Skip to content

πŸ”’ Security Alerts β€” IBM/READIΒ #31

Description

@security-ops-bot

πŸ”’ Security Alerts β€” IBM/READI

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

Attention: @stefano81 @mrsabath

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Fix PR
🟠 high CVE-2024-35515 sqlitedict <= 2.1.0 β€” β€”
🟑 medium CVE-2026-1839 transformers < 5.0.0rc3 5.0.0rc3 β€”
🟠 high CVE-2026-54293 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-4372 transformers < 5.3.0 5.3.0 β€”
🟠 high CVE-2026-5241 transformers < 5.5.0 5.5.0 β€”
🟠 high CVE-2026-12072 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-12074 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-12061 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-12075 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-12243 nltk < 3.10.0 3.10.0 β€”
🟠 high CVE-2026-78680 nltk <= 3.10.2 3.10.3 β€”
πŸ”΄ critical CVE-2026-79675 nltk <= 3.10.2 3.10.3 β€”
🟠 high CVE-2026-9856 transformers < 5.10.0 5.10.0 β€”
🟠 high CVE-2026-81726 nltk <= 3.10.3 β€” β€”
🟑 medium CVE-2026-81724 nltk <= 3.10.2 3.10.3 β€”
🟑 medium CVE-2026-12876 nltk <= 3.10.2 3.10.3 β€”
🟑 medium CVE-2026-81723 nltk <= 3.10.2 3.10.3 β€”
🟑 medium CVE-2026-81727 nltk <= 3.10.2 3.10.3 β€”
🟑 medium CVE-2026-81722 nltk <= 3.10.2 3.10.3 β€”
🟠 high CVE-2026-72818 nltk < 3.10.1 3.10.1 β€”
πŸ”΅ low CVE-2026-71514 nltk >= 3.9.4, < 3.10.3 3.10.3 β€”
🟑 medium CVE-2026-63311 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-62388 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-63312 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-62385 nltk <= 3.9.4 3.10.0 β€”
πŸ”΄ critical CVE-2026-78683 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-78682 nltk <= 3.10.2 3.10.3 β€”
🟠 high CVE-2026-78681 nltk <= 3.10.2 3.10.3 β€”
πŸ”΄ critical CVE-2026-79657 nltk <= 3.10.2 3.10.3 β€”
🟠 high CVE-2026-79676 nltk <= 3.10.2 3.10.3 β€”
🟠 high CVE-2026-79674 nltk <= 3.10.2 3.10.3 β€”
🟑 medium CVE-2026-69112 accelerate <= 1.14.0 β€” β€”
🟠 high CVE-2026-80205 nltk <= 3.9.4 3.10.0 β€”
🟠 high CVE-2026-80206 nltk <= 3.10.2 3.10.3 β€”
🟑 medium CVE-2026-81725 nltk <= 3.10.2 3.10.3 β€”

Code Scanning Alerts

Severity Rule Tool
πŸ”΅ low py/empty-except CodeQL
πŸ”΅ low py/ineffectual-statement CodeQL
πŸ”΅ low py/ineffectual-statement CodeQL
πŸ”΅ low py/commented-out-code CodeQL
πŸ”΅ low py/unused-import CodeQL
πŸ”΅ low py/unused-import CodeQL
πŸ”΅ low py/unused-import CodeQL
🟑 medium py/equals-hash-mismatch CodeQL
🟠 high py/missing-call-to-init CodeQL
🟠 high py/missing-call-to-init CodeQL
🟑 medium py/regex/duplicate-in-character-class CodeQL

Secret Scanning Alerts

No open secret scanning alerts.


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions