Package
graalvm-25-graalpy-venv
Component
setuptools
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The component is listed in the vendored dependency manifest inside pip's _vendor directory, but pip's vendoring drop rules exclude the setuptools package itself and ship only pkg_resources. The vulnerable module is not present in the distributed artifact, so the reported code cannot be reached.
Status
Status
Fixed version
25.0.1-r1Status
Status
Fixed version
25-r1Status