Compare commits

...

1 Commits

Author SHA1 Message Date
Rip&Tear
fc1cc1dd78 fix(deps): bump gitpython to 3.1.58 in crewai-tools[github]
gitpython 3.1.57 has GHSA-9rj7-rf2p-w77r, GHSA-4gmw-gg2m-w46p,
GHSA-hh9p-6wh2-4mfc, GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr
(further unguarded git option forwarding / arbitrary file read via
--pathspec-from-file). All are fixed in 3.1.58, which the root
override-dependencies already require; align the crewai-tools github
extra with it and regenerate the lockfile.
2026-08-09 22:30:48 +08:00
2 changed files with 7 additions and 4 deletions

View File

@@ -107,9 +107,12 @@ stagehand = [
"stagehand>=0.4.1",
]
github = [
# <3.1.57 has GHSA-p538-c434-8v24 (arbitrary file truncation) and
# GHSA-3f7w-8rr8-f37f (unguarded git option forwarding).
"gitpython>=3.1.57,<4",
# <3.1.58 has GHSA-p538-c434-8v24 (arbitrary file truncation),
# GHSA-3f7w-8rr8-f37f (unguarded git option forwarding),
# GHSA-9rj7-rf2p-w77r, GHSA-4gmw-gg2m-w46p, GHSA-hh9p-6wh2-4mfc,
# GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr (further unguarded git
# option forwarding / arbitrary file read); force 3.1.58+.
"gitpython>=3.1.58,<4",
"PyGithub==1.59.1",
]
rag = [

2
uv.lock generated
View File

@@ -1761,7 +1761,7 @@ requires-dist = [
{ name = "e2b-code-interpreter", marker = "extra == 'e2b'", specifier = "~=2.6.0" },
{ name = "exa-py", marker = "extra == 'exa-py'", specifier = ">=1.8.7" },
{ name = "firecrawl-py", marker = "extra == 'firecrawl-py'", specifier = ">=1.8.0" },
{ name = "gitpython", marker = "extra == 'github'", specifier = ">=3.1.57,<4" },
{ name = "gitpython", marker = "extra == 'github'", specifier = ">=3.1.58,<4" },
{ name = "hyperbrowser", marker = "extra == 'hyperbrowser'", specifier = ">=0.18.0" },
{ name = "langchain-apify", marker = "extra == 'apify'", specifier = ">=0.1.2,<1.0.0" },
{ name = "linkup-sdk", marker = "extra == 'linkup-sdk'", specifier = ">=0.2.2" },