Skip to content

chore(deps): update dependency langchain-community to v0.2.19 [security] #117

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
langchain-community (changelog) ==0.2.12 -> ==0.2.19 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-8309

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners May 28, 2025 09:12
@dpebot
Copy link
Collaborator

dpebot commented May 28, 2025

/gcbrun

@product-auto-label product-auto-label bot added the api: redis Issues related to the googleapis/langchain-google-memorystore-redis-python API. label May 28, 2025
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 4f326ff to ad142af Compare May 28, 2025 23:04
@dpebot
Copy link
Collaborator

dpebot commented May 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ad142af to 926dcc4 Compare May 29, 2025 05:15
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 926dcc4 to 2445254 Compare May 29, 2025 13:23
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2445254 to 4e1e101 Compare May 29, 2025 23:30
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 4e1e101 to 7281f40 Compare May 30, 2025 06:08
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 7281f40 to 1656901 Compare May 30, 2025 18:37
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1656901 to 9f56426 Compare May 31, 2025 01:40
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 9f56426 to 638da1e Compare May 31, 2025 11:23
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 638da1e to 1d36c35 Compare May 31, 2025 18:20
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1d36c35 to 60cef87 Compare June 1, 2025 01:37
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 60cef87 to 42f071b Compare June 1, 2025 09:47
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 42f071b to b08b378 Compare June 1, 2025 16:33
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from b08b378 to 2803e56 Compare June 2, 2025 00:31
@dpebot
Copy link
Collaborator

dpebot commented Jul 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 20558da to 7f240ad Compare July 12, 2025 10:55
@dpebot
Copy link
Collaborator

dpebot commented Jul 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 7f240ad to fa52308 Compare July 12, 2025 17:28
@dpebot
Copy link
Collaborator

dpebot commented Jul 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from fa52308 to 132d4f0 Compare July 13, 2025 00:50
@dpebot
Copy link
Collaborator

dpebot commented Jul 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 132d4f0 to 0b9f675 Compare July 13, 2025 11:14
@dpebot
Copy link
Collaborator

dpebot commented Jul 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 0b9f675 to 497dd19 Compare July 13, 2025 18:33
@dpebot
Copy link
Collaborator

dpebot commented Jul 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 497dd19 to 7c90374 Compare July 14, 2025 02:53
@dpebot
Copy link
Collaborator

dpebot commented Jul 14, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 7c90374 to b783c6b Compare July 14, 2025 11:06
@dpebot
Copy link
Collaborator

dpebot commented Jul 14, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from b783c6b to 682da98 Compare July 15, 2025 00:10
@dpebot
Copy link
Collaborator

dpebot commented Jul 15, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 682da98 to 25e4be3 Compare July 15, 2025 06:08
@dpebot
Copy link
Collaborator

dpebot commented Jul 15, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 25e4be3 to e71e35e Compare July 15, 2025 16:46
@dpebot
Copy link
Collaborator

dpebot commented Jul 15, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from e71e35e to 2b6b54b Compare July 16, 2025 01:50
@dpebot
Copy link
Collaborator

dpebot commented Jul 16, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2b6b54b to 22ee248 Compare July 16, 2025 13:56
@dpebot
Copy link
Collaborator

dpebot commented Jul 16, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 22ee248 to 39e9f5e Compare July 17, 2025 01:46
@dpebot
Copy link
Collaborator

dpebot commented Jul 17, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 39e9f5e to 39e1f2b Compare July 17, 2025 12:26
@dpebot
Copy link
Collaborator

dpebot commented Jul 17, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: redis Issues related to the googleapis/langchain-google-memorystore-redis-python API.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants