Files
WSL/tools/devops
Ben Hillis f69bb93363 Bump GitPython to 3.1.49 to fix Dependabot alerts (#40472)
Addresses CVEs in GitPython <= 3.1.48:

- Path traversal in reference APIs (patched in 3.1.48)

- Newline injection in config_writer().set_value() enabling RCE via core.hooksPath (patched in 3.1.49)

Co-authored-by: Ben Hillis <benhill@ntdev.microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-08 23:46:53 +00:00
..