From 8d0ce05f4ba132bba3cd4eee6fff447e5eac756c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 16 Jan 2026 06:48:56 +0000 Subject: [PATCH] fix: tools/ci_build/github/linux/docker/scripts/training/ortmodule/stage2/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FILELOCK-14912448 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-14908843 --- .../docker/scripts/training/ortmodule/stage2/requirements.txt | 2 ++ 1 file changed, 2 insertions(+) diff --git a/tools/ci_build/github/linux/docker/scripts/training/ortmodule/stage2/requirements.txt b/tools/ci_build/github/linux/docker/scripts/training/ortmodule/stage2/requirements.txt index 59121cbe7b5da..c689f8ad86ce3 100644 --- a/tools/ci_build/github/linux/docker/scripts/training/ortmodule/stage2/requirements.txt +++ b/tools/ci_build/github/linux/docker/scripts/training/ortmodule/stage2/requirements.txt @@ -8,3 +8,5 @@ wget pytorch-lightning==1.6.0 deepspeed==0.3.15 fairscale==0.4.6 +filelock>=3.20.3 # not directly required, pinned by Snyk to avoid a vulnerability +werkzeug>=3.1.5 # not directly required, pinned by Snyk to avoid a vulnerability