airbytehq / airbytehq/airbyte-python-cdk

NLTK dependency vulnerability (CVE-2026-79675)

Offen
#1,146 0 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
community
Vorherrschende Sprache
Python
Sterne
26
Forks
53
Ø Merge
2 T. 6 Std.
Gemergte PRs (30 T.)
10

Beschreibung

Our Dependabot scanner flagged CVE-2026-79675 in the NLTK dependency. CDK currently pins NLTK to 3.9.4, and the fix is available in 3.10.3, so we can't upgrade it in our connectors without changing the CDK pin.

Advisory: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3

I prepared a small update to 3.10.3 with a regenerated lockfile here: https://github.com/KadekM/airbyte-python-cdk/commit/8ec71db

All 27 existing unstructured-parser tests pass, along with the wheel build and dependency checks. I haven't run the full test suite or Docker builds.

I couldn't open a PR because contributions are restricted to collaborators. Could a maintainer take a look and cherry-pick the commit for an upcoming release?

Thanks!

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reviewing the CDK's NLTK version pin and the regenerated lockfile in commit 8ec71db. Run the 27 existing unstructured-parser tests, the wheel build, and dependency checks; done means the pin is updated to 3.10.3, the lockfile is regenerated, and those checks pass.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
build-system, security
Issue-Typ
Bug
Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Aktivitätsstatus
Aktiv
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
45/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.