From 9a80960ea02320ae96f0b24d0c05c58401e215de Mon Sep 17 00:00:00 2001 From: gusthoff Date: Sat, 26 Sep 2026 01:43:34 +0200 Subject: [PATCH] Vagrant: pin the venv's pip to a patched version `pip-audit` found six advisories (PYSEC-2026-1795, PYSEC-2026-1796, PYSEC-2026-196, PYSEC-2026-2875, PYSEC-2026-2876, PYSEC-2026-3721) against pip 25.1.1, the version apt's `python3-pip` installs and that `python3 -m venv` then carries into `/vagrant/venv` on both VMs. Fixes for these land across pip 25.3 through 26.2.0. CI already pins pip to 26.2.1 via `setup-python`'s `pip-version` input (commit `f1faa480`), for the same reason this now applies here: pip is the one tool that resolves every other pinned package, so leaving it unpinned left the resolver itself as the only unpinned, and in this case vulnerable, part of the environment. Add the identical pin directly to both provisioning blocks, right after venv creation and before installing `requirements_frozen.txt`. This does not touch either requirements file: pip excludes itself from its own freeze/compile output, so its version pin belongs outside the dependency closure those files describe, the same way CI already handles it. Verified live on the epub VM: `pip-audit` now reports 0 vulnerabilities in `/vagrant/venv`, down from 6. Co-Authored-By: Claude Sonnet 5 --- Vagrantfile | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/Vagrantfile b/Vagrantfile index 8cde07311..662eccf18 100644 --- a/Vagrantfile +++ b/Vagrantfile @@ -108,6 +108,9 @@ $frontend = <<-SHELL # Install learn deps python3 -m venv /vagrant/venv source /vagrant/venv/bin/activate + # Pinned like CI's setup-python pip-version input: pip itself is the one + # tool that resolves the pinned packages below, so it needs a pin too. + pip3 install --upgrade pip==26.2.1 pip3 install -r /vagrant/frontend/requirements_frozen.txt pip3 install -e /vagrant/frontend/python/rst_code_example_pipeline @@ -275,6 +278,9 @@ $epub = <<-SHELL # Install learn deps python3 -m venv /vagrant/venv source /vagrant/venv/bin/activate + # Pinned like CI's setup-python pip-version input: pip itself is the one + # tool that resolves the pinned packages below, so it needs a pin too. + pip3 install --upgrade pip==26.2.1 pip3 install -r /vagrant/frontend/requirements_frozen.txt pip3 install -e /vagrant/frontend/python/rst_code_example_pipeline