Skip to content

Update requirements.txt with joblib<1.2 to solve #565#567

Open
giacomorebecchi wants to merge 1 commit intoscikit-learn-contrib:masterfrom
giacomorebecchi:master
Open

Update requirements.txt with joblib<1.2 to solve #565#567
giacomorebecchi wants to merge 1 commit intoscikit-learn-contrib:masterfrom
giacomorebecchi:master

Conversation

@giacomorebecchi
Copy link
Copy Markdown

@giacomorebecchi giacomorebecchi commented Sep 23, 2022

Hi, I'm a BuildNN data scientist. While using HDBSCAN, I encountered issue #565 due to the minor update in joblib=1.2 that does not ensure retrocompatibility. I solved the problem specifying the joblib version to be lower than 1.2.

@jcfaracco
Copy link
Copy Markdown
Contributor

Lower versions of joblib (<1.2.0) are affected by CVE-2022-21797.

@whymauri
Copy link
Copy Markdown

whymauri commented Nov 8, 2022

Have you considered using HDBSAN 0.8.29 with Joblib 1.2.0? This avoids the compatibility issue and the critical CVE in Joblib <1.2.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants