Skip to content

chore: avoid distributed CVE#608

Merged
martindurant merged 3 commits intodask-contrib:mainfrom
ikrommyd:pin-distributed
Feb 3, 2026
Merged

chore: avoid distributed CVE#608
martindurant merged 3 commits intodask-contrib:mainfrom
ikrommyd:pin-distributed

Conversation

@ikrommyd
Copy link
Collaborator

@ikrommyd ikrommyd commented Feb 2, 2026

No description provided.

@codecov-commenter
Copy link

codecov-commenter commented Feb 2, 2026

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.05%. Comparing base (8cb8994) to head (3d90b72).
⚠️ Report is 317 commits behind head on main.
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #608      +/-   ##
==========================================
- Coverage   93.06%   90.05%   -3.02%     
==========================================
  Files          23       24       +1     
  Lines        3290     3610     +320     
==========================================
+ Hits         3062     3251     +189     
- Misses        228      359     +131     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@martindurant
Copy link
Collaborator

Note that the dask dependency reads "dask >=2023.04.0,<2025.4.0". Can you please check what actually gets installed? Since there is no dask release 2025.3.1, we can't pin to that.

@ikrommyd
Copy link
Collaborator Author

ikrommyd commented Feb 2, 2026

Note that the dask dependency reads "dask >=2023.04.0,<2025.4.0". Can you please check what actually gets installed? Since there is no dask release 2025.3.1, we can't pin to that.

There is a 2025.3.1 dask release https://pypi.org/project/dask/2025.3.1/

@ikrommyd
Copy link
Collaborator Author

ikrommyd commented Feb 2, 2026

2023.04.0 should be 2023.4.0 though

@martindurant
Copy link
Collaborator

Actually, not sure about that, the syntax of the tags might have changed years ago

@ikrommyd
Copy link
Collaborator Author

ikrommyd commented Feb 2, 2026

On pypi, it is 2023.4.0. This is what gets installed with the latest commit
image
The reason I didn't do ==2025.3.1 is just in case there ever is a backport like 2025.3.2 :)

@martindurant
Copy link
Collaborator

There is a 2025.3.1 dask release

Source only? There is a conda-forge package at least.

I see there is a corresponding tag ( https://github.com/dask/dask/releases/tag/2025.3.1 ), which was sorted by time of creation, not alphabetically.

@ikrommyd
Copy link
Collaborator Author

ikrommyd commented Feb 2, 2026

No there is dask-2025.3.1-py3-none-any.whl and conda-forge. It's a proper release in my understanding.

@martindurant
Copy link
Collaborator

Sorry, you're right - the interface changed, I think.

@ikrommyd
Copy link
Collaborator Author

ikrommyd commented Feb 2, 2026

There's problems with github actions FYI https://www.githubstatus.com/

@ikrommyd
Copy link
Collaborator Author

ikrommyd commented Feb 3, 2026

@martindurant actions are alive again, should be good to merge now?

@ikrommyd ikrommyd requested a review from martindurant February 3, 2026 19:13
@martindurant martindurant merged commit 03171ad into dask-contrib:main Feb 3, 2026
34 of 53 checks passed
@ikrommyd ikrommyd deleted the pin-distributed branch February 3, 2026 19:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants