From 5f2c81bb8fd7aee1ed3d7e0c12b9fa42f59aaeb6 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 20 Jan 2026 05:11:01 +0000 Subject: [PATCH] fix: requirements-cpu.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052805 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- requirements-cpu.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements-cpu.txt b/requirements-cpu.txt index 27ca8ca5dbc5..5362298dd7b9 100644 --- a/requirements-cpu.txt +++ b/requirements-cpu.txt @@ -2,5 +2,6 @@ -r requirements-common.txt # Dependencies for x86_64 CPUs -torch == 2.4.0+cpu; platform_machine != "ppc64le" +torch==2.9.0+cpu; platform_machine != "ppc64le" torchvision; platform_machine != "ppc64le" # required for the image processor of phi3v, this must be updated alongside torch +urllib3>=2.6.3 # not directly required, pinned by Snyk to avoid a vulnerability