From d48112803c1d6b8d2119e77c5d86eb07cc9a17f6 Mon Sep 17 00:00:00 2001 From: "snyk-io[bot]" <141718529+snyk-io[bot]@users.noreply.github.com> Date: Sun, 11 Jan 2026 21:03:01 +0000 Subject: [PATCH] fix: inference/worker/requirements-hf.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FILELOCK-14912448 --- inference/worker/requirements-hf.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/inference/worker/requirements-hf.txt b/inference/worker/requirements-hf.txt index 6df5ae0a4d..733c859df2 100644 --- a/inference/worker/requirements-hf.txt +++ b/inference/worker/requirements-hf.txt @@ -5,3 +5,4 @@ huggingface_hub sse-starlette torch uvicorn +filelock>=3.20.3 # not directly required, pinned by Snyk to avoid a vulnerability