Skip to content

Conversation

briensea
Copy link

gh-131860: Update bundled pip to address CVE-2023-5752

Summary:

This PR updates the bundled version of pip in CPython 3.9 to address CVE-2023-5752. The previous versions of pip included in these Python releases contained a security vulnerability that required users to manually update pip after creating a virtual environment.

Changes made:

  • Updated the bundled pip version in CPython 3.9 to the latest secure release.

Issue reference:

Closes gh-131860 (Update pip to address CVE-2023-5752)

@ghost
Copy link

ghost commented Mar 29, 2025

All commit authors signed the Contributor License Agreement.
CLA signed

@bedevere-app
Copy link

bedevere-app bot commented Mar 29, 2025

Most changes to Python require a NEWS entry. Add one using the blurb_it web app or the blurb command-line tool.

If this change has little impact on Python users, wait for a maintainer to apply the skip news label instead.

@picnixz picnixz changed the title Update pip version to 24.0. gh-131860: Update pip version to 24.0. Mar 29, 2025
@picnixz picnixz changed the title gh-131860: Update pip version to 24.0. gh-131860: Update bundled pip version to 24.0. Mar 29, 2025
@AA-Turner AA-Turner closed this Mar 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants