Skip to content

Update transformers to fix CVE-2023-7018 security vulnerability#810

Open
Mr-Neutr0n wants to merge 1 commit intosalesforce:mainfrom
Mr-Neutr0n:fix/transformers-security-cve-2023-7018
Open

Update transformers to fix CVE-2023-7018 security vulnerability#810
Mr-Neutr0n wants to merge 1 commit intosalesforce:mainfrom
Mr-Neutr0n:fix/transformers-security-cve-2023-7018

Conversation

@Mr-Neutr0n
Copy link

Summary

Related Issue

Fixes #807

Test plan

  • Verify package installation works with updated version
  • Run existing tests to ensure compatibility

Bumps transformers from pinned 4.33.2 to >=4.36.0 to address the high
severity vulnerability described in CVE-2023-7018.

Fixes salesforce#807
@Mr-Neutr0n
Copy link
Author

following up — this bumps transformers to patch CVE-2023-7018. any chance this could get a look?

@Mr-Neutr0n
Copy link
Author

Friendly bump! Let me know if there's anything I should update or improve to help move this forward.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Transformers package high security issues

1 participant