Skip to content

Conversation

@fosterseth
Copy link
Member

@fosterseth fosterseth commented Jan 29, 2026

SUMMARY

Bump wheel to address CVE-2026-24049

ISSUE TYPE
  • Bug, Docs Fix or other nominal change
COMPONENT NAME
  • API

Note

Low Risk
Dependency-only bump of wheel in build/venv bootstrap and pinned requirements; low behavioral risk but could affect packaging/build edge cases.

Overview
Updates the wheel dependency to newer patched versions to address CVE-2026-24049.

This bumps wheel in requirements.in (and regenerates requirements.txt pins) and also updates the venv bootstrap toolchain in the Makefile so newly created venvs install the updated wheel.

Written by Cursor Bugbot for commit 292262e. This will update automatically on new commits. Configure here.

@github-actions github-actions bot added the dependencies Pull requests that update a dependency file label Jan 29, 2026
Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Signed-off-by: Seth Foster <fosterbseth@gmail.com>
@sonarqubecloud
Copy link

@fosterseth fosterseth enabled auto-merge (squash) February 5, 2026 19:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant