Skip to content

release: bump version to 2.3.4#10838

Merged
radoering merged 1 commit intopython-poetry:2.3from
radoering:release/2.3.4
Apr 12, 2026
Merged

release: bump version to 2.3.4#10838
radoering merged 1 commit intopython-poetry:2.3from
radoering:release/2.3.4

Conversation

@radoering
Copy link
Copy Markdown
Member

Fixed

  • Fix a performance regression in the wheel installer that was introduced in Poetry 2.3.3 (#10821).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#10837).

Copy link
Copy Markdown

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@radoering radoering merged commit 7c7af71 into python-poetry:2.3 Apr 12, 2026
54 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant