askrella / whatsapp-chatgpt

ChatGPT + DALL-E + WhatsApp = AI Assistant :rocket: :robot:
3.42k stars 825 forks source link

[Snyk] Upgrade langchain from 0.0.156 to 0.0.162 #312

Closed steve-hb closed 3 months ago

steve-hb commented 11 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade langchain from 0.0.156 to 0.0.162.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **6 versions** ahead of your current version. - The recommended version was released **21 days ago**, on 2023-10-07. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-ZOD-5925617](https://snyk.io/vuln/SNYK-JS-ZOD-5925617) | **482/1000**
**Why?** Proof of Concept exploit, CVSS 7.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: langchain
  • 0.0.162 - 2023-10-07
  • 0.0.161 - 2023-10-06
  • 0.0.160 - 2023-10-04
  • 0.0.159 - 2023-10-04
  • 0.0.158 - 2023-10-03
  • 0.0.157 - 2023-10-02
  • 0.0.156 - 2023-09-29
from langchain GitHub release notes
Commit messages
Package name: langchain
  • c89ed3c Add runnable lambda from method (#2827)
  • b899748 Single table designs in dynamo require maximum flexibility. Adding key attribute to DynamoDB Chat History args. (#2804)
  • 4ede932 Allow overriding runName in withConfig (#2824)
  • 79b06ed Langsmith in readme update (#2823)
  • 8b0e1bd Fix ChatPrompts with LLMs (#2822)
  • 3f5f504 Fix typo (#2808)
  • c7eeaa6 Merge pull request #2810 from langchain-ai/release
  • dd5bd32 Release 0.0.161
  • 6f6dc62 Rerun build (#2809)
  • 466f317 fix: Add back Chaindesk retriever (#2767)
  • 859e390 light mode node-only (#2805)
  • b89ad8f Update expression language docs, add RunnableMap.from method (#2806)
  • 9f2d296 Adds EmbeddingsFilter, DocumentCompressorPipeline, and TavilyRetriever (#2803)
  • 37f8997 Implement Bedrock embeddings (#2796)
  • 7e17ee3 Support to pull prompt templates and model configuration from MakerSuiteHub (#2733)
  • cbe1ef1 Fix: Text splitter invalid loc.lines in case of chunk overlap (#2779)
  • b426a4d Merge pull request #2795 from langchain-ai/release
  • 8b4b095 Release 0.0.160
  • d148277 Fix: Corrected typos (#2793)
  • cdbc942 Upgrade pinecone-ts-client to v1.1.0 (#2648)
  • 005707e Merge pull request #2790 from langchain-ai/release
  • f88e08f Release 0.0.159
  • a652e43 Wfh/bump zod version (#2789)
  • ffcabb1 Use invoke method for non-streaming calls (#2787)
Compare

**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/steven.hornbogen/project/c5e6102f-627b-446c-a695-2c5241d1532f?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/steven.hornbogen/project/c5e6102f-627b-446c-a695-2c5241d1532f/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/steven.hornbogen/project/c5e6102f-627b-446c-a695-2c5241d1532f/settings/integration?pkg=langchain&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)