# Negative fixture for CVE-2026-19984: this project has no dependency on the
# affected package. `florence2` here is an unrelated upstream model package; the
# pin escapes the full hyphenated package name, so the bare name must not fire.
florence2==1.0.0
transformers==4.44.0
