Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052818 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052821 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052968 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052977 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052994 - https://snyk.io/vuln/SNYK-PYTHON-TRANSFORMERS-13018959
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the ✨ Finishing touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🧪 Early access (Sonnet 4.5): enabledWe are currently testing the Sonnet 4.5 model, which is expected to improve code review quality. However, this model may lead to increased noise levels in the review comments. Please disable the early access features if the noise level causes any inconvenience. Note:
Comment |
Snyk has created this PR to fix 6 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
extra/requirements.txtImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
Note
Pins
torch>=2.8.0andtransformers>=4.53.0and ensurescompelis included inextra/requirements.txt.extra/requirements.txt:torch>=2.8.0andtransformers>=4.53.0.compelis included.Written by Cursor Bugbot for commit e1cbdb9. This will update automatically on new commits. Configure here.