Skip to content

fix(mistral): exclude compromised mistralai 2.4.6 from dependencies#3305

Merged
julian-risch merged 1 commit into
mainfrom
fix/mistral-exclude-compromised-2.4.6
May 15, 2026
Merged

fix(mistral): exclude compromised mistralai 2.4.6 from dependencies#3305
julian-risch merged 1 commit into
mainfrom
fix/mistral-exclude-compromised-2.4.6

Conversation

@julian-risch
Copy link
Copy Markdown
Member

@julian-risch julian-risch commented May 15, 2026

Related Issues

None

Proposed Changes:

  • Exclude mistralai==2.4.6 from the mistral-haystack integration dependencies via !=2.4.6 version constraint
  • Added a comment referencing the GitHub security advisory (GHSA-wx9m-wx4f-4cmg)

How did you test it?

No code changes. Only a version exclusion in pyproject.toml.

Notes for the reviewer

mistralai 2.4.6 was a compromised PyPI release uploaded on 2026-05-12 at 00:05 UTC and removed at 03:05 UTC. See the security advisory: GHSA-wx9m-wx4f-4cmg

Checklist

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@julian-risch julian-risch marked this pull request as ready for review May 15, 2026 07:03
@julian-risch julian-risch requested a review from a team as a code owner May 15, 2026 07:03
@julian-risch julian-risch requested review from anakin87 and removed request for a team May 15, 2026 07:03
@github-actions
Copy link
Copy Markdown
Contributor

Coverage report (mistral)

This PR does not seem to contain any modification to coverable code.

@julian-risch julian-risch enabled auto-merge (squash) May 15, 2026 07:04
@julian-risch julian-risch merged commit 519b92f into main May 15, 2026
14 checks passed
@julian-risch julian-risch deleted the fix/mistral-exclude-compromised-2.4.6 branch May 15, 2026 07:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants