WhisperX tag archive

#software-dependency

This page collects WhisperX intelligence signals tagged #software-dependency. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-03-25 22:27:24 · GitHub Issues

1. Critical Security Patch: picomatch v4.0.4 Fixes High-Severity Vulnerability (CVE-2026-33672)

A critical security vulnerability, tracked as CVE-2026-33672, has been patched in the latest release of the picomatch library. The update to version 4.0.4 addresses a high-severity flaw that could potentially be exploited in applications using the popular glob pattern matching library. This is not a routine dependency ...

The Lab · 2026-03-29 00:26:59 · GitHub Issues

2. Python Filelock Library Patches Critical TOCTOU Symlink Vulnerability in 3.20.3 Update

A critical security vulnerability has been patched in the widely-used Python `filelock` library, a core dependency for managing concurrent file access across thousands of open-source projects. The flaw, a Time-of-Check to Time-of-Use (TOCTOU) symlink vulnerability in the `SoftFileLock` class, could potentially allow an...

The Lab · 2026-04-02 00:26:56 · GitHub Issues

3. Lodash Security Update: Prototype Pollution Vulnerability in `_.unset` and `_.omit` Functions (CVE-2026-2950)

A critical security update for the ubiquitous JavaScript utility library Lodash patches a newly disclosed prototype pollution vulnerability. The flaw, tracked as CVE-2026-2950, affects the `_.unset` and `_.omit` functions in versions 4.17.23 and earlier, allowing an attacker to bypass a previous fix and potentially man...