Skip to content

Bump lightGBM and numpy to fix CVE-2024-43598#44

Open
vee1e wants to merge 2 commits intomandiant:masterfrom
vee1e:master
Open

Bump lightGBM and numpy to fix CVE-2024-43598#44
vee1e wants to merge 2 commits intomandiant:masterfrom
vee1e:master

Conversation

@vee1e
Copy link

@vee1e vee1e commented Feb 2, 2026

Changed the versions to lightgbm>="4.6.0" and numpy = "== 1.26.0" to fix the presence of CVE-2024-43598, as mentioned in #42 .

Added an assertion and workaround for using the older model files, currently all test cases pass and rank_strings functions perfectly.

I'd also request to have the model dataset and training files published publicly if possible as mentioned in the discussion section of your README. It would make it easier for contributors to develop and expand on the project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant