mirror of
https://github.com/crewAIInc/crewAI.git
synced 2026-08-12 17:29:11 +00:00
Force torch>=2.13.0 via override-dependencies so the transitive docling/unstructured stack picks up the CVE-2025-3000 fix, and drop the now-unnecessary pip-audit ignore. chromadb's CVE-2026-45829 remains ignored: the upstream fix is merged but not released on PyPI. Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Rip&Tear <theCyberTech@users.noreply.github.com>