Skip to content

chore(deps): update pre-commit hook python-poetry/poetry to v2.3.3#1049

Merged
descope[bot] merged 1 commit intomainfrom
renovate/python-poetry-poetry-2.x
Apr 19, 2026
Merged

chore(deps): update pre-commit hook python-poetry/poetry to v2.3.3#1049
descope[bot] merged 1 commit intomainfrom
renovate/python-poetry-poetry-2.x

Conversation

@descope
Copy link
Copy Markdown
Contributor

@descope descope bot commented Apr 19, 2026

This PR contains the following updates:

Package Type Update Change Pending OpenSSF
python-poetry/poetry repository patch 2.3.22.3.3 2.3.4 OpenSSF Scorecard

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

python-poetry/poetry (python-poetry/poetry)

v2.3.3

Compare Source

Fixed
  • Fix a performance regression in the wheel installer that was introduced in Poetry 2.3.3 (#​10821).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#​10837).

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@descope descope bot added the renovate label Apr 19, 2026
@descope descope bot enabled auto-merge (squash) April 19, 2026 12:18
@github-actions
Copy link
Copy Markdown

Coverage report

The coverage rate went from 98.35% to 98.35% ➡️

None of the new lines are part of the tested code. Therefore, there is no coverage data about them.

@descope descope bot merged commit 627b7af into main Apr 19, 2026
31 checks passed
@descope descope bot deleted the renovate/python-poetry-poetry-2.x branch April 19, 2026 12:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants