Skip to content

Conversation

russellb
Copy link
Member

Fixes GHSA-9q5r-wfvf-rr7f

Signed-off-by: Russell Bryant rbryant@redhat.com

Fixes GHSA-9q5r-wfvf-rr7f

Signed-off-by: Russell Bryant <rbryant@redhat.com>
@russellb russellb requested a review from aarnphm September 18, 2025 17:56
Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request correctly updates the xgrammar dependency from version 0.1.23 to 0.1.24. This is a critical security fix to address a Regular Expression Denial of Service (ReDoS) vulnerability (GHSA-9q5r-wfvf-rr7f). The change is isolated to the requirements file and is the recommended action to patch the vulnerability. The change looks good to merge.

@mergify mergify bot added the ci/build label Sep 18, 2025
@mwm5945
Copy link

mwm5945 commented Sep 18, 2025

thanks for looking at this! I was trying to get it done via my companies process but happy to see it getting addressed quickly! I'll get the next one :D

@mgoin mgoin enabled auto-merge (squash) September 18, 2025 22:36
@github-actions github-actions bot added the ready ONLY add when PR is ready to merge/full CI is needed label Sep 18, 2025
auto-merge was automatically disabled September 19, 2025 00:11

Pull Request is not mergeable

@chaunceyjiang chaunceyjiang merged commit 486c559 into vllm-project:main Sep 19, 2025
91 checks passed
debroy-rh pushed a commit to debroy-rh/vllm that referenced this pull request Sep 19, 2025
Signed-off-by: Russell Bryant <rbryant@redhat.com>
FeiDaLI pushed a commit to FeiDaLI/vllm that referenced this pull request Sep 25, 2025
Signed-off-by: Russell Bryant <rbryant@redhat.com>
charlifu pushed a commit to ROCm/vllm that referenced this pull request Sep 25, 2025
Signed-off-by: Russell Bryant <rbryant@redhat.com>
Signed-off-by: charlifu <charlifu@amd.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci/build ready ONLY add when PR is ready to merge/full CI is needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants