ci: update virtualenv to higher than 20.26.6 #128
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR aims to address a CVE-2024-53899 vulnerability detected on py_maidr.
Type of Change
Checklist
Pull Request
Description
The Github autoscan of the py_maidr repository identified a CVE-2024-53899 vulnerability with the repository. Upon further investigation, it was revealed that the issue is with virtualenv before 20.26.6 as it allows command injection through the activation scripts for a virtual environment.
Related Issues
GHSA-rqc4-2hc7-8c8v - Github Advisory's account of CVE-2024-53899.
Changes Made
Virtualenv has been bumped up to 20.28.1.