airbytehq / airbytehq/airbyte-python-cdk

NLTK dependency vulnerability (CVE-2026-79675)

Abierto
#1,146 0 comentarios 1 reacción 0 asignados Ver en GitHub
community
Lenguaje dominante
Python
Estrellas
26
Forks
53
Merge medio
2 d 6 h
PR fusionados (30 d)
10

Descripción

Our Dependabot scanner flagged CVE-2026-79675 in the NLTK dependency. CDK currently pins NLTK to 3.9.4, and the fix is available in 3.10.3, so we can't upgrade it in our connectors without changing the CDK pin.

Advisory: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3

I prepared a small update to 3.10.3 with a regenerated lockfile here: https://github.com/KadekM/airbyte-python-cdk/commit/8ec71db

All 27 existing unstructured-parser tests pass, along with the wheel build and dependency checks. I haven't run the full test suite or Docker builds.

I couldn't open a PR because contributions are restricted to collaborators. Could a maintainer take a look and cherry-pick the commit for an upcoming release?

Thanks!

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by reviewing the CDK's NLTK version pin and the regenerated lockfile in commit 8ec71db. Run the 27 existing unstructured-parser tests, the wheel build, and dependency checks; done means the pin is updated to 3.10.3, the lockfile is regenerated, and those checks pass.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
build-system, security
Tipo de issue
Error
Dificultad
2/5
Tiempo estimado
1-3 horas
Estado de actividad
Activo
Claridad
Bien especificado
Aptitud para principiantes
45/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.