Skip to content

Conversation

dtrifiro
Copy link
Contributor

#18454 migrated all uses of the re stdlib module to the regex due to a security vulnerability explained here

We have no security vulnerabilities by using the re module in setup.py, it just causes more problems: e.g. it broke the ROCm build and possibly others, due to how vllm is built differently for different target devices.

Signed-off-by: Daniele Trifirò [email protected]

Copy link

👋 Hi! Thank you for contributing to the vLLM project.

💬 Join our developer Slack at https://slack.vllm.ai to discuss your PR in #pr-reviews, coordinate on features in #feat- channels, or join special interest groups in #sig- channels.

Just a reminder: PRs would not trigger full CI run by default. Instead, it would only run fastcheck CI which starts running only a small and essential subset of CI tests to quickly catch errors. You can run other CI tests on top of those by going to your fastcheck build on Buildkite UI (linked in the PR checks section) and unblock them. If you do not have permission to unblock, ping simon-mo or khluu to add you in our Buildkite org.

Once the PR is approved and ready to go, your PR reviewer(s) can run CI to test the changes comprehensively before merging.

To run CI, PR reviewers can either: Add ready label to the PR or enable auto-merge.

🚀

Copy link
Member

@DarkLight1337 DarkLight1337 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this is reasonable, thanks for fixing!

@DarkLight1337 DarkLight1337 enabled auto-merge (squash) May 30, 2025 08:00
@github-actions github-actions bot added the ready ONLY add when PR is ready to merge/full CI is needed label May 30, 2025
@houseroad
Copy link
Collaborator

This seems a better solution.

@vllm-bot vllm-bot merged commit 43ff405 into vllm-project:main May 30, 2025
99 of 102 checks passed
amitm02 pushed a commit to amitm02/vllm that referenced this pull request Jun 1, 2025
Signed-off-by: Daniele Trifirò <[email protected]>
Co-authored-by: Cyrus Leung <[email protected]>
Signed-off-by: amit <[email protected]>
amitm02 pushed a commit to amitm02/vllm that referenced this pull request Jun 1, 2025
Signed-off-by: Daniele Trifirò <[email protected]>
Co-authored-by: Cyrus Leung <[email protected]>
Signed-off-by: amit <[email protected]>
@dtrifiro dtrifiro deleted the remove-regex-build-dependency branch June 3, 2025 09:19
minpeter pushed a commit to minpeter/vllm that referenced this pull request Jun 24, 2025
Signed-off-by: Daniele Trifirò <[email protected]>
Co-authored-by: Cyrus Leung <[email protected]>
Signed-off-by: minpeter <[email protected]>
googlercolin pushed a commit to googlercolin/vllm that referenced this pull request Aug 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci/build ready ONLY add when PR is ready to merge/full CI is needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants