Skip to content

[DO NOT MERGE] Test: dependency review workflow#33

Open
mlakshmi-2-eightfold wants to merge 5 commits intomasterfrom
mlakshmi/test_dependency_review
Open

[DO NOT MERGE] Test: dependency review workflow#33
mlakshmi-2-eightfold wants to merge 5 commits intomasterfrom
mlakshmi/test_dependency_review

Conversation

@mlakshmi-2-eightfold
Copy link
Copy Markdown
Contributor

Testing if dependency-review-action catches langchain-core 0.1.5

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 14, 2026

Dependency Review

The following issues were found:
  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA b0bd94d.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

Vulnerabilities

requirements.txt

NameVersionVulnerabilitySeverityPatched Version
langchain-core0.1.5LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIscritical0.3.81
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templateshigh0.3.80
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functionshigh1.2.22
Only included vulnerabilities with severity high or higher.

Scanned Files

  • requirements.txt

@mlakshmi-2-eightfold mlakshmi-2-eightfold changed the title Test: dependency review workflow [DO NOT MERGE] Test: dependency review workflow Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant