Skip to content

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Jul 17, 2024

Updates the requirements on langchain-community to permit the latest version.

Release notes

Sourced from langchain-community's releases.

langchain-community==0.2.7

Release langchain-community==0.2.7

Changes since langchain-community==0.2.6

community: release 0.2.7 (prev was langchain) (#23997) core[minor],community[patch],standard-tests[patch]: Move InMemoryImplementation to langchain-core (#23986) community[patch]: Add constraint for pdfminer.six to unbreak CI (#23988) core[minor],community[minor]: Upgrade all @​root_validator() to @​pre_init (#23841) community[minor]: Support PGVector in PebbloRetrievalQA (#23874) community[patch]: Fix source path mismatch in PebbloSafeLoader (#23857) core[minor]: Add Graph Store component (#23092) core[minor]: add upsert, streaming_upsert, aupsert, astreaming_upsert methods to the VectorStore abstraction (#23774) community[patch]: Redis.delete should be a regular method not a static method (#23873) docs: Arxiv docs update (#23871) community: add support for 'cloud' parameter in JiraAPIWrapper (#23057) community: add model_name param valid for GPT4AllEmbeddings (#23867) community: add SingleStoreDB semantic cache (#23218) feat(community): add bind_tools function for ChatLiteLLM (#23823) huggingface: Fix huggingface tei support (#22653) community: fix typo in unit tests for test_zenguard.py (#23819) infra: update mypy 1.10, ruff 0.5 (#23721) community[deepinfra]: fix tool call parsing. (#23162) feat: Implement ChatBaichuan asynchronous interface (#23589) community: make bing web search as the only option (#23523) community[patch]: Fix MiniMaxChat validate_environment error (#23770) community[patch]: Update @​root_validators to use explicit pre=True or pre=False (#23737) feat(community): add support for tool_calls response (#23765) community[patch]: update @​root_validator in utilities namespace (#23768) Milvus vectorstore: fix pass ids as argument after upsert (#23761) community[patch]: root validator set explicit pre=False or pre=True (#23764) docs: updated PPLX model (#23723) community[patch]: Fix requests alias for load_tools (#23734) community[patch]: Update root_validators to use explicit pre=True or pre=False (#23736) community[patch]: Update root_validators to use pre=True or pre=False (#23731) community[patch]: Invoke callback prior to yielding token (#23638) community: Fix LanceDB similarity search bug (#23591) Jira: Allow Jira access using only the token (#23708) community: Register pandas df in duckdb when creating vector_store (#23690) openai, anthropic, ...: with_structured_output to pass in explicit tool choice (#23645) docs: standardize azure openai page (#23642) core: add RemoveMessage (#23636) community: fix extended tests (#23640) docs[patch]: Update diagrams (#23613) community:perplexity[patch]: standardize init args (#21794) community[patch]: set tool name for tongyi&qianfan llm (#22889) community: docstrings toolkits (#23616) community: fix lint (#23611) community[patch]: Test InMemoryVectorStore with RWAPI test suite (#23603) community: Standardise tool import for arxiv & semantic scholar (#23578) fix(community): allow support for disabling max_tokens args (#21534)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Updates the requirements on [langchain-community](https://github.com/langchain-ai/langchain) to permit the latest version.
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@v0.0.1rc0...langchain-community==0.2.7)

---
updated-dependencies:
- dependency-name: langchain-community
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jul 17, 2024
Copy link

dryrunsecurity bot commented Jul 17, 2024

DryRun Security Summary

The provided code changes update the version constraints for the langchain_community dependency in the setup.py and requirements.txt files, which should be reviewed to ensure that the updated versions do not introduce any known security vulnerabilities or compatibility issues with other dependencies.

Expand for full summary

Summary:

The provided code changes are related to updating the version constraints for the langchain_community dependency in the setup.py and requirements.txt files. From an application security perspective, these changes are worth reviewing to ensure that the updated version constraints do not introduce any known security vulnerabilities or compatibility issues with other dependencies.

The langchain_community library is a community-driven extension to the langchain library, which is a framework for building applications with large language models (LLMs). It's crucial to keep the dependencies up-to-date and secure, as they may be handling sensitive data or interacting with external services. Additionally, it's a good practice to monitor the release notes and security advisories for the langchain_community library, as well as the other dependencies used in the project, to stay informed about any potential security issues that may arise.

Files Changed:

  1. setup.py: The changes update the version constraint for the langchain_community dependency from <0.0.20 to <0.2.8 in both the 'ai' and 'streaming' extra requirements. This version bump should be reviewed to ensure that the new version does not introduce any security vulnerabilities or breaking changes that could impact the application.

  2. requirements.txt: The changes update the langchain_community dependency from version <0.0.20 to <0.2.8. This is a version bump for the langchain_community library, which should be reviewed to ensure that the new version does not introduce any security vulnerabilities or breaking changes. Additionally, the requirements.txt file contains a wide range of dependencies, and it's important to review the versions of all dependencies to ensure they are up-to-date and do not contain known security vulnerabilities.

Code Analysis

We ran 9 analyzers against 2 files and 1 analyzer had findings. 8 analyzers had no findings.

Analyzer Findings
Sensitive Files Analyzer 1 finding

Riskiness

🟢 Risk threshold not exceeded.

View PR in the DryRun Dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants