mirror of
https://github.com/crewAIInc/crewAI.git
synced 2026-08-10 08:21:54 +00:00
Some checks failed
CodeQL Advanced / Analyze (actions) (push) Has been cancelled
CodeQL Advanced / Analyze (python) (push) Has been cancelled
Vulnerability Scan / pip-audit (push) Has been cancelled
Build uv cache / build-cache (3.10) (push) Has been cancelled
Build uv cache / build-cache (3.11) (push) Has been cancelled
Build uv cache / build-cache (3.12) (push) Has been cancelled
Build uv cache / build-cache (3.13) (push) Has been cancelled
Nightly Canary Release / Check for new commits (push) Has been cancelled
Nightly Canary Release / Build nightly packages (push) Has been cancelled
Nightly Canary Release / Publish nightly to PyPI (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
* feat: add project_id to link OSS usage to an enterprise account Adds a stable per-project identifier so a project's OSS traces and runs can be attributed to an account after signup. There was no such identifier before: [tool.crewai] held only `type`, the deploy UUID was printed to the console but never persisted, Settings.org_uuid is global rather than per-project, and trace batches carried only crew_fingerprint/crew_name. The id lives in the project's pyproject.toml, so it is committed with the repository and stays stable across machines, teammates, CI, and containers - unlike a machine- or user-derived identifier, which is unstable in exactly the containerized production environments that matter most. crewai-core: - get_project_id(): read-only lookup of [tool.crewai].project_id. Safe for library code; never creates or modifies anything. - get_or_create_project_id(): mints a uuid4 and persists it, returning (id, created) so callers can tell the user. Best-effort - returns (None, False) for a missing, malformed, or read-only pyproject.toml rather than raising. - Insertion edits the raw TOML text instead of round-tripping through a writer, so comments, key order, and formatting elsewhere survive. The key is placed at the end of the [tool.crewai] table, before the next table header, so it cannot land in a neighbouring section. - LoginPayload and TraceExecutionContext gain optional project_id. Sent on two paths: - Traces: project_id is added to execution_context, which is sent on both the ephemeral and authenticated paths, so a project's traces remain attributable before and after the user creates an account. - Login: `crewai login` already sends the pseudonymous user_identifier on an authenticated request; adding project_id means one request carries account + user + project, which is the link itself. Minting is restricted to CLI commands the user explicitly invoked - `crewai create` for new projects and `crewai run` to backfill existing ones - and is announced when it happens. Library code only ever reads. Silently rewriting a user's pyproject.toml during Crew.kickoff() would be surprising. Privacy: project_id is a random uuid4 in a file the user commits. It is visible in a diff, contains nothing personal, and identifies a project rather than a person - so this needs none of the notice changes that attaching a user identifier to all telemetry would require. Tests: 18 new tests covering minting, stability, table placement, comment and formatting preservation, five pyproject layouts, the neighbouring-table regression, and graceful handling of missing/malformed/read-only files. Verified end-to-end that both create paths mint distinct ids, that the trace payload carries project_id on both the ephemeral and authenticated paths, and that the login payload carries user_identifier and project_id together. Follow-ups, deliberately not included: adding project_id to telemetry spans, and backend persistence of the (account, user_identifier, project_id) triple. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UNumDnNbiyw3pv1WakAe6t * refactor: drop the console announcement when minting project_id Minting now happens silently. With no message to print, the (id, created) tuple had no consumer, so simplify the API rather than keep the flag around for a hypothetical caller: - get_or_create_project_id() returns `str | None` instead of `tuple[str | None, bool]`. - Remove crewai_cli.utils.ensure_project_id, which existed only to print the message and discard the flag. The four call sites (crewai create crew, crewai create flow, crewai run, and tool-repository login) now call get_or_create_project_id directly. - Update tests for the simplified signature; still 18 tests covering minting, stability, table placement, formatting preservation, five pyproject layouts, and missing/malformed/read-only handling. Behaviour is otherwise unchanged: minting stays restricted to CLI commands the user invoked, library code still only reads via get_project_id, and a missing or read-only pyproject.toml still returns None rather than raising. