Skip to content

Conversation

@RinZ27
Copy link

@RinZ27 RinZ27 commented Jan 7, 2026

Hey maintainers,

I noticed pygments and tensorflow-io-gcs-filesystem in requirements.txt are lagging behind a few versions. The current versions have some known vulnerabilities (related to AST parsing and file handling) that could be risky if left unchecked.

I've bumped them to the latest patched releases (3.2.5 and 0.38.1). Did a quick local check and everything seems to load fine, but let me know if you hit any weirdness with the new versions.

Cheers.

Bump pygments to 3.2.5 and tensorflow-io-gcs-filesystem to 0.38.1 to address security advisories.
@google-cla
Copy link

google-cla bot commented Jan 7, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@RinZ27
Copy link
Author

RinZ27 commented Jan 7, 2026

Gonna close this one. Realized I jumped the gun on these version numbers—they aren't actually live on PyPI yet. Must have misread the changelogs.

My bad, sorry for the ping!

@RinZ27 RinZ27 closed this Jan 7, 2026
@RinZ27 RinZ27 deleted the security/dependency-bumps branch January 7, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant