fix: bump nltk to 3.10.3 for PYSEC-2026-3726 - #7162
Conversation
Force the xml extra and workspace override onto the patched release so pip-audit stops failing on the 3.10.0 symlink file-read advisory.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe pull request raises NLTK minimum versions from 3.10.0 to 3.10.3 in the XML optional dependency and uv override. It also updates comments with the related security advisories. ChangesNLTK security constraints
Suggested reviewers: Merge Risk: ⚪ Minimal · up to This PR raises the nltk minimum version and refreshes the lockfile to remove the reported vulnerability; no actionable merge-blocking risk remains beyond normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.) ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
crewai-tools[xml]extrauv.lockso pip-audit no longer reports PYSEC-2026-3726 (symlink file read in IPIPANCorpusReader on 3.10.0–3.10.1)Test plan
nltk==3.10.0: PYSEC-2026-3726uv.lockresolvesnltk3.10.3