounces@gnu.org X-Migadu-Queue-Id: 6D8D89404C9 X-Spam-Score: -2.06 X-Migadu-Scanner: scn0.migadu.com X-TUID: jH1CC2I8NG7j Hi, On Fri, 15 Jan 2021 at 18:18, Jorge P. de Morais Neto wrote: > Em [2021-01-15 sex 18:07:40+0100], zimoun escreveu: > > > As far as I know, Guix provides the security support that upstream > > releases. > > I too suppose so in general. But I would like a more authoritative > answer for the specific case of Python2. And, in fact, this should be > publicly documented---in the manual or in the website, as well as the > description of the python2 package and maybe also in the description of > all python2-.* packages. As far I know, Python 2 is End Of Life and not supported upstream. Therefore, if your question is: will Guix people fix Python 2 security? Then the answer is no. However, please indicate if an organization is still maintaining Python 2 and maybe Guix could package their release. > > Using the Guix time-machine, the code that works now should work > > exactly the same in the future, even if Python 2 is removed in the > > future Guix releases. Does it make sense? > > The problem is that OfflineIMAP is Internet software, and therefore, I > believe, it is important to have security support for it (including its > dependencies). In this case, please consider to switch from OfflineIMAP to something else. Guix is about packaging, not supporting security from deprecated upstream. All the best, simon