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UNumDnNbiyw3pv1WakAe6t * fix: harden project_id minting against TOML corruption; address review Several reviewers found ways the raw-text edit could produce invalid TOML. Each is now fixed and covered by a test that fails without the fix. Duplicate project_id key (Cursor bugbot, Copilot x2): - get_project_id() reports a blank or non-string value as "absent", so a file containing `project_id = ""` took the insert path and gained a second project_id line - a duplicate key, and therefore invalid TOML that no tomli-based tool could read afterwards. - _insert_project_id is now _set_project_id: it replaces an existing assignment inside [tool.crewai] instead of appending unconditionally. Table header with a trailing comment (CodeRabbit major, Cursor bugbot): - `[tool.crewai] # config` is valid TOML but failed exact string equality, so the fallback appended a second [tool.crewai] header - a redefined table, also invalid TOML, and silent because get_project_id swallows the resulting decode error. - Added _is_table_header(), which tolerates a trailing comment and does not match similar names such as [tool.crewai-extra]. Writing into malformed TOML (Cursor bugbot, Copilot): - get_or_create_project_id relied on get_project_id, which cannot distinguish "no id" from "unparsable file", so it appended to files it could not parse. - The locked path now parses explicitly and bails on a decode error, and re-parses the updated content before writing, so this feature can never be the reason a project's pyproject.toml stops parsing. Concurrency and atomicity (CodeRabbit major): - Two CLI processes could both see no id, mint different uuids, and clobber each other, leaving a caller holding an id that is not on disk. Minting now takes the existing crewai_core cross-process lock, re-reads under it, and returns the id that persists. - Writes go through a temp file in the same directory plus os.replace, so an interruption cannot truncate pyproject.toml. File mode is copied across, and the temp file is removed on failure. - os.replace only needs a writable directory, which would have let an atomic write silently overwrite a file the user marked read-only; writability is now checked explicitly so that case still returns None. Line endings (CodeRabbit): - Path.read_text/write_text normalized CRLF to LF, so minting would rewrite a CRLF-committed file entirely. Read and write now use newline="" and the inserted line ending is derived from the existing content. Default create path skipped minting (Cursor bugbot): - `crewai create crew` defaults to create_json_crew; only the --classic and flow paths minted, so most new projects had no id until a later command. Wired into create_json_crew as well. Verified all three paths now mint distinct ids. Do not mint during login (CodeRabbit major): - ToolCommand.login ran get_or_create_project_id, which is outside the sanctioned minting commands and is invoked by `crewai tools create` from a freshly scaffolded directory before the project is persisted. It now uses the read-only get_project_id. Verified login leaves pyproject.toml untouched. Not applied: Copilot asked for a console message when an id is written, in create_crew and create_flow. Minting was made deliberately silent in the previous commit, so the (id, created) tuple and the announcement are both gone by design. Tests: 32 in test_project_id.py, up from 18. New cases cover blank and non-string existing ids, three commented-header forms, similar table names, malformed input, CRLF and LF preservation, concurrent minting convergence, file-mode preservation, and temp-file cleanup. Confirmed the header and duplicate-key tests fail when the fixes are reverted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UNumDnNbiyw3pv1WakAe6t * fix: never create [tool.crewai], treat whitespace ids as absent, harden test `crewai run` could rewrite unrelated projects (Cursor bugbot, high): - get_or_create_project_id ran before the cwd was established as a CrewAI project, and _set_project_id appended a [tool.crewai] table when none existed. Any directory with a pyproject.toml could therefore gain one - including on `crewai run --definition`, which may otherwise succeed. - _set_project_id no longer creates the table; it returns None when [tool.crewai] is absent, so a key is only ever added to a table the project already declares. The templates all ship the table, so no create path needs the old fallback. - The minting call in run_crew moved after the --definition early return, so an explicit-flow run does not touch the cwd at all. - Presence is checked, not truthiness: an empty [tool.crewai] is still a CrewAI marker, and get_crewai_project_config returns {} both for that and for an absent table. - Verified an unrelated project's pyproject.toml is byte-identical after a mint attempt. Whitespace-only project_id accepted as valid (CodeRabbit): - `project_id = " "` is truthy, so it was returned as an identity and would have propagated into login payloads and tracing context. It also meant the '" "' parameter of the replacement test asserted nothing. - Added _usable_project_id, which strips before deciding, used by both get_project_id and the locked mint path. Concurrency test could hang CI (CodeRabbit, major): - Neither the barrier nor the joins had timeouts, so a thread dying early or blocking on the lock would hang the job rather than fail it. The result count was also unchecked, so a dead thread still passed. - Added timeouts, an explicit liveness assertion, a result-count assertion, a lock around the shared result list, and corrected the docstring: this covers the read-modify-write race with threads, not the cross-process backend. Tests: 35, up from 32. New coverage for the absent-table refusal and three whitespace forms; the blank-id replacement case now asserts a real uuid replaced the blank value. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UNumDnNbiyw3pv1WakAe6t * chore(deps): force gitpython 3.1.57+ for GHSA-p538-c434-8v24 and GHSA-3f7w-8rr8-f37f Unrelated to project_id; bundled here only because it blocks this PR's vulnerability scan. Two advisories were published for gitpython 3.1.55 after main last passed the scan: - GHSA-p538-c434-8v24: arbitrary file truncation via `git rev-list --output` argument injection. Fixed in 3.1.56. - GHSA-3f7w-8rr8-f37f: unguarded git option forwarding in IndexFile.checkout() and TagReference. Fixed in 3.1.57. - Bump the override floor to gitpython>=3.1.57 and declare the same floor in crewai-tools, so consumers installing the published package are covered and not only this repo's lock. - 3.1.57 was published 2026-07-26, past gitpython's exclude-newer-package cutoff of 2026-07-24, so that cutoff moves to 2026-07-27. Without it the floor is unresolvable. pip-audit against the updated lock reports no known vulnerabilities. Verified gitpython 3.1.57 resolves and that crewai_tools and crewai_cli.git still import. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UNumDnNbiyw3pv1WakAe6t --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
265 lines
11 KiB
TOML
265 lines
11 KiB
TOML
name = "crewai-workspace"
|
|
description = "Cutting-edge framework for orchestrating role-playing, autonomous AI agents. By fostering collaborative intelligence, CrewAI empowers agents to work together seamlessly, tackling complex tasks."
|
|
readme = "README.md"
|
|
requires-python = ">=3.10,<3.14"
|
|
authors = [
|
|
{ name = "Joao Moura", email = "joao@crewai.com" }
|
|
]
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
"ruff==0.15.1",
|
|
"mypy==1.19.1",
|
|
"pre-commit==4.5.1",
|
|
"bandit==1.9.2",
|
|
"pytest==9.0.3",
|
|
"pytest-asyncio==1.3.0",
|
|
"pytest-subprocess==1.5.3",
|
|
"vcrpy==8.2.1", # pinned, lower versions break pytest-recording
|
|
"pytest-recording==0.13.4",
|
|
"pytest-randomly==4.0.1",
|
|
"pytest-timeout==2.4.0",
|
|
"pytest-xdist==3.8.0",
|
|
"pytest-split==0.11.0",
|
|
"types-requests~=2.31.0.6",
|
|
"types-pyyaml==6.0.*",
|
|
"types-regex==2026.1.15.*",
|
|
"types-appdirs==1.4.*",
|
|
"boto3-stubs[bedrock-runtime]==1.42.40",
|
|
"types-psycopg2==2.9.21.20251012",
|
|
"types-pymysql==1.1.0.20250916",
|
|
"types-aiofiles~=25.1.0",
|
|
"types-redis~=4.6",
|
|
"commitizen>=4.13.9",
|
|
"pip-audit==2.9.0",
|
|
]
|
|
|
|
|
|
[tool.ruff]
|
|
src = ["lib/*"]
|
|
extend-exclude = [
|
|
"lib/crewai/src/crewai/cli/templates",
|
|
"lib/cli/src/crewai_cli/templates",
|
|
"lib/crewai/tests/",
|
|
"lib/crewai-tools/tests/",
|
|
"lib/cli/tests/",
|
|
]
|
|
respect-gitignore = true
|
|
force-exclude = true
|
|
fix = true
|
|
target-version = "py310"
|
|
|
|
[tool.ruff.format]
|
|
docstring-code-format = true
|
|
|
|
[tool.ruff.lint]
|
|
future-annotations = true
|
|
extend-select = [
|
|
"E", # pycodestyle errors (style issues)
|
|
"F", # Pyflakes (code errors)
|
|
"B", # flake8-bugbear (bug prevention)
|
|
"S", # bandit (security issues)
|
|
"RUF", # ruff-specific rules
|
|
"N", # pep8-naming (naming conventions)
|
|
"W", # pycodestyle warnings
|
|
"I", # isort (import formatting)
|
|
"T", # flake8-print (print statements)
|
|
# "D", # pydocstyle (docstring conventions) disabled until
|
|
"PERF", # performance issues
|
|
"PIE", # flake8-pie (unnecessary code)
|
|
"TID", # flake8-tidy-imports (import best practices)
|
|
"ASYNC", # async/await best practices
|
|
"RET", # flake8-return (return improvements)
|
|
"SIM118", # use `key in dict` instead of `key in dict.keys()`
|
|
"UP006", # use collections.abc
|
|
"UP007", # use X | Y for unions
|
|
"UP035", # use dict/list instead of typing.Dict/List
|
|
"UP037", # remove quotes from type annotations
|
|
"UP045", # use X | None instead of Optional[X]
|
|
"UP004", # use isinstance instead of type
|
|
"UP008", # use super() instead of super(Class, self)
|
|
"UP010", # use isinstance for type checks
|
|
"UP018", # use str() instead of "string"
|
|
"UP031", # use f-strings for .format()
|
|
"UP032", # use f-strings for .format() with positional
|
|
"I001", # sort imports
|
|
"I002", # remove unused imports
|
|
]
|
|
ignore = ["E501"] # ignore line too long globally
|
|
|
|
[tool.ruff.lint.flake8-tidy-imports]
|
|
ban-relative-imports = "all"
|
|
|
|
[tool.ruff.lint.flake8-type-checking]
|
|
runtime-evaluated-base-classes = ["pydantic.BaseModel"]
|
|
|
|
[tool.ruff.lint.isort]
|
|
no-sections = false
|
|
case-sensitive = true
|
|
combine-as-imports = true
|
|
force-single-line = false
|
|
force-sort-within-sections = true
|
|
known-first-party = []
|
|
section-order = ["future", "standard-library", "third-party", "first-party", "local-folder"]
|
|
lines-after-imports = 2
|
|
split-on-trailing-comma = true
|
|
|
|
[tool.ruff.lint.pydocstyle]
|
|
convention = "google"
|
|
ignore-decorators = ["typing.overload"]
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
"lib/crewai/tests/**/*.py" = ["S101", "RET504", "S105", "S106"] # Allow assert statements, unnecessary assignments, and hardcoded passwords in tests
|
|
"lib/crewai-tools/tests/**/*.py" = ["S101", "RET504", "S105", "S106", "RUF012", "N818", "E402", "RUF043", "S110", "B017"] # Allow various test-specific patterns
|
|
"lib/crewai-files/tests/**/*.py" = ["S101", "RET504", "S105", "S106", "B017", "F841"] # Allow assert statements and blind exception assertions in tests
|
|
"lib/cli/tests/**/*.py" = ["S101", "RET504", "S105", "S106"] # Allow assert statements in tests
|
|
"lib/crewai-core/tests/**/*.py" = ["S101", "RET504", "S105", "S106"] # Allow assert statements in tests
|
|
"lib/devtools/tests/**/*.py" = ["S101"]
|
|
|
|
|
|
[tool.mypy]
|
|
strict = true
|
|
disallow_untyped_defs = true
|
|
disallow_any_unimported = true
|
|
no_implicit_optional = true
|
|
check_untyped_defs = true
|
|
warn_return_any = true
|
|
show_error_codes = true
|
|
warn_unused_ignores = true
|
|
python_version = "3.12"
|
|
exclude = "(?x)(^lib/crewai/src/crewai/cli/templates/|^lib/cli/src/crewai_cli/templates/|^lib/crewai/tests/|^lib/crewai-tools/tests/|^lib/crewai-files/tests/|^lib/cli/tests/|^lib/devtools/tests/)"
|
|
plugins = ["pydantic.mypy"]
|
|
|
|
|
|
[tool.bandit]
|
|
exclude_dirs = ["lib/crewai/src/crewai/cli/templates", "lib/cli/src/crewai_cli/templates"]
|
|
|
|
|
|
[tool.pytest.ini_options]
|
|
markers = [
|
|
"telemetry: mark test as a telemetry test (don't mock telemetry)",
|
|
]
|
|
testpaths = [
|
|
"lib/crewai/tests",
|
|
"lib/crewai-tools/tests",
|
|
"lib/crewai-files/tests",
|
|
"lib/cli/tests",
|
|
"lib/crewai-core/tests",
|
|
]
|
|
asyncio_mode = "strict"
|
|
asyncio_default_fixture_loop_scope = "function"
|
|
addopts = "--tb=short -n auto --timeout=60 --dist=loadfile --max-worker-restart=2 --block-network --import-mode=importlib"
|
|
python_files = "test_*.py"
|
|
python_classes = "Test*"
|
|
python_functions = "test_*"
|
|
|
|
[tool.commitizen]
|
|
name = "cz_customize"
|
|
version_provider = "scm"
|
|
tag_format = "$version"
|
|
allowed_prefixes = ["Merge", "Revert"]
|
|
changelog_incremental = true
|
|
update_changelog_on_bump = false
|
|
|
|
[tool.commitizen.customize]
|
|
schema = "<type>(<scope>): <description>"
|
|
schema_pattern = "^(feat|fix|refactor|perf|test|docs|chore|ci|style|revert)(\\(.+\\))?!?: .{1,72}"
|
|
bump_pattern = "^(feat|fix|perf|refactor|revert)"
|
|
bump_map = { feat = "MINOR", fix = "PATCH", perf = "PATCH", refactor = "PATCH", revert = "PATCH" }
|
|
info = "Commits must follow Conventional Commits 1.0.0."
|
|
|
|
|
|
[tool.uv]
|
|
exclude-newer = "3 days"
|
|
# These security fixes are newer than the global supply-chain cutoff.
|
|
exclude-newer-package = { pypdf = "2026-06-24T00:00:00Z", msgpack = "2026-06-20T00:00:00Z", pydantic-settings = "2026-06-20T00:00:00Z", langsmith = "2026-06-20T00:00:00Z", gitpython = "2026-07-27T00:00:00Z" }
|
|
|
|
# composio-core pins rich<14 but textual requires rich>=14.
|
|
# onnxruntime 1.24+ dropped Python 3.10 wheels; cap it so qdrant[fastembed] resolves on 3.10.
|
|
# fastembed 0.7.x and docling 2.63 cap pillow<12; the removed APIs don't affect them.
|
|
# langchain-core <1.2.31 has GHSA-926x-3r5x-gfhw and is required by langchain-text-splitters 1.1.2+.
|
|
# langchain-core 1.0.0-1.3.2 has GHSA-pjwx-r37v-7724 (unsafe deserialization via broad load() allowlists); force 1.3.3+.
|
|
# langchain-text-splitters <1.1.2 has GHSA-fv5p-p927-qmxr (SSRF bypass in split_text_from_url).
|
|
# transformers 4.57.6 has CVE-2026-1839; force 5.4+ (docling 2.84 allows huggingface-hub>=1).
|
|
# cryptography 46.0.6 has CVE-2026-39892; force 46.0.7+.
|
|
# pypdf <6.10.2 has GHSA-4pxv-j86v-mhcw, GHSA-7gw9-cf7v-778f, GHSA-x284-j5p8-9c5p.
|
|
# pypdf <6.14.2 has GHSA-jm82-fx9c-mx94 and GHSA-5qjq-93h5-hrgp/GHSA-55h5-xmcq-c37v/GHSA-g867-7843-wf8q/GHSA-5xf7-4p34-54qr; force 6.14.2+.
|
|
# uv <0.11.15 has GHSA-4gg8-gxpx-9rph (and earlier GHSA-pjjw-68hj-v9mw); force 0.11.15+.
|
|
# python-multipart <0.0.27 has GHSA-pp6c-gr5w-3c5g (DoS via unbounded multipart headers).
|
|
# gitpython <3.1.50 has GHSA-mv93-w799-cj2w (config_writer newline injection bypassing the 3.1.49 patch -> RCE via core.hooksPath).
|
|
# gitpython <3.1.51 has GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj, and GHSA-956x-8gvw-wg5v.
|
|
# gitpython <=3.1.51 has GHSA-rwj8-pgh3-r573; fixed in 3.1.52.
|
|
# gitpython 3.1.52 has GHSA-3rp5-jjmw-4wv2, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and GHSA-r9mr-m37c-5fr3; force 3.1.55+.
|
|
# gitpython <3.1.56 has GHSA-p538-c434-8v24 (arbitrary file truncation via `git rev-list --output` argument
|
|
# injection) and <3.1.57 has GHSA-3f7w-8rr8-f37f (unguarded git option forwarding in IndexFile.checkout and
|
|
# TagReference); force 3.1.57+. Its exclude-newer-package cutoff is bumped to 2026-07-27 to admit that release.
|
|
# pyasn1 <0.6.4 has GHSA-8ppf-4f7h-5ppj and GHSA-hm4w-wwcw-mr6r; force 0.6.4+.
|
|
# urllib3 <2.7.0 has GHSA-qccp-gfcp-xxvc (ProxyManager cross-origin redirect leaks Authorization/Cookie) and GHSA-mf9v-mfxr-j63j (streaming decompression-bomb bypass); force 2.7.0+.
|
|
# langsmith <0.8.18 has GHSA-3644-q5cj-c5c7 (public prompt manifest deserialization, SSRF/secret disclosure)
|
|
# and GHSA-f4xh-w4cj-qxq8; force 0.8.18+.
|
|
# authlib <1.6.12 has GHSA-jj8c-mmj3-mmgv (CSRF bypass in cache-based state storage) and PYSEC-2026-188.
|
|
# pip 26.1.1 has PYSEC-2026-196; force 26.1.2+.
|
|
# aiohttp <=3.13.x has GHSA-jg22-mg44-37j8, GHSA-hg6j-4rv6-33pg; fixed in 3.14.0; force 3.14.0+.
|
|
# docling-core 2.74.0 has GHSA-j5xp-7m2f-49jv, GHSA-jmmv-h3mp-59v8; force 2.74.1+.
|
|
# pip <26.1.1 has GHSA-58qw-9mgm-455v (archive handling); OSV considers 26.1.1 unaffected.
|
|
# paramiko <5.0.0 has GHSA-r374-rxx8-8654 (SHA-1 in rsakey.py); OSV considers 5.0.0 unaffected. Transitive via composio-core.
|
|
# starlette <1.3.1 has PYSEC-2026-161, GHSA-jp82-jpqv-5vv3, and GHSA-82w8-qh3p-5jfq. Transitive via fastapi.
|
|
# msgpack <1.2.1 has GHSA-6v7p-g79w-8964; transitive via pip-audit[filecache].
|
|
# nltk <3.10.0 has GHSA-qvv7-cg9c-w4x3 (DNS-rebinding SSRF bypass in
|
|
# nltk.pathsec.urlopen), GHSA-fg7f-2386-8897 (ReDoS in ReviewsCorpusReader), and
|
|
# GHSA-xh95-f55m-82fw (path traversal in FramenetCorpusReader.frame); all fixed
|
|
# in 3.10.0. 3.10.0 also clears PYSEC-2026-597, whose last affected version is
|
|
# 3.9.4, so that ignore is no longer needed. Transitive via
|
|
# crewai-tools[xml] -> unstructured.
|
|
# pydantic-settings <2.14.2 has GHSA-4xgf-cpjx-pc3j.
|
|
# Keep OpenAI on the SDK range required by CrewAI when transitive dependencies
|
|
# loosen or pin their own lower versions.
|
|
override-dependencies = [
|
|
"openai>=2.30.0,<3",
|
|
"rich>=13.7.1",
|
|
"onnxruntime<1.24; python_version < '3.11'",
|
|
"pillow>=12.3.0",
|
|
"langchain-core>=1.3.3,<2",
|
|
"langchain-text-splitters>=1.1.2,<2",
|
|
"urllib3>=2.7.0",
|
|
"transformers>=5.4.0; python_version >= '3.10'",
|
|
"cryptography>=46.0.7",
|
|
"pypdf>=6.14.2,<7",
|
|
"uv>=0.11.15,<1",
|
|
"python-multipart>=0.0.27,<1",
|
|
"gitpython>=3.1.57,<4",
|
|
"pyasn1>=0.6.4",
|
|
"langsmith>=0.8.18,<1",
|
|
"authlib>=1.6.12",
|
|
"pip>=26.1.2",
|
|
"aiohttp>=3.14.0",
|
|
# [chunking] carried here because override-dependencies replace the whole
|
|
# requirement; without it the docling extra's chunking deps get stripped.
|
|
"docling-core[chunking]>=2.74.1",
|
|
"paramiko>=5.0.0",
|
|
"starlette>=1.3.1",
|
|
"msgpack>=1.2.1",
|
|
"pydantic-settings>=2.14.2",
|
|
"setuptools>=83.0.0", # PYSEC-2026-3447
|
|
"nltk>=3.10.0",
|
|
]
|
|
|
|
[tool.uv.workspace]
|
|
members = [
|
|
"lib/crewai",
|
|
"lib/crewai-tools",
|
|
"lib/devtools",
|
|
"lib/crewai-files",
|
|
"lib/cli",
|
|
"lib/crewai-core",
|
|
]
|
|
|
|
|
|
[tool.uv.sources]
|
|
crewai = { workspace = true }
|
|
crewai-tools = { workspace = true }
|
|
crewai-devtools = { workspace = true }
|
|
crewai-files = { workspace = true }
|
|
crewai-cli = { workspace = true }
|
|
crewai-core = { workspace = true }
|