Skip to content

Commit 5202098

Browse files
authored
fix(deps): resolve all 14 open Dependabot security alerts (#275)
- backend: pin langsmith>=0.8.0 (0.7.31->0.8.4), langchain-classic>=1.0.7 (1.0.2->1.0.7) - evaluation: pin langsmith>=0.8.0 (0.7.31->0.8.4), gitpython>=3.1.50 (3.1.45->3.1.50) - frontend: pin gitpython>=3.1.50 (3.1.44->3.1.50) - nextjs-frontend: yarn resolutions to override next@16.2.6 hard-pinned postcss@8.4.31->8.5.10 Signed-off-by: Jack Luar <jluar@precisioninno.com>
1 parent 664f8c3 commit 5202098

8 files changed

Lines changed: 4540 additions & 4529 deletions

File tree

backend/pyproject.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@ dependencies = [
1414
"httpx>=0.28.1",
1515
"huggingface-hub>=1.3.0",
1616
"langchain>=1.2.12",
17+
"langchain-classic>=1.0.7",
1718
"langchain-community>=0.4.1",
1819
"langchain-google-genai>=4.2.1",
1920
"langchain-google-vertexai>=3.2.2",
@@ -22,6 +23,7 @@ dependencies = [
2223
"langchain-ollama>=1.0.1",
2324
"langgraph>=1.1.0",
2425
"langgraph-checkpoint>=4.0.0",
26+
"langsmith>=0.8.0",
2527
"markdown==3.8.2",
2628
"myst-parser==4.0.1",
2729
"nest-asyncio>=1.6.0",

backend/uv.lock

Lines changed: 2030 additions & 2024 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

evaluation/pyproject.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,12 +11,14 @@ dependencies = [
1111
"google-auth>=2.47.0",
1212
"google-auth-httplib2==0.2.0",
1313
"google-auth-oauthlib==1.2.0",
14+
"gitpython>=3.1.50",
1415
"gspread==6.1.2",
1516
"python-dotenv==1.2.2",
1617
"requests==2.33.0",
1718
"streamlit>=1.40.0",
1819
"deepeval==3.0.0",
1920
"langchain-google-vertexai>=3.2.2",
21+
"langsmith>=0.8.0",
2022
"asyncio==3.4.3",
2123
"huggingface-hub==0.26.2",
2224
"instructor[vertexai]==1.5.2",

evaluation/uv.lock

Lines changed: 1683 additions & 1679 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

frontend/nextjs-frontend/package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,5 +40,8 @@
4040
},
4141
"eslintConfig": {
4242
"extends": "next"
43+
},
44+
"resolutions": {
45+
"postcss": "^8.5.10"
4346
}
4447
}

frontend/nextjs-frontend/yarn.lock

Lines changed: 4 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -2723,7 +2723,7 @@ ms@^2.1.1, ms@^2.1.3:
27232723
resolved "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz"
27242724
integrity sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==
27252725

2726-
nanoid@^3.3.11, nanoid@^3.3.6:
2726+
nanoid@^3.3.11:
27272727
version "3.3.12"
27282728
resolved "https://registry.yarnpkg.com/nanoid/-/nanoid-3.3.12.tgz#ab3d912e217a6d0a514f00a72a16543a28982c05"
27292729
integrity sha512-ZB9RH/39qpq5Vu6Y+NmUaFhQR6pp+M2Xt76XBnEwDaGcVAqhlvxrl3B2bKS5D3NH3QR76v3aSrKaF/Kiy7lEtQ==
@@ -2905,7 +2905,7 @@ path-parse@^1.0.7:
29052905
resolved "https://registry.npmjs.org/path-parse/-/path-parse-1.0.7.tgz"
29062906
integrity sha512-LDJzPVEEEPR+y48z93A0Ed0yXb8pAByGWo/k5YYdYgpY2/2EsOsksJrq7lOHxryrVOn1ejG6oAp8ahvOIQD8sw==
29072907

2908-
picocolors@^1.0.0, picocolors@^1.0.1, picocolors@^1.1.1:
2908+
picocolors@^1.0.1, picocolors@^1.1.1:
29092909
version "1.1.1"
29102910
resolved "https://registry.npmjs.org/picocolors/-/picocolors-1.1.1.tgz"
29112911
integrity sha512-xceH2snhtb5M9liqDsmEw56le376mTZkEX/jEb/RxNFyegNul7eNslCXP9FDj/Lcu0X8KEyMceP2ntpaHrDEVA==
@@ -2925,16 +2925,7 @@ postcss-value-parser@^4.2.0:
29252925
resolved "https://registry.npmjs.org/postcss-value-parser/-/postcss-value-parser-4.2.0.tgz"
29262926
integrity sha512-1NNCs6uurfkVbeXG4S8JFT9t19m45ICnif8zWLd5oPSZ50QnwMfK+H3jv408d4jw/7Bttv5axS5IiHoLaVNHeQ==
29272927

2928-
postcss@8.4.31:
2929-
version "8.4.31"
2930-
resolved "https://registry.npmjs.org/postcss/-/postcss-8.4.31.tgz"
2931-
integrity sha512-PS08Iboia9mts/2ygV3eLpY5ghnUcfLV/EXTOW1E2qYxJKGGBUtNjN76FYHnMs36RmARn41bC0AZmn+rR0OVpQ==
2932-
dependencies:
2933-
nanoid "^3.3.6"
2934-
picocolors "^1.0.0"
2935-
source-map-js "^1.0.2"
2936-
2937-
postcss@^8.4.41, postcss@^8.5.10:
2928+
postcss@8.4.31, postcss@^8.4.41, postcss@^8.5.10:
29382929
version "8.5.10"
29392930
resolved "https://registry.yarnpkg.com/postcss/-/postcss-8.5.10.tgz#8992d8c30acf3f12169e7c09514a12fed7e48356"
29402931
integrity sha512-pMMHxBOZKFU6HgAZ4eyGnwXF/EvPGGqUr0MnZ5+99485wwW41kW91A4LOGxSHhgugZmSChL5AlElNdwlNgcnLQ==
@@ -3322,7 +3313,7 @@ side-channel@^1.1.0:
33223313
side-channel-map "^1.0.1"
33233314
side-channel-weakmap "^1.0.2"
33243315

3325-
source-map-js@^1.0.2, source-map-js@^1.2.1:
3316+
source-map-js@^1.2.1:
33263317
version "1.2.1"
33273318
resolved "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz"
33283319
integrity sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==

frontend/pyproject.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ version = "1.0.0"
88
requires-python = ">=3.12"
99
dependencies = [
1010
"fastapi[standard]==0.115.14",
11+
"gitpython>=3.1.50",
1112
"streamlit>=1.54.0",
1213
"requests==2.33.0",
1314
"requests-oauthlib==2.0.0",

frontend/uv.lock

Lines changed: 815 additions & 813 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)