Skip to content

Conversation

@renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Confidence
langchain-community (changelog) ==0.3.3 -> ==0.3.27 age confidence

GitHub Vulnerability Alerts

CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners September 5, 2025 15:50
@product-auto-label product-auto-label bot added the api: datastore Issues related to the googleapis/langchain-google-datastore-python API. label Sep 5, 2025
@dpebot
Copy link
Collaborator

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 9dc316c to f9e7752 Compare September 5, 2025 21:49
@dpebot
Copy link
Collaborator

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f9e7752 to 2950acc Compare September 6, 2025 05:12
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2950acc to a85b3d9 Compare September 6, 2025 12:30
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a85b3d9 to c0e8999 Compare September 6, 2025 21:29
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from c0e8999 to 1c6dc1d Compare September 7, 2025 05:31
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1c6dc1d to 5b722c0 Compare September 7, 2025 13:44
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5b722c0 to 5338dc7 Compare September 7, 2025 20:36
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5338dc7 to edd22eb Compare September 8, 2025 05:44
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from edd22eb to 053a0e5 Compare September 8, 2025 13:11
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 053a0e5 to f6d479a Compare September 8, 2025 21:57
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f6d479a to 4536fc9 Compare September 9, 2025 04:42
@dpebot
Copy link
Collaborator

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 4536fc9 to a223ff7 Compare September 9, 2025 14:52
@dpebot
Copy link
Collaborator

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a223ff7 to 4e188c7 Compare September 9, 2025 21:11
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1e19782 to 6d21ec5 Compare October 4, 2025 09:38
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 6d21ec5 to bd99e66 Compare October 4, 2025 17:23
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from bd99e66 to f26faea Compare October 5, 2025 01:28
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f26faea to 9c48bac Compare October 5, 2025 09:41
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 9c48bac to 5ddaded Compare October 5, 2025 17:31
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5ddaded to f450ac3 Compare October 6, 2025 01:02
@dpebot
Copy link
Collaborator

dpebot commented Oct 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f450ac3 to ec5d560 Compare October 6, 2025 10:59
@dpebot
Copy link
Collaborator

dpebot commented Oct 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ec5d560 to 04b9d4c Compare October 6, 2025 19:09
@dpebot
Copy link
Collaborator

dpebot commented Oct 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 04b9d4c to 6502469 Compare October 7, 2025 00:34
@dpebot
Copy link
Collaborator

dpebot commented Oct 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 6502469 to f80e944 Compare October 7, 2025 09:15
@dpebot
Copy link
Collaborator

dpebot commented Oct 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f80e944 to 2879a27 Compare October 8, 2025 01:49
@dpebot
Copy link
Collaborator

dpebot commented Oct 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2879a27 to 7c99f0d Compare October 8, 2025 11:00
@dpebot
Copy link
Collaborator

dpebot commented Oct 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 7c99f0d to adc15b5 Compare October 8, 2025 20:41
@dpebot
Copy link
Collaborator

dpebot commented Oct 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from adc15b5 to 9997ac3 Compare October 9, 2025 06:09
@dpebot
Copy link
Collaborator

dpebot commented Oct 9, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: datastore Issues related to the googleapis/langchain-google-datastore-python API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants