poetry is vulnerable to Supply Chain Integrity Issue
59
Medium Risk
When poetry publish --build runs, a failing build step does not stop the publish flow in affected versions. If older wheels or sdists are already present in the configured dist/ directory, Poetry continues and uploads those stale artifacts to the target repository. Maintainers and CI pipelines that rely on --build to publish freshly built output can therefore release unintended package contents, breaking artifact integrity for downstream consumers. The fix propagates the build command exit code and aborts publishing when the build fails.
You are affected if you are using a version that falls within the vulnerable range.
poetry is vulnerable to Supply Chain Integrity Issue in versions 1.2.0 - 2.3.4.
Upgrade the poetry library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant