Skip to content

Update nltk requirement from >=3.8.2 to >=3.10.2 - #93

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/nltk-gte-3.10.0
Open

Update nltk requirement from >=3.8.2 to >=3.10.2#93
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/nltk-gte-3.10.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on nltk to permit the latest version.

Release notes

Sourced from nltk's releases.

v3.10.2

Version 3.10.2 2026-08-05

  • Remove inisec.py and document PYTHONSAFEPATH instead
  • Skip draft step in release workflow
  • Fix symlink escape in FramenetCorpusReader (CWE-59)
  • Guard tempfile.gettempdir() when building pathsec allowed roots
  • add tests for transitive_closure

Thanks to the following contributors to 3.10.2: Litesh Ghute, Eric Kafe, Evan Kiefer, tarann26 and Rav Singh Chandan

Changelog

Sourced from nltk's changelog.

Version 3.10.3 2026-08-12

  • docs: wrap Chat-80 HOWTO output
  • Sandbox Stanford JAR execution to nltk_data directories
  • Harden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)
  • Extend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)
  • Bound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)
  • fix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)
  • fix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)
  • fix(security): validate corpus-reader roots against the data sandbox (CWE-73)
  • fix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)
  • Additional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)

Thanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.

Version 3.10.2 2026-08-05

  • Remove inisec.py and document PYTHONSAFEPATH instead
  • Skip draft step in release workflow
  • Fix symlink escape in FramenetCorpusReader (CWE-59)
  • Guard tempfile.gettempdir() when building pathsec allowed roots
  • add tests for transitive_closure

Thanks to the following contributors to 3.10.2: Litesh Ghute, Eric Kafe, Evan Kiefer, tarann26 and Rav Singh Chandan

Version 3.10.1 2026-07-29

  • Expand ~ in env-var paths
  • Validate types after WordNet app pickle deserialization
  • Fix uncontrolled search path in HunposTagger
  • Use exact thirds in masi_distance
  • Avoid retaining bllip import exceptions
  • Fix word_tokenize: pad opening single quote before multi-letter words.
  • Implement Tree.pformat_latex_forest.
  • Prevent module hijacking in inline imports.
  • Fix ReDoS in TweetTokenizer URL and email regexes.

Thanks to the following contributors to 3.10.1: Abhinav, Litesh Ghute, Eric Kafe, Eryk Kaźmierczak, Selim C., Muhtasim Munif Fahim, Triniti K., and Tom Y. Mitich.

Version 3.10.0 2026-06-11

  • Enforce the stricter nltk.pathsec security policy by default
  • Document the new security model and migration guidance
  • Harden resource loading against path traversal and SSRF/DNS-rebinding
  • Harden downloader path handling and block XML entity expansion
  • Close remaining corpus-reader security edge cases
  • Replace unsafe exec() usage in the utility CLI

... (truncated)

Commits
  • 474af1f Scope release notes to the release version (#3737)
  • b69e06b Prepare a 3.10.2 RC (#3736)
  • 2516a4d Split sentences ending in a curly quote or guillemet in Punkt (#3728)
  • ee1a42e fix(security): close symlink escape in IPIPANCorpusReader (CWE-59) (#3727)
  • 0f89570 Skip draft step in release workflow (#3734)
  • 736d321 fix(security): close symlink escape in FramenetCorpusReader (CWE-59) (#3726)
  • dcf080a Guard tempfile.gettempdir() when building pathsec allowed roots (#3725)
  • 5f76b0a add tests for transitive_closure (#3703)
  • d762c70 ci(deps): bump the github-actions group with 2 updates (#3729)
  • e5b814e Remove inisec.py and document PYTHONSAFEPATH instead (#3732)
  • Additional commits viewable in compare view


This change is Reviewable

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 3, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 3, 2026
@vercel

vercel Bot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
100-python-projects Error Error Aug 13, 2026 12:57am
python-projects Ready Ready Preview Aug 13, 2026 12:57am
python-projects-1 Error Error Aug 13, 2026 12:57am
python-projects-rqac Ready Ready Preview Aug 13, 2026 12:57am

@codesandbox

codesandbox Bot commented Aug 3, 2026

Copy link
Copy Markdown

Review or Edit in CodeSandbox

Open the branch in Web EditorVS CodeInsiders

Open Preview

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@netlify

netlify Bot commented Aug 3, 2026

Copy link
Copy Markdown

Deploy Preview for joyful-gelato-ff27ed ready!

Name Link
🔨 Latest commit 6bad947
🔍 Latest deploy log https://app.netlify.com/projects/joyful-gelato-ff27ed/deploys/6a7d16336bffd700080637d3
😎 Deploy Preview https://deploy-preview-93--joyful-gelato-ff27ed.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Aug 3, 2026

Copy link
Copy Markdown

Deploy Preview for heroic-strudel-239c3c failed. Why did it fail? →

Name Link
🔨 Latest commit 6bad947
🔍 Latest deploy log https://app.netlify.com/projects/heroic-strudel-239c3c/deploys/6a7d1633d3331600086a8de2

@dependabot dependabot Bot changed the title Update nltk requirement from >=3.8.2 to >=3.10.0 Update nltk requirement from >=3.8.2 to >=3.10.2 Aug 13, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/nltk-gte-3.10.0 branch from 5926cb2 to 2ca0eb4 Compare August 13, 2026 00:50
@github-actions

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

Updates the requirements on [nltk](https://github.com/nltk/nltk) to permit the latest version.
- [Release notes](https://github.com/nltk/nltk/releases)
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](nltk/nltk@3.8.2...v3.10.2)

---
updated-dependencies:
- dependency-name: nltk
  dependency-version: 3.10.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/nltk-gte-3.10.0 branch from 2ca0eb4 to 6bad947 Compare August 13, 2026 00:56
@github-actions

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants