Skip to content

Upgrade GitPython to resolve GHSA-2f96-g7mh-g2hx GHSA-v396-v7q4-x2qj GHSA-956x-8gvw-wg5v#599

Merged
cigamit merged 1 commit into
mainfrom
GHSA-2f96-g7mh-g2hx
Jul 21, 2026
Merged

Upgrade GitPython to resolve GHSA-2f96-g7mh-g2hx GHSA-v396-v7q4-x2qj GHSA-956x-8gvw-wg5v#599
cigamit merged 1 commit into
mainfrom
GHSA-2f96-g7mh-g2hx

Conversation

@cigamit

@cigamit cigamit commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@cigamit
cigamit requested a review from TheWitness July 21, 2026 20:46
@cigamit cigamit self-assigned this Jul 21, 2026
Copilot AI review requested due to automatic review settings July 21, 2026 20:46
@cigamit cigamit added dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically python Pull requests that update python code labels Jul 21, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the project’s GitPython dependency to address the listed GitHub Security Advisories, ensuring the dependency set includes a non-vulnerable GitPython version while keeping the compiled/pinned requirements in sync.

Changes:

  • Bump the pinned gitpython version in requirements/requirements.txt to 3.1.53.
  • Raise the minimum GitPython version in requirements/requirements.in to >=3.1.51 and update the referenced GHSA IDs accordingly.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
requirements/requirements.txt Updates the pinned GitPython version to 3.1.53 to pull in security fixes.
requirements/requirements.in Raises the minimum GitPython constraint to >=3.1.51 to meet the advisory fix floor and updates the GHSA references.

@cigamit
cigamit merged commit deb7fd4 into main Jul 21, 2026
1 check passed
@cigamit
cigamit deleted the GHSA-2f96-g7mh-g2hx branch July 21, 2026 22:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants