Skip to main content

Filelock LTS: The CVE-Aware Ecosystem 🛡️

⚠️ Disclaimer: This project is not affiliated with, endorsed by, or associated with the official filelock maintainers. All patches and releases are independently maintained and provided on a best-effort basis to support legacy environments.

A unified security ecosystem ensuring filelock safety across ALL Python versions (3.7 - 3.14).

🚨 The Vulnerabilities: CVE-2025-68146 & CVE-2026-22701

A critical Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to truncate or corrupt sensitive files via symlink or junction attacks.

🛡️ The Solution

This repository acts as a smart dispatcher. Installing filelock-lts automatically delivers the correct security strategy for your Python runtime:

Python Version Strategy Base Version Status
3.7 Custom Backport 3.12.2 🛡️ SECURED (Unix + Win32)
3.8 Custom Backport 3.16.1 🛡️ SECURED (Unix + Win32)
3.9 Custom Backport 3.19.1 🛡️ SECURED (Unix + Win32)
3.10+ Upstream Proxy Official >= 3.20.1 ✅ REDIRECTED

📦 Installation

Standard Installation (Recommended):

pip install filelock-lts

This automatically selects the correct package for your environment.

Specific Version Targeting:

pip install filelock-lts-py38  # For Python 3.8 specifically

🔮 The Future: Proactive Dependency Security

The Filelock LTS ecosystem is evolving to provide earlier visibility and stronger controls around dependency risk:

  • Early Warning Releases: Placeholder LTS releases may be published when a potential upstream security issue is under investigation, allowing users to prepare before official advisories are issued.
  • Runtime Policy Enforcement (Optional): An opt-in runtime module that detects vulnerable dependency versions at runtime and enforces user-configured policies (warn, block, or isolate).
  • Configurable Security Policies: Teams can choose how unpatched dependencies are handled based on their risk tolerance and operational needs.

🏗️ Architecture

  • lts-dispatcher: The metadata dispatcher (this branch).
  • lts-py3.X: Isolated branches containing specific source code or dependency definitions for that Python version.

🤝 License

Unlicense (Public Domain). Security belongs to everyone.

Release files for filelock-lts 2026.22701

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for filelock-lts 2026.22701
File Size Uploaded
filelock_lts-2026.22701.tar.gz 2.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for filelock-lts 2026.22701
File Interpreter ABI Platform
filelock_lts-2026.22701-py3-none-any.whl Python 3 none any Details

Total release size: 5.1 kB

Release files / filelock_lts-2026.22701.tar.gz

Download URL filelock_lts-2026.22701.tar.gz
Size 2.6 kB
Tags Source
SHA-256 checksum
How to use checksums
0015b88dec511bf8ec9c023a1fed6e0d77a602ec8177bf5a4e8235150609a763
BLAKE2b-256 checksum
How to use checksums
48c7eea06ec5f9b9d2c11b359a9fa64e5185ef42b160277b3c4a693c49e5df82
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 30, 2026.

Transparency log

Release files / filelock_lts-2026.22701-py3-none-any.whl

Download URL filelock_lts-2026.22701-py3-none-any.whl
Size 2.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c11c408d3852d5aeb7b75e85b2d0bdcd1bb289641c81b2b2f6d3093b0bc49a87
BLAKE2b-256 checksum
How to use checksums
22731f9d06803363e8ee877de83922262f6f582d8d56e08cd8afabd5bff501e5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2026.22701 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page