From 9dcabea5e1d95c5d4ed7689bfcb0ea15a7c5e1fe Mon Sep 17 00:00:00 2001 From: "snyk-io[bot]" <141718529+snyk-io[bot]@users.noreply.github.com> Date: Fri, 9 Jan 2026 01:59:40 +0000 Subject: [PATCH] fix: data/datasets/zhihu-kol/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052805 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- data/datasets/zhihu-kol/requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/data/datasets/zhihu-kol/requirements.txt b/data/datasets/zhihu-kol/requirements.txt index c2894c5d9e..b07a8ba2cf 100644 --- a/data/datasets/zhihu-kol/requirements.txt +++ b/data/datasets/zhihu-kol/requirements.txt @@ -131,7 +131,7 @@ tqdm==4.64.1 traitlets==5.9.0 typing_extensions==4.5.0 uri-template==1.2.0 -urllib3==1.26.14 +urllib3==2.6.3 uvicorn==0.20.0 wcwidth==0.2.6 webcolors==1.12 @@ -140,3 +140,4 @@ websocket-client==1.5.1 Werkzeug==2.2.2 xxhash==3.2.0 yarl==1.8.2 +torch>=2.9.0 # not directly required, pinned by Snyk to avoid a vulnerability