Commit 0437589
fix(deps): resolve all Dependabot security vulnerabilities
- Upgrade langchain ecosystem to 1.x (langchain>=1.2.10, langgraph>=1.1.1)
- Add explicit secure versions for transitive deps (pillow>=12.1.1,
cryptography>=46.0.5, filelock>=3.20.3, PyJWT>=2.12.0, orjson>=3.11.6)
- Update aiohttp>=3.13.3 and nltk>=3.9.3
- Update langchain-core>=1.2.11 in test dependencies
- Upgrade Docusaurus to 3.9.2 with npm overrides for svgo, serialize-javascript,
minimatch, ajv, qs, and webpack to fix JS vulnerabilities
- Update streamlit requirements to use intugle>=1.3.0
Resolves 20+ open Dependabot security alerts including high severity issues
in PyJWT, orjson, tornado, pillow, cryptography, protobuf, and npm packages.1 parent afae16e commit 0437589
4 files changed
Lines changed: 1109 additions & 1222 deletions
File tree
- docsite
- src/intugle/streamlit_app
0 commit comments