mirror of
https://github.com/crewAIInc/crewAI.git
synced 2026-09-21 02:16:27 +00:00
`oxylabs` was pinned to exactly 2.0.0, so consumers could not take 3.0.0, out since March. 3.x keeps the `RealtimeClient` surface these tools use, and all four tools plus their failure paths were verified against the live API on both 2.0.0 and 3.0.0. The lockfile keeps oxylabs at 2.0.0, so this permits the upgrade rather than forcing it. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
186 lines
4.5 KiB
TOML
186 lines
4.5 KiB
TOML
[project]
|
|
name = "crewai-tools"
|
|
dynamic = ["version"]
|
|
description = "Set of tools for the crewAI framework"
|
|
readme = "README.md"
|
|
authors = [
|
|
{ name = "João Moura", email = "joaomdmoura@gmail.com" },
|
|
]
|
|
requires-python = ">=3.10, <3.14"
|
|
dependencies = [
|
|
"pytube~=15.0.0",
|
|
"requests>=2.33.0,<3",
|
|
"crewai==1.15.20",
|
|
"tiktoken>=0.8.0,<0.13",
|
|
"beautifulsoup4>=4.13.4,<5",
|
|
"python-docx~=1.2.0",
|
|
"youtube-transcript-api~=1.2.2",
|
|
"pymupdf~=1.26.6",
|
|
]
|
|
|
|
|
|
[project.urls]
|
|
Homepage = "https://crewai.com"
|
|
Repository = "https://github.com/crewAIInc/crewAI"
|
|
Documentation = "https://docs.crewai.com"
|
|
|
|
|
|
[project.optional-dependencies]
|
|
scrapfly-sdk = [
|
|
"scrapfly-sdk>=0.8.19",
|
|
]
|
|
sqlalchemy = [
|
|
"sqlalchemy>=2.0.35",
|
|
]
|
|
multion = [
|
|
"multion>=1.1.0",
|
|
]
|
|
firecrawl-py = [
|
|
"firecrawl-py>=1.8.0",
|
|
]
|
|
composio-core = [
|
|
"composio-core>=0.6.11.post1",
|
|
]
|
|
browserbase = [
|
|
"browserbase>=1.0.5",
|
|
]
|
|
weaviate-client = [
|
|
"weaviate-client>=4.10.2",
|
|
]
|
|
patronus = [
|
|
"patronus>=0.0.16",
|
|
]
|
|
serpapi = [
|
|
"serpapi>=0.1.5",
|
|
]
|
|
beautifulsoup4 = [
|
|
"beautifulsoup4>=4.12.3",
|
|
]
|
|
selenium = [
|
|
"selenium>=4.27.1",
|
|
]
|
|
spider-client = [
|
|
"spider-client>=0.1.25",
|
|
]
|
|
scrapegraph-py = [
|
|
"scrapegraph-py>=1.9.0,<2",
|
|
]
|
|
linkup-sdk = [
|
|
"linkup-sdk>=0.2.2",
|
|
]
|
|
tavily-python = [
|
|
"tavily-python~=0.7.14",
|
|
]
|
|
hyperbrowser = [
|
|
"hyperbrowser>=0.18.0",
|
|
]
|
|
snowflake = [
|
|
"cryptography>=43.0.3",
|
|
"snowflake-connector-python>=3.12.4",
|
|
# <1.11.0 has GHSA-8g6f-qw9x-4q6q (SQL injection, local file disclosure).
|
|
# Declared here, not only as a uv override, so consumers installing
|
|
# crewai-tools[snowflake] get this floor.
|
|
"snowflake-sqlalchemy>=1.11.0",
|
|
]
|
|
singlestore = [
|
|
"singlestoredb>=1.12.4",
|
|
"SQLAlchemy>=2.0.40",
|
|
]
|
|
exa-py = [
|
|
"exa-py>=1.8.7",
|
|
]
|
|
qdrant-client = [
|
|
"qdrant-client>=1.12.1",
|
|
]
|
|
apify = [
|
|
"langchain-apify>=0.1.2,<1.0.0",
|
|
]
|
|
|
|
databricks-sdk = [
|
|
"databricks-sdk>=0.46.0",
|
|
]
|
|
couchbase = [
|
|
"couchbase>=4.6.0",
|
|
]
|
|
mcp = [
|
|
"mcp>=1.28.1,<2",
|
|
"mcpadapt>=0.1.9",
|
|
]
|
|
stagehand = [
|
|
"stagehand>=0.4.1",
|
|
]
|
|
github = [
|
|
# <3.1.58 has GHSA-p538-c434-8v24 (arbitrary file truncation),
|
|
# GHSA-3f7w-8rr8-f37f (unguarded git option forwarding),
|
|
# GHSA-9rj7-rf2p-w77r, GHSA-4gmw-gg2m-w46p, GHSA-hh9p-6wh2-4mfc,
|
|
# GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr (further unguarded git
|
|
# option forwarding / arbitrary file read); force 3.1.58+. 3.1.58 then has
|
|
# PYSEC-2026-3785 through -3788; force 3.1.59+.
|
|
"gitpython>=3.1.59,<4",
|
|
"PyGithub==1.59.1",
|
|
]
|
|
rag = [
|
|
"python-docx>=1.1.0",
|
|
"lxml>=6.1.0,<7", # 6.1.0+ required for GHSA-vfmq-68hx-4jfw (XXE in iterparse)
|
|
]
|
|
xml = [
|
|
# <0.24.0 has GHSA-4mvj-m6j5-pmf7 (full-read SSRF via the url= argument of
|
|
# partition()). 0.24.0 requires Python >=3.11, so the floor is split rather
|
|
# than applied as a uv override: an override replaces the whole requirement
|
|
# including its marker, which would drop unstructured on 3.10 altogether.
|
|
# 3.10 therefore stays on the vulnerable line until the Python floor moves.
|
|
# TODO: collapse these two back to one entry when 3.10 support is dropped.
|
|
"unstructured[local-inference, all-docs]>=0.24.0; python_version >= '3.11'",
|
|
"unstructured[local-inference, all-docs]>=0.17.2; python_version < '3.11'",
|
|
# unstructured allows nltk>=3.9.2, but <3.10.3 still has PYSEC-2026-3726
|
|
# (symlink file read in IPIPANCorpusReader; 3.10.0-3.10.1) plus later
|
|
# 3.10.2 findings. 3.10.3 still has unpatched GHSA-8mgp-746c-j5xp
|
|
# (ignored in pip-audit until a release ships). TODO: drop that ignore
|
|
# when bumping nltk past 3.10.3. Declared here, not only as a uv
|
|
# override, so consumers installing crewai-tools[xml] get this floor.
|
|
"nltk>=3.10.3",
|
|
]
|
|
oxylabs = [
|
|
# 3.x keeps the RealtimeClient surface these tools use and adds sources;
|
|
# allow it rather than pinning consumers to a single release.
|
|
"oxylabs>=2.0.0,<4",
|
|
]
|
|
mongodb = [
|
|
"pymongo>=4.13"
|
|
]
|
|
mysql = [
|
|
"pymysql>=1.1.1"
|
|
]
|
|
postgresql = [
|
|
"psycopg2-binary>=2.9.10"
|
|
]
|
|
bedrock = [
|
|
"beautifulsoup4>=4.13.4",
|
|
"bedrock-agentcore>=1.18.1,<2.0.0",
|
|
"playwright>=1.52.0",
|
|
"nest-asyncio>=1.6.0",
|
|
]
|
|
contextual = [
|
|
"contextual-client>=0.1.0",
|
|
"nest-asyncio>=1.6.0",
|
|
]
|
|
daytona = [
|
|
"daytona~=0.140.0",
|
|
]
|
|
|
|
e2b = [
|
|
"e2b~=2.20.0",
|
|
"e2b-code-interpreter~=2.6.0",
|
|
]
|
|
|
|
|
|
[tool.uv]
|
|
exclude-newer = "3 days"
|
|
|
|
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[tool.hatch.version]
|
|
path = "src/crewai_tools/__init__.py"
|