-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency langchain to v0.0.329 [security] #23
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 9, 2023 09:53
8b49e32
to
2a69c9f
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.308 [security]
chore(deps): update dependency langchain to v0.0.310 [security]
Oct 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 9, 2023 13:05
2a69c9f
to
06729fe
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.310 [security]
chore(deps): update dependency langchain to v0.0.308 [security]
Oct 9, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 10, 2023 21:53
06729fe
to
84ee9e2
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.308 [security]
chore(deps): update dependency langchain to v0.0.312 [security]
Oct 10, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 15, 2023 09:19
84ee9e2
to
2039b9e
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.312 [security]
chore(deps): update dependency langchain to v0.0.314 [security]
Oct 15, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 15, 2023 17:30
2039b9e
to
79e69ae
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.314 [security]
chore(deps): update dependency langchain to v0.0.312 [security]
Oct 15, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 23, 2023 13:16
79e69ae
to
6f46c6e
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.312 [security]
chore(deps): update dependency langchain to v0.0.320 [security]
Oct 23, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 23, 2023 16:48
6f46c6e
to
19a4738
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.320 [security]
chore(deps): update dependency langchain to v0.0.312 [security]
Oct 23, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 25, 2023 20:19
19a4738
to
687679d
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.312 [security]
chore(deps): update dependency langchain to v0.0.317 [security]
Oct 25, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
October 30, 2023 23:05
687679d
to
29ab50c
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.317 [security]
chore(deps): update dependency langchain to v0.0.325 [security]
Oct 30, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
November 6, 2023 07:50
29ab50c
to
29a7311
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.325 [security]
chore(deps): update dependency langchain to v0.0.330 [security]
Nov 6, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
November 6, 2023 11:02
29a7311
to
37849f0
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.330 [security]
chore(deps): update dependency langchain to v0.0.325 [security]
Nov 6, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
November 11, 2023 07:15
37849f0
to
49cdbed
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.325 [security]
chore(deps): update dependency langchain to v0.0.329 [security]
Nov 11, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
November 16, 2023 10:46
49cdbed
to
8778a47
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.329 [security]
chore(deps): update dependency langchain to v0.0.336 [security]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
November 16, 2023 13:49
8778a47
to
7e3329e
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.336 [security]
chore(deps): update dependency langchain to v0.0.329 [security]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
December 3, 2023 11:27
7e3329e
to
aeb124d
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.329 [security]
chore(deps): update dependency langchain to v0.0.345 [security]
Dec 3, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
December 3, 2023 14:35
aeb124d
to
e10f8af
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.345 [security]
chore(deps): update dependency langchain to v0.0.329 [security]
Dec 3, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
December 7, 2023 10:23
e10f8af
to
d097ccd
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.329 [security]
chore(deps): update dependency langchain to v0.0.347 [security]
Dec 7, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
2 times, most recently
from
December 7, 2023 10:40
3436f1a
to
b5671db
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.347 [security]
chore(deps): update dependency langchain to v0.0.329 [security]
Dec 7, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
December 7, 2023 10:54
b5671db
to
014a7ea
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.329 [security]
chore(deps): update dependency langchain to v0.0.347 [security]
Dec 7, 2023
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
December 7, 2023 10:59
014a7ea
to
6196305
Compare
renovate
bot
force-pushed
the
renovate/pypi-langchain-vulnerability
branch
from
December 7, 2023 11:01
6196305
to
b99ea0e
Compare
renovate
bot
changed the title
chore(deps): update dependency langchain to v0.0.347 [security]
chore(deps): update dependency langchain to v0.0.329 [security]
Dec 7, 2023
benoutram
approved these changes
Dec 7, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.0.267
->==0.0.329
GitHub Vulnerability Alerts
CVE-2023-39631
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
Patches: Released in v.0.0.308. numexpr dependency is optional for langchain.
CVE-2023-36281
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the
load_prompt
parameter. This is related to__subclasses__
or a template.CVE-2023-46229
LangChain before 0.0.317 allows SSRF via
document_loaders/recursive_url_loader.py
because crawling can proceed from an external server to an internal server.CVE-2023-39659
An issue in langchain langchain-ai before version 0.0.325 allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.
CVE-2023-32786
In Langchain before 0.0.329, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
Release Notes
langchain-ai/langchain (langchain)
v0.0.329
Compare Source
What's Changed
ruff format
instead of black for code formatting. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12585actions/checkout@v4
in the docs lint job. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12581print()
statements which seemed leftover from debugging. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12648ruff
for both linting and formatting inlangchain-cli
. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12672templates
with ruff v0.1.3. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12676YahooFinanceNewsTool
by @leo-gan in https://github.com/langchain-ai/langchain/pull/12665_test_release.yml
workflow. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12668black
caching config from CI lint workflow. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12594ruff
autoformatter. by @obi1kenobi in https://github.com/langchain-ai/langchain/pull/12691New Contributors
CVEs
CVE-2023-32786 -- resolved by APIChain add restrictions to domains (GHSA-6h8p-4hx9-w66c) by @eyurtsev in https://github.com/langchain-ai/langchain/pull/12747
Full Changelog: langchain-ai/langchain@v0.0.327...v0.0.329
v0.0.327
Compare Source
What's Changed
poetry lock --no-update
for all templates by @dqbd in https://github.com/langchain-ai/langchain/pull/12531New Contributors
Full Changelog: langchain-ai/langchain@v0.0.326...v0.0.327
v0.0.326
Compare Source
What's Changed
_dalle_image_url
returns list of urls if n>1 by @silvhua in https://github.com/langchain-ai/langchain/pull/11800New Contributors
Full Changelog: langchain-ai/langchain@v0.0.325...v0.0.326
v0.0.325
Compare Source
What's Changed
New Contributors
CVEs
CVE-2023-39659 resolved in https://github.com/langchain-ai/langchain/pull/12427
Full Changelog: langchain-ai/langchain@v0.0.324...v0.0.325
v0.0.324
Compare Source
What's Changed
Configuration
📅 Schedule: Branch creation - "" in timezone Europe/London, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.