-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Overview
Zope Corporation has released a Zope hotfix product addressing a
potential vulnerability discovered during a recent security audit
of Zope 2.7 and 2.8.
Affected Versions
The hotfix affects versions 2.7.5 and earlier of Zope on the 2.7
release line, as well as versions 2.8a1 and 2.8a2 on the upcoming 2.8
release line. The vulnerability will be resolved in versions 2.7.6
and 2.8b1. We recommend that any site which permits untrusted users
to write PythonScripts apply this hotfix, and upgrade to a fixed
version of Zope as it becomes available.
Further Information
Please see the "product README",
http://www.zope.org/Products/Zope/Hotfix-2005-04-05/Hotfix-200405/README.txt
for details on the vulnerability, and for instructions on installing
the hotfix.
Downloading the Hotfix
- "Unix tarball",
http://www.zope.org/Products/Zope/Hotfix-2005-04-05/Hotfix-200405/Hotfix_20…
- "Windows ZIP archive",
http://www.zope.org/Products/Zope/Hotfix-2005-04-05/Hotfix-200405/Hotfix_20…
Tres Seaver.
- --
===============================================================
Tres Seaver tseaver(a)zope.com
Zope Corporation "Zope Dealers" http://www.zope.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFCUsvGGqWXf00rNCgRAt3qAJ42sH4BIPP9+S1g+ZnpwS9YopcggQCfYnvw
hXfT3SOxuL1y1adv5zmv3v8=
=smRT
-----END PGP SIGNATURE-----
Dear Zope Community,
on behalf of Zope Corporation and all Zope 2 developers and contributors
I am pleased to announce the release of Zope 2.8.0 a2
Zope 2.8.0 a2 can be downloaded from
http://www.zope.org/Products/Zope/2.8.0a2
The release notes can be found at
http://www.zope.org/Products/Zope/2.8.0a2/CHANGES.txt
For information on using Python 2.4 with Zope 2.8: see doc/INSTALL.txt
This release is a major step towards Zope 2.8.0 final (scheduled for May
2005) and now includes for the first time the "Five" framework to make some
Zope 3 technologies available within Zope 2. So you will be able to use Z3
technologies like interfaces, adapters, schemas and views within your Zope
2 installation and have hopefully the best from the Zope 2 and Zope 3 world.
Thanks to all who have worked on this release over the last weeks especially
Martijn, Jim, Tres and Tim.
Andreas Jung
Zope 2 Release Manager
I'm pleased to announce the release of ZODB 3.4 alpha 1. You can download a
source tarball or Windows installer from:
http://zope.org/Products/ZODB3.4
ZODB 3.4a1 contains all the bugfixes in the ZODB 3.3.1c1 released earlier
today, plus new features, such as a new BTree type mapping integers to
floats, an end to the limit on the number of open Connections per DB object,
and new tool fsoids.py for heavy FileStorage debugging. See
the news file for details:
http://zope.org/Products/ZODB3.4/NEWS.html
Note that ZODB 3.4 does not support any version of Zope 2.6 or 2.7. Zope
2.8a2 (to be released soon), and current Zope 3 development, use ZODB 3.4.
The ZODB 3.3 line will be retired with the release of ZODB 3.3.1 final.
I'm pleased to announce the release of ZODB 3.3.1c1. In the absence of new
critical bug reports, the same code will be released as ZODB 3.3.1 final in
a week or two. You can download a source tarball or Windows installer from:
http://zope.org/Products/ZODB3.3
There are several critical bugfixes and improvements in ZODB 3.3.1c1. See
the news file for details:
http://zope.org/Products/ZODB3.3/NEWS.html
Note that ZODB 3.3.1 does not support any version of Zope 2.6 or 2.7. Zope
2.8, and current Zope 3, development have moved to ZODB 3.4, so ZODB 3.3.1
final is expected to be the last release in the ZODB 3.3 line.
