airbytehq / airbytehq/airbyte-python-cdk

NLTK dependency vulnerability (CVE-2026-79675)

Aperta
#1,146 0 commenti 1 reazione 0 assegnatari Vedi su GitHub
community
Lingua principale
Python
Stelle
26
Fork
53
Merge medio
2g 6h
PR unite (30g)
10

Descrizione

Our Dependabot scanner flagged CVE-2026-79675 in the NLTK dependency. CDK currently pins NLTK to 3.9.4, and the fix is available in 3.10.3, so we can't upgrade it in our connectors without changing the CDK pin.

Advisory: https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3

I prepared a small update to 3.10.3 with a regenerated lockfile here: https://github.com/KadekM/airbyte-python-cdk/commit/8ec71db

All 27 existing unstructured-parser tests pass, along with the wheel build and dependency checks. I haven't run the full test suite or Docker builds.

I couldn't open a PR because contributions are restricted to collaborators. Could a maintainer take a look and cherry-pick the commit for an upcoming release?

Thanks!

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by reviewing the CDK's NLTK version pin and the regenerated lockfile in commit 8ec71db. Run the 27 existing unstructured-parser tests, the wheel build, and dependency checks; done means the pin is updated to 3.10.3, the lockfile is regenerated, and those checks pass.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
python
Ambito
build-system, security
Tipo di issue
Bug
Difficoltà
2/5
Tempo stimato
1-3 ore
Stato di attività
Attiva
Chiarezza
Specificata chiaramente
Idoneità per principianti
45/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.