Bump pip version to avoid known vulnerabilities
envgap__pypa__packaging-719
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
702353715de375a65e49d1ae4af21c35dce838b8- Manifest
tests/requirements.txt- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
pypa/packaging #719 · read the original issue
Hi again, I'd like to suggest to bump the pip version used for testing in order to avoid using a vulnerable version of pip. The known vulnerabilities are [GHSA-5xp3-jfq3-5q8x](https://osv.dev/list?ecosystem=&q=GHSA-5xp3-jfq3-5q8x) and [GHSA-gpvv-69j7-gwj8](https://osv.dev/list?ecosystem=&q=GHSA-gpvv-69j7-gwj8) Both vulnerabilities were fixed on the [21.1 version](https://pypi.org/project/pip/21.1/). It won't affect the tests because the 21.1 version of pip is also compatible to python versions >= 3.6. I'll submit a PR with the bump together with this issue.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]