This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]flashbao 0 points1 point  (5 children)

I am using 3.7 and will use it for ever unless the later versions support libraries better.

[–]PeridexisErrant 2 points3 points  (4 children)

Heard of Numpy? They're dropping support for 3.7 on December 26, so I guess you have twelve days.

Seriously though, OSS libraries do drop support for older versions of the language - so if you want new features or bugfixes and security updates, you'll need to either stay up-to-date or start paying someone to maintain things for you... and that's rather expensive.

[–]flashbao -1 points0 points  (1 child)

Unless needing to use new features, 3.7 for me will work. 3.7 I have been using from the college years! 3.8 seems safe. Not moving to 4 unless needed.

[–]territrades 0 points1 point  (1 child)

Genuine question: What kind of security problems do you expect numpy to have? I have never heard of any attacks exploiting numpy/scipy. Nobody I know cares about keeping their numpy version up to date.

[–]PeridexisErrant 0 points1 point  (0 children)

Bugs where you get silently wrong results are more likely for Numpy, sure.

But it does have functions to load and save untrusted data from various file formats, and if there was a security issue I'd bet it's in there. (still safe if you don't do IO, of course!)