Conversation
|
Hi @ziotom78 , the link above gives a 404 for me ... do you have another link describing the numpy bug perhaps? (I'd like to check whether I have to update my own package dependencies ...) |
|
Mmm… Unfortunately the link disappeared, I don't know what happened but the page with Dependabot «closed» issues is empty: https://github.com/litebird/litebird_sim/security/dependabot When I accepted the warning, I was assuming that it was related to the big yellow warning at the top of the 1.21 release page:
|
|
Ah, I see, thanks! OK, that only seems to be an issue for people who compile their own |
Dependabot discovered that we depend on a NumPy version (1.20.3) that has a critical bug:
https://github.com/litebird/litebird_sim/security/dependabot/poetry.lock/numpy/open/update-logs/172230966
In this PR I have updated NumPy to 1.21. This required to upgrade Numba from 0.54 to 0.55.
I updated Rich from version 6.2 (old!) to version 11.0.