Backport the following security fix from the upstream 21.1 release fixing CVE-2021-3572: https://github.com/pypa/pip/pull/9827 Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit cf949134b7371e23c4a8b44fc8b1d646628dfbce) Signed-off-by: Peter Korsgaard <peter@korsgaard.com>