Skip to content

Conversation

JelleZijlstra
Copy link
Member

@JelleZijlstra JelleZijlstra commented Sep 4, 2025

We got a security report on the typing-extensions version on one of these functions. I think it's generally to be expected that these functions can execute arbitrary code, but it can't hurt to make it explicit.


📚 Documentation preview 📚: https://cpython-previews--138508.org.readthedocs.build/

@JelleZijlstra JelleZijlstra merged commit 9158bcf into python:main Sep 5, 2025
27 checks passed
@github-project-automation github-project-automation bot moved this from Todo to Done in Docs PRs Sep 5, 2025
@JelleZijlstra JelleZijlstra deleted the annolib-security branch September 5, 2025 15:27
@JelleZijlstra JelleZijlstra added the needs backport to 3.14 bugs and security fixes label Sep 5, 2025
@miss-islington-app
Copy link

Thanks @JelleZijlstra for the PR 🌮🎉.. I'm working now to backport this PR to: 3.14.
🐍🍒⛏🤖

miss-islington pushed a commit to miss-islington/cpython that referenced this pull request Sep 5, 2025
(cherry picked from commit 9158bcf)

Co-authored-by: Jelle Zijlstra <[email protected]>
@bedevere-app
Copy link

bedevere-app bot commented Sep 5, 2025

GH-138550 is a backport of this pull request to the 3.14 branch.

@bedevere-app bedevere-app bot removed the needs backport to 3.14 bugs and security fixes label Sep 5, 2025
hugovk pushed a commit that referenced this pull request Sep 8, 2025
annotationlib: add note on security to docs (GH-138508)
(cherry picked from commit 9158bcf)

Co-authored-by: Jelle Zijlstra <[email protected]>
lkollar pushed a commit to lkollar/cpython that referenced this pull request Sep 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docs Documentation in the Doc dir skip issue skip news
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

5 participants