*What is it*
Zwiki is a Zope product for building wikis - a special kind of website
that's easy for anyone to edit.
See http://zwiki.org for more.
*What's changed*
Bugfixes, new japanese translation, chinese translation updates, new
search option.
See release notes below.
*Zwiki news this month*
We have been quiet but not idle. Bill Page and Martijn Pieters
contributed fixes, T.C. Chou updated the chinese translations and Masaya
Kato and a team of fellow translators contributed a japanese
translation. Zettai.net made a donation, again, in support of Zwiki
development and hosting. Thank you!
Bug reporting rate has been low and steady; bug closing rate has been
low. The next Zwiki Bug Day is.. today! april 1st being the first friday
of the month. I wasn't ready but it's going on anyway as scheduled, help
at http://zwiki.org/BugDay <http://zwiki.org/BugDay.> and #zwiki if you can.
In the documentation department I am doing a little work on
http://zwiki.org/NewAdministratorsGuide <http://zwiki.org/UsersGuide%29>
each day.
Discussion on the list, UserDiscussion page and irc channel has been
light. We've had a few incidents of wiki spam this month, both
intentional and otherwise. I switched zwiki.org to mail out all edits,
to make this more visible; we list subscribers are adapting to the
increased level of traffic and have discussed how to batch related edits
into fewer mails.
This month I resolved to focus on QA for 2005:
/"Alright.. this may be difficult, but (deep breath): I resolve not to
work on new Zwiki features in 2005. I may well accept them from others,
but I won't do them myself. This is to focus (my) energy on refactoring,
cleanup, polish, docs, and fixing "broken windows". More: /
* /in case that was unclear, this is not Zwiki winding down; it's a
quality push for 1.0. Feature work from others is welcome as ever./
* /tasks that are funded in some way will almost always jump to the
head of the queue and become priority no. 1, as before."/
See http://zwiki.org/ZwikiRoadmap2005 for more.
*Zopewiki news
*Edits on zopewiki.org have been light; small ongoing improvements from
a small number of people.
Someone has started a http://zopewiki.org/PageTemplateStyleGuide .
*Server news*
The zwiki.org/zopewiki.org server basically ran all month without
exceeding the 200M memory quota or restarting and performance has been
reasonable. Those wikis currently have 2164 and 464 pages respectively.
*About the Zwiki project*
Zwiki was started in 1999 by Simon Michael and now receives improvements
from many contributors. It is released under the GNU GPL. A new version
is released on the first of the month.
*Links*
http://zwiki.org - Zwiki home, with all download, documentation &
discussion links
http://zwiki.org/ZwikiFunding - how to donate or sponsor a feature
------------------------------------------------------------------------
*Release notes*
Zwiki 0.40.0 2005/04/01
Summary
Bugfixes, new japanese translation, chinese translation updates,
new search option.
Upgrade notes
This fixes a high-profile known issue in 0.39, #1062. If you
didn't already find the issue page and workaround, upgrade to this
version to fix it.
Changes
Browsing
* add a "thorough" non-catalog search to search form, commented
out (for spam hunting)
Editing
* fix the keys attribute error when creating pages in plone (#1062)
* deleting a top-level page redirects to the front page again; new
upUrl method (#917, Martijn Pieters, SM)
Issue tracking
* no bogus property change. Some very aggressive search engines
(spiders) seem to be following form action="xxxx" references in
pages as well as the usual href links. As a result probes by
such greedy theives can cause unexpected changes to wiki web
pages. One such example recently has been the triggering of the
Change button on the Issue pages. The script
changeIssueProperties should be more careful not to record any
change if the Change action is triggered with no actually
changes. (Bill Page)
General - i18n
* new japanese translation (Masaya Kato, Manabu Terada, Yoshiki
Shibukawa, Takayuki Shimizukawa, Junya Ogino, Takanori Suzuki)
* chinese translation updates (T.C. Chou)
* updated all po files from latest pot
General - skins
* the site_logo folder property didn't work in plone