From 4cbebb0ca959a8ddf3585e261ead9b24c191464c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 26 Sep 2025 15:05:16 +0000 Subject: [PATCH] fix: requirements-cpu.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052818 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052821 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052968 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052977 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052994 --- requirements-cpu.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements-cpu.txt b/requirements-cpu.txt index 2dcd86274a2a..a29cc1cd3dcc 100644 --- a/requirements-cpu.txt +++ b/requirements-cpu.txt @@ -2,5 +2,5 @@ -r requirements-common.txt # Dependencies for x86_64 CPUs -torch == 2.4.0; platform_machine != "ppc64le" +torch==2.8.0; platform_machine != "ppc64le" torchvision; platform_machine != "ppc64le" # required for the image processor of phi3v, this must be updated alongside torch