Skip to content

Potential Vulnerability in Cloned Code#1446

Closed
ivanaclairineirsan wants to merge 1 commit into
chaquo:masterfrom
ivanaclairineirsan:fix/CVE-2023-5752
Closed

Potential Vulnerability in Cloned Code#1446
ivanaclairineirsan wants to merge 1 commit into
chaquo:masterfrom
ivanaclairineirsan:fix/CVE-2023-5752

Conversation

@ivanaclairineirsan
Copy link
Copy Markdown

This PR fixes a potential security vulnerability in product/gradle-plugin/src/main/python/pip/_internal/vcs/bazaar.py

###Details:
Affected File: product/gradle-plugin/src/main/python/pip/_internal/vcs/bazaar.py

Original Fix: pypa/pip@389cb79

###What this PR does:
This PR applies the same security patch that was applied to the original repository to eliminate the potential vulnerability in the cloned code.

###References:

@mhsmith
Copy link
Copy Markdown
Member

mhsmith commented Mar 13, 2026

Thanks, but there is no vulnerability in this context, because the pip command line is entirely under the control of the app developer.

@mhsmith mhsmith closed this Mar 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants