aws / fmeval

Foundation Model Evaluations Library
http://aws.github.io/fmeval
Apache License 2.0
155 stars 40 forks source link

build(deps): bump aiohttp to fix vulnerability #194

Closed xiaoyi-cheng closed 4 months ago

xiaoyi-cheng commented 4 months ago

Issue #, if available: Got auto created PR to bump the version to fix CVE-2024-23829. but it only changed the poetry.lock file.

Description of changes: Pin aiohttp version to pyproject.toml to fix this vulnerability.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.