Debian Package Tracker
Register | Log in
Subscribe

python-pip

Choose email to subscribe with

general
  • source: python-pip (main)
  • version: 23.3+dfsg-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Stefano Rivera [DMD] – Scott Kitterman [DMD] – Carl Chenet [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 18.1-5
  • oldstable: 20.3.4-4+deb11u1
  • stable: 23.0.1+dfsg-1
  • testing: 23.3+dfsg-1
  • unstable: 23.3+dfsg-1
versioned links
  • 18.1-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20.3.4-4+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 23.0.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 23.3+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-pip (3 bugs: 0, 3, 0, 0)
  • python3-pip-whl
action needed
A new upstream version is available: 23.3.2 high
A new upstream version 23.3.2 is available, you should consider packaging it.
Created: 2023-10-23 Last update: 2024-01-30 04:36
debian/patches: 1 patch with invalid metadata, 1 patch to forward upstream high

Among the 5 debian patches available in version 23.3+dfsg-1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-11-19 09:39
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 23.3+dfsg-2, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit be5bde0ad6ed9fe3ebdc365954dd087148df64ed
Author: Stefano Rivera <stefanor@debian.org>
Date:   Fri Oct 20 12:17:15 2023 +0200

    Drop hands-off-system-packages.patch, now that PEP-668 is deployed.

commit 5c597651476399e5887005c36a65078041271905
Author: Stefano Rivera <stefanor@debian.org>
Date:   Fri Oct 20 12:17:00 2023 +0200

    Update patch description

commit e40a2766a6a3175e8c2a17e032fd49d51788caa0
Author: Stefano Rivera <stefanor@debian.org>
Date:   Fri Oct 20 12:08:02 2023 +0200

    Refresh patches
Created: 2023-10-20 Last update: 2024-01-24 20:43
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-02-10 Last update: 2023-06-12 00:08
1 low-priority security issue in bullseye low

There is 1 open security issue in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2023-5752: (needs triaging) When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-10-25 Last update: 2023-12-12 18:10
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-5752: (needs triaging) When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-10-25 Last update: 2023-12-12 18:10
news
[rss feed]
  • [2023-10-21] python-pip 23.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-19] Accepted python-pip 23.3+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2023-09-25] python-pip 23.2.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-22] Accepted python-pip 23.2.1+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2023-07-22] python-pip 23.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-20] Accepted python-pip 23.2+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2023-06-19] python-pip 23.1.2+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-06-11] Accepted python-pip 23.1.2+dfsg-2 (source) into unstable (Stefano Rivera)
  • [2023-05-04] Accepted python-pip 23.1.2+dfsg-1 (source) into experimental (Stefano Rivera)
  • [2023-03-02] python-pip 23.0.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-19] Accepted python-pip 23.0.1+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2023-02-09] python-pip 23.0+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-05] Accepted python-pip 23.0+dfsg-2 (source) into unstable (Stefano Rivera)
  • [2023-02-05] python-pip 23.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-05] python-pip 23.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-02] Accepted python-pip 23.0+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2023-01-23] python-pip 22.3.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-01-20] Accepted python-pip 22.3.1+dfsg-2 (source) into unstable (Stefano Rivera)
  • [2022-12-21] python-pip 22.3.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-15] Accepted python-pip 22.3.1+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2022-10-20] python-pip 22.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-17] Accepted python-pip 22.3+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2022-07-27] python-pip 22.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-22] Accepted python-pip 22.2+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2022-05-29] python-pip 22.1.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-26] Accepted python-pip 22.1.1+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2022-05-19] python-pip 22.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-16] Accepted python-pip 22.1+dfsg-1 (source) into unstable (Stefano Rivera)
  • [2022-03-16] Accepted python-pip 20.3.4-4+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Stefano Rivera)
  • [2022-02-05] python-pip 22.0.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 23.3+dfsg-1
  • 18 bugs

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing