◐ Shell
reader mode source ↗
Skip to content

gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py#151545

Merged
zooba merged 3 commits into
python:mainfrom
zooba:gh-151544
Jun 16, 2026
Merged

gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py#151545
zooba merged 3 commits into
python:mainfrom
zooba:gh-151544

Conversation

@zooba

@zooba zooba commented Jun 16, 2026

Copy link
Copy Markdown
Member

…ATH%/Modules/Setup.local for discovering sources in getpath.py
@zooba zooba added the 🔨 test-with-buildbots Test PR w/ buildbots; report in status section label Jun 16, 2026
@bedevere-bot

Copy link
Copy Markdown

🤖 New build scheduled with the buildbot fleet by @zooba for commit 70871e1 🤖

Results will be shown at:

https://buildbot.python.org/all/#/grid?branch=refs%2Fpull%2F151545%2Fmerge

If you want to schedule another build, you need to add the 🔨 test-with-buildbots label again.

@bedevere-bot bedevere-bot removed the 🔨 test-with-buildbots Test PR w/ buildbots; report in status section label Jun 16, 2026
@zooba

zooba commented Jun 16, 2026

Copy link
Copy Markdown
Member Author

!buildbot .*Android PR

@bedevere-bot

Copy link
Copy Markdown

🤖 New build scheduled with the buildbot fleet by @zooba for commit 70871e1 🤖

Results will be shown at:

https://buildbot.python.org/all/#/grid?branch=refs%2Fpull%2F151545%2Fmerge

The command will test the builders whose names match following regular expression: .*Android PR

The builders matched are:

  • AMD64 Android PR
  • aarch64 Android PR

@zooba

zooba commented Jun 16, 2026

Copy link
Copy Markdown
Member Author

Change has been reviewed separately with no concerns raised, and the buildbots are happy. We're not expediting releases for this one.

Hide details View details @zooba zooba merged commit 9e863fa into python:main Jun 16, 2026
187 of 191 checks passed
@miss-islington-app

Copy link
Copy Markdown

Thanks @zooba for the PR 🌮🎉.. I'm working now to backport this PR to: 3.11, 3.12, 3.13, 3.14, 3.15.
🐍🍒⛏🤖

@bedevere-app bedevere-app Bot removed the label Jun 16, 2026
@bedevere-app

bedevere-app Bot commented Jun 16, 2026

Copy link
Copy Markdown

GH-151564 is a backport of this pull request to the 3.15 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.15 pre-release feature fixes, bugs and security fixes label Jun 16, 2026
@bedevere-app

bedevere-app Bot commented Jun 16, 2026

Copy link
Copy Markdown

GH-151565 is a backport of this pull request to the 3.14 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.14 bugs and security fixes label Jun 16, 2026
@zooba zooba deleted the gh-151544 branch June 16, 2026 23:16
@bedevere-app

bedevere-app Bot commented Jun 16, 2026

Copy link
Copy Markdown

GH-151566 is a backport of this pull request to the 3.13 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.13 bugs and security fixes label Jun 16, 2026
@bedevere-app

bedevere-app Bot commented Jun 16, 2026

Copy link
Copy Markdown

GH-151567 is a backport of this pull request to the 3.12 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.12 only security fixes label Jun 16, 2026
@bedevere-app

bedevere-app Bot commented Jun 16, 2026

Copy link
Copy Markdown

GH-151568 is a backport of this pull request to the 3.11 branch.

@bedevere-app bedevere-app Bot removed the label Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants