Skip to content

Require patched GitPython in test images - #439

Open
ibrahim halatci (ihalatci) wants to merge 1 commit into
developfrom
ihalatci-fix-dependency-vulnerabilities
Open

ibrahim halatci (ihalatci) wants to merge 1 commit into
developfrom
ihalatci-fix-dependency-vulnerabilities

Conversation

@ihalatci

Copy link
Copy Markdown
Contributor

Change

Require GitPython >=3.1.62 in test-images/scripts/requirements.in to cover GHSA-59cr-6r3x-644w. This is a single-line dependency change; test images compile their requirements during builds.

Packaging automation already requires and locks GitPython 3.1.62 and setuptools 83.0.0. Advisory metadata confirms setuptools 83.0.0 covers GHSA-5rjg-fvgr-3xxf and GHSA-h35f-9h28-mq5c, so no setuptools changes are needed.

Supersedes #430, whose proposed GitPython 3.1.61 remains affected. Does not replace #424 or #431.

Validation

Passed in an isolated WSL Python 3.10 environment:

  • Dependency manifest constraints.
  • Installation of GitPython 3.1.62 and setuptools 83.0.0; pip check.
  • GitPython init/add/commit/rev-parse smoke test.
  • Setuptools canonically equivalent Unicode filename exclusion regression.
  • git diff --check.

Temporary validation environment removed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d9fa99c-0382-4580-93c8-9cb21e1528bc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants