Skip to content

Conversation

renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Mar 21, 2025

This PR contains the following updates:

Package Change Age Confidence
langchain-core (changelog) ==0.2.31 -> ==0.2.43 age confidence

GitHub Vulnerability Alerts

CVE-2024-10940

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners March 21, 2025 16:53
@dpebot
Copy link
Collaborator

dpebot commented Mar 21, 2025

/gcbrun

@product-auto-label product-auto-label bot added the api: redis Issues related to the googleapis/langchain-google-memorystore-redis-python API. label Mar 21, 2025
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 8c5f2c2 to eb792ce Compare September 5, 2025 15:39
@dpebot
Copy link
Collaborator

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from eb792ce to 234c5e8 Compare September 5, 2025 21:43
@dpebot
Copy link
Collaborator

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 234c5e8 to 4bfd107 Compare September 6, 2025 04:37
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 4bfd107 to 911e4b9 Compare September 6, 2025 12:30
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 911e4b9 to 882769a Compare September 6, 2025 21:23
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 882769a to b4d96a2 Compare September 7, 2025 05:46
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from b4d96a2 to 231bdf0 Compare September 7, 2025 13:28
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 231bdf0 to e6cc2d7 Compare September 7, 2025 20:43
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from e6cc2d7 to 50210b6 Compare September 8, 2025 04:57
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 50210b6 to a7abc8c Compare September 8, 2025 13:55
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from a7abc8c to 6819b22 Compare September 8, 2025 21:26
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 6819b22 to eb36c0d Compare September 9, 2025 06:24
@dpebot
Copy link
Collaborator

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from eb36c0d to 490e17a Compare September 9, 2025 14:33
@dpebot
Copy link
Collaborator

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 99e3699 to c5f656a Compare September 30, 2025 23:32
@dpebot
Copy link
Collaborator

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from c5f656a to 1b00de2 Compare October 1, 2025 21:42
@dpebot
Copy link
Collaborator

dpebot commented Oct 1, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 1b00de2 to 2747229 Compare October 2, 2025 06:21
@dpebot
Copy link
Collaborator

dpebot commented Oct 2, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 2747229 to bad943b Compare October 2, 2025 14:13
@dpebot
Copy link
Collaborator

dpebot commented Oct 2, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from bad943b to 67ff33d Compare October 2, 2025 21:48
@dpebot
Copy link
Collaborator

dpebot commented Oct 2, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 67ff33d to b1c0853 Compare October 3, 2025 04:39
@dpebot
Copy link
Collaborator

dpebot commented Oct 3, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from b1c0853 to 396d5b2 Compare October 3, 2025 12:53
@dpebot
Copy link
Collaborator

dpebot commented Oct 3, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 396d5b2 to 20410ab Compare October 3, 2025 21:43
@dpebot
Copy link
Collaborator

dpebot commented Oct 3, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 20410ab to 964368e Compare October 4, 2025 05:41
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 964368e to 89304ba Compare October 4, 2025 13:58
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 89304ba to 6e4efb6 Compare October 4, 2025 21:55
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 6e4efb6 to 4ae7d51 Compare October 5, 2025 05:50
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 4ae7d51 to 9228079 Compare October 5, 2025 13:02
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-core-vulnerability branch from 9228079 to 3360ab9 Compare October 5, 2025 21:29
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: redis Issues related to the googleapis/langchain-google-memorystore-redis-python API.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants