Skip to content

Commit 34f0c70

Browse files
Revert "[MEDIUM] Upgrade python-wheel to 0.46.3 for CVE-2026-24049" (#16013)
1 parent 08dd928 commit 34f0c70

6 files changed

Lines changed: 9 additions & 55 deletions

File tree

SPECS/python-wheel/Use-vendored-packaging-to-canonicalize-requirements.patch

Lines changed: 0 additions & 38 deletions
This file was deleted.
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
22
"Signatures": {
3-
"wheel-0.46.3.tar.gz": "36327d3bba035d9c3509421a42b59914fe9aab79d894b21cb9be17353abf6d2c"
3+
"wheel-0.43.0.tar.gz": "23060d7cc8afafc2930554624b4bae7d58031830672048622c926675ab91e3b0"
44
}
5-
}
5+
}

SPECS/python-wheel/python-wheel.spec

Lines changed: 1 addition & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,15 @@
11
# The function of bootstrap is that it disables the wheel subpackage
22
%bcond_with bootstrap
3-
%global pypi_name wheel
43
%bcond main_python 1
54
Summary: Built-package format for Python
65
Name: python-%{pypi_name}
7-
Version: 0.46.3
6+
Version: 0.43.0
87
Release: 1%{?dist}
98
License: MIT
109
Vendor: Microsoft Corporation
1110
Distribution: Azure Linux
1211
URL: https://github.com/pypa/wheel
1312
Source0: %{url}/archive/%{version}/%{pypi_name}-%{version}.tar.gz
14-
Patch0: Use-vendored-packaging-to-canonicalize-requirements.patch
1513
%global pypi_name wheel
1614
%global python_wheel_name %{pypi_name}-%{version}-py3-none-any.whl
1715
%global python_wheeldir %{_datadir}/python-wheels
@@ -60,9 +58,6 @@ A Python wheel of wheel to use with virtualenv.
6058
%prep
6159
%autosetup -n %{pypi_name}-%{version} -p1
6260

63-
# flit_core expects [project].license to be a table/dict, not a string
64-
sed -i 's/^license = "MIT"$/license = { text = "MIT" }/' pyproject.toml
65-
6661
%generate_buildrequires
6762
%pyproject_buildrequires
6863

@@ -120,9 +115,6 @@ pip3 install iniconfig
120115
%endif
121116

122117
%changelog
123-
* Wed Jan 28 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 0.46.3-1
124-
- Updated to 0.46.3 to fix CVE-2026-24049
125-
126118
* Fri May 10 2024 Betty Lakes <bettylakes@microsoft.com> - 0.43.0-1
127119
- Updated to 0.43.0
128120

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25583,8 +25583,8 @@
2558325583
"type": "other",
2558425584
"other": {
2558525585
"name": "python-wheel",
25586-
"version": "0.46.3",
25587-
"downloadUrl": "https://github.com/pypa/wheel/archive/0.46.3/wheel-0.46.3.tar.gz"
25586+
"version": "0.43.0",
25587+
"downloadUrl": "https://github.com/pypa/wheel/archive/0.43.0/wheel-0.43.0.tar.gz"
2558825588
}
2558925589
}
2559025590
},

toolkit/resources/manifests/package/toolchain_aarch64.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -530,7 +530,7 @@ procps-ng-lang-4.0.4-1.azl3.aarch64.rpm
530530
pyproject-rpm-macros-1.12.0-2.azl3.noarch.rpm
531531
pyproject-srpm-macros-1.12.0-2.azl3.noarch.rpm
532532
python-markupsafe-debuginfo-2.1.3-1.azl3.aarch64.rpm
533-
python-wheel-wheel-0.46.3-1.azl3.noarch.rpm
533+
python-wheel-wheel-0.43.0-1.azl3.noarch.rpm
534534
python3-3.12.9-9.azl3.aarch64.rpm
535535
python3-audit-3.1.2-1.azl3.aarch64.rpm
536536
python3-cracklib-2.9.11-1.azl3.aarch64.rpm
@@ -557,7 +557,7 @@ python3-rpm-generators-14-11.azl3.noarch.rpm
557557
python3-setuptools-69.0.3-5.azl3.noarch.rpm
558558
python3-test-3.12.9-9.azl3.aarch64.rpm
559559
python3-tools-3.12.9-9.azl3.aarch64.rpm
560-
python3-wheel-0.46.3-1.azl3.noarch.rpm
560+
python3-wheel-0.43.0-1.azl3.noarch.rpm
561561
readline-8.2-2.azl3.aarch64.rpm
562562
readline-debuginfo-8.2-2.azl3.aarch64.rpm
563563
readline-devel-8.2-2.azl3.aarch64.rpm

toolkit/resources/manifests/package/toolchain_x86_64.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -538,7 +538,7 @@ procps-ng-lang-4.0.4-1.azl3.x86_64.rpm
538538
pyproject-rpm-macros-1.12.0-2.azl3.noarch.rpm
539539
pyproject-srpm-macros-1.12.0-2.azl3.noarch.rpm
540540
python-markupsafe-debuginfo-2.1.3-1.azl3.x86_64.rpm
541-
python-wheel-wheel-0.46.3-1.azl3.noarch.rpm
541+
python-wheel-wheel-0.43.0-1.azl3.noarch.rpm
542542
python3-3.12.9-9.azl3.x86_64.rpm
543543
python3-audit-3.1.2-1.azl3.x86_64.rpm
544544
python3-cracklib-2.9.11-1.azl3.x86_64.rpm
@@ -565,7 +565,7 @@ python3-rpm-generators-14-11.azl3.noarch.rpm
565565
python3-setuptools-69.0.3-5.azl3.noarch.rpm
566566
python3-test-3.12.9-9.azl3.x86_64.rpm
567567
python3-tools-3.12.9-9.azl3.x86_64.rpm
568-
python3-wheel-0.46.3-1.azl3.noarch.rpm
568+
python3-wheel-0.43.0-1.azl3.noarch.rpm
569569
readline-8.2-2.azl3.x86_64.rpm
570570
readline-debuginfo-8.2-2.azl3.x86_64.rpm
571571
readline-devel-8.2-2.azl3.x86_64.rpm

0 commit comments

Comments
 (0)