PyPi: Baybe

CVE-2024-27318

Transitive

Safety vulnerability ID: 66978

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 23, 2024 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Baybe 0.8.2 has updated its onnx dependency to version 1.16.0 or newer to address the security issue CVE-2024-27318.

Affected package

baybe

Latest version: 0.11.3

A Bayesian Back End for Design of Experiments

Affected versions

Fixed versions

Vulnerability changelog

Added
- Simulation user guide
- Example for transfer learning backtesting utility
- `pyupgrade` pre-commit hook
- Better human readable `__str__` representation of objective and targets
- Alternative dataframe deserialization from `pd.DataFrame` constructors

Changed
- More detailed and sophisticated search space user guide
- Support for Python 3.12
- Upgraded syntax to Python 3.9
- Bumped `onnx` version to fix vulnerability
- Increased threshold for low-dimensional GP priors
- Replaced `fit_gpytorch_mll_torch` with `fit_gpytorch_mll`

Fixed
- `telemetry` dependency is no longer a group (enables Poetry installation)

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application