The current version requirement for scikit-learn forces us to use a version that has known vulnerabilities (https://github.com/advisories/GHSA-jw8x-6495-233v). Is there any specific reason for the version constraint? If not, I'd happily open a PR to upgrade.