hdbscan icon indicating copy to clipboard operation
hdbscan copied to clipboard

Update requirements.txt with joblib<1.2 to solve #565

Open giacomorebecchi opened this issue 2 years ago • 2 comments

Hi, I'm a BuildNN data scientist. While using HDBSCAN, I encountered issue #565 due to the minor update in joblib=1.2 that does not ensure retrocompatibility. I solved the problem specifying the joblib version to be lower than 1.2.

giacomorebecchi avatar Sep 23 '22 08:09 giacomorebecchi

Lower versions of joblib (<1.2.0) are affected by CVE-2022-21797.

jcfaracco avatar Oct 01 '22 03:10 jcfaracco

Have you considered using HDBSAN 0.8.29 with Joblib 1.2.0? This avoids the compatibility issue and the critical CVE in Joblib <1.2.0

whymauri avatar Nov 08 '22 04:11 whymauri