Skip to content

Python dependency audit: medium/low vulnerability tracking#4975

Description

@github-actions

Python dependency audit: medium/low vulnerability tracking

This issue is maintained by the scheduled/manual dependency audit.
It only tracks current medium and low findings. Blocking
critical, high, and unknown findings are handled by failed CI.

Latest workflow run: https://github.com/zenml-io/zenml/actions/runs/31358386005

Current non-blocking findings

Severity Package Installed Advisory Fix versions
medium pymdown-extensions 10.21.3 PYSEC-2026-3609
CVE-2026-61632, GHSA-9xwg-3r6f-jcx2
11.0.0

Suggested maintenance flow

  1. Review whether the affected package is reachable in ZenML's
    installed server, dev, and local environment.
  2. Prefer an upgrade when a compatible fixed version exists.
  3. If an upgrade is blocked, leave a short note explaining the
    blocker and revisit it on the next scheduled audit.

Metadata

Metadata

Assignees

Labels

P2Security issue severity - P2/MediumdependenciesPull requests that update a dependency filesecurityRelated to security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions