Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 18, 2024

Bumps the langchain group with 5 updates in the / directory:

Package From To
@langchain/community 0.3.9 0.3.15
@langchain/core 0.3.15 0.3.18
@langchain/google-genai 0.1.0 0.1.4
@langchain/openai 0.3.11 0.3.13
langchain 0.3.4 0.3.6

Updates @langchain/community from 0.3.9 to 0.3.15

Release notes

Sourced from @​langchain/community's releases.

0.2.0@next

What's Changed

... (truncated)

Commits

Updates @langchain/core from 0.3.15 to 0.3.18

Release notes

Sourced from @​langchain/core's releases.

0.2.0@next

What's Changed

... (truncated)

Commits

Updates @langchain/google-genai from 0.1.0 to 0.1.4

Release notes

Sourced from @​langchain/google-genai's releases.

Release 0.1.4

What's Changed

New Contributors

Full Changelog: langchain-ai/langchainjs@0.1.3...0.1.4

Release 0.1.3

What's Changed

... (truncated)

Commits
  • 9072eb6 Merge pull request #4071 from langchain-ai/release
  • a51a4a7 Release 0.0.18
  • c311576 community[patch]: Change recommended entrypoint, bump versions (#4069)
  • 0e3c944 Merge pull request #4070 from langchain-ai/release
  • 6147b6d Release 0.1.16
  • 7039315 Adds tool use use case docs (#4068)
  • 82a2f49 community[minor]: feat: turbopuffer vector store (#3780)
  • 0eb0865 langchain[minor]: remote runnable stream log, additional serialization update...
  • 788e45f Update runnable config ensure and merge to match py (#4067)
  • 0987db6 Add fake embeddings classes to core (#4066)
  • Additional commits viewable in compare view

Updates @langchain/openai from 0.3.11 to 0.3.13

Release notes

Sourced from @​langchain/openai's releases.

0.2.0@next

What's Changed

... (truncated)

Commits

Updates langchain from 0.3.4 to 0.3.6

Release notes

Sourced from langchain's releases.

Release 0.3.6

What's Changed

... (truncated)

Commits
  • defea2b Release 0.3.6
  • cf672b5 fix(langchain): Fix serialization for initChatModel (#7222)
  • d420b71 chore(langchain): add throw err for JsonOutputFunctionsParser.parse (#7204)
  • 986ab14 fix(langchain): Fix structured parser with triple backticks, adds tests (#7199)
  • 7124f18 chore(community): Release 0.3.15 (#7221)
  • 633dca9 feat(community): add filters to LibSQLVectorStore (#7209)
  • fb9eaf6 chore(azure-cosmosdb): Release 0.2.2 (#7219)
  • eb26657 feat(cosmosdbnosql): Add Chat History Integration (#7057)
  • cbc7069 feat(community): replace vectordb package with new @lancedb/lancedb (#7202)
  • 074d1e1 feat(community): allow metadata generics to flow through LibSQLVectorStore (#...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the...

Description has been truncated

…5 updates

Bumps the langchain group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@langchain/community](https://github.com/langchain-ai/langchainjs) | `0.3.9` | `0.3.15` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) | `0.3.15` | `0.3.18` |
| [@langchain/google-genai](https://github.com/langchain-ai/langchainjs) | `0.1.0` | `0.1.4` |
| [@langchain/openai](https://github.com/langchain-ai/langchainjs) | `0.3.11` | `0.3.13` |
| [langchain](https://github.com/langchain-ai/langchainjs) | `0.3.4` | `0.3.6` |



Updates `@langchain/community` from 0.3.9 to 0.3.15
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Changelog](https://github.com/langchain-ai/langchainjs/blob/main/release_workspace.js)
- [Commits](https://github.com/langchain-ai/langchainjs/commits)

Updates `@langchain/core` from 0.3.15 to 0.3.18
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Changelog](https://github.com/langchain-ai/langchainjs/blob/main/release_workspace.js)
- [Commits](https://github.com/langchain-ai/langchainjs/commits)

Updates `@langchain/google-genai` from 0.1.0 to 0.1.4
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Changelog](https://github.com/langchain-ai/langchainjs/blob/main/release_workspace.js)
- [Commits](langchain-ai/langchainjs@0.1.0...0.1.4)

Updates `@langchain/openai` from 0.3.11 to 0.3.13
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Changelog](https://github.com/langchain-ai/langchainjs/blob/main/release_workspace.js)
- [Commits](https://github.com/langchain-ai/langchainjs/commits)

Updates `langchain` from 0.3.4 to 0.3.6
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Changelog](https://github.com/langchain-ai/langchainjs/blob/main/release_workspace.js)
- [Commits](langchain-ai/langchainjs@0.3.4...0.3.6)

---
updated-dependencies:
- dependency-name: "@langchain/community"
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: langchain
- dependency-name: "@langchain/core"
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: langchain
- dependency-name: "@langchain/google-genai"
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: langchain
- dependency-name: "@langchain/openai"
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: langchain
- dependency-name: langchain
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: langchain
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Nov 18, 2024
@github-actions
Copy link

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@google/generative-ai 0.21.0 UnknownUnknown
npm/@langchain/community 0.3.15 UnknownUnknown
npm/@langchain/core 0.3.18 UnknownUnknown
npm/@langchain/google-genai 0.1.4 UnknownUnknown
npm/@langchain/openai 0.3.13 UnknownUnknown
npm/langchain 0.3.6 UnknownUnknown
npm/openai 4.72.0 UnknownUnknown
npm/@google/generative-ai 0.21.0 UnknownUnknown
npm/@langchain/community 0.3.15 UnknownUnknown
npm/@langchain/core 0.3.18 UnknownUnknown
npm/@langchain/google-genai 0.1.4 UnknownUnknown
npm/@langchain/openai 0.3.13 UnknownUnknown
npm/@types/node 18.19.64 🟢 6.9
Details
CheckScoreReason
Code-Review🟢 8Found 25/30 approved changesets -- score normalized to 8
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Vulnerabilities🟢 100 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/@types/node 22.9.0 🟢 6.9
Details
CheckScoreReason
Code-Review🟢 8Found 25/30 approved changesets -- score normalized to 8
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Vulnerabilities🟢 100 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/@types/node-fetch 2.6.12 🟢 6.9
Details
CheckScoreReason
Code-Review🟢 8Found 25/30 approved changesets -- score normalized to 8
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Vulnerabilities🟢 100 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/langchain 0.3.6 UnknownUnknown
npm/langsmith 0.2.5 🟢 6.1
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
Security-Policy⚠️ 0security policy file not detected
Packaging🟢 10packaging workflow detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities🟢 100 existing vulnerabilities detected
npm/openai 4.72.0 UnknownUnknown
npm/psl 1.10.0 🟢 4.8
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/29 approved changesets -- score normalized to 0
Maintained🟢 1023 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Security-Policy⚠️ 0security policy file not detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities🟢 82 existing vulnerabilities detected

Scanned Files

  • package-lock.json
  • pnpm-lock.yaml

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Nov 19, 2024

Superseded by #182.

@dependabot dependabot bot closed this Nov 19, 2024
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/langchain-8dc07c31b1 branch November 19, 2024 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants