NVIDIA / NVIDIA/accelerated-computing-hub

[SECURITY]: Pin all package versions

Open
#171 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Jupyter Notebook
Stars
2k
Forks
338
Avg merge
1d 11h
Merged PRs (30d)
16

Description

We need to pin ALL dependencies to specific versions to avoid supply chain attacks and ensure stability. We've had a few incidents where updates in dependencies have broken us.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Start by inventorying the repository's dependency declarations and identifying every unpinned package; done means all dependencies use specific versions and the project remains stable.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.