-
Notifications
You must be signed in to change notification settings - Fork 1
chore(deps): update dependency langchain-community to v0.3.27 [security] #93
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate-bot
wants to merge
1
commit into
googleapis:main
Choose a base branch
from
renovate-bot:renovate/pypi-langchain-community-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
chore(deps): update dependency langchain-community to v0.3.27 [security] #93
renovate-bot
wants to merge
1
commit into
googleapis:main
from
renovate-bot:renovate/pypi-langchain-community-vulnerability
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Collaborator
|
/gcbrun |
71f8a72 to
363ae62
Compare
Collaborator
|
/gcbrun |
363ae62 to
c6b610e
Compare
Collaborator
|
/gcbrun |
c6b610e to
6bd8806
Compare
Collaborator
|
/gcbrun |
6bd8806 to
41c0964
Compare
Collaborator
|
/gcbrun |
41c0964 to
d5e5fb8
Compare
Collaborator
|
/gcbrun |
d5e5fb8 to
b647a4f
Compare
Collaborator
|
/gcbrun |
b647a4f to
bd62012
Compare
Collaborator
|
/gcbrun |
bd62012 to
572d53b
Compare
Collaborator
|
/gcbrun |
572d53b to
c528315
Compare
Collaborator
|
/gcbrun |
c528315 to
6c4a902
Compare
Collaborator
|
/gcbrun |
6c4a902 to
cce9e09
Compare
Collaborator
|
/gcbrun |
cce9e09 to
49e6715
Compare
Collaborator
|
/gcbrun |
49e6715 to
44f95b0
Compare
Collaborator
|
/gcbrun |
5236df6 to
57c4e19
Compare
Collaborator
|
/gcbrun |
57c4e19 to
4e7c180
Compare
Collaborator
|
/gcbrun |
4e7c180 to
c1af027
Compare
Collaborator
|
/gcbrun |
c1af027 to
a0771f2
Compare
Collaborator
|
/gcbrun |
a0771f2 to
6779b44
Compare
Collaborator
|
/gcbrun |
6779b44 to
119b306
Compare
Collaborator
|
/gcbrun |
119b306 to
6a678c5
Compare
Collaborator
|
/gcbrun |
6a678c5 to
fc71581
Compare
Collaborator
|
/gcbrun |
fc71581 to
80af72c
Compare
Collaborator
|
/gcbrun |
80af72c to
eec84f2
Compare
Collaborator
|
/gcbrun |
eec84f2 to
39b9b9b
Compare
Collaborator
|
/gcbrun |
39b9b9b to
f2a80a5
Compare
Collaborator
|
/gcbrun |
f2a80a5 to
cf0e57f
Compare
Collaborator
|
/gcbrun |
cf0e57f to
d99ecbf
Compare
Collaborator
|
/gcbrun |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
api: cloudsql-sqlserver
Issues related to the googleapis/langchain-google-cloud-sql-mssql-python API.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.3.1->==0.3.27GitHub Vulnerability Alerts
CVE-2025-6984
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.