Skip to content

security: track ignored CVE-2026-1839 until upstream fix #124

@arn0ld87

Description

@arn0ld87

Package: transformers==4.57.6
Pinned by: sentence-transformers==3.0.0 (limits transformers<5)

Risk: Medium — HuggingFace transformers, used via sentence-transformers for embeddings.

Target: Upgrade to transformers>=4.58.0 once sentence-transformers relaxes the pin.

Deadline: 2026-07-30 (+90 days)

Action: Monitor sentence-transformers releases for transformers pin relaxation. Re-run pip-audit after each dependency update.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions