-
Notifications
You must be signed in to change notification settings - Fork 7
chore(deps): update dependency langchain-core to v0.2.43 [security] #114
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate-bot
wants to merge
1
commit into
googleapis:main
Choose a base branch
from
renovate-bot:renovate/pypi-langchain-core-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
chore(deps): update dependency langchain-core to v0.2.43 [security] #114
renovate-bot
wants to merge
1
commit into
googleapis:main
from
renovate-bot:renovate/pypi-langchain-core-vulnerability
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Collaborator
|
/gcbrun |
8c5f2c2 to
eb792ce
Compare
Collaborator
|
/gcbrun |
eb792ce to
234c5e8
Compare
Collaborator
|
/gcbrun |
234c5e8 to
4bfd107
Compare
Collaborator
|
/gcbrun |
4bfd107 to
911e4b9
Compare
Collaborator
|
/gcbrun |
911e4b9 to
882769a
Compare
Collaborator
|
/gcbrun |
882769a to
b4d96a2
Compare
Collaborator
|
/gcbrun |
b4d96a2 to
231bdf0
Compare
Collaborator
|
/gcbrun |
231bdf0 to
e6cc2d7
Compare
Collaborator
|
/gcbrun |
e6cc2d7 to
50210b6
Compare
Collaborator
|
/gcbrun |
50210b6 to
a7abc8c
Compare
Collaborator
|
/gcbrun |
a7abc8c to
6819b22
Compare
Collaborator
|
/gcbrun |
6819b22 to
eb36c0d
Compare
Collaborator
|
/gcbrun |
eb36c0d to
490e17a
Compare
Collaborator
|
/gcbrun |
20410ab to
964368e
Compare
Collaborator
|
/gcbrun |
964368e to
89304ba
Compare
Collaborator
|
/gcbrun |
89304ba to
6e4efb6
Compare
Collaborator
|
/gcbrun |
6e4efb6 to
4ae7d51
Compare
Collaborator
|
/gcbrun |
4ae7d51 to
9228079
Compare
Collaborator
|
/gcbrun |
9228079 to
3360ab9
Compare
Collaborator
|
/gcbrun |
3360ab9 to
463cec9
Compare
Collaborator
|
/gcbrun |
463cec9 to
b3551c6
Compare
Collaborator
|
/gcbrun |
b3551c6 to
ee416ab
Compare
Collaborator
|
/gcbrun |
ee416ab to
16adb91
Compare
Collaborator
|
/gcbrun |
16adb91 to
717f2f3
Compare
Collaborator
|
/gcbrun |
717f2f3 to
e5408d4
Compare
Collaborator
|
/gcbrun |
e5408d4 to
38930a3
Compare
Collaborator
|
/gcbrun |
38930a3 to
a730616
Compare
Collaborator
|
/gcbrun |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.2.31->==0.2.43GitHub Vulnerability Alerts
CVE-2024-10940
A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.