Skip to content

Vagrant: pin the venv's pip to a patched version - #1387

Merged
gusthoff merged 1 commit into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/python/pip-update/2026-09-26
Sep 26, 2026
Merged

gusthoff merged 1 commit into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/python/pip-update/2026-09-26

Conversation

@gusthoff

Copy link
Copy Markdown
Collaborator
  • pip-audit found six advisories.
  • Fixes for these land across pip 25.3 through 26.2.0.
  • Verified live on the epub VM: pip-audit now reports 0 vulnerabilities in /vagrant/venv, down from 6.

`pip-audit` found six advisories (PYSEC-2026-1795, PYSEC-2026-1796,
PYSEC-2026-196, PYSEC-2026-2875, PYSEC-2026-2876, PYSEC-2026-3721)
against pip 25.1.1, the version apt's `python3-pip` installs and that
`python3 -m venv` then carries into `/vagrant/venv` on both VMs.
Fixes for these land across pip 25.3 through 26.2.0.

CI already pins pip to 26.2.1 via `setup-python`'s `pip-version`
input (commit `f1faa480`), for the same reason this now applies here:
pip is the one tool that resolves every other pinned package, so
leaving it unpinned left the resolver itself as the only unpinned,
and in this case vulnerable, part of the environment. Add the
identical pin directly to both provisioning blocks, right after venv
creation and before installing `requirements_frozen.txt`.

This does not touch either requirements file: pip excludes itself
from its own freeze/compile output, so its version pin belongs
outside the dependency closure those files describe, the same way CI
already handles it.

Verified live on the epub VM: `pip-audit` now reports 0
vulnerabilities in `/vagrant/venv`, down from 6.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@gusthoff
gusthoff merged commit 36efa23 into AdaCore:main Sep 26, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant