[MEDIUM] Upgrade python-virtualenv to 20.36.1 for CVE-2026-22702#15507
Conversation
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
There are no breaking changes on the API side as per the changelog, this release needs Python to 3.8+ and we already have 3.10
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
remove the CVE-2024-53899.patch file from SPEC folder
Removed |
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
LGTM. Buddy Build is fine. Source Tarball Uploaded to blob.
|
As per the AI summary, Upgraded Embedded Seed Packages Specific Behavioral Fixes & Changes If you are upgrading from 20.25 to 20.36, it is highly recommended to recreate your virtual environments to ensure compatibility with the updated embedded pip and setuptools versions. Could you please reverify once if everything is fine in upgrade? |
|
I feel there is no breaking changes according to changelogs. Co-pilot also suggested no breaking changes. |
kgodara912
left a comment
There was a problem hiding this comment.
Considering no breaking changes from the original version as most of the summary says that no need to recreate existing environments and it should work as is. Buddy build is successful. LGTM.
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Upgrade python-virtualenv to 20.36.1 for CVE-2026-22702
Reference: #15494
Change Log
Does this affect the toolchain?
NO
Links to CVEs
Test Methodology
Build and test is successful
