+Bumped GitPython in six `requirements/static/ci/py3.*/lint.lock` files from vulnerable `==3.1.50` to `==3.1.60` (matching the rest of the lock chain) and aligned the CI-static lower bound in `requirements/static/ci/{common,darwin}.txt` from `>=3.1.50` to `>=3.1.59`. Fixes CVE-2026-78676 (GHSA-284h-m62q-gf8w) — GitPython re-serialization corrupts a dormant multi-line quoted config value into an executable directive (e.g. `core.hooksPath`), enabling RCE via crafted config files. Lint environments installed from these six lock files were within the vulnerable range; the runtime lock files (`{cloud,darwin,docs,freebsd,linux,windows}.lock`) and base pin were already at `>=3.1.60` and unaffected.
0 commit comments