[pre-commit.ci] pre-commit autoupdate#202
Conversation
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedCVE-2026-45829 is a pre-authentication code injection vulnerability in chromadb that affects all versions from 1.0.0 through 1.5.9 (the current latest release). The OSV advisory confirms A fix requires the chromadb maintainers to release a new version that addresses this vulnerability. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in A fix requires the upstream chromadb maintainers to release a version that addresses this CVE and register it with the PyPI vulnerability database. Once a patched release is published, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
e2c400c to
a288667
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in Vulnerability details: A pre-authentication code injection vulnerability in ChromaDB 1.0.0+ allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository with Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability is a critical pre-authentication code injection flaw (CWE-94) that affects ChromaDB versions 1.0.0 through 1.5.9 (the current latest release). The OSV advisory uses The vulnerability allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository with Why this cannot be auto-fixedA fix requires the upstream ChromaDB maintainers to release a new version. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in A fix requires the upstream chromadb maintainers to release a new version. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability is a pre-authentication code injection vulnerability (CVSS 4.0: Critical) affecting chromadb versions 1.0.0 through 1.5.9 (all versions on PyPI). The OSV advisory lists A fix requires the upstream maintainers at chroma-core/chroma to release a new version. See issue #6717 for tracking. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
a288667 to
8850df8
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability affects What was auto-fixed in this run
Recommended next steps
This PR will not be auto-merged until the chromadb vulnerability is resolved. |
d70f276 to
df8cfff
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in A fix requires the upstream chromadb maintainers to release a patched version. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability Bumping to the latest version (1.5.9) would not resolve the vulnerability — it remains present in all currently published releases. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in A fix requires the upstream maintainers to release a new version. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in
Bumping to any newer chromadb version does not resolve the issue — the upstream maintainers must release a patched version. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved upstream. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability is a pre-authentication code injection flaw affecting chromadb 1.0.0 and later. According to the OSV advisory, all versions up to and including the latest release (1.5.9) are affected. A fix requires the upstream chromadb maintainers to release a patched version. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in The CVE describes a pre-authentication code injection vulnerability that requires Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
df8cfff to
327ce71
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedCVE-2026-45829 is a pre-authentication code injection vulnerability in chromadb ≥ 1.0.0. According to the OSV advisory, all versions from 1.0.0 through 1.5.9 (the current latest) are affected and there is no What was fixed automatically
Recommended next steps
This PR will not be auto-merged until the chromadb vulnerability is resolved. |
Security Vulnerability — No Patch Available Yet (Updated)aieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedCVE-2026-45829 is a pre-authentication code injection vulnerability in chromadb ≥ 1.0.0. According to the OSV advisory, all versions from 1.0.0 through 1.5.9 (the current latest) are affected and there is no What was fixed automatically
Recommended next steps
This PR will not be auto-merged until the chromadb vulnerability is resolved. |
53392a0 to
a501bb1
Compare
updates: - [github.com/astral-sh/uv-pre-commit: 0.11.16 → 0.11.23](astral-sh/uv-pre-commit@0.11.16...0.11.23) - [github.com/astral-sh/ruff-pre-commit: v0.15.14 → v0.15.18](astral-sh/ruff-pre-commit@v0.15.14...v0.15.18)
a501bb1 to
b434843
Compare
updates: