Skip to content

fix(core): bump vendored certifi to 2026.07.22 for CVE-2023-37920 - #553

Merged
yndu13 merged 1 commit into
masterfrom
feature/aone-85355743-update-vendored-certifi
Aug 18, 2026
Merged

fix(core): bump vendored certifi to 2026.07.22 for CVE-2023-37920#553
yndu13 merged 1 commit into
masterfrom
feature/aone-85355743-update-vendored-certifi

Conversation

@yndu13

@yndu13 yndu13 commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Update vendored certifi in aliyun-python-sdk-core from 2018.01.18 to 2026.07.22 and refresh cacert.pem (removes e-Tugra roots, fixes CVE-2023-37920).
  • Keep __file__-based where() so the nested vendored package path still resolves the CA bundle.
  • Bump package to 2.16.1; add unit tests for version, bundle path, and e-Tugra exclusion.

Replace the 2018 CA bundle that still trusts e-Tugra roots so SAP security
compliance scanners stop flagging aliyun-python-sdk-core.
@yndu13 yndu13 self-assigned this Aug 17, 2026
@yndu13
yndu13 merged commit 73f1259 into master Aug 18, 2026
4 of 16 checks passed
@yndu13
yndu13 deleted the feature/aone-85355743-update-vendored-certifi branch August 18, 2026 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant