Filelock LTS (py3.11) - ➡️ REDIRECT
⚠️ Disclaimer: This project is not affiliated with, endorsed by, or associated with the official
filelockmaintainers. All patches and releases are independently maintained and provided on a best-effort basis to support legacy environments.
| Metric | Details |
|---|---|
| CVE | CVE-2025-68146 |
| Version | 2025.68146 |
| Base Core | filelock Upstream >= 3.20.1 |
| Python | Python 3.11 |
| License | Unlicense (Public Domain) |
➡️ Modern Python Redirect
This package ensures you are using a secure version of filelock on Python 3.11.
Since Python 3.11 is supported by the official upstream maintainers, this LTS package acts as a Meta-Package / Proxy.
How it works
Installing this package automatically installs the official filelock >= 3.20.1, which contains the official fix for CVE-2025-68146.
pip install filelock-lts-py3.11
Why use this?
- Consistency: Use
filelock-ltsacross your entire fleet (legacy and modern) without changing requirements files. - Continuity: Ensures automated security redirect logic remains active even if upstream release patterns change.
🔮 The Future: Proactive Dependency Security
The Filelock LTS ecosystem is evolving to provide earlier visibility and stronger controls around dependency risk:
- Early Warning Releases: Placeholder LTS releases may be published when a potential upstream security issue is under investigation, allowing users to prepare before official advisories are issued.
- Runtime Policy Enforcement (Optional): An opt-in runtime module that detects vulnerable dependency versions at runtime and enforces user-configured policies (warn, block, or isolate).
- Configurable Security Policies: Teams can choose how unpatched dependencies are handled based on their risk tolerance and operational needs.
Release files for filelock-lts-py311 2025.68146.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| filelock_lts_py311-2025.68146.2.tar.gz | 9.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| filelock_lts_py311-2025.68146.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.0 kB
Release files / filelock_lts_py311-2025.68146.2.tar.gz
| Download URL | filelock_lts_py311-2025.68146.2.tar.gz |
|---|---|
| Size | 9.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
620742b92e1baef69911de0b11b7bc27904dde5fb5208525768a7e1d1065c1c5
|
|
BLAKE2b-256 checksum How to use checksums |
d1f685f9cb757b0d8c3c8f7a86e3b941b3d8a3a3a05923bedab148ee3d978a61
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 25, 2025.
Transparency logRelease files / filelock_lts_py311-2025.68146.2-py3-none-any.whl
| Download URL | filelock_lts_py311-2025.68146.2-py3-none-any.whl |
|---|---|
| Size | 3.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d15d885f0c9a2db3b4b538bd47107bc04047205dbcf2734ed2c73bb5823d8e04
|
|
BLAKE2b-256 checksum How to use checksums |
9e3825b460a5bbadf17e60061dc50c879a88f711b33e2f533e9d524b090c797f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 25, 2025.
Transparency log