Skip to content

chore(deps): bump poetry from 2.4.1 to 2.4.2 - #1378

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/poetry-2.4.2
Open

chore(deps): bump poetry from 2.4.1 to 2.4.2#1378
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/poetry-2.4.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps poetry from 2.4.1 to 2.4.2.

Release notes

Sourced from poetry's releases.

2.4.2

Fixed

  • Fix an issue where Poetry installs an artifact that is not listed in the lockfile when the package source does not provide a hash for this artifact (#11030).
  • Fix a path traversal vulnerability when downloading files from a compromised URL and/or package source (#11029).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#11027).
Changelog

Sourced from poetry's changelog.

[2.4.2] - 2026-08-29

Fixed

  • Fix an issue where Poetry installs an artifact that is not listed in the lockfile when the package source does not provide a hash for this artifact (#11030).
  • Fix a path traversal vulnerability when downloading files from a compromised URL and/or package source (#11029).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#11027).
Commits
  • 15ce1fc release: bump version to 2.4.2
  • 3dd0f2d perf: avoid unnecessary downloads when the index does not provide hashes
  • c2f9af2 Fail closed when a locked hash cannot be checked
  • 3a194dd fix: reject invalid link filenames when downloading files (#11029)
  • 22173fd fix: refuse to write files outside the target directory during sdist extracti...
  • See full diff in compare view

@dependabot
dependabot Bot requested a review from dlrsp-dev as a code owner September 1, 2026 20:24
@dependabot dependabot Bot added the 📦 dependencies Update of dependencies label Sep 1, 2026
@dlrsp-actions
dlrsp-actions Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from 478115d to feb5dec Compare September 2, 2026 12:24
@dlrsp-actions
dlrsp-actions Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from feb5dec to 20ff08e Compare September 2, 2026 12:32
@dlrsp-actions
dlrsp-actions Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from 20ff08e to e034200 Compare September 2, 2026 12:44
@dependabot
dependabot Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from e034200 to a5c06a0 Compare September 3, 2026 12:28
@dlrsp-actions
dlrsp-actions Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from a5c06a0 to 8cf7b40 Compare September 3, 2026 12:31
@dlrsp-actions
dlrsp-actions Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from 8cf7b40 to 974b3ee Compare September 5, 2026 11:31
Bumps [poetry](https://github.com/python-poetry/poetry) from 2.4.1 to 2.4.2.
- [Release notes](https://github.com/python-poetry/poetry/releases)
- [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md)
- [Commits](python-poetry/poetry@2.4.1...2.4.2)

---
updated-dependencies:
- dependency-name: poetry
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dlrsp-actions
dlrsp-actions Bot force-pushed the dependabot/pip/poetry-2.4.2 branch from 974b3ee to b0f4572 Compare September 5, 2026 11:38
@dlrsp-actions dlrsp-actions Bot added the needs-human-review Policy gate blocked; human review required label Sep 5, 2026
@dlrsp-actions

dlrsp-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Policy gate blocked this PR: default-fail: matched catch-all policy

@dlrsp-actions dlrsp-actions Bot removed the needs-human-review Policy gate blocked; human review required label Sep 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

📦 dependencies Update of dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant