release v0.1.5 - #8
Conversation
| ] | ||
|
|
||
| [[package]] | ||
| name = "soxr" |
There was a problem hiding this comment.
License Risk: soxr@1.0.0 uses LGPL-2.1-or-later
LGPL-2.1-or-later violates license policy.
Severity: High 🚨
Status: Confirmed 🟡
License Details:
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "regex" |
There was a problem hiding this comment.
License Risk: regex@2026.4.4 uses CNRI-Python
CNRI-Python violates license policy.
Severity: High 🚨
Status: Open 🔴
License Details:
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "torchvision" |
There was a problem hiding this comment.
Dependency Risk: torchvision@0.18.0 has 9 transitive vulnerabilities
🔍 Upgrade to 0.27.1 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "diffusers" |
There was a problem hiding this comment.
Dependency Risk: diffusers@0.37.1 has 5 vulnerabilities
🔍 Upgrade to 0.39.0 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "regex" |
There was a problem hiding this comment.
License Risk: regex@2026.4.4 uses CNRI-Python
CNRI-Python violates license policy.
Severity: High 🚨
Status: Open 🔴
License Details:
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "rotary-embedding-torch" |
There was a problem hiding this comment.
Dependency Risk: rotary-embedding-torch@0.5.3 has 9 transitive vulnerabilities
🔍 Upgrade to 0.9.1 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "regex" |
There was a problem hiding this comment.
License Risk: regex@2026.4.4 uses CNRI-Python
CNRI-Python violates license policy.
Severity: High 🚨
Status: Open 🔴
License Details:
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "apex" |
There was a problem hiding this comment.
Reputation Risk: apex@0.1 has a low reputation score
The package has a low reputation score, consider finding an alternative.
Score factors:
- Low # of releases: 5
- No recent releases, last published: 13 years ago
- Low # of dependents: 3
Severity: High 🚨
Status: Open 🔴
Resources:
- How to Find Alternative Packages to Low-Reputation Open Source Packages?
- Identifying Low Reputation Packages: Key Factors and Their Importance
- What is OpenSSF Scorecard?
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "flash-attn" |
There was a problem hiding this comment.
Dependency Risk: flash-attn@2.5.9 has 10 vulnerabilities
🔍 Upgrade to 2.8.3.post1 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "chatterbox-tts" |
There was a problem hiding this comment.
Dependency Risk: chatterbox-tts@0.1.1 has 31 transitive vulnerabilities
No fix available for chatterbox-tts@0.1.1 that fixes any of the transitive vulnerabilities.
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "regex" |
There was a problem hiding this comment.
License Risk: regex@2026.4.4 uses CNRI-Python
CNRI-Python violates license policy.
Severity: High 🚨
Status: Open 🔴
License Details:
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "torch" |
There was a problem hiding this comment.
Dependency Risk: torch@2.3.0 has 9 direct vulnerabilities
🔍 Upgrade to 2.12.1 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "regex" |
There was a problem hiding this comment.
License Risk: regex@2026.4.4 uses CNRI-Python
CNRI-Python violates license policy.
Severity: High 🚨
Status: Open 🔴
License Details:
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "diffusers" |
There was a problem hiding this comment.
Dependency Risk: diffusers@0.33.0 has 5 vulnerabilities
🩹 Upgrade to 0.33.1 (patch version) to mitigate 0% of critical and high risks (60% of all)
🔍 Upgrade to 0.39.0 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
| ] | ||
|
|
||
| [[package]] | ||
| name = "diffusers" |
There was a problem hiding this comment.
Dependency Risk: diffusers@0.29.1 has 5 vulnerabilities
🩹 Upgrade to 0.29.2 (patch version) to mitigate 0% of critical and high risks (60% of all)
🔍 Upgrade to 0.39.0 (minor version) to mitigate 100% of critical and high risks (100% of all)
Severity: High 🚨
Status: Open 🔴
Suggested reviewers 🧐: @dulaj-me
More details:
If you see an issue, please contact Shasheen in the #security-engineering Slack channel.
Take action by replying with an [arnica] command 💬
Actions
Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.
To acknowledge the finding as a valid code risk: [arnica] ack <acknowledge additional details>
To dismiss the risk with a reason: [arnica] dismiss <fp|accept|capacity> <dismissal reason>
Examples
-
[arnica] ack This is a valid risk and I'm looking into it -
[arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive) -
[arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system -
[arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint
No description provided.