You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Someone without access to the configuration or linted code, but with access
to the cache directory (predictable PYLINT_HOME on a multi-user host) can no
longer write a crafted pickle that will runs arbitrary code when pylint access its
stat cache. The result cache is now stored as JSON instead of pickle,
preventing code-execution. The workaround is upgrading or not pointing PYLINT_HOME
to an untrusted, shared, or group-writable directory. The default value, ~/.cache/pylint,
is writable only by the user running pylint. (CVE with the same information pending)
False Positives Fixed
Fixed a false positive for no-self-use on a method that only uses self before a locally defined class (or other nested method), because
the checker's could-be-a-function tracking state was not restored after
visiting the nested method.
Fix a false positive for unnecessary-direct-lambda-call when a directly called
lambda in a class body wraps a comprehension containing an assignment expression.
PEP 572 makes that a SyntaxError without the lambda's scope, so following the
message produced code that would not compile.
Fix a false positive for :ref:bad-exception-cause when the bases of the class
being raised from cannot be inferred, such as an exception deriving from a
C extension class. :ref:raising-non-exception and
:ref:catching-non-exception already guard the same inherit_from_std_ex
helper with has_known_bases.
method-hidden is no longer silenced when the hidden method shares its name with
a builtin function or with a function defined at module level. Only members of the
ancestor classes themselves can excuse the method now.
Fix a block-scoped # pylint: disable= directive placed inside an if
body leaking into sibling elif/else blocks for messages such as stop-iteration-return, which default to a line-based (rather than
node-based) message scope.
Fix a crash in method-hidden when a method shadows a name that builtins
binds to a node without a statement, such as help or license. Every class
inherits from object, which lives in the builtins module, so no base class
was needed to trigger it.
Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>
Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer TIP This summary will be updated as you push new changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.0.8→4.0.9Release Notes
pylint-dev/pylint (pylint)
v4.0.9Compare Source
What's new in Pylint 4.0.9?
Release date: 2026-09-23
Security Fixes
to the cache directory (predictable
PYLINT_HOMEon a multi-user host) can nolonger write a crafted pickle that will runs arbitrary code when pylint access its
stat cache. The result cache is now stored as JSON instead of pickle,
preventing code-execution. The workaround is upgrading or not pointing
PYLINT_HOMEto an untrusted, shared, or group-writable directory. The default value,
~/.cache/pylint,is writable only by the user running pylint. (CVE with the same information pending)
False Positives Fixed
Fixed a false positive for
no-self-useon a method that only usesselfbefore a locally defined class (or other nested method), becausethe checker's could-be-a-function tracking state was not restored after
visiting the nested method.
Closes #3705
Fix a false positive for :ref:
not-callablewhen calling functions constructed withtypes.FunctionTypeortypes.LambdaType.Closes #7500
Fix a false positive for
unnecessary-direct-lambda-callwhen a directly calledlambda in a class body wraps a comprehension containing an assignment expression.
PEP 572 makes that a
SyntaxErrorwithout the lambda's scope, so following themessage produced code that would not compile.
Closes #9294
Fix a false positive for :ref:
unnecessary-ellipsiswhen an ellipsis is thesole body statement of a method defined on a
Protocol.Closes #9319
Fix a false positive for :ref:
bad-exception-causewhen the bases of the classbeing raised from cannot be inferred, such as an exception deriving from a
C extension class. :ref:
raising-non-exceptionand:ref:
catching-non-exceptionalready guard the sameinherit_from_std_exhelper with
has_known_bases.Refs #11399
False Negatives Fixed
method-hiddenis no longer silenced when the hidden method shares its name witha builtin function or with a function defined at module level. Only members of the
ancestor classes themselves can excuse the method now.
Refs #11361
Other Bug Fixes
Fix a block-scoped
# pylint: disable=directive placed inside anifbody leaking into sibling
elif/elseblocks for messages such asstop-iteration-return, which default to a line-based (rather thannode-based) message scope.
Closes #3136
Fix a false positive for
declare-non-slotwhen a class variable isannotated with
ClassVarwithout an initial value.Closes #9950
Fix a crash in the
no-memberchecker when attribute lookup raises anInferenceError.Closes #11356
Fix a crash in the
unnecessary-default-type-argscheck when aGeneratoror
AsyncGeneratorsubscript holds an empty tuple, such asGenerator[()].Closes #11357
Fix a crash in
method-hiddenwhen a method shadows a name thatbuiltinsbinds to a node without a statement, such as
helporlicense. Every classinherits from
object, which lives in thebuiltinsmodule, so no base classwas needed to trigger it.
Closes #11361
Closes #8079
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.