Skip to content

security(vex): 5 dependency advisory(ies) with no fix - #159

Merged
git-steer[bot] merged 1 commit into
mainfrom
security/vex-no-fix
Jun 25, 2026
Merged

security(vex): 5 dependency advisory(ies) with no fix#159
git-steer[bot] merged 1 commit into
mainfrom
security/vex-no-fix

Conversation

@git-steer

@git-steer git-steer Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Dependencies with no upstream fix (OpenVEX)

git-steer's daily scan found 5 open Dependabot alert(s) on this repo for which no patched version is currently available. They cannot be auto-remediated by a version bump, so they are documented here as OpenVEX under_investigation — visible and machine-consumable — rather than silently ignored.

CVE / GHSA Package Severity PURL
CVE-2026-54293 nltk HIGH pkg:pypi/nltk
CVE-2025-3000 torch LOW pkg:pypi/torch
CVE-2026-0847 nltk HIGH pkg:pypi/nltk
CVE-2026-33236 nltk HIGH pkg:pypi/nltk
GHSA-rf74-v2fm-23pw nltk MEDIUM pkg:pypi/nltk

Artifact: .well-known/openvex/no-fix.openvex.json (OpenVEX 0.2.0). Regenerated each scan; entries clear automatically when an upstream fix lands. A maintainer should assess exploitability and promote each to not_affected (+justification) or affected (+action_statement).

Generated by git-steer · ADR-004 C-004-003

@git-steer git-steer Bot added automated Created by automation security Security vulnerability vex labels Jun 25, 2026
@git-steer
git-steer Bot merged commit 6fffb91 into main Jun 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Created by automation security Security vulnerability vex

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants