PKG-Defender v1.0.8
PKG-Defender v1.0.8
Released August 25, 2026
What's Changed
Security
- Relocked
aiohttp3.14.1 → 3.14.3 to remediate CVE-2026-69244 /
CVE-2026-69243 / CVE-2026-59881 (client-side exposure only; the pyproject
constraint is unchanged). The 3.14.1 → 3.14.3 delta crosses no breaking-change
entries — breaking items belong to releases ≤3.14.1, already inside the prior pin. - GitHub Action dependencies: bumped the npm
undicioverride 6.27.0 → 6.28.0
(CVE-2026-16728 / CVE-2026-15157 / CVE-2026-16729), refreshedbrace-expansion
2.1.2 → 2.1.4 and 1.1.16 → 1.1.18 (GHSA-rgw5-rvv9-x895 / CVE-2026-69152) and
js-yaml3.15.0 → 3.15.1 (GHSA-5p4m-2wfm-xmqj); rebuilt the committed
dist/index.jsbundle so the shipped Action runs patched undici. Added a
lock-version regression guard test. The undici delta crosses no
breaking-change entries — breaking items belong to releases ≤6.27.0, already
inside the prior override. - Replaced
@actions/globwithfast-glob@3.3.xin the GitHub Action to
remediate two HIGH-severity denial-of-service vulnerabilities in
brace-expansion: GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 (exponential-time
expansion) and GHSA-mh99-v99m-4gvg (unbounded expansion causing OOM crash).
Updated glob API usage inindex.js, mocks intests/action.test.js(12
regression tests added), and rebuiltdist/index.js.
Changed
- Widened dependency constraints —
packaging>=23.0,<24.0→>=23.0,<27.0
andrich>=13.0,<14.0→>=13.0,<16.0. Locked versions are unchanged;
this resolves resolution conflicts when co-installed with newer toolchains. - Refreshed product tagline and short description ("Stop supply chain attacks
before they reach your machine") across PyPI metadata, CLI help headers, the
man page, and documentation landing pages.
Removed
- Release pipeline smoke-test job (unreliable — intermittent timeouts and
pip syntax regressions blocked releases) - Homebrew tap auto-merge step (manual merge preferred for reliability)
📖 8 Commits since v1.0.7
| Commit | Description | Author |
|---|---|---|
ae99ccb |
chore(docs): update readme badges | Division 7 |
dd8b7e6 |
chore(release): prepare v1.0.8 | Division 7 |
a2e4c62 |
ci(dependabot): target pip/docker version updates at develop | Division 7 |
e91f41f |
fix(security): bump aiohttp/undici/brace-expansion/js-yaml to resolve recent OSSF Scorecard findings | Division 7 |
d857745 |
chore(pkgd-action): update action.yml action name and associated test expectations |
Division 7 |
e67230e |
fix(pkgd-action): replace @actions/glob with fast-glob to fix brace-expansion CVEs |
Division 7 |
c644265 |
fix(tests): remove smoke-test from required release jobs list | Division 7 |
53dacf0 |
fix(ci): modify release workflow to resolve pypi smoke test timeout; remove auto-merge from homebrew tap PR job | Division 7 |