safety icon indicating copy to clipboard operation
safety copied to clipboard

please consider the usage of nltk

Open oz123 opened this issue 8 months ago • 5 comments

Checklist

Safety version

I was trying to add safety to the gentoo repositories. However, it relies on nltk. The package relies on problematic data, and hence will not be included in the main repository. Gentoo won't include the package with this data, which in turn will not work without the the data. Maybe gentoo isn't a big crowd, but it might affect other Linux distributions (or consumers of safety,

Python version

3.11

Operating System

Gentoo Linux

Describe the problem you'd like to have solved

Please consider an alternative to nltk?

Describe the ideal solution

A solution that does not involve nltk?

Alternatives and current workarounds

No response

Additional context

No response

What I Did

I tried packaging safety, but I discovered that nltk was removed from gentoo for the reasons above.

oz123 avatar May 08 '25 20:05 oz123

Hi @oz123, thank you for opening this issue!

We appreciate your effort in reporting this. Our team will review it and get back to you soon. If you have any additional details or updates, feel free to add them to this issue.

Note: If this is a serious security issue that could impact the security of Safety CLI users, please email [email protected] immediately.

Thank you for contributing to Safety CLI!

github-actions[bot] avatar May 08 '25 20:05 github-actions[bot]

Hi @oz123, thanks for raising this concern. We are considering it, and this will probably be a yes, but we don't yet have an ETA.

I'll share updates here as soon as we move forward with the decision.

yeisonvargasf avatar May 08 '25 21:05 yeisonvargasf

As I already created a PR, it is easier to say yes ;-) I added some tests to make this more convincing. Let me know if there is anything else needed.

oz123 avatar May 08 '25 21:05 oz123

Hi @oz123, Thanks for the tests and your PR! I raised this again to the internal team to see if everyone is okay with switching dependencies.

yeisonvargasf avatar Jun 22 '25 17:06 yeisonvargasf

Hi @yeisonvargasf any update on this?

oz123 avatar Oct 05 '25 20:10 oz123