Skip to content

fix(deps): patch fsspec and multidict audit findings - #531

Merged
arekay-nv merged 1 commit into
mainfrom
fix/dependency-audit
Oct 8, 2026
Merged

arekay-nv merged 1 commit into
mainfrom
fix/dependency-audit

Conversation

@arekay-nv

@arekay-nv arekay-nv commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

What does this PR do?

Fix the dependency audit failure observed on #530 by updating the two flagged
transitive packages and adding security floors to the existing uv constraints:

Package Previous Updated Advisory
fsspec 2026.2.0 2026.6.0 CVE-2026-104851
multidict 6.7.1 6.9.1 CVE-2026-104874

Both versions satisfy the existing datasets/aiohttp requirements. Only
pyproject.toml and the affected entries in uv.lock change. The existing NLTK
exception tracked in #520 remains unchanged; no audit exceptions are added.

This PR targets main independently of the Markdown formatting PR #530.
Original failure: https://github.com/mlcommons/endpoints/actions/runs/37708929786/job/113089941178

Type of change

  • Bug fix

Testing

  • Synced the same dev/test/performance extras as the CI audit job.
  • uv run pip-audit --ignore-vuln PYSEC-2026-3740: no known vulnerabilities, one existing exception.
  • uv pip check: all installed packages compatible.
  • uv lock --check with local uv 0.12.10 and CI's uv 0.12.23.
  • Verified all other locked package records are unchanged.
  • Focused dataset and HTTP unit/integration tests: 317 passed, 1 skipped.
  • Ran uv run pre-commit run --all-files: all hooks pass except three
    macOS-only mypy errors for Linux CPU-affinity APIs in unchanged source.
    The same mypy environment passes all 333 source files with --platform linux.
  • git diff --check.

Checklist

  • Code follows project style.
  • GitHub Actions audit, pre-commit, and build jobs pass (local macOS caveat above).

@arekay-nv
arekay-nv requested a review from a team October 8, 2026 00:44
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

MLCommons CLA bot All contributors have signed the MLCommons CLA ✍️ ✅

@github-actions
github-actions Bot requested a review from nvzhihanj October 8, 2026 00:44
@github-actions github-actions Bot added the size/normal PR Review Policy: <=500 non-test lines & <=20 files label Oct 8, 2026
@arekay-nv
arekay-nv requested a review from nv-alicheng October 8, 2026 00:55
@arekay-nv
arekay-nv merged commit d56ae18 into main Oct 8, 2026
11 checks passed
@arekay-nv
arekay-nv deleted the fix/dependency-audit branch October 8, 2026 01:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/normal PR Review Policy: <=500 non-test lines & <=20 files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants