Skip to content

Bump onnx to >=1.18.0 to fix path traversal vulnerability#829

Merged
mike-w-wilson merged 1 commit intomainfrom
jg/onnx_fix
Apr 3, 2026
Merged

Bump onnx to >=1.18.0 to fix path traversal vulnerability#829
mike-w-wilson merged 1 commit intomainfrom
jg/onnx_fix

Conversation

@jkgoodrich
Copy link
Copy Markdown
Contributor

@jkgoodrich jkgoodrich commented Apr 3, 2026

Summary

  • Bumps onnx from ==1.17.0 to >=1.18.0 to resolve the high-severity path traversal via symlink vulnerability (GitHub security alert)

Test plan

  • Verify Dependabot alert is resolved after merge

🤖 Generated with Claude Code

onnx 1.17.0 is vulnerable to path traversal via symlink. Updating
the pin to >=1.18.0 resolves the GitHub security alert.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@mike-w-wilson mike-w-wilson merged commit 2137d57 into main Apr 3, 2026
6 checks passed
@mike-w-wilson mike-w-wilson deleted the jg/onnx_fix branch April 3, 2026 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants