Filelock LTS: The CVE-Aware Ecosystem 🛡️
⚠️ Disclaimer: This project is not affiliated with, endorsed by, or associated with the official
filelockmaintainers. All patches and releases are independently maintained and provided on a best-effort basis to support legacy environments.
A unified security ecosystem ensuring filelock safety across ALL Python versions (3.7 - 3.14).
🚨 The Vulnerabilities: CVE-2025-68146 & CVE-2026-22701
A critical Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to truncate or corrupt sensitive files via symlink or junction attacks.
🛡️ The Solution
This repository acts as a smart dispatcher. Installing filelock-lts automatically delivers the correct security strategy for your Python runtime:
| Python Version | Strategy | Base Version | Status |
|---|---|---|---|
| 3.7 | Custom Backport | 3.12.2 |
🛡️ SECURED (Unix + Win32) |
| 3.8 | Custom Backport | 3.16.1 |
🛡️ SECURED (Unix + Win32) |
| 3.9 | Custom Backport | 3.19.1 |
🛡️ SECURED (Unix + Win32) |
| 3.10+ | Upstream Proxy | Official >= 3.20.1 |
✅ REDIRECTED |
📦 Installation
Standard Installation (Recommended):
pip install filelock-lts
This automatically selects the correct package for your environment.
Specific Version Targeting:
pip install filelock-lts-py38 # For Python 3.8 specifically
🔮 The Future: Proactive Dependency Security
The Filelock LTS ecosystem is evolving to provide earlier visibility and stronger controls around dependency risk:
- Early Warning Releases: Placeholder LTS releases may be published when a potential upstream security issue is under investigation, allowing users to prepare before official advisories are issued.
- Runtime Policy Enforcement (Optional): An opt-in runtime module that detects vulnerable dependency versions at runtime and enforces user-configured policies (warn, block, or isolate).
- Configurable Security Policies: Teams can choose how unpatched dependencies are handled based on their risk tolerance and operational needs.
🏗️ Architecture
lts-dispatcher: The metadata dispatcher (this branch).lts-py3.X: Isolated branches containing specific source code or dependency definitions for that Python version.
🤝 License
Unlicense (Public Domain). Security belongs to everyone.
Release files for filelock-lts 2026.22701
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| filelock_lts-2026.22701.tar.gz | 2.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| filelock_lts-2026.22701-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 5.1 kB
Release files / filelock_lts-2026.22701.tar.gz
| Download URL | filelock_lts-2026.22701.tar.gz |
|---|---|
| Size | 2.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0015b88dec511bf8ec9c023a1fed6e0d77a602ec8177bf5a4e8235150609a763
|
|
BLAKE2b-256 checksum How to use checksums |
48c7eea06ec5f9b9d2c11b359a9fa64e5185ef42b160277b3c4a693c49e5df82
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 30, 2026.
Transparency logRelease files / filelock_lts-2026.22701-py3-none-any.whl
| Download URL | filelock_lts-2026.22701-py3-none-any.whl |
|---|---|
| Size | 2.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c11c408d3852d5aeb7b75e85b2d0bdcd1bb289641c81b2b2f6d3093b0bc49a87
|
|
BLAKE2b-256 checksum How to use checksums |
22731f9d06803363e8ee877de83922262f6f582d8d56e08cd8afabd5bff501e5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 30, 2026.
Transparency log