Skip to content

[research proj] [lxmert] remove bleach dependency#9970

Merged
LysandreJik merged 1 commit into
masterfrom
stas00-patch-3
Feb 3, 2021
Merged

[research proj] [lxmert] remove bleach dependency#9970
LysandreJik merged 1 commit into
masterfrom
stas00-patch-3

Conversation

@stas00
Copy link
Copy Markdown
Contributor

@stas00 stas00 commented Feb 3, 2021

github reports bleach==3.1.5 to have a vulnerability and it's not really used anywhere in the code, and because it has a fixed version set that is vulnerable, so just as well remove it completely from deps.
https://github.com/huggingface/transformers/security/dependabot/examples/research_projects/lxmert/requirements.txt/bleach/open

@LysandreJik, @sgugger, @patrickvonplaten

Copy link
Copy Markdown
Contributor

@patrickvonplaten patrickvonplaten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree! Thanks for taking care of it

Copy link
Copy Markdown
Member

@LysandreJik LysandreJik left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, LGTM!

@LysandreJik LysandreJik merged commit d55e10b into master Feb 3, 2021
@LysandreJik LysandreJik deleted the stas00-patch-3 branch February 3, 2021 10:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants