-
-
Notifications
You must be signed in to change notification settings - Fork 10.4k
[CI/Build] remove regex from build dependencies #18945
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CI/Build] remove regex from build dependencies #18945
Conversation
Signed-off-by: Daniele Trifirò <[email protected]>
👋 Hi! Thank you for contributing to the vLLM project. 💬 Join our developer Slack at https://slack.vllm.ai to discuss your PR in #pr-reviews, coordinate on features in #feat- channels, or join special interest groups in #sig- channels. Just a reminder: PRs would not trigger full CI run by default. Instead, it would only run Once the PR is approved and ready to go, your PR reviewer(s) can run CI to test the changes comprehensively before merging. To run CI, PR reviewers can either: Add 🚀 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah this is reasonable, thanks for fixing!
This seems a better solution. |
Signed-off-by: Daniele Trifirò <[email protected]> Co-authored-by: Cyrus Leung <[email protected]> Signed-off-by: amit <[email protected]>
Signed-off-by: Daniele Trifirò <[email protected]> Co-authored-by: Cyrus Leung <[email protected]> Signed-off-by: amit <[email protected]>
Signed-off-by: Daniele Trifirò <[email protected]> Co-authored-by: Cyrus Leung <[email protected]> Signed-off-by: minpeter <[email protected]>
Signed-off-by: Daniele Trifirò <[email protected]> Co-authored-by: Cyrus Leung <[email protected]>
#18454 migrated all uses of the
re
stdlib module to theregex
due to a security vulnerability explained hereWe have no security vulnerabilities by using the
re
module insetup.py
, it just causes more problems: e.g. it broke the ROCm build and possibly others, due to how vllm is built differently for different target devices.Signed-off-by: Daniele Trifirò [email protected]