This update for python3 fixes the following issue:
%action can pass the dash-prefix safety check and allow for command injection
(bsc#1262319).BaseCookie.js_output() does not neutralize characters in cookie values embedded in JS (bsc#1262654).lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile when process is
under memory pressure(bsc#1262098).