cp: security: bump nltk >=3.10.0 and fix inisec import blocks (2290) into r0.5.0 - #2291
Merged
Conversation
## Summary
Bump \`nltk>=3.10.0\` in \`iheval\` and \`rolemrc\` (CVE fix), and
pre-import \`regex\` and \`defusedxml.ElementTree\` in all servers whose
import chains reach nltk.
## Root cause
\`nltk>=3.9\` added \`NLTKSafeImportFinder\` (\`nltk/inisec.py\`) which
blocks any import triggered by nltk if the module's resolved path is
inside the process CWD. In CI, server venvs live at
\`resources_servers/<name>/.venv/\` — inside the repo root — so
legitimate site-packages get blocked. Pre-importing before the nltk
chain fires puts packages in \`sys.modules\`, bypassing the check.
\`ifbench\` also needs the pre-imports in \`conftest.py\` so
\`_ensure_nltk_data()\` can download punkt without being silently
blocked during \`pytest_configure\`.
## Changes
| File | Change |
|---|---|
| \`resources_servers/{iheval,rolemrc}/requirements.txt\` | bump
\`nltk>=3.10.0\` |
|
\`resources_servers/{iheval,rolemrc,ifbench,instruction_following,toolsandbox}/app.py\`
| pre-import \`regex\`, \`defusedxml.ElementTree\` |
| \`resources_servers/ifbench/tests/conftest.py\` | same pre-imports
before \`ensure_ifbench()\` |
## Local test results
| Server | Result |
|---|---|
| iheval | 88/88 ✓ |
| rolemrc | 55/55 ✓ |
| ifbench | 15/15 ✓ |
| instruction_following | 15/15 ✓ |
| toolsandbox | 19/19 ✓ |
## Full test suite run
https://github.com/NVIDIA-NeMo/Gym/actions/runs/30840804435
---------
Signed-off-by: Kajal Jain <kajalj@nvidia.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: NeMo Bot <nemo-bot@nvidia.com>
Author
|
/ok to test 387d9da |
kajalj22
approved these changes
Aug 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
beep boop [🤖]: Hi @kajalj22 👋,