chore(deps): update dependency langchain-community to v0.2.19 [security]#117
Open
renovate-bot wants to merge 1 commit intogoogleapis:mainfrom
Open
Conversation
Collaborator
|
/gcbrun |
4f326ff to
ad142af
Compare
Collaborator
|
/gcbrun |
ad142af to
926dcc4
Compare
Collaborator
|
/gcbrun |
926dcc4 to
2445254
Compare
Collaborator
|
/gcbrun |
2445254 to
4e1e101
Compare
Collaborator
|
/gcbrun |
4e1e101 to
7281f40
Compare
Collaborator
|
/gcbrun |
7281f40 to
1656901
Compare
Collaborator
|
/gcbrun |
1656901 to
9f56426
Compare
Collaborator
|
/gcbrun |
9f56426 to
638da1e
Compare
Collaborator
|
/gcbrun |
638da1e to
1d36c35
Compare
Collaborator
|
/gcbrun |
1d36c35 to
60cef87
Compare
Collaborator
|
/gcbrun |
60cef87 to
42f071b
Compare
Collaborator
|
/gcbrun |
42f071b to
b08b378
Compare
Collaborator
|
/gcbrun |
b08b378 to
2803e56
Compare
Collaborator
|
/gcbrun |
12002a2 to
70ac379
Compare
Collaborator
|
/gcbrun |
70ac379 to
7eb9b0e
Compare
Collaborator
|
/gcbrun |
7eb9b0e to
b6ed7be
Compare
Collaborator
|
/gcbrun |
b6ed7be to
dbcb183
Compare
Collaborator
|
/gcbrun |
dbcb183 to
49de1a2
Compare
Collaborator
|
/gcbrun |
49de1a2 to
6e78c79
Compare
Collaborator
|
/gcbrun |
6e78c79 to
339cddc
Compare
Collaborator
|
/gcbrun |
339cddc to
b394d7b
Compare
Collaborator
|
/gcbrun |
b394d7b to
c151fbe
Compare
Collaborator
|
/gcbrun |
c151fbe to
7c20842
Compare
Collaborator
|
/gcbrun |
7c20842 to
fdaae79
Compare
Collaborator
|
/gcbrun |
fdaae79 to
a17b027
Compare
Collaborator
|
/gcbrun |
a17b027 to
7d0a614
Compare
Collaborator
|
/gcbrun |
7d0a614 to
91aad41
Compare
Collaborator
|
/gcbrun |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.2.12->==0.2.19GitHub Vulnerability Alerts
CVE-2024-8309
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.