Security vulnerability in dask < 2021.10.0
See original GitHub issueThere is a security vulnerability in the required version of dask
used by auto-sklearn
.
Could you update the requirements of dask
to a version >= 2021.10.0
?
Issue Analytics
- State:
- Created 2 years ago
- Comments:6 (4 by maintainers)
Top Results From Across the Web
vulnerability in dask < 2021.10.0 · Issue #122 - GitHub
An issue was discovered in Dask (aka python-dask) through 2021.09.1. Single machine Dask clusters started with dask.distributed.LocalCluster or ...
Read more >dask 2021.10.0 vulnerabilities | Snyk - Snyk Vulnerability Database
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities (in both your packages & their dependencies) and provides ...
Read more >Vulnerability Details : CVE-2021-42343
CVE-2021-42343 : An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started ...
Read more >CVE-2021-42343 Detail - NVD
An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.
Read more >Dask on Twitter: "The latest release of `distributed` (2021.10.0) fixes ...
Versions of `distributed` earlier than `2021.10.0` had a potential security vulnerability relating to single-machine Dask clusters. Clusters started with `dask.
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Hi @EchoDelta,
Apologies, we sorted out the upload rights yesterday, the fixed master branch will be on PyPi within a few hours.
Hi @EchoDelta, I’m making a hotfix for master, just going to wait until the tests pass before merging.