Skip to content

chore: bump transformers from 4.53.0 to 5.0.0rc1#198

Draft
adubovik wants to merge 1 commit intodevelopmentfrom
chore/bump-transformers-to-v5
Draft

chore: bump transformers from 4.53.0 to 5.0.0rc1#198
adubovik wants to merge 1 commit intodevelopmentfrom
chore/bump-transformers-to-v5

Conversation

@adubovik
Copy link
Collaborator

Fixes vulnerability CVE-2025-14920.

@adubovik adubovik requested a review from Allob as a code owner January 20, 2026 15:29
@adubovik adubovik self-assigned this Jan 20, 2026
@adubovik
Copy link
Collaborator Author

adubovik commented Jan 20, 2026

/deploy-review

GitHub actions run: 21177273914

Stage Status
deploy-review Success ✅
chat Success ✅

@adubovik adubovik marked this pull request as draft January 20, 2026 17:38
@adubovik
Copy link
Collaborator Author

The migration to the release candidate version of the package is too risky. We don't know how thoroughly the only client of this package - sentence-transformers - has tested integration with Transformers v5.

Moreover, we don't know where SNYK scanner gets the information that transformers-5.0.0rc1 has actually fixed the vulnerability issue. There is nothing relevant on the transformers release logs.

It's decided to postpone the fix until the transformers package gets the official v5 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant