Skip to content

fix(deps): upgrade pip to 26.2.1 for security fix (dev only) - #246

Merged
matrixise merged 1 commit into
masterfrom
security/upgrade-pip
Sep 24, 2026
Merged

matrixise merged 1 commit into
masterfrom
security/upgrade-pip

Conversation

@matrixise

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades pip from 26.1.2 to 26.2.1 in requirements/dev.txt (transitive via pip-api, used by pip-audit)
  • Resolves 1 open medium Dependabot alert: pip would incorrectly handle doubly-encoded package URLs from indexes
  • Advisory: GHSA-qwm4-qh6w-59xr

Test plan

  • python manage.py test pythonie --settings=pythonie.settings.tests (SQLite, 7/7 passed)
  • ruff check pythonie clean

@matrixise
matrixise force-pushed the security/upgrade-pip branch 6 times, most recently from 165e3cb to f6a5293 Compare September 24, 2026 06:37
Resolves a medium severity Dependabot alert: pip would incorrectly
handle doubly-encoded package URLs from indexes. Transitive dev
dependency via pip-api (pip-audit).

GHSA-qwm4-qh6w-59xr

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant