Skip to content

Please update pip to at least version of pip 25.2 #1080

Description

@combro2k

There is a 5 day old reported vulnerability: GHSA-4xh5-x5gv-qwph
Can you please update python 3.12 based images with pip version at least 25.2?
To be specific the -slim one :-)

Activity

  1. changed the title [-]Please update pip to latest version:[/-] [+]Please update pip to at least version of pip 25.2[/+] on Sep 29, 2025
  2. ad-m-ss commented on Sep 29, 2025

    @ad-m-ss

    These images by design use the pip/setuptools versions that are bundled with the version of Python being installed.

    Python 3.11 comes with setuptools v65.5.0: https://github.com/python/cpython/tree/3.11/Lib/ensurepip/_bundled

    So this is expected, and not something that will be changed in these images. (Updating to setuptools 70+ would be a breaking change for a start.)

    You will either need to either:

    1. Update to Python 3.12 or newer (which no longer bundles setuptools)
    2. Update setuptools in your own Dockerfile
    3. Ask upstream CPython to update to newer setuptools in Python 3.11
    4. Suppress the vulnerability alert if appropriate (you didn't say what vulnerability you were referring to, but it's quite possible it's a non-issue in practice - many setuptools codepaths are not used when it's used as a pip build backend, or need several other criteria to be a problem etc)

    See also:

    See: #1012 (comment)

    Therefore you should raise that request upstream, or update yourself.

  3. mabecke commented on Nov 10, 2025

    @mabecke

    Hi @ad-m-ss I see that for 3.13 the bundled pip was updated to 25.3 last week https://github.com/python/cpython/tree/3.13/Lib/ensurepip/_bundled

    Seems like this change isn't going through for the built image, as 3.13 still has pip 25.1 even though it was recently re-built.

    Can we please re-open the issue? Or would you prefer to have a new one specifically for 3.13 and pip 25.3?

    Thanks

  4. ad-m-ss commented on Nov 10, 2025

    @ad-m-ss

    What do you mean by re-open? I do not have authority to close / open anything here, and it looks it was never closed. I am just watching and know a little policies.

  5. tianon commented on Nov 10, 2025

    @tianon
    Member

    If you look at python/cpython@9a3a147, you'll see that it's not part of any release tags yet (you can compare that to an older commit like python/cpython@1ba09b2 which was included in 3.13.6+ to see what I mean), so that means it should be part of the next 3.13 release.

    See also python/cpython@v3.13.9...3.13 for a full list of what might be in that next release (comparing the latest release tag, v3.13.9 to that in-progress 3.13 release branch).

  6. tianon commented on Nov 10, 2025

    @tianon
    Member

    (As a matter of process: if that stays for the release and doesn't get reverted, the bump will happen automatically as part of / with the release bump.)

  7. yhdhvyfhv commented on Aug 11, 2026

    @yhdhvyfhv

    Could you confirm if the vulnerability reported in GHSA-4xh5-x5gv-qwph affects the current -slim image setup, or is it only relevant for other configurations?

  8. tianon commented on Aug 11, 2026

    @tianon
    Member
    $ docker run --rm --pull=always python:3.13-slim pip --version
    3.13-slim: Pulling from library/python
    26c307b5e35a: Already exists 
    f5ea60e5d57e: Pull complete 
    c915bfca5450: Pull complete 
    31a024bb115a: Pull complete 
    Digest: sha256:ffb752e139c0a19692a43af8d8523b274222dd68eebad5d583b45c2201c6e30a
    Status: Downloaded newer image for python:3.13-slim
    pip 26.2.1 from /usr/local/lib/python3.13/site-packages/pip (python 3.13)

    vs https://github.com/advisories/GHSA-4xh5-x5gv-qwph's "Affected versions": "<= 25.2"

    3.12 is still affected, which tracks because upstream (Python) hasn't backported that update:

    $ docker run --rm --pull=always python:3.12-slim pip --version
    3.12-slim: Pulling from library/python
    26c307b5e35a: Already exists 
    5a31db4cd478: Pull complete 
    c85ad0bcaca8: Pull complete 
    b3c7a9bdb4f2: Pull complete 
    Digest: sha256:229a2c5bfa27522db7815ea81f9bed70af17ccb9de9fc7ad142b1877b5830d36
    Status: Downloaded newer image for python:3.12-slim
    pip 25.0.1 from /usr/local/lib/python3.12/site-packages/pip (python 3.12)
  9. tatumjakhiya26 commented on Sep 12, 2026

    @tatumjakhiya26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions