My reason for wondering this is that once again a Python vulnerability has appeared and once again (I presume) various port developers will be struggling (or being urged to struggle) with checking their applications against the required upgrade before that upgrade can be released, resulting in a long wait before servers get upgraded to cover the vulnerability. In the meantime, presumably, some machines remain at risk.
I realise porters are not necessarily the developers of the software they package, but it does raise the question of whether dependency on a language version is really good programming practice and whether we should encourage compiled alternatives wherever possible.
What do others think?
I realise porters are not necessarily the developers of the software they package, but it does raise the question of whether dependency on a language version is really good programming practice and whether we should encourage compiled alternatives wherever possible.
What do others think?