v0.11.3 (2025-10-19)
Bug Fixes
- Ignore tarfile symlink vulnerability in pip-audit (
01dad6b)
GHSA-4xh5-x5gv-qwph pypa/pip#13607
As we're not affected, this seems to be the most pragmatic approach for this curveball.
Continuous Integration
The current python action (as bumped by dependabot) seems to still be running pip 25.2 which pip-audit flagged for known vulnerability
Detailed Changes: 0.11.2...0.11.3