Compare commits

...

2 Commits

Author SHA1 Message Date
harshgupta-mem0 884e056853 fix(deps): upgrade litellm to >=1.88.1 and python-dotenv to 1.2.2 (CVE-2026-28684)
litellm 1.83.7 hard-pinned python-dotenv==1.0.1 (vulnerable). litellm 1.88.1
relaxed this to python-dotenv>=1.0.0,<2.0, unblocking the upgrade to 1.2.2.

Updates pyproject.toml constraint and manually patches poetry.lock entries
with verified PyPI hashes. The lock file content-hash will need a full
poetry lock regeneration on Python 3.10-3.13 (litellm does not yet support
Python 3.14, which is the local system Python).

Resolves Dependabot alert #760.
2026-06-12 20:08:58 +05:30
harshgupta-mem0 fbf6b8c0db fix(@mem0/community): upgrade @langchain/community to ^1.1.18 (CVE-2026-27795, CVE-2026-26019)
Bumps @langchain/community from ^0.3.36 to ^1.1.18 and @langchain/core from
^0.3.42 to ^1.1.27 to resolve two SSRF CVEs in RecursiveUrlLoader.

Resolves Dependabot alerts #496 and #538.
2026-06-12 19:48:13 +05:30
3 changed files with 12 additions and 12 deletions
+2 -2
View File
@@ -75,8 +75,8 @@
"typescript": "5.5.4"
},
"dependencies": {
"@langchain/community": "^0.3.36",
"@langchain/core": "^0.3.42",
"@langchain/community": "^1.1.18",
"@langchain/core": "^1.1.27",
"axios": "^1.16.0",
"mem0ai": "^2.1.8",
"uuid": "^11.1.1",
Generated
+9 -9
View File
@@ -3494,15 +3494,15 @@ pytest = ["pytest (>=7.0.0)", "rich (>=13.9.4,<14.0.0)"]
[[package]]
name = "litellm"
version = "1.83.7"
version = "1.88.1"
description = "Library to easily interface with LLM API providers"
optional = true
python-versions = "<4.0,>=3.9"
python-versions = "<3.14,>=3.10"
groups = ["main"]
markers = "extra == \"llms\""
files = [
{file = "litellm-1.83.7-py3-none-any.whl", hash = "sha256:5784a1d9a9a4a8acd6ca1e347003a5e2e1b3c749b4d41e7da4904577adade111"},
{file = "litellm-1.83.7.tar.gz", hash = "sha256:e2f2cb99df2e2b2eab63f1354faa45c88dd7c8d40c18eb648afb1b349c689633"},
{file = "litellm-1.88.1-py3-none-any.whl", hash = "sha256:369b84e57d9426582ddc35e731956ddb6618cda97cc44e4e4d2dfa75982a6e3a"},
{file = "litellm-1.88.1.tar.gz", hash = "sha256:89c6b74cc7912d6365793006ff951c0450fe847625008dfe49de8a7dc4529aa5"},
]
[package.dependencies]
@@ -3515,7 +3515,7 @@ jinja2 = "3.1.6"
jsonschema = "4.23.0"
openai = "2.30.0"
pydantic = "2.12.5"
python-dotenv = "1.0.1"
python-dotenv = "1.2.2"
tiktoken = "0.12.0"
tokenizers = "0.22.2"
@@ -6866,15 +6866,15 @@ six = ">=1.5"
[[package]]
name = "python-dotenv"
version = "1.0.1"
version = "1.2.2"
description = "Read key-value pairs from a .env file and set them as environment variables"
optional = true
python-versions = ">=3.8"
python-versions = ">=3.10"
groups = ["main"]
markers = "extra == \"vector-stores\" or extra == \"llms\" or extra == \"extras\""
files = [
{file = "python-dotenv-1.0.1.tar.gz", hash = "sha256:e324ee90a023d808f1959c46bcbc04446a10ced277783dc6ee09987c37ec10ca"},
{file = "python_dotenv-1.0.1-py3-none-any.whl", hash = "sha256:f7b63ef50f1b690dddf550d03497b66d609393b40b564ed0d674909a68ebf16a"},
{file = "python_dotenv-1.2.2-py3-none-any.whl", hash = "sha256:1d8214789a24de455a8b8bd8ae6fe3c6b69a5e3d64aa8a8e5d68e694bbcb285a"},
{file = "python_dotenv-1.2.2.tar.gz", hash = "sha256:2c371a91fbd7ba082c2c1dc1f8bf89ca22564a087c2c287cd9b662adde799cf3"},
]
[package.extras]
+1 -1
View File
@@ -55,7 +55,7 @@ vector_stores = [
llms = [
"groq>=0.3.0",
"together>=0.2.10",
"litellm>=1.83.7",
"litellm>=1.88.1",
"openai>=1.90.0",
"ollama>=0.3.0",
"vertexai>=0.1.0",