Skip to content

Conversation

deadbits
Copy link
Owner

@deadbits deadbits commented Dec 6, 2023

The pinned version of urllib3 was an outdated / vulnerable package. I'm pretty sure the vulnerable code wasn't used anywhere in this app, but just to make things easier I've removed the urllib3 requirement entirely and it is now correctly installed as a dependency of chromadb.

I think I originally pinned it due to some conflict that was resolved when I bumped the chromadb version a few weeks back.

@deadbits deadbits self-assigned this Dec 6, 2023
@deadbits deadbits merged commit 945bf57 into main Dec 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant