Python 3.9 compatible filelock with CVE-2025-68146 patch
Project description
Filelock LTS (py3.10) - ➡️ REDIRECT
⚠️ Disclaimer: This project is not affiliated with, endorsed by, or associated with the official
filelockmaintainers. All patches and releases are independently maintained and provided on a best-effort basis to support legacy environments.
| Metric | Details |
|---|---|
| CVE | CVE-2025-68146 |
| Version | 2025.68146 |
| Base Core | filelock Upstream >= 3.20.1 |
| Python | Python 3.10 |
| License | Unlicense (Public Domain) |
➡️ Modern Python Redirect
This package ensures you are using a secure version of filelock on Python 3.10.
Since Python 3.10 is supported by the official upstream maintainers, this LTS package acts as a Meta-Package / Proxy.
How it works
Installing this package automatically installs the official filelock >= 3.20.1, which contains the official fix for CVE-2025-68146.
pip install filelock-lts-py3.10
Why use this?
- Consistency: Use
filelock-ltsacross your entire fleet (legacy and modern) without changing requirements files. - Continuity: Ensures automated security redirect logic remains active even if upstream release patterns change.
🔮 The Future: Proactive Dependency Security
The Filelock LTS ecosystem is evolving to provide earlier visibility and stronger controls around dependency risk:
- Early Warning Releases: Placeholder LTS releases may be published when a potential upstream security issue is under investigation, allowing users to prepare before official advisories are issued.
- Runtime Policy Enforcement (Optional): An opt-in runtime module that detects vulnerable dependency versions at runtime and enforces user-configured policies (warn, block, or isolate).
- Configurable Security Policies: Teams can choose how unpatched dependencies are handled based on their risk tolerance and operational needs.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file filelock_lts_py310-2025.68146.1.tar.gz.
File metadata
- Download URL: filelock_lts_py310-2025.68146.1.tar.gz
- Upload date:
- Size: 20.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
94a0734e218e77862e26ed4a1cebf2e39919935c9a80f089f8cd18fa5f2fa306
|
|
| MD5 |
68bb50c0ce7be12d77562d173394f678
|
|
| BLAKE2b-256 |
2d335b7c189552f6547cfb0bb167537e2b5f654869c0ad81bc28b421b7ffdbc5
|
Provenance
The following attestation bundles were made for filelock_lts_py310-2025.68146.1.tar.gz:
Publisher:
publish.yml on 1minds3t/filelock-lts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
filelock_lts_py310-2025.68146.1.tar.gz -
Subject digest:
94a0734e218e77862e26ed4a1cebf2e39919935c9a80f089f8cd18fa5f2fa306 - Sigstore transparency entry: 779624702
- Sigstore integration time:
-
Permalink:
1minds3t/filelock-lts@1dfd6ac63cfe30bf3e6ad52cff5b39070afc8a33 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/1minds3t
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@1dfd6ac63cfe30bf3e6ad52cff5b39070afc8a33 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file filelock_lts_py310-2025.68146.1-py3-none-any.whl.
File metadata
- Download URL: filelock_lts_py310-2025.68146.1-py3-none-any.whl
- Upload date:
- Size: 17.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a97864827b779378f3cf666260d2123d82f43afa934980825be08efef66be177
|
|
| MD5 |
e756d45345a4e0d0b2cad6196b99ce74
|
|
| BLAKE2b-256 |
3c7c88da4ef7695611174db27f842d7902e1b84a64d3f1ab487898b02f4c459f
|
Provenance
The following attestation bundles were made for filelock_lts_py310-2025.68146.1-py3-none-any.whl:
Publisher:
publish.yml on 1minds3t/filelock-lts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
filelock_lts_py310-2025.68146.1-py3-none-any.whl -
Subject digest:
a97864827b779378f3cf666260d2123d82f43afa934980825be08efef66be177 - Sigstore transparency entry: 779624705
- Sigstore integration time:
-
Permalink:
1minds3t/filelock-lts@1dfd6ac63cfe30bf3e6ad52cff5b39070afc8a33 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/1minds3t
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@1dfd6ac63cfe30bf3e6ad52cff5b39070afc8a33 -
Trigger Event:
workflow_dispatch
-
Statement type: