[Snyk] Fix for 3 vulnerabilities - #96
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-NLTK-17817780 - https://snyk.io/vuln/SNYK-PYTHON-STARLETTE-13733964 - https://snyk.io/vuln/SNYK-PYTHON-STARLETTE-8186175
|
This update includes a medium-risk upgrade for starlette@0.27.0 → starlette@0.49.1Risk: Medium This upgrade spans multiple minor versions and introduces a significant breaking change related to Python version compatibility.
Recommendation: Verify that your production environment and development workflows are running on Python 3.9 or a more recent version before applying this upgrade. Source: Starlette Changelog, EOL Information nltk@3.8.1 → nltk@3.10.0Risk: Medium This upgrade introduces a significant behavioral change related to security policy.
Recommendation: After upgrading, test any functionality that loads NLTK resources (e.g., tokenizers, corpora, models) to ensure it is not impacted by the new security constraints. Review the NLTK documentation for the new security model if you encounter issues. Source: NLTK ChangeLog
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
❌ Deploy Preview for heroic-strudel-239c3c failed. Why did it fail? →
|
Vulnerable Libraries (10)
More info on how to fix Vulnerable Libraries in Python. 👉 Go to the dashboard for detailed results. 📥 Happy? Share your feedback with us. |
❌ Deploy Preview for joyful-gelato-ff27ed failed. Why did it fail? →
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Snyk has created this PR to fix 3 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Directory Traversal
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Allocation of Resources Without Limits or Throttling
This change is