Skip to content

Bump virtualenv from 20.33.1 to 20.36.1 - #68

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/uv/virtualenv-20.36.1
Open

Bump virtualenv from 20.33.1 to 20.36.1#68
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/uv/virtualenv-20.36.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor

Bumps virtualenv from 20.33.1 to 20.36.1.

Release notes

Sourced from virtualenv's releases.

20.36.0

What's Changed

New Contributors

Full Changelog: pypa/virtualenv@20.35.3...20.36.0

20.35.4

What's Changed

New Contributors

Full Changelog: pypa/virtualenv@20.35.3...20.35.4

20.35.3

What's Changed

Full Changelog: pypa/virtualenv@20.35.1...20.35.3

20.35.2

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Bugfixes - 20.36.1

  • Fix TOCTOU vulnerabilities in app_data and lock directory creation that could be exploited via symlink attacks - reported by :user:tsigouris007, fixed by :user:gaborbernat. (:issue:3013)

v20.36.0 (2026-01-07)


Features - 20.36.0

  • Add support for PEP 440 version specifiers in the --python flag. Users can now specify Python versions using operators like >=, <=, ~=, etc. For example: virtualenv --python=">=3.12" myenv . (:issue:2994`)

v20.35.4 (2025-10-28)


Bugfixes - 20.35.4

  • Fix race condition in _virtualenv.py when file is overwritten during import, preventing NameError when _DISTUTILS_PATCH is accessed - by :user:gracetyy. (:issue:2969)

  • Upgrade embedded wheels:

    • pip to 25.3 from 25.2 (:issue:2989)

v20.35.3 (2025-10-10)


Bugfixes - 20.35.3

  • Accept RuntimeError in test_too_many_open_files, by :user:esafak (:issue:2935)

v20.35.2 (2025-10-10)


Bugfixes - 20.35.2

  • Revert out changes related to the extraction of the discovery module - by :user:gaborbernat. (:issue:2978)

v20.35.1 (2025-10-09)


... (truncated)

Commits
  • d0ad11d release 20.36.1
  • dec4cec Merge pull request #3013 from gaborbernat/fix-sec
  • 5fe5d38 release 20.36.0 (#3011)
  • 9719376 release 20.36.0
  • 0276db6 Add support for PEP 440 version specifiers in the --python flag. (#3008)
  • 4f900c2 Fix Interpreter discovery bug wrt. Microsoft Store shortcut using Latin-1 (#3...
  • 13afcc6 fix: resolve EncodingWarning in tox upgrade environment (#3007)
  • 31b5d31 [pre-commit.ci] pre-commit autoupdate (#2997)
  • 7c28422 fix: update filelock dependency version to 3.20.1 to fix CVE CVE-2025-68146 (...
  • 365628c test_too_many_open_files: assert on errno.EMFILE instead of strerror (#3001)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Dependency updates python:uv Pull requests that update python:uv code labels May 17, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Architecture diagram
sequenceDiagram
    participant User as CLI User
    participant CLI as virtualenv CLI
    participant Discover as Interpreter Discovery
    participant Config as Configuration
    participant AppData as AppData/Lock Manager
    participant FS as File System

    Note over User,FS: Virtual Environment Creation Flow

    User->>CLI: virtualenv --python ">=3.12" myenv
    CLI->>Config: Parse CLI arguments
    Config->>Config: CHANGED: Evaluate PEP 440 specifier
    alt PEP 440 specifier provided
        Config->>Discover: CHANGED: Pass version specifier (e.g., >=3.12)
        Discover->>Discover: CHANGED: Resolve best matching interpreter
        alt Interpreter found
            Discover-->>Config: Python path resolved
        else No match
            Discover-->>Config: Error: no matching interpreter
        end
    else Exact version
        Config->>Discover: Pass exact version string
        Discover->>FS: Search for Python installations
        FS-->>Discover: Interpreter paths
        Discover-->>Config: Python path resolved
    end

    CLI->>AppData: CHANGED: Acquire app_data lock (TOCTOU fix)
    AppData->>FS: CHANGED: Create directory with safe symlink checks
    alt Lock acquired
        AppData-->>CLI: Lock granted
        CLI->>FS: Create virtual environment structure
    else TOCTOU attack detected
        AppData-->>CLI: Error: security violation
        CLI-->>User: Error message
    end

    CLI->>FS: Install seed packages (pip, setuptools, wheel)
    FS-->>CLI: Packages installed
    CLI-->>User: Virtual environment created

    Note over FS: Microsoft Store Interpreter Fix (Latin-1 encoding)
    Discover->>FS: CHANGED: Read interpreter symlink with Latin-1 encoding
    FS-->>Discover: Correctly decoded shortcut path
Loading

Re-trigger cubic

Bumps [virtualenv](https://github.com/pypa/virtualenv) from 20.33.1 to 20.36.1.
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@20.33.1...20.36.1)

---
updated-dependencies:
- dependency-name: virtualenv
  dependency-version: 20.36.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/virtualenv-20.36.1 branch from 864b617 to d5cec16 Compare June 10, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants