Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,3 +5,5 @@ transformers>=4.21.0
ftfy
tensorboard
Jinja2
protobuf>=6.33.5 # not directly required, pinned by Snyk to avoid a vulnerability
torch>=2.10.0 # not directly required, pinned by Snyk to avoid a vulnerability
Comment on lines +8 to +9

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

The specified versions for protobuf (6.33.5) and torch (2.10.0) appear to be invalid as they do not exist on the public PyPI repository. This will cause pip install to fail with an error.

To fix this, valid and existing versions for these packages must be used.

Furthermore, please be aware of potential downstream compatibility issues. The significant version bumps for torch and protobuf will likely require upgrading other dependencies:

  • torchvision is tightly coupled with torch and will likely need to be upgraded to a compatible version.
  • tensorboard has a dependency on protobuf and will also likely need an upgrade to be compatible with a newer major version of protobuf (e.g., v4.x or newer).