Skip to content

fix: bump langchain-core and pillow for security fixes#86

Merged
cbullinger merged 1 commit intomainfrom
dependabot/25_and_26
Feb 13, 2026
Merged

fix: bump langchain-core and pillow for security fixes#86
cbullinger merged 1 commit intomainfrom
dependabot/25_and_26

Conversation

@cbullinger
Copy link
Copy Markdown
Collaborator

Summary

Addresses Dependabot security alerts #25 and #26.

Changes

  • langchain-core: 1.2.91.2.11
  • pillow: 12.1.012.1.1

Vulnerability Details

Alert #25 - langchain-core

Alert #26 - pillow

Testing

  • ✅ All 65 unit tests pass
  • ✅ Application builds successfully
  • ✅ Application runs correctly
  • ✅ requirements.txt regenerated via pip-compile

- langchain-core: 1.2.9 → 1.2.11 (CVE-2026-26013 fix per Dependabot alert #25)
- pillow: 12.1.0 → 12.1.1 (CVE-2026-25990 fix per Dependabot alert #26)
@cbullinger cbullinger merged commit ac17650 into main Feb 13, 2026
1 check passed
@cbullinger cbullinger deleted the dependabot/25_and_26 branch March 27, 2026 20:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant