Skip to content

fix(deps): vuln virtualenv (minor → 20.39.1) [datadog_checks_dev/pyproject.toml] - #24959

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pep621/datadog_checks_dev/0-1787553563
Draft

fix(deps): vuln virtualenv (minor → 20.39.1) [datadog_checks_dev/pyproject.toml]#24959
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pep621/datadog_checks_dev/0-1787553563

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • datadog_checks_dev/pyproject.toml (pep621)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
virtualenv 20.26.1 20.39.1 minor Direct 3 HIGH, 3 MEDIUM

Security Details

🚨 Critical & High Severity (3 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
virtualenv PYSEC-2024-187 high - 20.26.1 20.26.6 -
virtualenv CVE-2024-53899 high - 20.26.1 - -
virtualenv GHSA-rqc4-2hc7-8c8v HIGH virtualenv allows command injection through activation scripts for a virtual environment 20.26.1 20.26.6 -
ℹ️ Other Vulnerabilities (3)
Package CVE Severity Summary Unsafe Version Fixed In Case
virtualenv GHSA-597g-3phw-6986 MODERATE virtualenv Has TOCTOU Vulnerabilities in Directory Creation 20.26.1 20.36.1 -
virtualenv CVE-2026-22702 MODERATE virtualenv Has TOCTOU Vulnerabilities in Directory Creation 20.26.1 - -
virtualenv PYSEC-2026-2009 MODERATE virtualenv Has TOCTOU Vulnerabilities in Directory Creation 20.26.1 20.36.1 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@dd-octo-sts

dd-octo-sts Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Validation Report

Validation Description Status
qa-label Validate the pull request declares whether it needs QA for the next Agent release

Run ddev validate all changed --fix to attempt to auto-fix supported validations.

Passed validations (20)
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

@datadog-datadog-prod-us1-2

datadog-datadog-prod-us1-2 Bot commented Aug 24, 2026

Copy link
Copy Markdown

Pipelines  Tests  Code Coverage

⚠️ Warnings

🚦 2 Pipeline jobs failed

Check PR | run / Check PR changelog

View in Datadog · View in GitHub Actions

Package "datadog_checks_dev" has changes that require a changelog. Please run ddev release changelog new to add it.

Validate repository | Run Validations / Validate

View in Datadog · View in GitHub Actions

PR #24959 is missing an Agent-release QA decision label. Every pull request must declare whether its changes require QA validation.

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 89.00% (+0.34%)

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: c92ec14 | Docs | View more details | Give us feedback!

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

evalya-impact-summary

evalya impact analysis
Impact analysis: 0 selected, 0 skipped (of 0 test tasks)
Publish tasks:   1 (always emitted)
Diff (1 file):
  datadog_checks_dev/pyproject.toml

Debug a specific task: evalya plan impact --path <path> --task <task>

Learn more about CI impact filtering

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants