Drop Python 3.10 and fix scan exceptions after the version update - #22
Merged
Merged
Conversation
Python 3.10 reaches end of life this month and its builds fail the vulnerability scan, so it is no longer built. Published 3.10 tags stay available. The scan exceptions were pinned to the previous Python versions and stopped matching after the version update. 3.12.15 and 3.13.16 now pass without an exception. 3.11.17 contains the upstream tarfile fix, but the vulnerability data does not list a fixed 3.11 release yet, so CVE-2026-82049 is ignored for exactly that version.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Builds for Python 3.10–3.13 have failed the vulnerability scan since the version update on 2026-10-02, so revision
r3was never published. The scan exceptions were pinned to the previous Python versions and stopped matching once the versions changed.This change makes the builds pass again:
3.10tags stay available.Details
.grype.yaml: a single rule, CVE-2026-82049 for thepythonbinary at exactly3.11.17.PYTHON310from the workflow matrix, the revision alias map, the base image pins, and the README tag list.Validation
Follow-up
r3points at a commit that cannot pass the scan.Closes #10
Closes #12