Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency @langchain/community to ^0.3.3 [security] #6

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Oct 30, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@langchain/community (source) ^0.2.0 -> ^0.3.3 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-7042

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.


Release Notes

langchain-ai/langchainjs (@​langchain/community)

v0.3.3

Compare Source

What's Changed

New Contributors

Full Changelog: langchain-ai/langchainjs@0.3.2...0.3.3

v0.3.2

Compare Source

What's Changed

Full Changelog: langchain-ai/langchainjs@0.3.1...0.3.2

v0.3.1

Compare Source

What's Changed

Full Changelog: langchain-ai/langchainjs@0.3.0...0.3.1

v0.3.0

Compare Source

What's Changed

Full Changelog: langchain-ai/langchainjs@0.2.19...0.3.0

v0.2.33

Compare Source

v0.2.32

Compare Source

v0.2.31

Compare Source

v0.2.30

Compare Source

v0.2.29

Compare Source

v0.2.28

Compare Source

v0.2.27

Compare Source

v0.2.26

Compare Source

v0.2.25

Compare Source

v0.2.24

Compare Source

v0.2.23

Compare Source

v0.2.22

Compare Source

v0.2.21

Compare Source

v0.2.20

Compare Source

v0.2.19

Compare Source

What's Changed

New Contributors


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from ec7cc79 to e47d889 Compare October 31, 2024 23:43
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Oct 31, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from e47d889 to abb8f1c Compare November 18, 2024 08:30
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Nov 18, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from abb8f1c to 7bce946 Compare November 19, 2024 14:58
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Nov 19, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from 7bce946 to 2c33599 Compare December 2, 2024 23:53
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Dec 2, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from 2c33599 to a4c15e6 Compare December 5, 2024 02:54
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Dec 5, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from a4c15e6 to af6e6ca Compare December 19, 2024 05:57
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Dec 19, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from af6e6ca to c6d4705 Compare December 21, 2024 20:32
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Dec 21, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from c6d4705 to 875de6c Compare December 23, 2024 02:56
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Dec 23, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from 875de6c to b8b5deb Compare December 25, 2024 02:42
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Dec 25, 2024
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from b8b5deb to e718cd8 Compare January 16, 2025 07:06
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Jan 16, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from e718cd8 to cd40467 Compare January 17, 2025 19:37
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Jan 17, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from cd40467 to aa0c946 Compare January 24, 2025 08:00
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Jan 24, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from aa0c946 to 8f457fd Compare January 25, 2025 18:48
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Jan 25, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from 8f457fd to e5a9031 Compare February 1, 2025 02:49
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Feb 1, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from e5a9031 to 46772cb Compare February 5, 2025 16:20
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Feb 5, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from 46772cb to 94f3393 Compare February 9, 2025 19:46
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.3 [security] fix(deps): update dependency @langchain/community to ^0.3.0 [security] Feb 9, 2025
@renovate renovate bot force-pushed the renovate/npm-langchain-community-vulnerability branch from 94f3393 to 07e9f45 Compare February 13, 2025 04:07
@renovate renovate bot changed the title fix(deps): update dependency @langchain/community to ^0.3.0 [security] fix(deps): update dependency @langchain/community to ^0.3.3 [security] Feb 13, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants