Skip to content

deps: bump nltk to 3.10.3 to clear reported advisories - #35

Open
katsugtgz wants to merge 1 commit into
aiming-lab:mainfrom
katsugtgz:deps/nltk-3.10.3
Open

deps: bump nltk to 3.10.3 to clear reported advisories#35
katsugtgz wants to merge 1 commit into
aiming-lab:mainfrom
katsugtgz:deps/nltk-3.10.3

Conversation

@katsugtgz

Copy link
Copy Markdown

Bumps nltk from 3.9.1 to 3.10.3 in Agent0/requirements.txt.

Evidence:

  • Agent0/requirements.txt pinned nltk==3.9.1
  • pip-audit 2.10.0 reported advisories for nltk@3.9.1, including PYSEC-2026-597, PYSEC-2026-2085, PYSEC-2026-2235, PYSEC-2026-2236, PYSEC-2026-2237, PYSEC-2026-3582, PYSEC-2026-3583, PYSEC-2026-3584, GHSA-rf74-v2fm-23pw (aliases include CVE-2026-12243, CVE-2026-12252)
  • updated version: 3.10.3

Validation:

  • pip-audit reports no known vulnerabilities for nltk@3.10.3
  • python3 -c "from nltk.tokenize import sent_tokenize" passes with nltk 3.10.3 after downloading punkt_tab

Scope: Agent0/requirements.txt pin change only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant