Skip to content

PKG-Defender v1.0.8

Choose a tag to compare

@github-actions github-actions released this 25 Aug 00:19
· 18 commits to main since this release
v1.0.8
7d8b4dc
PKG-Defender Logo

PKG-Defender v1.0.8

Released August 25, 2026


What's Changed

Security

  • Relocked aiohttp 3.14.1 → 3.14.3 to remediate CVE-2026-69244 /
    CVE-2026-69243 / CVE-2026-59881 (client-side exposure only; the pyproject
    constraint is unchanged). The 3.14.1 → 3.14.3 delta crosses no breaking-change
    entries — breaking items belong to releases ≤3.14.1, already inside the prior pin.
  • GitHub Action dependencies: bumped the npm undici override 6.27.0 → 6.28.0
    (CVE-2026-16728 / CVE-2026-15157 / CVE-2026-16729), refreshed brace-expansion
    2.1.2 → 2.1.4 and 1.1.16 → 1.1.18 (GHSA-rgw5-rvv9-x895 / CVE-2026-69152) and
    js-yaml 3.15.0 → 3.15.1 (GHSA-5p4m-2wfm-xmqj); rebuilt the committed
    dist/index.js bundle so the shipped Action runs patched undici. Added a
    lock-version regression guard test. The undici delta crosses no
    breaking-change entries — breaking items belong to releases ≤6.27.0, already
    inside the prior override.
  • Replaced @actions/glob with fast-glob@3.3.x in the GitHub Action to
    remediate two HIGH-severity denial-of-service vulnerabilities in
    brace-expansion: GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 (exponential-time
    expansion) and GHSA-mh99-v99m-4gvg (unbounded expansion causing OOM crash).
    Updated glob API usage in index.js, mocks in tests/action.test.js (12
    regression tests added), and rebuilt dist/index.js.

Changed

  • Widened dependency constraints — packaging>=23.0,<24.0 → >=23.0,<27.0
    and rich>=13.0,<14.0 → >=13.0,<16.0. Locked versions are unchanged;
    this resolves resolution conflicts when co-installed with newer toolchains.
  • Refreshed product tagline and short description ("Stop supply chain attacks
    before they reach your machine") across PyPI metadata, CLI help headers, the
    man page, and documentation landing pages.

Removed

  • Release pipeline smoke-test job (unreliable — intermittent timeouts and
    pip syntax regressions blocked releases)
  • Homebrew tap auto-merge step (manual merge preferred for reliability)

📖 8 Commits since v1.0.7
Commit Description Author
ae99ccb chore(docs): update readme badges Division 7
dd8b7e6 chore(release): prepare v1.0.8 Division 7
a2e4c62 ci(dependabot): target pip/docker version updates at develop Division 7
e91f41f fix(security): bump aiohttp/undici/brace-expansion/js-yaml to resolve recent OSSF Scorecard findings Division 7
d857745 chore(pkgd-action): update action.yml action name and associated test expectations Division 7
e67230e fix(pkgd-action): replace @actions/glob with fast-glob to fix brace-expansion CVEs Division 7
c644265 fix(tests): remove smoke-test from required release jobs list Division 7
53dacf0 fix(ci): modify release workflow to resolve pypi smoke test timeout; remove auto-merge from homebrew tap PR job Division 7

View Complete Changelog →