Python dependency audit: medium/low vulnerability tracking
This issue is maintained by the scheduled/manual dependency audit.
It only tracks current medium and low findings. Blocking
critical, high, and unknown findings are handled by failed CI.
Latest workflow run: https://github.com/zenml-io/zenml/actions/runs/31358386005
Current non-blocking findings
Suggested maintenance flow
- Review whether the affected package is reachable in ZenML's
installed server, dev, and local environment.
- Prefer an upgrade when a compatible fixed version exists.
- If an upgrade is blocked, leave a short note explaining the
blocker and revisit it on the next scheduled audit.
Python dependency audit: medium/low vulnerability tracking
This issue is maintained by the scheduled/manual dependency audit.
It only tracks current
mediumandlowfindings. Blockingcritical,high, andunknownfindings are handled by failed CI.Latest workflow run: https://github.com/zenml-io/zenml/actions/runs/31358386005
Current non-blocking findings
CVE-2026-61632, GHSA-9xwg-3r6f-jcx2
Suggested maintenance flow
installed
server,dev, andlocalenvironment.blocker and revisit it on the next scheduled audit.