Skip to content

update deps away from insecure versions#1207

Merged
erickgalinkin merged 1 commit intoNVIDIA:mainfrom
leondz:update/fix_reqs_versions_2505
May 12, 2025
Merged

update deps away from insecure versions#1207
erickgalinkin merged 1 commit intoNVIDIA:mainfrom
leondz:update/fix_reqs_versions_2505

Conversation

@leondz
Copy link
Collaborator

@leondz leondz commented May 12, 2025

tqdm CVE-2024-34062
langchain (various CVE-2023-46229)
litellm (various incl CVE-2025-0628) - nb unicode bug now fixed in their main
transformers (various incl CVE-2024-11394, CVE-2025-1194)
jinja2 (CVE-2025-27516)

@leondz leondz requested a review from erickgalinkin May 12, 2025 06:44
@leondz leondz added the architecture Architectural upgrades label May 12, 2025
Copy link
Collaborator

@erickgalinkin erickgalinkin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Versions updated, tests passing, I'm happy with it.

@erickgalinkin erickgalinkin merged commit b7c0a3e into NVIDIA:main May 12, 2025
12 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators May 12, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

architecture Architectural upgrades

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants