| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
|
Thank you for contributing! 👋 |
Sorry, something went wrong.
|
Thank you for contributing! 👋 |
Sorry, something went wrong.
|
Thank you for contributing! 👋 |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
This PR contains the following updates:
CVE-2026-7246 / GHSA-47fr-3ffg-hgmw / PYSEC-2026-2132
More informationDetails
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Severity
References
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
Release Notes
pallets/click (click)v8.3.3
Compare Source
v8.3.2
Compare Source
Released 2026-04-02
used without an explicit value. :issue:3084 :pr:3152
:issue:3136 :pr:3199 :pr:3202 :pr:3209 :pr:3212 :pr:3224
:issue:824 :issue:2991 :issue:2993 :issue:3110 :pr:3139 :pr:3140
logging interaction, multi-threaded safety, and sequential invocation
isolation. Add high-iteration stress tests behind a stress marker
with a dedicated CI job. :pr:3139
default=True. :issue:3121 :pr:3201 :pr:3213 :pr:3225
v8.3.1
Compare Source
This is the Click 8.3.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.
PyPI: https://pypi.org/project/click/8.3.1/
Changes: https://click.palletsprojects.com/page/changes/#version-8-3-1
Milestone: https://github.com/pallets/click/milestone/28
v8.3.0
Compare Source
Released 2025-09-17
Improved flag option handling: Reworked the relationship between flag_value
and default parameters for better consistency:
to CLI functions (no more unexpected transformations)
by defaulting to their flag_value
:issue:3024 :pr:3030
Allow default to be set on Argument for nargs = -1. :issue:2164
:pr:3030
Show correct auto complete value for nargs option in combination with flag
option :issue:2813
Fix handling of quoted and escaped parameters in Fish autocompletion. :issue:2995 :pr:3013
Lazily import shutil. :pr:3023
Properly forward exception information to resources registered with
click.core.Context.with_resource(). :issue:2447 :pr:3058
Fix regression related to EOF handling in CliRunner. :issue:2939 :pr:2940
v8.2.2
Compare Source
Released 2025-07-31
flag options, as well as parsing and normalization of environment variables.
:issue:2952 :pr:2956
parameter param_hint that did not allow for a sequence of string where the
underlying function _join_param_hints allows for it. :issue:2777 :pr:2990
screen. Refs :issue:2911 :pr:3004
colons. :issue:2703 :pr:2846
as a ValueError on close in a multi-threaded test session.
:issue:2993 :pr:2991
v8.2.1
Compare Source
Released 2025-05-20
:issue:2897 :pr:2930
v8.2.0
Compare Source
Released 2025-05-10
Drop support for Python 3.7, 3.8, and 3.9. :pr:2588 :pr:2893
Use modern packaging metadata with pyproject.toml instead of setup.cfg.
:pr:2438
Use flit_core instead of setuptools as build backend. :pr:2543
Deprecate the __version__ attribute. Use feature detection, or
importlib.metadata.version("click"), instead. :issue:2598
BaseCommand is deprecated. Command is the base class for all
commands. :issue:2589
MultiCommand is deprecated. Group is the base class for all group
commands. :issue:2590
The current parser and related classes and methods, are deprecated.
:issue:2205
optparse in the standard library.
remaining arguments while parsing.
unneeded. Parsing works directly without building a separate parser.
Enable deferred evaluation of annotations with
from __future__ import annotations. :pr:2270
When generating a command's name from a decorated function's name, the
suffixes _command, _cmd, _group, and _grp are removed.
:issue:2322
Show the types.ParamType.name for types.Choice options within
--help message if show_choices=False is specified.
:issue:2356
Do not display default values in prompts when Option.show_default is
False. :pr:2509
Add get_help_extra method on Option to fetch the generated extra
items used in get_help_record to render help text. :issue:2516
:pr:2517
Keep stdout and stderr streams independent in CliRunner. Always
collect stderr output and never raise an exception. Add a new
output stream to simulate what the user sees in its terminal. Removes
the mix_stderr parameter in CliRunner. :issue:2522 :pr:2523
Option.show_envvar now also shows environment variable in error messages.
:issue:2695 :pr:2696
Context.close will be called on exit. This results in all
Context.call_on_close callbacks and context managers added via
Context.with_resource to be closed on exit as well. :pr:2680
Add ProgressBar(hidden: bool) to allow hiding the progressbar. :issue:2609
A UserWarning will be shown when multiple parameters attempt to use the
same name. :issue:2396
When using Option.envvar with Option.flag_value, the flag_value
will always be used instead of the value of the environment variable.
:issue:2746 :pr:2788
Add Choice.get_invalid_choice_message method for customizing the
invalid choice message. :issue:2621 :pr:2622
If help is shown because no_args_is_help is enabled (defaults to True
for groups, False for commands), the exit code is 2 instead of 0.
:issue:1489 :pr:1489
Contexts created during shell completion are closed properly, fixing
a ResourceWarning when using click.File. :issue:2644 :pr:2800
:pr:2767
click.edit(filename) now supports passing an iterable of filenames in
case the editor supports editing multiple files at once. Its return type
is now also typed: AnyStr if text is passed, otherwise None.
:issue:2067 :pr:2068
Specialized typing of progressbar(length=...) as ProgressBar[int].
:pr:2630
Improve echo_via_pager behaviour in face of errors.
:issue:2674
raises an exception.
to terminate.
allows the user to search for future output of the generator when
using less and then aborting the program using ctrl-c.
deprecated: bool | str can now be used on options and arguments. This
previously was only available for Command. The message can now also be
customised by using a str instead of a bool. :issue:2263 :pr:2271
(Deprecated) help to help (DEPRECATED).
Add a catch_exceptions parameter to CliRunner. If
catch_exceptions is not passed to CliRunner.invoke, the value
from CliRunner is used. :issue:2817 :pr:2818
Option.flag_value will no longer have a default value set based on
Option.default if Option.is_flag is False. This results in
Option.default not needing to implement __bool__. :pr:2829
Incorrect click.edit typing has been corrected. :pr:2804
Choice is now generic and supports any iterable value.
This allows you to use enums and other non-str values. :pr:2796
:issue:605
Fix setup of help option's defaults when using a custom class on its
decorator. Removes HelpOption. :issue:2832 :pr:2840
Configuration
📅 Schedule: (in timezone US/Central)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.