Repository navigation
Please update pip to at least version of pip 25.2 #1080
Description
Activity
- changed the title
[-]Please update pip to latest version:[/-][+]Please update pip to at least version of pip 25.2[/+]on Sep 29, 2025 These images by design use the pip/setuptools versions that are bundled with the version of Python being installed.
Python 3.11 comes with setuptools v65.5.0: https://github.com/python/cpython/tree/3.11/Lib/ensurepip/_bundled
So this is expected, and not something that will be changed in these images. (Updating to setuptools 70+ would be a breaking change for a start.)
You will either need to either:
- Update to Python 3.12 or newer (which no longer bundles setuptools)
- Update setuptools in your own
Dockerfile - Ask upstream CPython to update to newer setuptools in Python 3.11
- Suppress the vulnerability alert if appropriate (you didn't say what vulnerability you were referring to, but it's quite possible it's a non-issue in practice - many setuptools codepaths are not used when it's used as a pip build backend, or need several other criteria to be a problem etc)
See also:
See: #1012 (comment)
Therefore you should raise that request upstream, or update yourself.
Reacted by Tianon GraviReacted by Tianon GraviHi @ad-m-ss I see that for 3.13 the bundled pip was updated to 25.3 last week https://github.com/python/cpython/tree/3.13/Lib/ensurepip/_bundled
Seems like this change isn't going through for the built image, as 3.13 still has pip 25.1 even though it was recently re-built.
Can we please re-open the issue? Or would you prefer to have a new one specifically for 3.13 and pip 25.3?
Thanks
What do you mean by re-open? I do not have authority to close / open anything here, and it looks it was never closed. I am just watching and know a little policies.
Reacted by mabeckeReacted by Tianon GraviIf you look at python/cpython@9a3a147, you'll see that it's not part of any release tags yet (you can compare that to an older commit like python/cpython@1ba09b2 which was included in 3.13.6+ to see what I mean), so that means it should be part of the next 3.13 release.
See also python/cpython@v3.13.9...3.13 for a full list of what might be in that next release (comparing the latest release tag, v3.13.9 to that in-progress 3.13 release branch).
(As a matter of process: if that stays for the release and doesn't get reverted, the bump will happen automatically as part of / with the release bump.)
Could you confirm if the vulnerability reported in GHSA-4xh5-x5gv-qwph affects the current
-slimimage setup, or is it only relevant for other configurations?$ docker run --rm --pull=always python:3.13-slim pip --version 3.13-slim: Pulling from library/python 26c307b5e35a: Already exists f5ea60e5d57e: Pull complete c915bfca5450: Pull complete 31a024bb115a: Pull complete Digest: sha256:ffb752e139c0a19692a43af8d8523b274222dd68eebad5d583b45c2201c6e30a Status: Downloaded newer image for python:3.13-slim pip 26.2.1 from /usr/local/lib/python3.13/site-packages/pip (python 3.13)
vs https://github.com/advisories/GHSA-4xh5-x5gv-qwph's "Affected versions": "<= 25.2"
3.12 is still affected, which tracks because upstream (Python) hasn't backported that update:
$ docker run --rm --pull=always python:3.12-slim pip --version 3.12-slim: Pulling from library/python 26c307b5e35a: Already exists 5a31db4cd478: Pull complete c85ad0bcaca8: Pull complete b3c7a9bdb4f2: Pull complete Digest: sha256:229a2c5bfa27522db7815ea81f9bed70af17ccb9de9fc7ad142b1877b5830d36 Status: Downloaded newer image for python:3.12-slim pip 25.0.1 from /usr/local/lib/python3.12/site-packages/pip (python 3.12)
tatumjakhiya26 commented
on Sep 12, 2026 on Sep 12, 2026 · Hidden as low-qualityshow commentMore actions
There is a 5 day old reported vulnerability: GHSA-4xh5-x5gv-qwph
Can you please update python 3.12 based images with
pipversion at least 25.2?To be specific the
-slimone :-)