airbytehq / airbytehq/airbyte-python-cdk

NLTK dependency vulnerability (CVE-2026-79675)

Ouverte
#1,146 0 commentaires 1 réaction 0 personnes assignées Voir sur GitHub
community
Langage dominant
Python
Étoiles
26
Forks
53
Merge moyen
2 j 6 h
PR mergées (30 j)
10

Description

Our Dependabot scanner flagged CVE-2026-79675 in the NLTK dependency. CDK currently pins NLTK to 3.9.4, and the fix is available in 3.10.3, so we can't upgrade it in our connectors without changing the CDK pin.

Advisory: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3

I prepared a small update to 3.10.3 with a regenerated lockfile here: https://github.com/KadekM/airbyte-python-cdk/commit/8ec71db

All 27 existing unstructured-parser tests pass, along with the wheel build and dependency checks. I haven't run the full test suite or Docker builds.

I couldn't open a PR because contributions are restricted to collaborators. Could a maintainer take a look and cherry-pick the commit for an upcoming release?

Thanks!

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start by reviewing the CDK's NLTK version pin and the regenerated lockfile in commit 8ec71db. Run the 27 existing unstructured-parser tests, the wheel build, and dependency checks; done means the pin is updated to 3.10.3, the lockfile is regenerated, and those checks pass.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
build-system, security
Type d'issue
Bug
Difficulté
2/5
Temps estimé
1-3 heures
Activité
Active
Clarté
Clairement spécifiée
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.