Skip to content

chore(deps): update dependency langchain-community to v0.2.19 [security] #117

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
langchain-community (changelog) ==0.2.12 -> ==0.2.19 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-8309

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners May 28, 2025 09:12
@dpebot
Copy link
Collaborator

dpebot commented May 28, 2025

/gcbrun

@product-auto-label product-auto-label bot added the api: redis Issues related to the googleapis/langchain-google-memorystore-redis-python API. label May 28, 2025
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 4f326ff to ad142af Compare May 28, 2025 23:04
@dpebot
Copy link
Collaborator

dpebot commented May 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ad142af to 926dcc4 Compare May 29, 2025 05:15
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 926dcc4 to 2445254 Compare May 29, 2025 13:23
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2445254 to 4e1e101 Compare May 29, 2025 23:30
@dpebot
Copy link
Collaborator

dpebot commented May 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 4e1e101 to 7281f40 Compare May 30, 2025 06:08
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 7281f40 to 1656901 Compare May 30, 2025 18:37
@dpebot
Copy link
Collaborator

dpebot commented May 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1656901 to 9f56426 Compare May 31, 2025 01:40
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 9f56426 to 638da1e Compare May 31, 2025 11:23
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 638da1e to 1d36c35 Compare May 31, 2025 18:20
@dpebot
Copy link
Collaborator

dpebot commented May 31, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1d36c35 to 60cef87 Compare June 1, 2025 01:37
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 60cef87 to 42f071b Compare June 1, 2025 09:47
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 42f071b to b08b378 Compare June 1, 2025 16:33
@dpebot
Copy link
Collaborator

dpebot commented Jun 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from b08b378 to 2803e56 Compare June 2, 2025 00:31
@dpebot
Copy link
Collaborator

dpebot commented Jun 27, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a362d70 to 44ad107 Compare June 27, 2025 22:23
@dpebot
Copy link
Collaborator

dpebot commented Jun 27, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 44ad107 to 270ba1b Compare June 28, 2025 05:25
@dpebot
Copy link
Collaborator

dpebot commented Jun 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 270ba1b to 6fe868e Compare June 28, 2025 14:48
@dpebot
Copy link
Collaborator

dpebot commented Jun 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 6fe868e to e8f1bbc Compare June 28, 2025 21:27
@dpebot
Copy link
Collaborator

dpebot commented Jun 28, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from e8f1bbc to e178a22 Compare June 29, 2025 06:25
@dpebot
Copy link
Collaborator

dpebot commented Jun 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from e178a22 to 0e74032 Compare June 29, 2025 12:59
@dpebot
Copy link
Collaborator

dpebot commented Jun 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 0e74032 to 8a90ccf Compare June 29, 2025 21:38
@dpebot
Copy link
Collaborator

dpebot commented Jun 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 8a90ccf to 3283aaa Compare June 30, 2025 06:08
@dpebot
Copy link
Collaborator

dpebot commented Jun 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 3283aaa to c1349c1 Compare June 30, 2025 19:02
@dpebot
Copy link
Collaborator

dpebot commented Jun 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from c1349c1 to 311283e Compare July 1, 2025 03:56
@dpebot
Copy link
Collaborator

dpebot commented Jul 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 311283e to a9b115e Compare July 1, 2025 10:52
@dpebot
Copy link
Collaborator

dpebot commented Jul 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a9b115e to ec55cf3 Compare July 2, 2025 00:24
@dpebot
Copy link
Collaborator

dpebot commented Jul 2, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ec55cf3 to e0a848f Compare July 2, 2025 10:44
@dpebot
Copy link
Collaborator

dpebot commented Jul 2, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from e0a848f to 13d04a9 Compare July 2, 2025 23:56
@dpebot
Copy link
Collaborator

dpebot commented Jul 2, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: redis Issues related to the googleapis/langchain-google-memorystore-redis-python API.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants