Repository navigation
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates
nltkto address 84 of the 85 advisories affecting the pinned 3.9.2 (GHSA-2jhm-w3mp-jcwr, GHSA-3gq4-3j92-5w49, GHSA-3gqm-fcw5-w839, GHSA-469j-vmhf-r6v7, GHSA-568f-pv23-39p4, GHSA-5wp5-5229-5g6q, GHSA-68j8-pq59-fqgm, GHSA-6hm5-jgcp-p838, GHSA-6hwm-xvph-95vm, GHSA-6ww7-3frv-cqxh, GHSA-72r2-7mfr-5xr9, GHSA-7p94-766c-hgjp, GHSA-848c-c2cx-j7qx, GHSA-8mgp-746c-j5xp (still unfixed upstream, see below), GHSA-8mpw-7fpc-4gqj, GHSA-97qj-x29f-37w7, GHSA-9r6g-266r-89x4, GHSA-cw6x-m8jw-qmrh, GHSA-f794-5jv7-7672, GHSA-ff5c-cp5c-9wjf, GHSA-ffj6-66c4-86gw, GHSA-fg7f-2386-8897, GHSA-gfwx-w7gr-fvh7, GHSA-h8wq-7xc4-p3qx, GHSA-jm6w-m3j8-898g, GHSA-m42h-3232-vpv3, GHSA-m4rf-3fr8-xwx3, GHSA-p3m8-78j2-g5p3, GHSA-p4gq-832x-fm9v, GHSA-p4rw-rvv2-7xwr, GHSA-qvv7-cg9c-w4x3, GHSA-qx2g-xrx7-vfh8, GHSA-r6gq-whwq-mvg9, GHSA-rf74-v2fm-23pw, GHSA-rhp5-r9x4-f5g2, GHSA-rrv8-h7p8-rx55, GHSA-vp2x-qp44-57v7, GHSA-w3v8-gmh9-3wv7, GHSA-ww6m-cw3f-q94g, GHSA-x5ph-mj9p-rfr8, GHSA-x99w-6fgc-pmfw, GHSA-xh95-f55m-82fw and their PYSEC/CVE aliases).Evidence:
requirements_with_versions.txtpinnednltk==3.9.2osv-scanneron arequirements.txtcontainingnltk==3.9.2reported 85 vulnerabilities before the updatenltk==3.10.3(latest upstream release)Validation:
osv-scannerafter the update reports a single remaining advisory,GHSA-8mgp-746c-j5xp(CVE-2026-81726). This one has no fixed version published yet;3.10.3is the highest available release and is what the advisory data points to as the current line.pip-audit -r requirements.txt --no-depsagrees: 72 known vulnerabilities on3.9.2, onlyPYSEC-2026-3740(same advisory) on3.10.3vet scanconfirms the same single remaining advisory onnltk@3.10.3pytest --tb=short || true, so there is no gate this change can break locally. The diff is one line inrequirements_with_versions.txt.Note:
osv-scannerstill reportsGHSA-8mgp-746c-j5xpfornltk@3.10.3(no fixed version exists upstream). This patch clears everything else.Scope: dependency pin update only.