pypa / setuptools

Official project repository for the Setuptools build system
https://pypi.org/project/setuptools/
MIT License
2.34k stars 1.14k forks source link

Undisclosed vulnerability #4331

Open jaraco opened 2 weeks ago

jaraco commented 2 weeks ago

On April 22, the Setuptools project received a report of a possible vulnerability through Tidelift. This issue tracks the repair and eventual disclosure of that vulnerability.

This issue affects deprecated portions of Setuptools and is not believed to affect the bulk of users, especially those reliant on modern packaging installers (e.g. pip).

Status: