Problem
inference-sdk (latest version 0.63.5) pins aiohttp to <=3.10.11, which has 9 known CVEs:
Current constraint
Request
Please update the aiohttp dependency to >=3.13.3 (or remove the upper bound) to allow users to fix these security vulnerabilities.
Impact
Projects using inference-sdk cannot update aiohttp to patched versions, leaving them exposed to these CVEs.
References
Thank you!
Problem
inference-sdk(latest version 0.63.5) pins aiohttp to<=3.10.11, which has 9 known CVEs:Current constraint
Request
Please update the aiohttp dependency to
>=3.13.3(or remove the upper bound) to allow users to fix these security vulnerabilities.Impact
Projects using
inference-sdkcannot update aiohttp to patched versions, leaving them exposed to these CVEs.References
Thank you!