Skip to content

deps: bump nltk from 3.9.2 to 3.10.3 in requirements_with_versions.txt - #3226

Open
katsugtgz wants to merge 1 commit into
geekcomputers:masterfrom
katsugtgz:deps-nltk-3.10.3
Open

katsugtgz wants to merge 1 commit into
geekcomputers:masterfrom
katsugtgz:deps-nltk-3.10.3

Conversation

@katsugtgz

Copy link
Copy Markdown

Updates nltk to address 84 of the 85 advisories affecting the pinned 3.9.2 (GHSA-2jhm-w3mp-jcwr, GHSA-3gq4-3j92-5w49, GHSA-3gqm-fcw5-w839, GHSA-469j-vmhf-r6v7, GHSA-568f-pv23-39p4, GHSA-5wp5-5229-5g6q, GHSA-68j8-pq59-fqgm, GHSA-6hm5-jgcp-p838, GHSA-6hwm-xvph-95vm, GHSA-6ww7-3frv-cqxh, GHSA-72r2-7mfr-5xr9, GHSA-7p94-766c-hgjp, GHSA-848c-c2cx-j7qx, GHSA-8mgp-746c-j5xp (still unfixed upstream, see below), GHSA-8mpw-7fpc-4gqj, GHSA-97qj-x29f-37w7, GHSA-9r6g-266r-89x4, GHSA-cw6x-m8jw-qmrh, GHSA-f794-5jv7-7672, GHSA-ff5c-cp5c-9wjf, GHSA-ffj6-66c4-86gw, GHSA-fg7f-2386-8897, GHSA-gfwx-w7gr-fvh7, GHSA-h8wq-7xc4-p3qx, GHSA-jm6w-m3j8-898g, GHSA-m42h-3232-vpv3, GHSA-m4rf-3fr8-xwx3, GHSA-p3m8-78j2-g5p3, GHSA-p4gq-832x-fm9v, GHSA-p4rw-rvv2-7xwr, GHSA-qvv7-cg9c-w4x3, GHSA-qx2g-xrx7-vfh8, GHSA-r6gq-whwq-mvg9, GHSA-rf74-v2fm-23pw, GHSA-rhp5-r9x4-f5g2, GHSA-rrv8-h7p8-rx55, GHSA-vp2x-qp44-57v7, GHSA-w3v8-gmh9-3wv7, GHSA-ww6m-cw3f-q94g, GHSA-x5ph-mj9p-rfr8, GHSA-x99w-6fgc-pmfw, GHSA-xh95-f55m-82fw and their PYSEC/CVE aliases).

Evidence:

  • requirements_with_versions.txt pinned nltk==3.9.2
  • osv-scanner on a requirements.txt containing nltk==3.9.2 reported 85 vulnerabilities before the update
  • updated version: nltk==3.10.3 (latest upstream release)

Validation:

  • osv-scanner after the update reports a single remaining advisory, GHSA-8mgp-746c-j5xp (CVE-2026-81726). This one has no fixed version published yet; 3.10.3 is the highest available release and is what the advisory data points to as the current line.
  • pip-audit -r requirements.txt --no-deps agrees: 72 known vulnerabilities on 3.9.2, only PYSEC-2026-3740 (same advisory) on 3.10.3
  • vet scan confirms the same single remaining advisory on nltk@3.10.3
  • no repo test suite exercises this file; the repo CI installs tools separately and runs pytest --tb=short || true, so there is no gate this change can break locally. The diff is one line in requirements_with_versions.txt.

Note: osv-scanner still reports GHSA-8mgp-746c-j5xp for nltk@3.10.3 (no fixed version exists upstream). This patch clears everything else.

Scope: dependency pin update only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant