Skip to content

Commit 0437589

Browse files
raphael-intuglesujayintugle
authored andcommitted
fix(deps): resolve all Dependabot security vulnerabilities
- Upgrade langchain ecosystem to 1.x (langchain>=1.2.10, langgraph>=1.1.1) - Add explicit secure versions for transitive deps (pillow>=12.1.1, cryptography>=46.0.5, filelock>=3.20.3, PyJWT>=2.12.0, orjson>=3.11.6) - Update aiohttp>=3.13.3 and nltk>=3.9.3 - Update langchain-core>=1.2.11 in test dependencies - Upgrade Docusaurus to 3.9.2 with npm overrides for svgo, serialize-javascript, minimatch, ajv, qs, and webpack to fix JS vulnerabilities - Update streamlit requirements to use intugle>=1.3.0 Resolves 20+ open Dependabot security alerts including high severity issues in PyJWT, orjson, tornado, pillow, cryptography, protobuf, and npm packages.
1 parent afae16e commit 0437589

4 files changed

Lines changed: 1109 additions & 1222 deletions

File tree

0 commit comments

Comments
 (0)