Re: Next LTS version after 1.4?

2014-11-05 Thread Rob Yates
On Monday, August 25, 2014 6:10:52 AM UTC-4, Aymeric Augustin wrote: > > > 1.4 is LTS until March 2015. Based on past release schedules, 1.8 should > be released a few months later. > > We could extend 1.4 support a bit and then make 1.8 the next LTS. In my > opinion, that's the most reasonable p

Re: Security Advisory: BREACH and Django

2013-08-06 Thread Rob Yates
This is a fascinating attack. I scanned all of the information that I could find and it wasn't clear how this could be used to breach CSRF protection. Is there more detail somewhere on that specific attack vector? -Rob On Tuesday, August 6, 2013 10:42:01 AM UTC-4, Jacob Kaplan-Moss wrote: