Skip to content

chore(deps): update dependency langchain-core to v0.3.15 [security] #85

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
langchain-core (changelog) ==0.3.6 -> ==0.3.15 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-10940

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners March 21, 2025 16:53
@dpebot
Copy link
Collaborator

dpebot commented Mar 21, 2025

/gcbrun

@product-auto-label product-auto-label bot added the api: cloudsql-sqlserver Issues related to the googleapis/langchain-google-cloud-sql-mssql-python API. label Mar 21, 2025
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 96829b0 to 2feb378 Compare May 28, 2025 09:40
@dpebot
Copy link
Collaborator

dpebot commented May 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 2feb378 to 2d24bf2 Compare May 28, 2025 23:04
@dpebot
Copy link
Collaborator

dpebot commented May 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 2d24bf2 to 94f1d72 Compare May 29, 2025 05:29
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 94f1d72 to 8f97bcb Compare May 29, 2025 14:02
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 8f97bcb to c895ca1 Compare May 30, 2025 02:45
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from c895ca1 to 1cb6047 Compare May 30, 2025 11:51
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 1cb6047 to 1aea5dc Compare May 30, 2025 21:29
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 1aea5dc to 5c13305 Compare May 31, 2025 07:02
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 5c13305 to 9596162 Compare May 31, 2025 14:28
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 9596162 to 9e725a3 Compare May 31, 2025 21:20
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 9e725a3 to 6033b01 Compare June 1, 2025 04:56
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 6033b01 to e168155 Compare June 1, 2025 13:43
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from e168155 to af93972 Compare June 1, 2025 20:46
@dpebot
Copy link
Collaborator

dpebot commented Jun 26, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from e21fca9 to 1aac627 Compare June 27, 2025 02:56
@dpebot
Copy link
Collaborator

dpebot commented Jun 27, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 1aac627 to b13237e Compare June 27, 2025 11:00
@dpebot
Copy link
Collaborator

dpebot commented Jun 27, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from b13237e to 9de97ef Compare June 27, 2025 22:39
@dpebot
Copy link
Collaborator

dpebot commented Jun 27, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 9de97ef to 4daeabc Compare June 28, 2025 05:29
@dpebot
Copy link
Collaborator

dpebot commented Jun 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 4daeabc to b0aaafd Compare June 28, 2025 14:38
@dpebot
Copy link
Collaborator

dpebot commented Jun 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from b0aaafd to 23001fd Compare June 28, 2025 21:56
@dpebot
Copy link
Collaborator

dpebot commented Jun 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 23001fd to ce26114 Compare June 29, 2025 04:42
@dpebot
Copy link
Collaborator

dpebot commented Jun 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from ce26114 to d864d3d Compare June 29, 2025 14:30
@dpebot
Copy link
Collaborator

dpebot commented Jun 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from d864d3d to 4718896 Compare June 29, 2025 22:10
@dpebot
Copy link
Collaborator

dpebot commented Jun 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 4718896 to 54242c3 Compare June 30, 2025 05:05
@dpebot
Copy link
Collaborator

dpebot commented Jun 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 54242c3 to 2908d52 Compare June 30, 2025 16:57
@dpebot
Copy link
Collaborator

dpebot commented Jun 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 2908d52 to e8858fd Compare July 1, 2025 02:57
@dpebot
Copy link
Collaborator

dpebot commented Jul 1, 2025

/gcbrun

@loeng2023 loeng2023 removed their assignment Jul 1, 2025
@loeng2023 loeng2023 merged commit 52fc4f3 into googleapis:main Jul 1, 2025
11 checks passed
@renovate-bot renovate-bot deleted the renovate/pypi-langchain-core-vulnerability branch July 1, 2025 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: cloudsql-sqlserver Issues related to the googleapis/langchain-google-cloud-sql-mssql-python API.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants