Skip to content

build: bump virtualenv to 21.14.5 in uv.lock to clear eight advisories - #26

Merged
man8 merged 1 commit into
mainfrom
bump-virtualenv-lockfile
Oct 6, 2026
Merged

man8 merged 1 commit into
mainfrom
bump-virtualenv-lockfile

Conversation

@man8-octoflow

@man8-octoflow man8-octoflow Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

pip-audit reports eight advisories (four distinct, each listed twice) in virtualenv 21.7.0, which fails the audit job on every pull request. The advisories are PYSEC-2026-4011 and -4014 (fixed in 21.7.12), -4012 (fixed in 21.7.11) and -4013 (fixed in 21.7.13). This bumps the lockfile past all of them.

Changes

  • uv lock --upgrade-package virtualenv: virtualenv 21.7.0 to 21.14.5, and its dependency python-discovery 1.5.0 to 1.6.1. uv.lock only (7 insertions, 7 deletions).
  • pyproject.toml is unchanged.

Testing

  • uv tree --invert --package virtualenv: virtualenv is reached only through pre-commit in the dev extra, so the library's runtime dependencies are not affected.
  • uv export --all-extras --no-emit-project --format requirements-txt then pip-audit --strict --no-deps --disable-pip: before, exit 1 with 8 known vulnerabilities in virtualenv 21.7.0; after, exit 0, "No known vulnerabilities found".
  • ruff check, ruff format --check, mypy --strict src, pytest -q (1506 passed) and pre-commit run --all-files at both the pre-commit and pre-push stages all pass on the bumped lockfile.

Context

Development tooling only, no runtime or API change, so no changelog entry.

Checklist

  • uv run ruff check . and uv run ruff format --check . pass
  • uv run mypy --strict src passes
  • uv run pytest -q passes and coverage stays at or above 90%
  • uv run pre-commit run --all-files --hook-stage pre-commit passes
  • uv run pre-commit run --all-files --hook-stage pre-push passes
  • [~] New public functions, methods, and classes have docstrings
  • No real credentials, tokens, or PII are added to the diff
  • [~] TODO/FIXME/HACK/XXX markers name an issue (e.g. TODO(#123))

🤖 Generated with Claude Code

pip-audit reports eight advisories (four distinct, each listed twice) in
virtualenv 21.7.0, fixed in 21.7.11 to 21.7.13. `uv lock --upgrade-package
virtualenv` moves virtualenv to 21.14.5 and its dependency python-discovery to
1.6.1. pyproject.toml is unchanged. virtualenv is reached only through
pre-commit in the dev extra, so the library's runtime path is not affected.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@man8-octoflow
man8-octoflow Bot requested a review from man8 as a code owner October 6, 2026 12:07
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: man8/targetprocess-py/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: ea607e24-7eed-40f7-8fc6-c417fe4965ed

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@man8
man8 merged commit 6de1b5a into main Oct 6, 2026
8 checks passed
@man8
man8 deleted the bump-virtualenv-lockfile branch October 6, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant