Skip to content

Commit 4b8ebe4

Browse files
fix(security): upgrade filelock to 3.20.1 to mitigate toctou symlink vulnerability
upgraded filelock to address a toctou race condition that allowed symlink attacks during lock file creation, potentially enabling arbitrary file truncation on unix and windows platforms
1 parent 8265cec commit 4b8ebe4

2 files changed

Lines changed: 119 additions & 121 deletions

File tree

requirements.txt

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ curl-cffi==0.13.0
2828
# via yfinance
2929
distlib==0.4.0
3030
# via virtualenv
31-
filelock==3.20.0
31+
filelock==3.20.1
3232
# via
3333
# huggingface-hub
3434
# torch
@@ -69,9 +69,9 @@ multitasking==0.0.12
6969
# via yfinance
7070
networkx==3.6.1
7171
# via torch
72-
nodeenv==1.9.1
72+
nodeenv==1.10.0
7373
# via pre-commit
74-
numpy==2.3.5
74+
numpy==2.4.0
7575
# via
7676
# pandas
7777
# transformers
@@ -129,7 +129,7 @@ platformdirs==4.5.1
129129
# via
130130
# virtualenv
131131
# yfinance
132-
pre-commit==4.5.0
132+
pre-commit==4.5.1
133133
# via sentify
134134
protobuf==6.33.2
135135
# via yfinance
@@ -153,14 +153,14 @@ requests==2.32.5
153153
# huggingface-hub
154154
# transformers
155155
# yfinance
156-
ruff==0.14.9
156+
ruff==0.14.10
157157
safetensors==0.7.0
158158
# via transformers
159159
setuptools==80.9.0 ; python_full_version >= '3.12'
160160
# via torch
161161
six==1.17.0
162162
# via python-dateutil
163-
soupsieve==2.8
163+
soupsieve==2.8.1
164164
# via beautifulsoup4
165165
sympy==1.14.0
166166
# via torch
@@ -191,5 +191,5 @@ websockets==15.0.1
191191
# via yfinance
192192
werkzeug==3.1.4
193193
# via flask
194-
yfinance==0.2.66
194+
yfinance==1.0
195195
# via sentify

0 commit comments

Comments
 (0)