Skip to content

Conversation

@russellb
Copy link
Member

Versions prior to 3.1.6 are vulnerable to these 3 CVEs. We should ensure
we are using >=3.1.6 to avoid any potential security vulnerability via
jinja2.

Signed-off-by: Russell Bryant [email protected]

Versions prior to 3.1.6 are vulnerable to these 3 CVEs. We should ensure
we are using >=3.1.6 to avoid any potential security vulnerability via
jinja2.

* GHSA-gmj6-6f8f-6699
* GHSA-q2x7-8rv6-6q7h
* GHSA-cpwx-vrp4-4pq7

Signed-off-by: Russell Bryant <[email protected]>
@github-actions
Copy link

👋 Hi! Thank you for contributing to the vLLM project.

💬 Join our developer Slack at https://slack.vllm.ai to discuss your PR in #pr-reviews, coordinate on features in #feat- channels, or join special interest groups in #sig- channels.

Just a reminder: PRs would not trigger full CI run by default. Instead, it would only run fastcheck CI which starts running only a small and essential subset of CI tests to quickly catch errors. You can run other CI tests on top of those by going to your fastcheck build on Buildkite UI (linked in the PR checks section) and unblock them. If you do not have permission to unblock, ping simon-mo or khluu to add you in our Buildkite org.

Once the PR is approved and ready to go, your PR reviewer(s) can run CI to test the changes comprehensively before merging.

To run CI, PR reviewers can either: Add ready label to the PR or enable auto-merge.

🚀

@robertgshaw2-redhat robertgshaw2-redhat enabled auto-merge (squash) March 14, 2025 19:28
@mergify mergify bot added the ci/build label Mar 14, 2025
@github-actions github-actions bot added the ready ONLY add when PR is ready to merge/full CI is needed label Mar 14, 2025
@robertgshaw2-redhat robertgshaw2-redhat merged commit ee3778d into vllm-project:main Mar 15, 2025
67 checks passed
lulmer pushed a commit to lulmer/vllm that referenced this pull request Apr 7, 2025
shreyankg pushed a commit to shreyankg/vllm that referenced this pull request May 3, 2025
RichardoMrMu pushed a commit to RichardoMrMu/vllm that referenced this pull request May 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci/build ready ONLY add when PR is ready to merge/full CI is needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants