Skip to content

fix: bump langchain-core and pillow for security fixes#87

Merged
cbullinger merged 1 commit intodevelopmentfrom
dependabot/25_and_26-dev
Feb 13, 2026
Merged

fix: bump langchain-core and pillow for security fixes#87
cbullinger merged 1 commit intodevelopmentfrom
dependabot/25_and_26-dev

Conversation

@cbullinger
Copy link
Collaborator

Summary

Addresses Dependabot security alerts #25 and #26.

Changes

  • langchain-core: 1.2.91.2.11
  • pillow: 12.1.012.1.1

Vulnerability Details

Alert #25 - langchain-core

Alert #26 - pillow

Testing

  • ✅ All 65 unit tests pass
  • ✅ Application builds successfully
  • ✅ Application runs correctly
  • ✅ requirements.txt regenerated via pip-compile

- langchain-core: 1.2.9 → 1.2.11 (CVE-2026-26013 fix per Dependabot alert #25)
- pillow: 12.1.0 → 12.1.1 (CVE-2026-25990 fix per Dependabot alert #26)
Copy link
Collaborator

@tmcneil-mdb tmcneil-mdb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm!

Copy link
Collaborator

@tmcneil-mdb tmcneil-mdb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm!

@cbullinger cbullinger merged commit 709b350 into development Feb 13, 2026
2 checks passed
@cbullinger cbullinger deleted the dependabot/25_and_26-dev branch February 13, 2026 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants