[Snyk] Fix for 4 vulnerabilities - #13193
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-MISTUNE-19256865 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-19256808 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-19256864 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-19256915
|
This update includes two packages. The upgrade for nltk@3.6.3 → nltk@3.10.3Risk: Medium This upgrade spans several minor versions and introduces significant changes to environment support and behavior. Breaking Changes & Key Updates:
Recommendation: Verify that your environment uses Python 3.10 or newer. Review any usage of Source: NLTK Release Notes mistune@3.0.2 → mistune@3.3.3Risk: Low This is a minor version upgrade consisting of bug fixes, security patches, and performance improvements. The changelog does not indicate any breaking API changes within this version range. Source: Mistune Changelog
|
Snyk has created this PR to fix 4 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
manual-testing-sandbox/requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Uncontrolled Recursion
🦉 Deserialization of Untrusted Data