Skip to content

Add wheel-0.47.0 to seed packages as mitigation of CVE-2026-24049#3167

Merged
gaborbernat merged 2 commits into
pypa:mainfrom
apophizzz:apophizzz/seeding/wheel-0.47.0
Jun 11, 2026
Merged

Add wheel-0.47.0 to seed packages as mitigation of CVE-2026-24049#3167
gaborbernat merged 2 commits into
pypa:mainfrom
apophizzz:apophizzz/seeding/wheel-0.47.0

Conversation

@apophizzz

Copy link
Copy Markdown
Contributor

Hi!

Me and my team ran into the issue that even with the latest version of virtualenv each venv gets seeded with wheel 0.45.1, which is vulnerable in terms of CVE-2026-24049.
This PR adds the most current version of the wheel package to the list of seeding packages at the time this PR was authored.

@gaborbernat gaborbernat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@gaborbernat gaborbernat merged commit 5389c25 into pypa:main Jun 11, 2026
58 checks passed
@apophizzz apophizzz deleted the apophizzz/seeding/wheel-0.47.0 branch June 11, 2026 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants