Skip to content

chore(deps): update dependency setuptools to v65 [security]#1415

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/pypi-setuptools-vulnerability
Open

chore(deps): update dependency setuptools to v65 [security]#1415
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/pypi-setuptools-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Aug 13, 2025

This PR contains the following updates:

Package Change Age Confidence
setuptools (changelog) ==57.5.0==65.5.1 age confidence

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

CVE-2022-40897 / GHSA-r9hx-vwmv-q579

More information

Details

Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in package_index. This has been patched in version 65.5.1.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pypa/setuptools (setuptools)

v65.5.1

Compare Source

v65.5.0

Compare Source

v65.4.1

Compare Source

v65.4.0

Compare Source

v65.3.0

Compare Source

v65.2.0

Compare Source

v65.1.1

Compare Source

v65.1.0

Compare Source

v65.0.2

Compare Source

v65.0.1

Compare Source

v65.0.0

Compare Source

v64.0.3

Compare Source

v64.0.2

Compare Source

v64.0.1

Compare Source

v64.0.0

Compare Source

v63.4.3

Compare Source

v63.4.2

Compare Source

v63.4.1

Compare Source

v63.4.0

Compare Source

v63.3.0

Compare Source

v63.2.0

Compare Source

v63.1.0

Compare Source

v63.0.0

Compare Source

v62.6.0

Compare Source

v62.5.0

Compare Source

v62.4.0

Compare Source

v62.3.4

Compare Source

v62.3.3

Compare Source

v62.3.2

Compare Source

v62.3.1

Compare Source

v62.3.0

Compare Source

v62.2.0

Compare Source

v62.1.0

Compare Source

v62.0.0

Compare Source

v61.3.1

Compare Source

v61.3.0

Compare Source

v61.2.0

Compare Source

v61.1.1

Compare Source

v61.1.0

Compare Source

v61.0.0

Compare Source

v60.10.0

Compare Source

v60.9.3

Compare Source

v60.9.2

Compare Source

v60.9.1

Compare Source

v60.9.0

Compare Source

v60.8.2

Compare Source

v60.8.1

Compare Source

v60.8.0

Compare Source

v60.7.1

Compare Source

v60.7.0

Compare Source

v60.6.0

Compare Source

v60.5.0

Compare Source

v60.4.0

Compare Source

v60.3.1

Compare Source

v60.3.0

Compare Source

v60.2.0

Compare Source

v60.1.1

Compare Source

v60.1.0

Compare Source

v60.0.5

Compare Source

v60.0.4

Compare Source

v60.0.3

Compare Source

v60.0.2

Compare Source

v60.0.1

Compare Source

v60.0.0

Compare Source

v59.8.0

Compare Source

v59.7.0

Compare Source

v59.6.0

Compare Source

v59.5.0

Compare Source

v59.4.0

Compare Source

v59.3.0

Compare Source

v59.2.0

Compare Source

v59.1.1

Compare Source

v59.1.0

Compare Source

v59.0.1

Compare Source

v58.5.3

Compare Source

v58.5.2

Compare Source

v58.5.1

Compare Source

v58.5.0

Compare Source

v58.4.0

Compare Source

v58.3.0

Compare Source

v58.2.0

Compare Source

v58.1.0

Compare Source

v58.0.4

Compare Source

v58.0.3

Compare Source

v58.0.2

Compare Source

v58.0.1

Compare Source

v58.0.0

Compare Source


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/pypi-setuptools-vulnerability branch from 0e3f5f5 to d7f3e76 Compare October 16, 2025 01:07
@renovate renovate bot changed the title chore(deps): update dependency setuptools to v78 [security] chore(deps): update dependency setuptools to v65 [security] Oct 16, 2025
@renovate renovate bot changed the title chore(deps): update dependency setuptools to v65 [security] chore(deps): update dependency setuptools to v65 [security] - autoclosed Mar 27, 2026
@renovate renovate bot closed this Mar 27, 2026
@renovate renovate bot deleted the renovate/pypi-setuptools-vulnerability branch March 27, 2026 01:17
@renovate renovate bot changed the title chore(deps): update dependency setuptools to v65 [security] - autoclosed chore(deps): update dependency setuptools to v65 [security] Mar 30, 2026
@renovate renovate bot reopened this Mar 30, 2026
@renovate renovate bot force-pushed the renovate/pypi-setuptools-vulnerability branch from d7f3e76 to 8727895 Compare March 30, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants