Skip to content
This repository was archived by the owner on Sep 17, 2026. It is now read-only.

security: remediate additional issue 179 dependencies - #185

Merged
D3f0 merged 1 commit into
mainfrom
security/issue-179-remediation
Sep 16, 2026
Merged

D3f0 merged 1 commit into
mainfrom
security/issue-179-remediation

Conversation

@D3f0

@D3f0 D3f0 commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator

Summary

Follow-up security remediation for #179, based on the latest main.

Addresses

This PR refreshes the lockfile and upgrades compatible vulnerable dependencies:

  • cryptography to 50.0.1
  • docling to 2.127.0
  • docling-core to 2.96.0
  • GitPython to 3.1.62
  • idna to 3.19
  • langchain-core to 0.3.86
  • langsmith to 0.12.5
  • nltk to 3.10.3
  • Pillow to 12.3.0
  • protobuf to 6.33.6
  • pyarrow to 25.0.1
  • pyasn1 to 0.6.4
  • pydantic-settings to 2.15.0
  • PyJWT to 2.14.0
  • python-multipart to 0.0.32
  • setuptools to 84.0.0
  • soupsieve to 2.9.2
  • tornado to 6.5.10
  • transformers to 4.57.6
  • virtualenv to 21.7.10

Existing patched versions from the prior security PR remain in the lockfile, including LiteLLM, MCP, aiohttp, MkDocs Material, and pymdown-extensions.

Intentionally unresolved

  • chromadb: issue 🔒 Security Alerts — IBM/Agentics #179 reports no patched version.
  • json-repair: the current CrewAI constraint keeps version 0.25.2; remediation requires a CrewAI/dependency upgrade or upstream fix.
  • torch: macOS x86_64 resolution remains pinned to 2.2.2 by the current Docling dependency graph; this requires a separate platform/dependency compatibility change.
  • urllib3: current resolver constraints retain 2.3.0; further remediation requires upgrading the dependent packages that constrain it.

The exposed Google API key also requires external revocation and replacement and is not addressed by this code-only PR.

Verification

  • uv lock --check: passed
  • git diff --check: passed
  • actionlint: passed
  • Full pytest suite: 8 passed, 7 skipped
  • Core package/security import smoke check: passed for the installed core environment

Release

After merging and externally rotating the Google API key, issue the security patch release through the normal release workflow.

Upgrade compatible vulnerable transitive dependencies, including cryptography, docling, docling-core, GitPython, langchain-core, langsmith, nltk, Pillow, protobuf, pyarrow, pyasn1, PyJWT, python-multipart, setuptools, soupsieve, tornado, transformers, and virtualenv. Refresh the lockfile while retaining chromadb and json-repair versions without available patched releases.

Signed-off-by: Nahuel Defossé <nahuel.deofsse@ibm.com>
@D3f0
D3f0 merged commit 0d045c9 into main Sep 16, 2026
5 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant