chore(deps): [fsi-quant-assistant] Update dependency google-cloud-aiplatform [SECURITY]#350
Open
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
Conversation
|
…latform [SECURITY]
02593c5 to
2b5e3b9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.127.0→1.133.01.137.0→1.138.0==1.74.0→==1.133.0==1.101.0→==1.133.0==1.75.0→==1.133.0==1.48.0→==1.133.01.135.0→1.136.01.133.0→1.134.0GitHub Vulnerability Alerts
CVE-2026-2472
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.
CVE-2026-2473
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).
This vulnerability was patched and no customer action is needed.
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
CVE-2026-2472 / GHSA-qv8j-hgpc-vrq8
More information
Details
Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:AmberReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
CVE-2026-2473 / GHSA-wh2j-26j7-9728
More information
Details
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).
This vulnerability was patched and no customer action is needed.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:ClearReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
googleapis/python-aiplatform (google-cloud-aiplatform)
v1.133.0Compare Source
Features
optimize_promptmethod (715cc5b)Bug Fixes
examples_dataframetype toPandasDataFramein Prompt Optimizer. (a2564cc)v1.132.0Compare Source
Features
Documentation
restart_job_on_worker_restartin message.google.cloud.aiplatform.v1beta1.Schedulingis changed (71747e8)timeoutin message.google.cloud.aiplatform.v1beta1.Schedulingis changed (71747e8)v1.131.0Compare Source
Features
Bug Fixes
v1.130.0Compare Source
Features
min_gpu_driver_versionis added to message.google.cloud.aiplatform.v1beta1.MachineSpec(26dfdfe)Documentation
ReplicatedVoiceConfig.mime_typecomment (26dfdfe)ReplicatedVoiceConfig.mime_typecomment (26dfdfe)v1.129.0Compare Source
⚠ BREAKING CHANGES
transfer_to_agentis removed from message.google.cloud.aiplatform.v1beta1.EventActionsbigtable_metadatafield name inFeatureOnlineStoreenableDirectBigtableAccessfield name in FeatureOnlineStore`bigtable_metadatafield name inFeatureViewFeatures
gpu_partition_sizeinmachine_specv1 api (e0bc3d8)ReplicatedVoiceConfigtoVoiceConfigto enable Gemini TTS voice replication (e0bc3d8)ReplicatedVoiceConfigtoVoiceConfigto enable Gemini TTS voice replication (e0bc3d8)SUCCESSFULLY_DEPLOYEDandFAILED_TO_DEPLOYtoDeploymentStage(e0bc3d8)SUCCESSFULLY_DEPLOYEDandFAILED_TO_DEPLOYtoDeploymentStage(e0bc3d8)Bug Fixes
transfer_to_agentis removed from message.google.cloud.aiplatform.v1beta1.EventActions(e0bc3d8)adk deploy agent_engine(9301551)from vertexai.types import TypeNamewithout needing to runfrom vertexai import typesfirst (46285bf)from vertexai.types import TypeNamewithout needing to runfrom vertexai import typesfirst (f4a6cbe)bigtable_metadatafield name inFeatureOnlineStore(e0bc3d8)bigtable_metadatafield name inFeatureView(e0bc3d8)enableDirectBigtableAccessfield name in FeatureOnlineStore` (e0bc3d8)Documentation
filterin message.google.cloud.aiplatform.v1beta1.ListSessionsRequestis changed (e0bc3d8)package_specin message.google.cloud.aiplatform.v1.ReasoningEngineSpecis changed (e0bc3d8)package_specin message.google.cloud.aiplatform.v1beta1.ReasoningEngineSpecis changed (e0bc3d8)ReasoningEngineSpecis changed (e0bc3d8)ReasoningEngineSpecis changed (e0bc3d8)Miscellaneous Chores
v1.128.0Compare Source
Features
pass_ratetoAggregatedMetricResultand calculate it for adaptive rubric metrics. (1f1f67e)build optionsin Agent Engine GCS Deployment. (28499a9)build optionsin Agent Engine source-based Deployment. (f7e718f)Bug Fixes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.