Dear Rasa Community. I’ve been exploring the Rasa framework for building conversational AI applications and have been impressed with its capabilities. However, before proceeding further, I wanted to address some security concerns that have been brought to my attention.
Upon reviewing the framework, I noticed that there have been vulnerabilities reported in some of Rasa’s dependencies, such as Pillow and cryptography (e.g., CVE-2023-50447 and CVE-2023-49083). As security is a top priority for our project, I wanted to inquire about the following:
- Is there a recommended approach or best practice for ensuring the secure usage of Rasa Open Source, particularly in regards to managing and addressing vulnerabilities in its dependencies?
- Are there any plans or initiatives in place to address security vulnerabilities in Rasa’s dependencies in upcoming releases?
- Could you provide insights into the dependency management process within the Rasa framework, including how vulnerabilities are monitored, addressed, and communicated to users?
- Are there any specific versions or configurations of Rasa Open Source that are known to be more secure or have fewer vulnerabilities in their dependencies?