-
Notifications
You must be signed in to change notification settings - Fork 4
chore(deps): update dependency langchain-community to v0.3.27 [security] #97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate-bot
wants to merge
1
commit into
googleapis:main
Choose a base branch
from
renovate-bot:renovate/pypi-langchain-community-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
chore(deps): update dependency langchain-community to v0.3.27 [security] #97
renovate-bot
wants to merge
1
commit into
googleapis:main
from
renovate-bot:renovate/pypi-langchain-community-vulnerability
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
/gcbrun |
9dc316c
to
f9e7752
Compare
/gcbrun |
f9e7752
to
2950acc
Compare
/gcbrun |
2950acc
to
a85b3d9
Compare
/gcbrun |
a85b3d9
to
c0e8999
Compare
/gcbrun |
c0e8999
to
1c6dc1d
Compare
/gcbrun |
1c6dc1d
to
5b722c0
Compare
/gcbrun |
5b722c0
to
5338dc7
Compare
/gcbrun |
5338dc7
to
edd22eb
Compare
/gcbrun |
edd22eb
to
053a0e5
Compare
/gcbrun |
053a0e5
to
f6d479a
Compare
/gcbrun |
f6d479a
to
4536fc9
Compare
/gcbrun |
4536fc9
to
a223ff7
Compare
/gcbrun |
a223ff7
to
4e188c7
Compare
/gcbrun |
4e188c7
to
1ce6e0f
Compare
/gcbrun |
1ce6e0f
to
164a399
Compare
/gcbrun |
164a399
to
d6d5779
Compare
/gcbrun |
d6d5779
to
c379b85
Compare
/gcbrun |
c379b85
to
88a2ccf
Compare
/gcbrun |
88a2ccf
to
148ac58
Compare
/gcbrun |
148ac58
to
d4726cb
Compare
/gcbrun |
d4726cb
to
1e1b954
Compare
/gcbrun |
1e1b954
to
7ef43af
Compare
/gcbrun |
7ef43af
to
825e66e
Compare
/gcbrun |
825e66e
to
1cb3a0a
Compare
/gcbrun |
1cb3a0a
to
65e187d
Compare
/gcbrun |
65e187d
to
7a6f07c
Compare
/gcbrun |
7a6f07c
to
26355d0
Compare
/gcbrun |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.3.3
->==0.3.27
GitHub Vulnerability Alerts
CVE-2025-6984
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.