Skip to content

Bump nltk from 3.9.3 to 3.9.4 in /mindsdb/integrations/handlers/huggingface_handler#12396

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mindsdb/integrations/handlers/huggingface_handler/nltk-3.9.4
Open

Bump nltk from 3.9.3 to 3.9.4 in /mindsdb/integrations/handlers/huggingface_handler#12396
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mindsdb/integrations/handlers/huggingface_handler/nltk-3.9.4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 18, 2026

Bumps nltk from 3.9.3 to 3.9.4.

Changelog

Sourced from nltk's changelog.

Version 3.9.4 2026-03-24

  • Support Python 3.14
  • Fix bug in Levenshtein distance when substitution_cost > 2
  • Fix bug in Treebank detokeniser re quote ordering
  • Fix bug in Jaro similarity for empty strings
  • Several security enhancements
  • Fix GHSA-rf74-v2fm-23pw: unbounded recursion in JSONTaggedDecoder
  • Implement TextTiling vocabulary introduction method (Hearst 1997)
  • Fix ALINE feature matrix errors and add comprehensive tests
  • Support multiple VerbNet versions, fix longid/shortid regex for VerbNet ids
  • Let downloader fallback to md5 when sha256 is unavailable
  • Several other minor bugfixes and code cleanups

Thanks to the following contributors to 3.9.4: Min-Yen Kan, Eric Kafe, Emily Voss, bowiechen, Hrudhai01, jancallewaert, Mr-Neutr0n, pollak.peter89, ylwango613,

Version 3.9.3 2026-02-21

  • Fix CVE-2025-14009: secure ZIP extraction in nltk.downloader (#3468)
  • Block path traversal/arbitrary reads in nltk.data for protocol-less refs (#3467)
  • Block path traversal/abs paths in corpus readers and FS pointers (#3479, #3480)
  • Validate external StanfordSegmenter JARs using SHA256 (#3477)
  • Add optional sandbox enforcement for filestring() (#3485)
  • Maintenance: downloader/zipped models, CI/tooling updates

Thanks to the following contributors to 3.9.3: Chris Clauss, Eric Kafe, HyperPS, purificant, Shivansh-Game, Christopher Smith

Version 3.9.2 2025-10-01

  • Update download checksums to use SHA256 in built index
  • Fix percentage escape in new-style string formatting
  • replace shortened URLs using goo.gl
  • Make Wordnet interoperable with various taggers and tagged corpora
  • Fix saving PerceptronTagger
  • Document how to reproduce old Wordnet studies
  • properly initialize Portuguese corpus reader
  • support for mixed rules conversion into Chomsky Normal Form
  • only import tkinter if a GUI is needed
  • issue #2112 with Corenlp
  • new environment variable NLTK_DOWNLOADER_FORCE_INTERACTIVE_SHELL
  • Lesk defaults to most frequent sense in case of ties

Thanks to the following contributors to 3.9.2: Jose Cols, Peter de Blanc, GeneralPoxter, Eric Kafe, William LaCroix, Jason Liu, Samer Masterson, Mike014, purificant, Andrew Ernest Ritz, samertm, Ikram Ul Haq, Christopher Smith, Ryan Mannion

Version 3.9.1 2024-08-19

... (truncated)

Commits
  • ad9c96b Update copyright year
  • 7edcddf Updates for 3.9.4 release
  • 67a2736 Merge pull request #3180 from yzhaoinuw/bug-on-edit_distance_align
  • 2b17ac5 Fix edit_distance_align backtrace for high substitution costs
  • 4b72976 Merge pull request #3018 from JuanIMartinezB/bug/shortid-longid
  • 8a5619f Merge pull request #3222 from Syzygy2048/feature/texttiling-vocabulary-introd...
  • c6574d7 Merge pull request #3289 from ihitamandal/codeflash/optimize-windowdiff-2024-...
  • 98ff5d9 Merge pull request #3435 from Hrudhai01/fix-3260-detokenize-quotes
  • aec4fce Merge pull request #3522 from ekaf/pathsec
  • eec4ee3 Merge pull request #3526 from nltk/update-contributing
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Apr 18, 2026
@entelligence-ai-pr-reviews
Copy link
Copy Markdown
Contributor

EntelligenceAI PR Summary

Upgrades the nltk dependency to 3.9.4 in the HuggingFace handler to incorporate upstream bug fixes and patches.

  • Updated nltk from 3.9.13.9.4 in requirements.txt
  • Updated nltk from 3.9.13.9.4 in requirements_cpu.txt

Confidence Score: 5/5 - Safe to Merge

Safe to merge — this PR performs a straightforward patch-level dependency bump of nltk from 3.9.1 to 3.9.4 in both requirements.txt and requirements_cpu.txt within the HuggingFace handler directory. The change is minimal and scoped, touching only version strings in two requirements files with no logic, configuration, or API surface changes. Patch releases in semantic versioning (3.9.1 → 3.9.4) are expected to be backward-compatible bug fixes, and no review comments or heuristic issues were raised against this PR.

Key Findings:

  • The change is limited to version string updates in huggingface_handler/requirements.txt and huggingface_handler/requirements_cpu.txt, making regression risk extremely low.
  • nltk 3.9.x patch releases are backward-compatible by convention, and no breaking changes between 3.9.1 and 3.9.4 are known in the nltk changelog.
  • Both CPU and standard requirements files are updated consistently, avoiding a version mismatch between the two dependency tracks.
  • No automated review comments, heuristic flags, or unresolved prior concerns were identified against this PR.
Files requiring special attention
  • mindsdb/integrations/handlers/huggingface_handler/requirements.txt
  • mindsdb/integrations/handlers/huggingface_handler/requirements_cpu.txt

@entelligence-ai-pr-reviews
Copy link
Copy Markdown
Contributor

Upgrades the nltk dependency to 3.9.4 in the HuggingFace handler to incorporate upstream bug fixes and patches.

  • Updated nltk from 3.9.13.9.4 in requirements.txt
  • Updated nltk from 3.9.13.9.4 in requirements_cpu.txt

Bumps [nltk](https://github.com/nltk/nltk) from 3.9.1 to 3.9.4.
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](nltk/nltk@3.9.1...3.9.4)

---
updated-dependencies:
- dependency-name: nltk
  dependency-version: 3.9.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump nltk from 3.9.1 to 3.9.4 in /mindsdb/integrations/handlers/huggingface_handler Bump nltk from 3.9.3 to 3.9.4 in /mindsdb/integrations/handlers/huggingface_handler Apr 23, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/mindsdb/integrations/handlers/huggingface_handler/nltk-3.9.4 branch from d28f5ee to 2ff2f35 Compare April 23, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants