Skip to content

fix(deps): update NLTK and AnyIO security floors - #93

Merged
nabinchha merged 1 commit into
mainfrom
codex/fix-latest-vulnerability-report
Sep 23, 2026
Merged

nabinchha merged 1 commit into
mainfrom
codex/fix-latest-vulnerability-report

Conversation

@nabinchha

Copy link
Copy Markdown
Contributor

Summary

  • require NLTK 3.10.3 in the workspace and retrieval plugin, resolving the NLTK findings in the latest vulnerability report that have released fixes
  • require AnyIO 4.14.2 or newer; the lockfile resolves 4.15.1 and addresses CVE-2026-64847
  • keep NLTK/Punkt behavior unchanged rather than replacing it with a custom tokenizer

CVE-2026-81726 remains affected through NLTK 3.10.3 and has no patched release. This PR does not claim to resolve it; we are holding that item for an upstream release or a separately approved, narrowly scoped exception.

Linked Issue

Repository collaborator performing routine dependency/security maintenance; no separate issue.

Validation

  • make sync
  • make all (321 tests; lint, validation, metadata/license checks, and strict docs build passed)
  • built the retrieval wheel and verified its metadata requires anyio>=4.14.2,<5 and nltk>=3.10.3,<3.11
  • verified the isolated retrieval environment resolves AnyIO 4.15.1 and NLTK 3.10.3

Checklist

  • Linked issue not required; repository collaborator performing routine maintenance
  • Existing plugin structure unchanged
  • assert_valid_plugin(plugin) passes via make all
  • Unit tests pass via make all
  • Plugin installs standalone via make all
  • Plugin docs/checks pass via make all
  • Documentation builds
  • No catalog update required
  • No ownership change
  • Existing CODEOWNERS retained
  • NVIDIA SPDX headers pass

@nabinchha
nabinchha merged commit adc6595 into main Sep 23, 2026
8 checks passed
@nabinchha
nabinchha deleted the codex/fix-latest-vulnerability-report branch September 23, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants