Hi all,
First, thank you for all the incredible work that goes into maintaining pyRevi, it remains an indispensable tool for our daily workflows.
I’m currently navigating some internal IT compliance reviews regarding software dependencies. Our security tooling flagged that the bundled CPython runtime currently ships with version 3.12.3, which has a few documented CVEs in vulnerability databases (even though, practically speaking, pyRevit runs locally and doesn’t expose a network attack surface).
I understand that managing and embedding Python runtimes alongside IronPython and .NET interop is a massive balancing act. I wanted to ask:
-
Roadmap / Feasibility: Is there a planned roadmap or timeline for bumping the bundled CPython runtime to the latest stable release (e.g., Python 3.14+)?
-
Custom Overrides: For those of us dealing with strict enterprise security policies, is there a supported way to point pyRevit’s CPython engine to an external, centrally managed local Python installation rather than using the hardcoded bundled version?
Any insight into how the team handles runtime version lifecycles would be greatly appreciated.
Here is a link to the know vulnerabilities of python 3.12.3:
Regards
Charlie