crickets-and-comb / crickets-and-comb/shared

Pin `nltk>=3.9.3` when released, drop ignore

Open
#152 0 comments 0 reactions 1 assignee Claimed by @KalebCoberly View on GitHub
bug good first issue help wanted
Dominant language
Makefile
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

There's a vulnerability, CVE-2025-14009, in `nltk<=3.9.2`. It's been fixed in `nltk`'s `develop` branch, but not yet released.

We've pinned our packages to the `nltk`'s `develop` branch for now, but we don't want to release anything until we can pin to `nltk>=3.9.3`. We're also ignoring CVE-2025-14009 in the `shared/Makefile` `security` target until then.

Once `nltk` 3.9.3 is released, add the pin and drop the ignore.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.