Skip to content

chore(deps): update dependency langchain-community to v0.3.27 [security] - autoclosed#123

Closed
renovate-bot wants to merge 1 commit into
googleapis:mainfrom
renovate-bot:renovate/pypi-langchain-community-vulnerability
Closed

chore(deps): update dependency langchain-community to v0.3.27 [security] - autoclosed#123
renovate-bot wants to merge 1 commit into
googleapis:mainfrom
renovate-bot:renovate/pypi-langchain-community-vulnerability

Conversation

@renovate-bot
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
langchain-community (changelog) ==0.3.3 -> ==0.3.27 age confidence

GitHub Vulnerability Alerts

CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team September 5, 2025 17:15
@product-auto-label product-auto-label Bot added the api: cloudsql-mysql Issues related to the googleapis/langchain-google-cloud-sql-mysql-python API. label Sep 5, 2025
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 8d4831c to 108a2e1 Compare September 6, 2025 00:56
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 108a2e1 to ab3dbe3 Compare September 6, 2025 09:28
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ab3dbe3 to 3bad708 Compare September 6, 2025 17:09
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 3bad708 to 13bb466 Compare September 7, 2025 00:31
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 13bb466 to 8cc8d71 Compare September 7, 2025 09:08
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 8cc8d71 to 23b9fa8 Compare September 7, 2025 18:02
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 23b9fa8 to 411456f Compare September 8, 2025 00:30
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 411456f to 22495b2 Compare September 8, 2025 10:58
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 22495b2 to bf62675 Compare September 8, 2025 17:47
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from bf62675 to ca14cb7 Compare September 9, 2025 01:30
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ca14cb7 to a0936e3 Compare September 9, 2025 10:25
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a0936e3 to a4984b8 Compare September 9, 2025 16:36
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a4984b8 to fcaee97 Compare September 10, 2025 02:49
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ffa409a to b1f5d4d Compare September 30, 2025 02:02
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from b1f5d4d to 9fb6d9f Compare September 30, 2025 09:37
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 9fb6d9f to 5dce5ee Compare September 30, 2025 20:45
@dpebot
Copy link
Copy Markdown

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5dce5ee to e52ee95 Compare October 1, 2025 21:03
@dpebot
Copy link
Copy Markdown

dpebot commented Oct 1, 2025

/gcbrun

19 similar comments
@dpebot
Copy link
Copy Markdown

dpebot commented Oct 2, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 2, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 7, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 7, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link
Copy Markdown

dpebot commented Oct 9, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: cloudsql-mysql Issues related to the googleapis/langchain-google-cloud-sql-mysql-python API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants