|
|
|
|
|
by shanipribadi
1269 days ago
|
|
the 3.0.0 version that is available on pypi is now an empty package with updated description of This is not the real torchtriton package but uploaded here to discover dependency confusion vulnerabilities the compromised version is still available in pypi as version 2.0.0+0d7e753227 https://pypi.org/project/torchtriton/#history. So technically, if you are pulling the older version of pytorch-nightly (specifically 2.0.0.dev20221230), it will still pull that compromised dependency (because torch have explicit version lock to it). |
|
All PyTorch nightlies with this dependency have been deleted