Skip to content

Vulnerabilities in torch, pandas, and Pillow #206

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
murphycw opened this issue Feb 4, 2025 · 0 comments
Open

Vulnerabilities in torch, pandas, and Pillow #206

murphycw opened this issue Feb 4, 2025 · 0 comments

Comments

@murphycw
Copy link

murphycw commented Feb 4, 2025

I'd like to use this library in my work! However, the Wiz Vulnerability Scanner found "critical" vulnerabilities in the versions of torch and Pillow you're using as well as a "high" vulnerability in the version of pandas you're using.

Any chance you can make your requirements more flexible? Also, I use Python 3.10

torch

The following vulnerabilities impact torch versions <2.2.0: GHSA-47fc-vmwq-366v, GHSA-5pcm-hx3q-hm94, GHSA-pg7h-5qx3-wjr3.

These can be remediated by updating to version 2.2.0 or higher.

pandas

The following vulnerability impacts pandas versions <2.2.3: CVE-2024-9880.

It can be remediated by updating to version 2.2.3 or higher.

Pillow

The following vulnerabilities impact pillow versions <10.3.0: GHSA-m2vv-5vj5-2hm7, GHSA-8ghj-p4vj-mr35, GHSA-j7hp-h8jx-5ppr, GHSA-3f63-hfp8-52jq, GHSA-44wm-f244-xhp3, GHSA-56pw-mpj4-fxww.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant