Skip to content

Conversation

@renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Confidence
langchain-community (changelog) ==0.3.3 -> ==0.3.27 age confidence

GitHub Vulnerability Alerts

CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners September 5, 2025 17:15
@product-auto-label product-auto-label bot added the api: cloudsql-mysql Issues related to the googleapis/langchain-google-cloud-sql-mysql-python API. label Sep 5, 2025
@dpebot
Copy link
Collaborator

dpebot commented Sep 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 8d4831c to 108a2e1 Compare September 6, 2025 00:56
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 108a2e1 to ab3dbe3 Compare September 6, 2025 09:28
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ab3dbe3 to 3bad708 Compare September 6, 2025 17:09
@dpebot
Copy link
Collaborator

dpebot commented Sep 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 3bad708 to 13bb466 Compare September 7, 2025 00:31
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 13bb466 to 8cc8d71 Compare September 7, 2025 09:08
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 8cc8d71 to 23b9fa8 Compare September 7, 2025 18:02
@dpebot
Copy link
Collaborator

dpebot commented Sep 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 23b9fa8 to 411456f Compare September 8, 2025 00:30
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 411456f to 22495b2 Compare September 8, 2025 10:58
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 22495b2 to bf62675 Compare September 8, 2025 17:47
@dpebot
Copy link
Collaborator

dpebot commented Sep 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from bf62675 to ca14cb7 Compare September 9, 2025 01:30
@dpebot
Copy link
Collaborator

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from ca14cb7 to a0936e3 Compare September 9, 2025 10:25
@dpebot
Copy link
Collaborator

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a0936e3 to a4984b8 Compare September 9, 2025 16:36
@dpebot
Copy link
Collaborator

dpebot commented Sep 9, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from a4984b8 to fcaee97 Compare September 10, 2025 02:49
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from fc648ec to 95025b0 Compare October 4, 2025 09:37
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 95025b0 to aa5e68e Compare October 4, 2025 16:44
@dpebot
Copy link
Collaborator

dpebot commented Oct 4, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from aa5e68e to e6bdd3b Compare October 5, 2025 01:37
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from e6bdd3b to 8398afd Compare October 5, 2025 08:35
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 8398afd to 25ef5f4 Compare October 5, 2025 18:30
@dpebot
Copy link
Collaborator

dpebot commented Oct 5, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 25ef5f4 to d38c98c Compare October 6, 2025 00:29
@dpebot
Copy link
Collaborator

dpebot commented Oct 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from d38c98c to cfeb5c4 Compare October 6, 2025 10:55
@dpebot
Copy link
Collaborator

dpebot commented Oct 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from cfeb5c4 to 5f8829d Compare October 6, 2025 20:30
@dpebot
Copy link
Collaborator

dpebot commented Oct 6, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 5f8829d to 482bfa1 Compare October 7, 2025 04:45
@dpebot
Copy link
Collaborator

dpebot commented Oct 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 482bfa1 to d915f9c Compare October 7, 2025 15:29
@dpebot
Copy link
Collaborator

dpebot commented Oct 7, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from d915f9c to 30e3cec Compare October 8, 2025 08:07
@dpebot
Copy link
Collaborator

dpebot commented Oct 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 30e3cec to 2245b43 Compare October 8, 2025 13:36
@dpebot
Copy link
Collaborator

dpebot commented Oct 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 2245b43 to 32b3b17 Compare October 8, 2025 22:46
@dpebot
Copy link
Collaborator

dpebot commented Oct 8, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-langchain-community-vulnerability branch from 32b3b17 to fe4773a Compare October 9, 2025 05:42
@dpebot
Copy link
Collaborator

dpebot commented Oct 9, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: cloudsql-mysql Issues related to the googleapis/langchain-google-cloud-sql-mysql-python API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants