From b6e62f4358da1ddf9156f1bb7e215accd75ed862 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 9 Jan 2026 22:33:31 +0000 Subject: [PATCH] fix: requirements-tpu.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- requirements-tpu.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements-tpu.txt b/requirements-tpu.txt index 4c606cf0a910..cf884ad39d2a 100644 --- a/requirements-tpu.txt +++ b/requirements-tpu.txt @@ -5,3 +5,4 @@ # Currently, the TPU backend uses a nightly version of PyTorch XLA. # You can install the dependencies in Dockerfile.tpu. ray[default] +urllib3>=2.6.3 # not directly required, pinned by Snyk to avoid a vulnerability