Skip to content

chore(deps): update dependency langchain-community to v0.3.27 [security] - autoclosed#97

Closed
renovate-bot wants to merge 1 commit intogoogleapis:mainfrom
renovate-bot:renovate/pypi-langchain-community-vulnerability
Closed

chore(deps): update dependency langchain-community to v0.3.27 [security] - autoclosed#97
renovate-bot wants to merge 1 commit intogoogleapis:mainfrom
renovate-bot:renovate/pypi-langchain-community-vulnerability

Conversation

@renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Confidence
langchain-community (changelog) ==0.3.3 -> ==0.3.27 age confidence

GitHub Vulnerability Alerts

CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team September 5, 2025 15:50
@product-auto-label product-auto-label bot added the api: datastore Issues related to the googleapis/langchain-google-datastore-python API. label Sep 5, 2025
@dpebot
Copy link

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 9dc316c to f9e7752 Compare September 5, 2025 21:49
@dpebot
Copy link

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f9e7752 to 2950acc Compare September 6, 2025 05:12
@dpebot
Copy link

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2950acc to a85b3d9 Compare September 6, 2025 12:30
@dpebot
Copy link

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a85b3d9 to c0e8999 Compare September 6, 2025 21:29
@dpebot
Copy link

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from c0e8999 to 1c6dc1d Compare September 7, 2025 05:31
@dpebot
Copy link

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1c6dc1d to 5b722c0 Compare September 7, 2025 13:44
@dpebot
Copy link

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5b722c0 to 5338dc7 Compare September 7, 2025 20:36
@dpebot
Copy link

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5338dc7 to edd22eb Compare September 8, 2025 05:44
@dpebot
Copy link

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from edd22eb to 053a0e5 Compare September 8, 2025 13:11
@dpebot
Copy link

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 053a0e5 to f6d479a Compare September 8, 2025 21:57
@dpebot
Copy link

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from f6d479a to 4536fc9 Compare September 9, 2025 04:42
@dpebot
Copy link

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 4536fc9 to a223ff7 Compare September 9, 2025 14:52
@dpebot
Copy link

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a223ff7 to 4e188c7 Compare September 9, 2025 21:11
@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 7239a62 to 5070e99 Compare September 29, 2025 20:32
@dpebot
Copy link

dpebot commented Sep 29, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5070e99 to 1d9c642 Compare September 30, 2025 04:45
@dpebot
Copy link

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 1d9c642 to 5a0fe5e Compare September 30, 2025 16:10
@dpebot
Copy link

dpebot commented Sep 30, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5a0fe5e to d0e94d5 Compare September 30, 2025 23:35
@dpebot
Copy link

dpebot commented Sep 30, 2025

/gcbrun

20 similar comments
@dpebot
Copy link

dpebot commented Oct 1, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 2, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 2, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 3, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 4, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 5, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 6, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 7, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 7, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 8, 2025

/gcbrun

@dpebot
Copy link

dpebot commented Oct 9, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: datastore Issues related to the googleapis/langchain-google-datastore-python API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants