Skip to content

Commit 34d9ae6

Browse files
committed
Bump aiohttp to CVE free version
1 parent 4ffeb00 commit 34d9ae6

File tree

3 files changed

+103
-97
lines changed

3 files changed

+103
-97
lines changed

pdm.lock

Lines changed: 43 additions & 40 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pyproject.toml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -91,6 +91,7 @@ description = "OpenShift Lightspeed is an AI powered assistant that runs on Open
9191
authors = []
9292
# NOTE: langchain bumps causes mypy issues
9393
dependencies = [
94+
"aiohttp>=3.12.14", # CVE free version
9495
"pdm>=2.21.0",
9596
"httpx>=0.27.2",
9697
"fastapi>=0.115.6",
@@ -111,7 +112,7 @@ dependencies = [
111112
"kubernetes>=30.1.0",
112113
"psycopg2-binary>=2.9.9",
113114
"azure-identity>=1.18.0",
114-
"langchain-community>0.3.27", # CVE version
115+
"langchain-community>0.3.27", # CVE free version
115116
"sqlalchemy>=2.0.35",
116117
"ibm-watsonx-ai>=1.3.6",
117118
"certifi>=2024.8.30",
@@ -124,7 +125,7 @@ dependencies = [
124125
"requests>=2.32.2",
125126
"transformers>=4.50.3",
126127
"langchain-mcp-adapters>=0.0.11",
127-
"mcp>=1.10.0", # CVEs in lower version
128+
"mcp>=1.10.0", # CVE free version
128129
]
129130
requires-python = ">=3.11.1,<=3.12.10"
130131
readme = "README.md"

0 commit comments

Comments
 (0)