importlib_metadata icon indicating copy to clipboard operation
importlib_metadata copied to clipboard

zipp version CVE-2024-5569

Open karistom opened this issue 1 year ago • 2 comments

To address CVE-2024-5569 vulnerability issue, updated zipp version.

Related git issue: https://github.com/python/importlib_metadata/issues/495

karistom avatar Jul 22 '24 03:07 karistom

@jaraco please review it, then build and test the change. Thanks.

karistom avatar Jul 22 '24 03:07 karistom

I updated the zipp clause.

karistom avatar Jul 22 '24 05:07 karistom

As discussed in #495, this isn't the right approach to take. importlib_metadata is compatible with the fixed version and will pick it up by default. It's up to downstream integrators to force the update if needed.

jaraco avatar Aug 19 '24 16:08 jaraco