tensorflow / model-analysis

Model analysis tools for TensorFlow
Apache License 2.0
1.26k stars 276 forks source link

CVE in Pyarrow dependency #178

Open vanHavel opened 10 months ago

vanHavel commented 10 months ago

System information

Describe the problem

pyarrow in versions less than 14.0.1 contains the critical security vulnerability CVE-2023-47248. If possible, please update the dependency of pyarrow to a version >= 14.0.1.

singhniraj08 commented 9 months ago

@vanHavel, Thank you for raising this feature request. We have already received this issue in other TFX child library and are working actively on updating the pyarrow dependency. We will update this thread once pyarrow dependency is updated. Thank you!