Sourced from virtualenv's releases.
21.7.12
What's Changed
- 🔧 chore(changelog): drop dead CVE-2026-24049 fragment by
@gaborbernatin pypa/virtualenv#3249- 🐛 fix(activation): escape batch quote() against injection by
@gaborbernatin pypa/virtualenv#3250- 🐛 fix(seed): verify downloaded wheel digests by
@gaborbernatin pypa/virtualenv#3251Full Changelog: https://github.com/pypa/virtualenv/compare/21.7.11...21.7.12
21.7.11
What's Changed
- Add OpenSSF Scorecard workflow by
@gaborbernatin pypa/virtualenv#3238- Document AI-assisted contributions and licensing policy by
@gaborbernatin pypa/virtualenv#3239- 👷 ci(release): attest and sign release provenance by
@gaborbernatin pypa/virtualenv#3242- 👷 ci: harden Scorecard-scored checks in CI by
@gaborbernatin pypa/virtualenv#3241- 🐛 fix(ci): parallelize graalpy tests, recover crashed workers by
@gaborbernatin pypa/virtualenv#3240- 🐛 fix(ci): mark real-shell activation tests as slow by
@gaborbernatin pypa/virtualenv#3243- 👷 ci: run macOS jobs on macos-26 by
@gaborbernatin pypa/virtualenv#3244- 🐛 fix(activation): undo a live activation before activate.bat saves values by
@darrenhuaiin pypa/virtualenv#3245- 🐛 fix(create): keep pyvenv.cfg values on a single line by
@gaborbernatin pypa/virtualenv#3247- 🔧 chore(test): add opt-in Atheris fuzz harness by
@gaborbernatin pypa/virtualenv#3246- 📝 docs(readme): add OpenSSF Best Practices badge by
@gaborbernatin pypa/virtualenv#3248Full Changelog: https://github.com/pypa/virtualenv/compare/21.7.10...21.7.11
21.7.10
What's Changed
- 🔧 chore: check spelling with typos in pre-commit by
@even-evenin pypa/virtualenv#3235- 🐛 fix(activation): keep and restore the user's TCL_LIBRARY and TK_LIBRARY by
@darrenhuaiin pypa/virtualenv#3234- 🐛 fix(create): skip blank and comment lines in pyvenv.cfg by
@r3wretrhyin pypa/virtualenv#3232- 🐛 fix(activation): restore PKG_CONFIG_PATH that was not set before by
@darrenhuaiin pypa/virtualenv#3233New Contributors
@r3wretrhymade their first contribution in pypa/virtualenv#3232Full Changelog: https://github.com/pypa/virtualenv/compare/21.7.9...21.7.10
21.7.9
What's Changed
- fix(test): EncodingWarning: 'encoding' argument not specified by
@even-evenin pypa/virtualenv#3228- 🐛 fix(config): ignore a config file that fails to parse instead of crashing by
@darrenhuaiin pypa/virtualenv#3230
... (truncated)
Sourced from virtualenv's changelog.
Bugfixes - 21.7.12
- Fix
activate.batrunning arbitrary commands from a crafted--prompt,VIRTUALENV_PROMPT, or config file value. (:issue:3250)- Verify a downloaded seed wheel's sha256 against PyPI before seeding it into a virtual environment, skipped when a custom pip index is configured. (:issue:
3251)
v21.7.11 (2026-09-17)
Bugfixes - 21.7.11
- Running
activate.batagain beforedeactivateno longer makesdeactivateleave the environment'sPKG_CONFIG_PATH,TCL_LIBRARYandTK_LIBRARYbehind, or lose values the user had set before the first activation - by :user:darrenhuai. (:issue:3245)- Write
pyvenv.cfgvalues on a single line, so a prompt carrying a line boundary can no longer inject configuration.--prompt, theVIRTUALENV_PROMPTenvironment variable and the config file all set the prompt, andpyvenv.cfghas no escape syntax, so a newline, a carriage return, or any other boundarystr.splitlinesrecognizes, such asU+2028, started a new configuration line. Reading the file back picked up those lines as keys, and since the last value for a key wins, they replaced anything written earlier, includinghome. (:issue:3247)Improved Documentation - 21.7.11
- Document the policy for AI-assisted contributions and the licensing rules for dependencies. (:issue:
3239)Misc - 21.7.11
- :issue:
3238, :issue:3240, :issue:3241, :issue:3242, :issue:3243, :issue:3244, :issue:3246
v21.7.10 (2026-09-15)
Bugfixes - 21.7.10
- Skip blank lines,
#comments and lines without=inpyvenv.cfginstead of raisingValueError- by :user:r3wretrhy. (:issue:3232)deactivatein bash, fish and PowerShell unsetsPKG_CONFIG_PATHwhen activation found it unset, instead of keeping the environment'slib/pkgconfig. csh activation no longer drops aPKG_CONFIG_PATHthe user had set. Activation in batch, fish, nushell and PowerShell no longer adds a trailing separator whenPKG_CONFIG_PATHis unset, and PowerShell and nushell build the value with the host's path separators - by :user:darrenhuai. (:issue:3233)- Activation in bash, csh, fish and PowerShell keeps the user's
TCL_LIBRARYandTK_LIBRARY, anddeactivaterestores them. csh and PowerShell removed both variables on every activation, fish did so when the interpreter has
... (truncated)
9666b42
release 21.7.12a01ed3e
🐛 fix(seed): verify downloaded wheel digests (#3251)d721ff1
🐛 fix(activation): escape batch quote() against injection (#3250)087a2ef
🔧 chore(changelog): drop dead CVE-2026-24049 fragment (#3249)73e352a
release 21.7.1168ee5a3
📝 docs(readme): add OpenSSF Best Practices badge (#3248)787d1c9
🔧 chore(test): add opt-in Atheris fuzz harness (#3246)a30f995
🐛 fix(create): keep pyvenv.cfg values on a single line (#3247)469dd28
🐛 fix(activation): undo a live activation before activate.bat saves
values (#...a045a14
👷 ci: run macOS jobs on macos-26 (#3244)