Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MAINT, BLD: Update wheel and GitPython versions. #23130

Merged
merged 1 commit into from Jan 31, 2023

Conversation

charris
Copy link
Member

@charris charris commented Jan 30, 2023

This is motivated by Dependabot security alerts.

I don't recall if we need the wheel pin to 1.37.1, but suspect it was on account of 1.38.0 being buggy.

This is motivated by Dependabot security alerts.
@mattip
Copy link
Member

mattip commented Jan 31, 2023

If I recall correctly, in both wheel and gitpython the problem was that someone opened a CVE against those versions. The CVE themselves were questionable. In the case of gitpython, the maintainer did not even try to dispute it, and took the approach that the community reported it, so the community should fix it. For wheel, the maintainer put "vulnerability" in a commit message, which generated a CVE, and it took a few days for that commit to make it into a release. In the mean time that version was marked as "bad"

@mattip mattip merged commit b306531 into numpy:main Jan 31, 2023
@mattip
Copy link
Member

mattip commented Jan 31, 2023

Thanks @charris

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants