← All tasks
pythonexplosion/thinc #496Not a task: not reproduced

Pydantic security vulnerability CVE-2021-29510

envgap__explosion__thinc-496

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
5f43dd08022ab06592ca87a671102b7edea8a08a
Manifest
requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

explosion/thinc #496 · read the original issue
Hi there 👋 



I'm not sure if this is important for **thinc**, but I'll mention just in case. Feel free to close it. 😅 



[Pydantic](https://github.com/samuelcolvin/pydantic/) published a security vulnerability yesterday, which you can check it [here](https://github.com/samuelcolvin/pydantic/security/advisories/GHSA-5jqp-qgf6-3pvh).



The way that was handled on FastAPI is to not allow versions that are different from the ones with the security patch, as you can see [here](https://github.com/tiangolo/fastapi/commit/a6293397bc403254d80e8f50afbb43ae1693df46). 



I guess this is relevant as we don't want to allow a Pydantic version with this security vulnerability as requirement. 😗  
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]