-
Notifications
You must be signed in to change notification settings - Fork 26
OpenCE 1.11.x CVE list #1324
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
@cdeepali could you pls assess the 3 items listed. In term of priority: |
|
@rolweber pls suggest if we can update onnx to v1.17.0 in OpenCE v1.11.6 for CVE - GHSA-h36j-8vv3-cj52. |
While updating langchain-core to v0.3.51 we need to update langchain-community to v0.3.21 and while doing so we have observed that this would require updating numpy to v1.16.2 due to the following error: Thus it is concluded to not to update langchain-core in 1.11.6. https://ibm-systems-power.slack.com/archives/C571VTK0T/p1744698311553279?thread_ts=1744120875.281359&cid=C571VTK0T |
@cdeepali guess Roland brought this up already, there is another critical one that we should consider if possible https://github.ibm.com/ax/planning/issues/15708 |
Regarding onnx CVE - the fix for GHSA-h36j-8vv3-cj52 is in onnx/onnx@1b70f9b which was included in 1.11.5 as part of fix of another CVE - GHSA-6rq9-53c3-f7vj |
Summary of candidates to be assessed for the next opence release 1.11.x:
The text was updated successfully, but these errors were encountered: