Hi,
I'd like to make a stable upload for urwid, fixing CVE-2026-9323.
The sec team marked it as no-DSA hence proposing stabe upload.
I have manually tested the code and also uploaded to debusine for qa
checks.
The change is only two line. Dropped the `random` module and added
`secrets` and then backported compatible way since upstream patch
wont' fix exactly.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable