[Snyk] Upgrade langchain from 0.3.31 to 0.3.37#861
[Snyk] Upgrade langchain from 0.3.31 to 0.3.37#861graymalkin77 wants to merge 1 commit intomasterfrom
Conversation
Snyk has created this PR to upgrade langchain from 0.3.31 to 0.3.37. See this package in npm: langchain See this project in Snyk: https://app.snyk.io/org/cognigy-gmbh/project/2b95d610-232a-4de1-a323-41b1bc8fc770?utm_source=github&utm_medium=referral&page=upgrade-pr
There was a problem hiding this comment.
Pull request overview
This PR upgrades the langchain dependency from version 0.3.31 to 0.3.37, addressing a 6-version gap in the dependency update.
Changes:
- Bump langchain package version from 0.3.31 to 0.3.37
Files not reviewed (1)
- extensions/diffbot/package-lock.json: Language not supported
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
This is a patch version upgrade that addresses a critical security vulnerability (CVE-2025-68664). According to LangChain's release policy, minor/patch versions do not contain breaking changes. The update is recommended to ensure system security. [2, 6] Source: Release notes
|
Snyk has created this PR to upgrade langchain from 0.3.31 to 0.3.37.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 6 versions ahead of your current version.
The recommended version was released a month ago.
Release notes
Package name: langchain
-
0.3.37 - 2025-12-23
-
0.3.36 - 2025-10-13
-
0.3.35 - 2025-09-29
-
0.3.34 - 2025-09-15
-
0.3.33 - 2025-09-04
-
0.3.32 - 2025-09-02
-
0.3.31 - 2025-08-19
from langchain GitHub release notesImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: