Skip to content

URGENT: exclude compromised lightning versions#262

Open
jemrobinson wants to merge 1 commit intomainfrom
lightning-security-fix
Open

URGENT: exclude compromised lightning versions#262
jemrobinson wants to merge 1 commit intomainfrom
lightning-security-fix

Conversation

@jemrobinson
Copy link
Copy Markdown
Member

@jemrobinson jemrobinson commented Apr 30, 2026

Lightning 2.6.2 and 2.6.3 are compromised https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud

Check whether you have installed them and treat all SSH keys, git/Azure/AWS etc. credentials as compromised.

@jemrobinson jemrobinson requested a review from a team April 30, 2026 19:09
@jemrobinson jemrobinson changed the title Exclude compromised lightning versions URGENT: exclude compromised lightning versions Apr 30, 2026
@github-actions
Copy link
Copy Markdown

Coverage report

This PR does not seem to contain any modification to coverable code.

Copy link
Copy Markdown
Contributor

@louisavz louisavz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants