Package
py3.13-pip-base
Component
setuptools
Latest update
6.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The MANIFEST.in exclusion bypass is in setuptools' sdist machinery, and the upstream fix in 83.0.0 is confined to egg_info.py and unicode_utils.py. Only pkg_resources is vendored from the setuptools distribution — the setuptools package itself is dropped by the vendoring configuration — so neither file is shipped and the vulnerable code is not present.
Status