Skip to content

deps: bump nltk from 3.9.2 to 3.10.3 in requirements_with_versions.txt - #3226

Merged
geekcomputers merged 1 commit into
geekcomputers:masterfrom
katsugtgz:deps-nltk-3.10.3
Oct 9, 2026
Merged

geekcomputers merged 1 commit into
geekcomputers:masterfrom
katsugtgz:deps-nltk-3.10.3

Conversation

@katsugtgz

Copy link
Copy Markdown
Contributor

Updates nltk to address 84 of the 85 advisories affecting the pinned 3.9.2 (GHSA-2jhm-w3mp-jcwr, GHSA-3gq4-3j92-5w49, GHSA-3gqm-fcw5-w839, GHSA-469j-vmhf-r6v7, GHSA-568f-pv23-39p4, GHSA-5wp5-5229-5g6q, GHSA-68j8-pq59-fqgm, GHSA-6hm5-jgcp-p838, GHSA-6hwm-xvph-95vm, GHSA-6ww7-3frv-cqxh, GHSA-72r2-7mfr-5xr9, GHSA-7p94-766c-hgjp, GHSA-848c-c2cx-j7qx, GHSA-8mgp-746c-j5xp (still unfixed upstream, see below), GHSA-8mpw-7fpc-4gqj, GHSA-97qj-x29f-37w7, GHSA-9r6g-266r-89x4, GHSA-cw6x-m8jw-qmrh, GHSA-f794-5jv7-7672, GHSA-ff5c-cp5c-9wjf, GHSA-ffj6-66c4-86gw, GHSA-fg7f-2386-8897, GHSA-gfwx-w7gr-fvh7, GHSA-h8wq-7xc4-p3qx, GHSA-jm6w-m3j8-898g, GHSA-m42h-3232-vpv3, GHSA-m4rf-3fr8-xwx3, GHSA-p3m8-78j2-g5p3, GHSA-p4gq-832x-fm9v, GHSA-p4rw-rvv2-7xwr, GHSA-qvv7-cg9c-w4x3, GHSA-qx2g-xrx7-vfh8, GHSA-r6gq-whwq-mvg9, GHSA-rf74-v2fm-23pw, GHSA-rhp5-r9x4-f5g2, GHSA-rrv8-h7p8-rx55, GHSA-vp2x-qp44-57v7, GHSA-w3v8-gmh9-3wv7, GHSA-ww6m-cw3f-q94g, GHSA-x5ph-mj9p-rfr8, GHSA-x99w-6fgc-pmfw, GHSA-xh95-f55m-82fw and their PYSEC/CVE aliases).

Evidence:

  • requirements_with_versions.txt pinned nltk==3.9.2
  • osv-scanner on a requirements.txt containing nltk==3.9.2 reported 85 vulnerabilities before the update
  • updated version: nltk==3.10.3 (latest upstream release)

Validation:

  • osv-scanner after the update reports a single remaining advisory, GHSA-8mgp-746c-j5xp (CVE-2026-81726). This one has no fixed version published yet; 3.10.3 is the highest available release and is what the advisory data points to as the current line.
  • pip-audit -r requirements.txt --no-deps agrees: 72 known vulnerabilities on 3.9.2, only PYSEC-2026-3740 (same advisory) on 3.10.3
  • vet scan confirms the same single remaining advisory on nltk@3.10.3
  • no repo test suite exercises this file; the repo CI installs tools separately and runs pytest --tb=short || true, so there is no gate this change can break locally. The diff is one line in requirements_with_versions.txt.

Note: osv-scanner still reports GHSA-8mgp-746c-j5xp for nltk@3.10.3 (no fixed version exists upstream). This patch clears everything else.

Scope: dependency pin update only.

@geekcomputers
geekcomputers merged commit fd5a288 into geekcomputers:master Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants