Skip to content

Update dependency poetry to v2.4.2 - #205

Merged
robbinjanssen merged 1 commit into
masterfrom
renovate/all-minor-patch
Aug 31, 2026
Merged

Update dependency poetry to v2.4.2#205
robbinjanssen merged 1 commit into
masterfrom
renovate/all-minor-patch

Conversation

@exonet-ci

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
poetry (changelog) ==2.4.1==2.4.2 age confidence

Release Notes

python-poetry/poetry (poetry)

v2.4.2

Compare Source

Fixed
  • Fix an issue where Poetry installs an artifact that is not listed in the lockfile when the package source does not provide a hash for this artifact (#​11030).
  • Fix a path traversal vulnerability when downloading files from a compromised URL and/or package source (#​11029).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#​11027).

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • "before 4am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@exonet-ci exonet-ci added dependencies Upgrade or downgrade of project dependencies. development labels Aug 30, 2026
@robbinjanssen
robbinjanssen merged commit 50dfa88 into master Aug 31, 2026
11 checks passed
@robbinjanssen
robbinjanssen deleted the renovate/all-minor-patch branch August 31, 2026 07:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Upgrade or downgrade of project dependencies. development

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants