diff --git a/pkgs/by-name/op/openllm/package.nix b/pkgs/by-name/op/openllm/package.nix index d197e40c8dd3..321e25db6daa 100644 --- a/pkgs/by-name/op/openllm/package.nix +++ b/pkgs/by-name/op/openllm/package.nix @@ -64,6 +64,9 @@ python3Packages.buildPythonApplication (finalAttrs: { description = "Run any open-source LLMs, such as Llama 3.1, Gemma, as OpenAI compatible API endpoint in the cloud"; homepage = "https://github.com/bentoml/OpenLLM"; changelog = "https://github.com/bentoml/OpenLLM/releases/tag/${finalAttrs.src.tag}"; + knownVulnerabilities = [ + "CVE-2026-15035" + ]; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ happysalada diff --git a/pkgs/development/python-modules/bentoml/default.nix b/pkgs/development/python-modules/bentoml/default.nix index 99703c943757..07dab66f838d 100644 --- a/pkgs/development/python-modules/bentoml/default.nix +++ b/pkgs/development/python-modules/bentoml/default.nix @@ -248,6 +248,14 @@ buildPythonPackage { description = "Build Production-Grade AI Applications"; homepage = "https://github.com/bentoml/BentoML"; changelog = "https://github.com/bentoml/BentoML/releases/tag/${src.tag}"; + knownVulnerabilities = [ + "CVE-2026-27905" + "CVE-2026-33744" + "CVE-2026-35043" + "CVE-2026-35044" + "CVE-2026-44345" + "CVE-2026-44346" + ]; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ happysalada