Skip to content

chore(deps): bump langchain-core to 0.3.81 — patches CRIT#2

Closed
t4sh wants to merge 2 commits into
mainfrom
chore/deps-langchain-core-0.3.81
Closed

chore(deps): bump langchain-core to 0.3.81 — patches CRIT#2
t4sh wants to merge 2 commits into
mainfrom
chore/deps-langchain-core-0.3.81

Conversation

@t4sh
Copy link
Copy Markdown
Contributor

@t4sh t4sh commented Apr 18, 2026

Patches CRIT GHSA-c67j-w6g6-q2cm — LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs.

Minimum safe pin on the 0.3.x series. The 1.2.x major-version migration (which would clear the remaining langchain-family alerts) is deferred as a separate project.

Part of the github-hygiene sweep (post security + license hardening).

GHSA-c67j-w6g6-q2cm — LangChain serialization injection vulnerability
enables secret extraction in dumps/loads APIs. Fix version 0.3.81 is the
minimum safe pin on the 0.3.x series; the 1.2.x major-version migration
is deferred as a separate project.

Part of the github-hygiene sweep, following security + license hardening.
@t4sh t4sh force-pushed the chore/deps-langchain-core-0.3.81 branch from 21aa64d to 9793a84 Compare April 18, 2026 15:03
Python 3.8 reached EOL on 2024-10-07. The 3.8 job has been failing on
main pre-existing to this PR due to older setuptools being unable to
parse the PEP 639-style license field in pyproject.toml (sees both the
bare `license = "MIT"` string and the `License :: OSI Approved :: MIT`
classifier as conflicting definitions).

Matrix now runs 3.9 through 3.12.
@t4sh
Copy link
Copy Markdown
Contributor Author

t4sh commented Apr 18, 2026

Closing without merge — rolling back; proto to remain unchanged for now. The CRITICAL langchain-core Dependabot alert (GHSA-c67j-w6g6-q2cm) stays open.

@t4sh t4sh closed this Apr 18, 2026
@t4sh t4sh deleted the chore/deps-langchain-core-0.3.81 branch April 18, 2026 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant