Skip to content

Commit 3037ab0

Browse files
committed
fix: upgrade vulnerable dependencies for security
CRITICAL SECURITY FIXES: - deepspeed: 0.9.5 -> >=0.15.1 (fixes CVE-2024-43497 RCE vulnerability) - transformers: 4.39.3 -> >=4.53.0 (fixes 12 vulnerabilities including ReDoS) - gradio: unpinned -> >=5.31.0 (fixes 35+ vulnerabilities including XSS, LFI) These vulnerabilities pose significant security risks: - Remote Code Execution (deepspeed) - Cross-Site Scripting attacks (gradio) - Local File Inclusion (gradio) - Regular Expression DoS attacks (transformers) Upgrading to latest secure versions to protect against exploitation.
1 parent a31261c commit 3037ab0

File tree

2 files changed

+5
-3
lines changed

2 files changed

+5
-3
lines changed

pyproject.toml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,14 +43,15 @@ keywords = [
4343
dependencies = [
4444
"torch >= 1.9.0",
4545
"pytorch-lightning",
46-
"transformers==4.39.3",
46+
"transformers>=4.53.0",
4747
"datasets==2.14.5",
4848
"pyarrow >= 8.0.0, < 21.0.0",
49+
"scipy >= 1.0.0",
4950
"evaluate==0.4.0",
5051
"bitsandbytes==0.41.1",
5152
"sentencepiece",
52-
"deepspeed==0.9.5",
53-
"gradio",
53+
"deepspeed>=0.15.1",
54+
"gradio>=5.31.0",
5455
"click",
5556
"wget",
5657
"ai21",

requirements-dev.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,3 +3,4 @@ pytest
33
autoflake
44
absolufy-imports
55
pyarrow >= 8.0.0, < 21.0.0
6+
scipy >= 1.0.0

0 commit comments

Comments
 (0)