Skip to content

fix: secure pip tooling while preserving frozen v1 evidence - #59

Merged
AlbertXXuu merged 1 commit into
mainfrom
fix/pip-security-maintenance
Sep 4, 2026
Merged

AlbertXXuu merged 1 commit into
mainfrom
fix/pip-security-maintenance

Conversation

@AlbertXXuu

@AlbertXXuu AlbertXXuu commented Sep 4, 2026 •

Copy link
Copy Markdown
Owner

PR #58 changes pip in the immutable v1.0.0 package inventory, so the license-snapshot consistency gate correctly fails. Meanwhile, current installation environments need the CVE-2026-13346 fix.

This maintenance change upgrades pip to at least 26.2 before supported installations and in every CI environment, including the fresh wheel venv. It explains the historical inventory in SECURITY.md and adds a regression test that still rejects changing only its pip pin. The frozen constraints, license snapshot, and report are unchanged; no runtime/model dependency or release version is changed.

Validation on Windows:

  • Existing Python 3.13.5 and 3.11.0 environments upgraded to pip 26.2.1; pip check passes, with no other installed package version changed.
  • Fresh Python 3.11 editable installation and a separate installed-wheel environment both pass dependency checks and the offline contributor smoke. The wheel imports from its installed location outside the checkout.
  • Focused license/readiness tests: 13 passed. Strict readiness: 19/19 passed.
  • Full Python 3.11 suite: 203 tests, OK with one existing Windows Gradio skip. Existing Python 3.13 contributor smoke also passes.
  • Repository audit, diff whitespace check, and before/after frozen-file hashes pass. The committed frozen Git blobs are unchanged.

Linux verification and disposition:

The vulnerable historical pin remains historical evidence, so this is not an automatic manifest fix or a claim that the advisory is inaccurate. No new model benchmark or release is part of this maintenance.

@AlbertXXuu
AlbertXXuu merged commit 478a554 into main Sep 4, 2026
4 checks passed
@AlbertXXuu
AlbertXXuu deleted the fix/pip-security-maintenance branch September 4, 2026 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant