-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 23 Jun 2026 11:32:14 +0100
Source: pydantic-settings
Architecture: source
Version: 2.14.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Changes:
pydantic-settings (2.14.2-1) unstable; urgency=medium
.
* New upstream release:
- GHSA-4xgf-cpjx-pc3j: NestedSecretsSettingsSource with
secrets_nested_subdir=True could follow a symbolic link inside
secrets_dir pointing outside it, reading out-of-tree files into
settings values and bypassing the secrets_dir_max_size cap.
* Standards-Version: 4.7.4.
Checksums-Sha1:
ff745c3b954a2212de71f9f27a8695c56f313b04 2647 pydantic-settings_2.14.2-1.dsc
39edddebf8450bfcaad2bd85cc8294d37d4db00c 240038 pydantic-settings_2.14.2.orig.tar.gz
0f44f3f4f7c0ea93719c9f96027309016e8b43ed 3704 pydantic-settings_2.14.2-1.debian.tar.xz
Checksums-Sha256:
85c8d6fdae433cd4aa7a04eaae17451ae754899134c28f1ae6e102fcb81bf84e 2647 pydantic-settings_2.14.2-1.dsc
fb47dfe61d96affd207243d8691715fb302924de648a63564fcfa1dcee9790be 240038 pydantic-settings_2.14.2.orig.tar.gz
a9b52bdd237fdb6ab82a886625b8b2c78aaf5c588fb9c9bc5b1ed7ffed23a61a 3704 pydantic-settings_2.14.2-1.debian.tar.xz
Files:
40caeb4bf184826acd78fd372687a286 2647 python optional pydantic-settings_2.14.2-1.dsc
6116e90ed68021ac7addefedd7fb96e5 240038 python optional pydantic-settings_2.14.2.orig.tar.gz
1de6f2ebc041674fab57609a40a89985 3704 python optional pydantic-settings_2.14.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEErApP8SYRtvzPAcEROTWH2X2GUAsFAmo6YQkACgkQOTWH2X2G
UAsidA/+LSYU8rSlNAC45PyG9rlanoPN8hCZKAiUZYLUzG9FxkGvN0IBcx/989Uc
AoqBU+z8mHAvqIqzwh4jF81EsakPF0DE4xNFslx/Zoh0yva685/IHn2hmLdteGoQ
v0E/JWBjgfTYBoa7K0G9XXo2vpIDGWhPoS8kN54ayJ4aByQSevYCcTo35P+OxJOX
2a5MFqbaVD3YTDqF7SfY74290QgDHQrw1kN+tAI0jLpiqn14yLBCggNsmK94+hFo
BL2UBG8x4jROcXALVWDH3kcSVAscuGl0VQOH6nJBuy0OhPwwULGpfvN1hYx6riG0
giAJSvZKIn/scOjlgICrOJW4GRR9WNQaiMP+fvThTKjb5yDSnsR4uDjTLRAI4X8j
adHrYr/aMFdD9K11TkchRMc8WDI2nKhnM5Unrj5KA69MnZzhsxzhVc2GykTDTKCl
+UWnIEr/37PNOP5XlwwismNAOZ+a9EY+I2nDy1Gb0XIMAisAZGMEHx0BQlRI4wgG
dGv1kYcEMK/mrghqOnMfcnH6rXwnAN4gBFz4QjfdDDlMddo5dSuc95NyEiOmJRUm
5ImkvWwYyqEPOTGUmhFqP+69Bdjt7ymUCZR1W5qJpBJ+CWQmmU1h68r3K8lho2Kb
+Z98EJVNKH8Eg88DsG5RgtOJ16813b/j6tB5bWGla3HI8kfBIgc=
=RdH1
-----END PGP SIGNATURE-----