Skip to content

build(deps): update dependencies - #211

Open
DRL-NextGen wants to merge 1 commit into
mainfrom
auto-update-dependencies-2026-08-24
Open

build(deps): update dependencies#211
DRL-NextGen wants to merge 1 commit into
mainfrom
auto-update-dependencies-2026-08-24

Conversation

@DRL-NextGen

Copy link
Copy Markdown
Member

Removed packages

Package Version
cligj 0.7.2
distro 1.9.0

Added packages

Package Version
httpx2-jsfetch 1.0
jsonnet 0.22.0
ray-haproxy 2.8.25

Upgraded packages

Package From To Type
https://github.com/ibm/detect-secrets.git (38ba7e335083e0a4db8c53e9be414795b27891e9) 🔴
https://github.com/BiomedSciAI/biomed-multi-alignment (8cc56e9494b489ca86a63b76fa4cd2921f8af7f7) 🔴
https://github.com/UKAEA-IBM-STFC-Fusion-FMs/tokamind (40acef326253e6e30d962b4b8da06716cf2f1263) 🔴
https://github.com/BiomedSciAI/biomed-multi-omic.git (8b5694a922be7ccb1d3ee5c280c4dcef2eb95df9) 🔴
https://github.com/mathiaszinnen/focal_loss_torch.git (69fd65795f2688c2c302029f383f1b58978c1123) 🔴
affine 2.4.0 3.0.0 🔴
alembic 1.19.0 1.19.1 🟢
anthropic 0.120.2 1.0.0 🔴
appnope 0.1.4 1.0.0 🔴
charset-normalizer 3.4.9 3.5.1 🟡
cuda-pathfinder 1.6.0 1.7.0 🟡
databricks-sdk 0.124.0 0.133.0 🔴
deepmerge 2.1.0 3.0 🔴
diffusers 0.39.0 0.40.0 🔴
fastar 0.11.0 0.12.0 🔴
fastjsonschema 2.22.1 2.22.2 🟢
filelock 3.32.2 3.32.4 🟢
gitpython 3.1.58 3.1.59 🟢
google-api-core 2.33.0 2.34.0 🟡
google-auth 2.56.2 2.56.3 🟢
googleapis-common-protos 1.75.0 1.75.1 🟢
greenlet 3.5.4 3.5.5 🟢
gunicorn 26.0.0 26.1.0 🟡
httpcore2 2.9.1 2.12.0 🟡
httpx2 2.9.1 2.12.0 🟡
huggingface-hub 1.26.0 1.28.0 🟡
hydra-core 1.3.4 1.3.5 🟢
idna 3.18 3.19 🟡
ipywidgets 8.1.8 8.1.9 🟢
jsonargparse 4.50.0 4.51.0 🟡
juliapkg 0.1.24 0.1.26 🔴
jupyterlab-widgets 3.0.16 3.0.17 🟢
litdata 0.2.67 0.2.71 🔴
ml-dtypes 0.5.4 0.6.0 🔴
narwhals 2.24.0 2.25.0 🟡
nbformat 5.10.4 5.11.1 🟡
nvidia-cublas 13.1.0.3 13.1.0.3, 13.6.1.10 🟢
nvidia-cudnn-frontend 1.26.0 1.27.0 🟡
obstore 0.11.0 0.11.1 🔴
openai 2.53.0 3.3.1 🔴
optree 0.19.1 0.20.0 🔴
platformdirs 4.11.0 4.11.3 🟢
pre-commit 4.6.1 4.6.2 🟢
proto-plus 1.28.2 1.28.3 🟢
pyarrow 25.0.0 25.0.1 🟢
pybase64 1.4.3 1.5.0 🟡
pybind11 3.0.4 3.1.0 🟡
pydantic-settings 2.14.2 2.15.0 🟡
pygments 2.20.0 2.21.0 🟡
pymdown-extensions 11.0.1 11.0.2 🟢
pystac-ext-classification 2.0.0 2.0.1 🟢
pystac-ext-datacube 2.2.0 2.2.1 🟢
pystac-ext-eo 1.1.0 1.1.1 🟢
pystac-ext-file 2.1.0 2.1.1 🟢
pystac-ext-grid 1.1.0 1.1.1 🟢
pystac-ext-item-assets 1.0.0 1.0.1 🟢
pystac-ext-label 1.0.1 1.0.2 🟢
pystac-ext-mgrs 1.0.0 1.0.1 🟢
pystac-ext-mlm 1.4.0 1.4.1 🟢
pystac-ext-pointcloud 1.0.0 1.0.1 🟢
pystac-ext-projection 2.0.0 2.0.1 🟢
pystac-ext-raster 1.1.0 1.1.1 🟢
pystac-ext-sar 1.0.0 1.0.1 🟢
pystac-ext-sat 1.0.0 1.0.1 🟢
pystac-ext-scientific 1.0.0 1.0.1 🟢
pystac-ext-storage 2.0.0 2.0.1 🟢
pystac-ext-table 1.2.0 1.2.1 🟢
pystac-ext-timestamps 1.1.0 1.1.1 🟢
pystac-ext-version 1.2.0 1.2.1 🟢
pystac-ext-view 1.0.0 1.0.1 🟢
pystac-ext-xarray-assets 1.0.0 1.0.1 🟢
python-discovery 1.5.1 1.5.2 🟢
python-dotenv 1.2.2 1.2.3 🟢
python-json-logger 4.1.0 4.2.0 🟡
pyzmq 27.1.0 27.2.0 🟡
quack-kernels 0.6.1 0.6.3 🔴
rasterio 1.5.0 1.5.1 🟢
ray 2.56.1 2.58.0 🟡
ruff 0.16.1 0.16.4 🔴
scipy 1.18.0 1.18.1 🟢
sentry-sdk 2.66.1 2.68.0 🟡
soupsieve 2.9.1 2.9.2 🟢
sqlalchemy 2.0.51 2.0.52 🟢
sqlparse 0.5.5 0.6.0 🔴
starlette 1.4.0 1.6.0 🟡
stringzilla 5.0.7 5.1.2 🟡
tifffile 2026.7.31 2026.8.23 🟡
tiktoken 0.13.0 0.14.0 🔴
torch-einops-utils 0.1.20 0.1.21 🔴
torchcodec 0.15.0 0.16.0 🔴
torchgeo 0.9.0 0.10.0 🔴
tornado 6.5.7 6.5.8 🟢
transformers 5.14.1 5.15.1 🟡
typing-inspection 0.4.2 0.4.4 🔴
uv 0.12.1 0.12.5 🔴
uvicorn 0.52.1 0.52.4 🔴
virtualenv 21.7.1 21.7.4 🟢
widgetsnbextension 4.0.15 4.0.16 🟢
x-transformers 2.25.5 2.27.2 🟡
xxhash 3.8.1 4.0.1 🔴
zensical 0.0.53 0.0.57 🔴

