[Snyk] Upgrade @langchain/textsplitters from 0.0.3 to 0.1.0#855
[Snyk] Upgrade @langchain/textsplitters from 0.0.3 to 0.1.0#855graymalkin77 wants to merge 1 commit intomasterfrom
Conversation
Snyk has created this PR to upgrade @langchain/textsplitters from 0.0.3 to 0.1.0. See this package in npm: @langchain/textsplitters See this project in Snyk: https://app.snyk.io/org/cognigy-gmbh/project/bb40500e-e358-4d3a-ada4-1ea4c64dd27c?utm_source=github&utm_medium=referral&page=upgrade-pr
There was a problem hiding this comment.
Pull request overview
This PR upgrades the @langchain/textsplitters dependency from version 0.0.3 to 0.1.0 to address a critical deserialization vulnerability (SNYK-JS-LANGCHAINCORE-14563113) with a severity score of 853.
- Updates
@langchain/textsplittersdependency to address critical security vulnerability
Files not reviewed (1)
- extensions/confluence/package-lock.json: Language not supported
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
Recent versions of LangChain (v0.1.0 and newer) have moved Source: LangChain Releases
|
Snyk has created this PR to upgrade @langchain/textsplitters from 0.0.3 to 0.1.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 2 versions ahead of your current version.
The recommended version was released a year ago.
Issues fixed by the recommended upgrade:
SNYK-JS-LANGCHAINCORE-14563113
Release notes
Package name: @langchain/textsplitters
-
0.1.0 - 2024-09-13
-
0.1.0-rc.0 - 2024-09-07
-
0.0.3 - 2024-06-06
from @langchain/textsplitters GitHub release notesImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: