-
Notifications
You must be signed in to change notification settings - Fork 95
Description
I'd like to use this library in my work! However, the Wiz Vulnerability Scanner found "critical" vulnerabilities in the versions of torch
and Pillow
you're using as well as a "high" vulnerability in the version of pandas
you're using.
Any chance you can make your requirements more flexible? Also, I use Python 3.10
torch
The following vulnerabilities impact torch versions <2.2.0: GHSA-47fc-vmwq-366v, GHSA-5pcm-hx3q-hm94, GHSA-pg7h-5qx3-wjr3.
These can be remediated by updating to version 2.2.0 or higher.
pandas
The following vulnerability impacts pandas versions <2.2.3: CVE-2024-9880.
It can be remediated by updating to version 2.2.3 or higher.
Pillow
The following vulnerabilities impact pillow versions <10.3.0: GHSA-m2vv-5vj5-2hm7, GHSA-8ghj-p4vj-mr35, GHSA-j7hp-h8jx-5ppr, GHSA-3f63-hfp8-52jq, GHSA-44wm-f244-xhp3, GHSA-56pw-mpj4-fxww.