Signed-off-by: DRL NextGen <220003231+DRL-NextGen@users.noreply.github.com>
@DRL-NextGen DRL-NextGen added ci Enable CI integration dependency-update This PR is about upgrading dependencies labels Aug 24, 2026
@DRL-NextGen

Copy link
Copy Markdown
Member Author

Checks Summary

Last run: 2026-08-24T06:24:37.478Z

Mend Unified Agent vulnerability scan found 6 vulnerabilities:

Severity Identifier Package Details Fix
🔺 High CVE-2026-65918 torchvision-0.26.0-cp312-cp312-manylinux_2_28_x86_64.whl
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vul...PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.
Not Available
🔺 High CVE-2026-58659 lightning-2.6.5-py3-none-any.whl
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerabi...PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.
Not Available
🔷 Medium CVE-2025-3000 torch-2.11.0-cp312-cp312-manylinux_2_28_x86_64.whl
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function to...A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
torch - 2.13.0
🔷 Medium CVE-2026-59890 setuptools-80.10.2-py3-none-any.whl
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python...setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.
Upgrade to version setuptools - 83.0.0,setuptools - 83.0.0,https://github.com/pypa/setuptools.git - 83.0.0
🔷 Medium CVE-2026-73558 vllm-0.26.0-cp38-abi3-manylinux_2_28_x86_64.whl
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overf...vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed in the same inference batch to receive a partial or complete copy of another user's inference result. This issue is fixed in version 0.27.0.
Upgrade to version https://github.com/vllm-project/vllm.git - v0.27.0,vllm - 0.27.0,vllm - 0.27.0
🔸 Low CVE-2025-63396 torch-2.11.0-cp312-cp312-manylinux_2_28_x86_64.whl
An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.prof...An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
Not Available

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Enable CI integration dependency-update This PR is about upgrading dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant