Skip to content

chore(deps): update dependency langchain-community to v0.2.5 [security]#57

Merged
averikitsch merged 2 commits intogoogleapis:mainfrom
renovate-bot:renovate/pypi-langchain-community-vulnerability
Jun 25, 2024
Merged

chore(deps): update dependency langchain-community to v0.2.5 [security]#57
averikitsch merged 2 commits intogoogleapis:mainfrom
renovate-bot:renovate/pypi-langchain-community-vulnerability

Conversation

@renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Jun 14, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
langchain-community ==0.2.1 -> ==0.2.5 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-2965

Denial of service in SitemapLoader Document Loader in the langchain-community package, affecting versions below 0.2.5. The parse_sitemap method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on this functionality.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate-bot renovate-bot requested review from a team June 14, 2024 23:28
@dpebot
Copy link

dpebot commented Jun 14, 2024

/gcbrun

@product-auto-label product-auto-label bot added the api: bigtable Issues related to the googleapis/langchain-google-bigtable-python API. label Jun 14, 2024
@ron-gal ron-gal assigned averikitsch and unassigned ron-gal Jun 17, 2024
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 294fb34 to ad62a7f Compare June 25, 2024 16:12
@dpebot
Copy link

dpebot commented Jun 25, 2024

/gcbrun

@dpebot
Copy link

dpebot commented Jun 25, 2024

/gcbrun

@averikitsch averikitsch merged commit a8849ab into googleapis:main Jun 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: bigtable Issues related to the googleapis/langchain-google-bigtable-python API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants