Skip to content

Update bundled setuptools provided by ensurepip in current 3.8.x through 3.11.x to include fix for CVE-2022-40897? #102202

@LianwMS

Description

@LianwMS

Just found the image are impacted. Any fix plan?
GHSA-r9hx-vwmv-q579

Linked PRs

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.10only security fixes3.8 (EOL)end of life3.9only security fixesrelease-blockerstdlibStandard Library Python modules in the Lib/ directorytopic-ensurepiptype-bugAn unexpected behavior, bug, or errortype-securityA security issue

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions