-
-
Notifications
You must be signed in to change notification settings - Fork 17.2k
uv: fix CVE-2025-62518 #454422
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
uv: fix CVE-2025-62518 #454422
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This report is automatically generated by the PR / Check / cherry-pick CI workflow.
Some of the commits in this PR require the author's and reviewer's attention.
Please follow the backporting guidelines and cherry-pick with the -x flag.
This requires changes to the unstable master and staging branches first, before backporting them.
Occasionally, commits are not cherry-picked at all, for example when updating minor versions of packages which have already advanced to the next major on unstable.
These commits can optionally be marked with a Not-cherry-picked-because: <reason> footer.
If you need to merge this PR despite the warnings, please dismiss this review shortly before merging.
Warning
Couldn't locate original commit hash in message of 000b8ec.
Hint: The full diffs are also available in the runner logs with slightly better highlighting.
We patch rather than bump the version.
000b8ec to
b36e88b
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This report is automatically generated by the PR / Check / cherry-pick CI workflow.
Some of the commits in this PR require the author's and reviewer's attention.
Please follow the backporting guidelines and cherry-pick with the -x flag.
This requires changes to the unstable master and staging branches first, before backporting them.
Occasionally, commits are not cherry-picked at all, for example when updating minor versions of packages which have already advanced to the next major on unstable.
These commits can optionally be marked with a Not-cherry-picked-because: <reason> footer.
If you need to merge this PR despite the warnings, please dismiss this review shortly before merging.
Warning
Couldn't locate original commit hash in message of a1d2687.
Hint: The full diffs are also available in the runner logs with slightly better highlighting.
b36e88b to
a1d2687
Compare
Prince213
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Built on x86_64-linux:
/nix/store/y6k316mbyp9g4m2m0j09m15y24c6yxc6-uv-0.7.22
/nix/store/fa6daxbcalxx6nj67ixmfbin108i65nm-python3.12-uv-0.7.22
/nix/store/gp400286199h6pvgwv0sp54gx7p9vmc4-python3.12-uv-build-0.7.22
We patch rather than bump the version.
b0a2466
Related to:
Things done
passthru.tests.nixpkgs-reviewon this PR. See nixpkgs-review usage../result/bin/.Add a 👍 reaction to pull requests you find important.