-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency @langchain/community to ^0.3.3 [security] #26
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/npm-langchain-community-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #26 +/- ##
=======================================
Coverage 93.09% 93.09%
=======================================
Files 14 14
Lines 304 304
Branches 47 13 -34
=======================================
Hits 283 283
Misses 21 21 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
a03dbf0
to
0d9472d
Compare
0d9472d
to
046345e
Compare
046345e
to
37867cb
Compare
37867cb
to
ca6140d
Compare
ca6140d
to
b5202a6
Compare
b5202a6
to
de4c82e
Compare
de4c82e
to
b653213
Compare
b653213
to
003a3f2
Compare
003a3f2
to
ba675ff
Compare
ba675ff
to
d7137b9
Compare
d7137b9
to
3d0343b
Compare
3d0343b
to
b4b7611
Compare
b4b7611
to
55fa0e8
Compare
55fa0e8
to
88b3391
Compare
88b3391
to
7bcda1a
Compare
7bcda1a
to
2d02e4b
Compare
2d02e4b
to
d0e1015
Compare
d0e1015
to
abc4cc7
Compare
abc4cc7
to
f7e153a
Compare
f7e153a
to
ea2e60b
Compare
ea2e60b
to
04f9894
Compare
04f9894
to
e75f7f8
Compare
e75f7f8
to
3d5f1ee
Compare
3d5f1ee
to
eb5ca4e
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.2.23
->^0.3.3
GitHub Vulnerability Alerts
CVE-2024-7042
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.
Release Notes
langchain-ai/langchainjs (@langchain/community)
v0.3.3
Compare Source
What's Changed
@upstash/ratelimit
version by @CahidArda in https://github.com/langchain-ai/langchainjs/pull/6832Prisma.sql
tagged template by @hmShuvo314 in https://github.com/langchain-ai/langchainjs/pull/6889New Contributors
Full Changelog: langchain-ai/langchainjs@0.3.2...0.3.3
v0.3.2
Compare Source
What's Changed
Full Changelog: langchain-ai/langchainjs@0.3.1...0.3.2
v0.3.1
Compare Source
What's Changed
Full Changelog: langchain-ai/langchainjs@0.3.0...0.3.1
v0.3.0
Compare Source
What's Changed
Full Changelog: langchain-ai/langchainjs@0.2.19...0.3.0
v0.2.33
Compare Source
v0.2.32
Compare Source
v0.2.31
Compare Source
v0.2.30
Compare Source
v0.2.29
Compare Source
v0.2.28
Compare Source
v0.2.27
Compare Source
v0.2.26
Compare Source
v0.2.25
Compare Source
v0.2.24
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.