Skip to content

cve vulnerability on main#709

Merged
dorotat-nv merged 7 commits into
mainfrom
dorotat/fix-cve-main
Mar 4, 2025
Merged

cve vulnerability on main#709
dorotat-nv merged 7 commits into
mainfrom
dorotat/fix-cve-main

Conversation

@dorotat-nv
Copy link
Copy Markdown
Collaborator

@dorotat-nv dorotat-nv commented Feb 28, 2025

Description

Addressing CVE vulnerability GHSA-g4r7-86gm-pgqc
It is introduced in requirements_eval.txt (NeMo) by lm_eval package, which depends on sqlitedict (all versions have critical vulnerability).

Type of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Refactor
  • Documentation update
  • Other (please describe): vulnerability

CI Pipeline Configuration

Configure CI behavior by applying the relevant labels:

Note

By default, the notebooks validation tests are skipped unless explicitly enabled.

Usage

TODO: Add code snippet

Pre-submit Checklist

  • I have tested these changes locally
  • I have updated the documentation accordingly
  • I have added/updated tests as needed
  • All existing tests pass successfully

Signed-off-by: Dorota Toczydlowska <115542912+dorotat-nv@users.noreply.github.com>
Signed-off-by: Dorota Toczydlowska <115542912+dorotat-nv@users.noreply.github.com>
Signed-off-by: Dorota Toczydlowska <115542912+dorotat-nv@users.noreply.github.com>
@dorotat-nv dorotat-nv requested a review from ohadmo as a code owner March 3, 2025 17:48
dorotat-nv and others added 2 commits March 3, 2025 18:57
Signed-off-by: Dorota Toczydlowska <115542912+dorotat-nv@users.noreply.github.com>
@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Mar 4, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.93%. Comparing base (82bb20a) to head (3a06ea7).
⚠️ Report is 519 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #709   +/-   ##
=======================================
  Coverage   85.93%   85.93%           
=======================================
  Files         120      120           
  Lines        7310     7310           
=======================================
  Hits         6282     6282           
  Misses       1028     1028           
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dorotat-nv dorotat-nv enabled auto-merge March 4, 2025 18:51
@dorotat-nv dorotat-nv added this pull request to the merge queue Mar 4, 2025
@trvachov
Copy link
Copy Markdown
Collaborator

trvachov commented Mar 4, 2025

Thank you for proactive fixing this!

Merged via the queue into main with commit 7d6f99a Mar 4, 2025
@dorotat-nv dorotat-nv deleted the dorotat/fix-cve-main branch March 4, 2025 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants