[Snyk] Fix for 5 vulnerabilities - #13080
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-KERAS-18507704 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-18507646 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-18507677 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-18507687 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-18507692
|
This upgrade involves a major, high-risk update to keras@2.6.0 → keras@3.12.3Risk: HIGH The upgrade from Keras 2 to Keras 3 is a major rewrite with significant breaking changes. Keras 3 has been redesigned as a multi-backend framework that can run on top of TensorFlow, JAX, and PyTorch. Key Breaking Changes:
Recommendation: nltk@3.6.3 → nltk@3.10.0Risk: MEDIUM This upgrade spans several minor versions and includes environment and behavioral changes. Key Changes:
Recommendation:
|
Snyk has created this PR to fix 5 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
manual-testing-sandbox/requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Directory Traversal
🦉 Server-side Request Forgery (SSRF)
🦉 Regular Expression Denial of Service (ReDoS)