Hi debian-security (2021.09.15_23:32:14_+0000) > As mentioned in debian-devel recently [1], at the DebConf 21 Debian > Python BoF [2] we discussed the idea of reverting our unbundling patches > to python-pip. The group consensus was that it wasn't worth the effort > to maintain these patches.
FYI, this is now done, as of pip 21.3.1+dfsg-1. Updated embedded-code-copies: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/64edb42f3ba4e9c79aefea7338b195f7975bfe70 SR -- Stefano Rivera http://tumbleweed.org.za/ +1 415 683 3272