Skip to content

fix(deps): vuln virtualenv (minor → 20.39.1) [datadog_checks_dev] - #24759

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pep621/datadog_checks_dev/1-1785768200
Draft

fix(deps): vuln virtualenv (minor → 20.39.1) [datadog_checks_dev]#24759
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pep621/datadog_checks_dev/1-1785768200

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • datadog_checks_dev (pep621)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
virtualenv 20.26.1 20.39.1 minor Direct 3 HIGH, 3 MEDIUM

Security Details

🚨 Critical & High Severity (3 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
virtualenv GHSA-rqc4-2hc7-8c8v HIGH virtualenv allows command injection through activation scripts for a virtual environment 20.26.1 20.26.6 -
virtualenv CVE-2024-53899 HIGH - 20.26.1 - -
virtualenv PYSEC-2024-187 HIGH - 20.26.1 20.26.6 -
ℹ️ Other Vulnerabilities (3)
Package CVE Severity Summary Unsafe Version Fixed In Case
virtualenv PYSEC-2026-2009 medium virtualenv Has TOCTOU Vulnerabilities in Directory Creation 20.26.1 20.36.1 -
virtualenv CVE-2026-22702 medium virtualenv Has TOCTOU Vulnerabilities in Directory Creation 20.26.1 - -
virtualenv GHSA-597g-3phw-6986 MODERATE virtualenv Has TOCTOU Vulnerabilities in Directory Creation 20.26.1 20.36.1 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-official

datadog-official Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Pipelines  Tests  Code Coverage

⚠️ Warnings

🚦 2 Pipeline jobs failed

Check PR | run / Check PR changelog   View in Datadog   GitHub Actions

See error Package "datadog_checks_dev" has changes that require a changelog. Please run `ddev release changelog new` to add it.

Validate repository | Run Validations / Validate   View in Datadog   GitHub Actions

See error Cache save failed: Unable to reserve cache, another job may be creating this cache.

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 88.76% (+0.46%)

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 2a8a1b1 | Docs | Datadog PR Page | Give us feedback!

Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with master — rebased onto 8d78fd9.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-94e5d1
dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/pep621/datadog_checks_dev/1-1785768200 branch from 740d5dc to 2a8a1b1 Compare August 7, 2026 18:01
@dd-octo-sts

dd-octo-sts Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Validation Report

Validation Description Status
qa-label Validate the pull request declares whether it needs QA for the next Agent release

Run ddev validate all changed --fix to attempt to auto-fix supported validations.

Passed validations (20)
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants