-
Notifications
You must be signed in to change notification settings - Fork 4
chore(deps): update dependency langchain-community to v0.3.27 [security] #97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate-bot
wants to merge
1
commit into
googleapis:main
Choose a base branch
from
renovate-bot:renovate/pypi-langchain-community-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
chore(deps): update dependency langchain-community to v0.3.27 [security] #97
renovate-bot
wants to merge
1
commit into
googleapis:main
from
renovate-bot:renovate/pypi-langchain-community-vulnerability
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Collaborator
|
/gcbrun |
9dc316c to
f9e7752
Compare
Collaborator
|
/gcbrun |
f9e7752 to
2950acc
Compare
Collaborator
|
/gcbrun |
2950acc to
a85b3d9
Compare
Collaborator
|
/gcbrun |
a85b3d9 to
c0e8999
Compare
Collaborator
|
/gcbrun |
c0e8999 to
1c6dc1d
Compare
Collaborator
|
/gcbrun |
1c6dc1d to
5b722c0
Compare
Collaborator
|
/gcbrun |
5b722c0 to
5338dc7
Compare
Collaborator
|
/gcbrun |
5338dc7 to
edd22eb
Compare
Collaborator
|
/gcbrun |
edd22eb to
053a0e5
Compare
Collaborator
|
/gcbrun |
053a0e5 to
f6d479a
Compare
Collaborator
|
/gcbrun |
f6d479a to
4536fc9
Compare
Collaborator
|
/gcbrun |
4536fc9 to
a223ff7
Compare
Collaborator
|
/gcbrun |
a223ff7 to
4e188c7
Compare
Collaborator
|
/gcbrun |
1e19782 to
6d21ec5
Compare
Collaborator
|
/gcbrun |
6d21ec5 to
bd99e66
Compare
Collaborator
|
/gcbrun |
bd99e66 to
f26faea
Compare
Collaborator
|
/gcbrun |
f26faea to
9c48bac
Compare
Collaborator
|
/gcbrun |
9c48bac to
5ddaded
Compare
Collaborator
|
/gcbrun |
5ddaded to
f450ac3
Compare
Collaborator
|
/gcbrun |
f450ac3 to
ec5d560
Compare
Collaborator
|
/gcbrun |
ec5d560 to
04b9d4c
Compare
Collaborator
|
/gcbrun |
04b9d4c to
6502469
Compare
Collaborator
|
/gcbrun |
6502469 to
f80e944
Compare
Collaborator
|
/gcbrun |
f80e944 to
2879a27
Compare
Collaborator
|
/gcbrun |
2879a27 to
7c99f0d
Compare
Collaborator
|
/gcbrun |
7c99f0d to
adc15b5
Compare
Collaborator
|
/gcbrun |
adc15b5 to
9997ac3
Compare
Collaborator
|
/gcbrun |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.3.3->==0.3.27GitHub Vulnerability Alerts
CVE-2025-6984
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.