FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[3.14] gh-135034: Normalize link targets in tarfile, add `os.path.realpath(strict='allow_missing')` (gh-135037) by ambv · Pull Request #135065 · python/cpython · GitHub

/ cpython Public

[3.14] gh-135034: Normalize link targets in tarfile, add os.path.realpath(strict='allow_missing') (gh-135037) - #135065

Merged
ambv merged 1 commit into
python:3.14from
ambv:backport-3612d8f-3.14
Jun 3, 2025
Merged

[3.14] gh-135034: Normalize link targets in tarfile, add os.path.realpath(strict='allow_missing') (gh-135037)#135065
ambv merged 1 commit into
python:3.14from
ambv:backport-3612d8f-3.14

Conversation

ambv commented Jun 3, 2025
edited by github-actions Bot
Loading

Copy link
Copy Markdown
Contributor

Addresses CVEs 2024-12718, 2025-4138, 2025-4330, and 2025-4517.

(cherry picked from commit 3612d8f)


📚 Documentation preview 📚: https://cpython-previews--135065.org.readthedocs.build/

…path(strict='allow_missing')` (python#135037)

Addresses CVEs 2024-12718, 2025-4138, 2025-4330, and 2025-4517.

Signed-off-by: Łukasz Langa <lukasz@langa.pl>
Co-authored-by: Petr Viktorin <encukou@gmail.com>
Co-authored-by: Seth Michael Larson <seth@python.org>
Co-authored-by: Adam Turner <9087854+AA-Turner@users.noreply.github.com>
Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
(cherry picked from commit 3612d8f)
ambv requested a review from ethanfurman as a code owner June 3, 2025 11:13
ambv changed the title gh-135034: Normalize link targets in tarfile, add os.path.realpath(strict='allow_missing') (gh-135037) [3.14] gh-135034: Normalize link targets in tarfile, add os.path.realpath(strict='allow_missing') (gh-135037) Jun 3, 2025
ambv merged commit 9e0ac76 into python:3.14 Jun 3, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL