public/virtualenv.pyz is the zipapp bootstrap.pypa.io serves. virtualenv's
release workflow builds it, attests its
provenance and commits it here, so a flaw in the zipapp is a flaw in virtualenv.
Report vulnerabilities through virtualenv's security policy; its advisory form takes private reports. That policy covers these files too.
Verify a release shows how to check that a downloaded
virtualenv.pyz came from that workflow.