{"enrichment":{"capability":"Disables the PyArrow CVE-2023-47248 deserialization vulnerability on PyArrow versions before 14.0.1 by patching unsafe pickle handling when imported.","verdict":"A lightweight, dependency-free security patch for older PyArrow installations vulnerable to CVE-2023-47248. Recommended only if you cannot upgrade PyArrow itself to 14.0.1+; otherwise upgrading PyArrow directly is the better path. No known vulnerabilities in the hotfix itself."},"id":"pyarrow-hotfix","links":{"html":"https://skillfed.io/packages/pyarrow-hotfix","md":"https://skillfed.io/packages/pyarrow-hotfix.md","pypi":"https://pypi.org/project/pyarrow-hotfix/"},"maintenance":{"status":"aging"},"meta":{"latest_release":"2025-04-25","license_spdx":null,"license_treatment":"permissive","name":"pyarrow-hotfix","python_support":"supports_current","summary":null},"popularity":{"tier":"top_1000"},"security":{"n_vulnerabilities":0},"version":"0.7"}
