Skip to content

Conversation

@danlu1
Copy link
Contributor

@danlu1 danlu1 commented Jan 21, 2026

Problem:

The older version of setuptools pulls in jaraco.context 5.3.0, which results in a path traversal vulnerability flagged during code scanning.

Solution:

Upgrade setuptools to 80.10.1+ so it includes a patch for this issue.

@danlu1 danlu1 requested a review from a team as a code owner January 21, 2026 18:39
Copy link
Member

@BryanFauble BryanFauble left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Copy link
Member

@BryanFauble BryanFauble left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actually - Could you also update the pipfile.lock too?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants