Skip to content

Conversation

@ibm-mend-app
Copy link

@ibm-mend-app ibm-mend-app bot commented Nov 14, 2025

This PR contains the following updates:

Package Change Age Confidence
@langchain/community (source) ^0.3.34 -> ^1.0.0 age confidence

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
Medium Medium 5.3 CVE-2025-64718

Release Notes

langchain-ai/langchainjs (@​langchain/community)

v0.3.58

Compare Source


  • If you want to rebase/retry this PR, check this box

@ibm-mend-app ibm-mend-app bot added the security fix Security fix generated by WhiteSource label Nov 14, 2025
@ibm-mend-app
Copy link
Author

ibm-mend-app bot commented Nov 14, 2025

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm error code ERESOLVE
npm error ERESOLVE unable to resolve dependency tree
npm error
npm error While resolving: @arabold/[email protected]
npm error Found: @langchain/[email protected]
npm error node_modules/@langchain/core
npm error   peerOptional @langchain/core@">=0.1.29 <0.4.0" from @getzep/[email protected]
npm error   node_modules/@getzep/zep-cloud
npm error     peerOptional @getzep/zep-cloud@"^1.0.6" from @langchain/[email protected]
npm error     node_modules/@langchain/community
npm error       @langchain/community@"^1.0.0" from the root project
npm error   peer @langchain/core@">=0.3.58 <0.4.0" from [email protected]
npm error   node_modules/langchain
npm error     langchain@"0.3.28" from the root project
npm error     peerOptional langchain@">=0.1.19 <0.4.0" from @getzep/[email protected]
npm error     node_modules/@getzep/zep-cloud
npm error       peerOptional @getzep/zep-cloud@"^1.0.6" from @langchain/[email protected]
npm error       node_modules/@langchain/community
npm error         @langchain/community@"^1.0.0" from the root project
npm error   3 more (@langchain/aws, @langchain/google-genai, @langchain/google-vertexai)
npm error
npm error Could not resolve dependency:
npm error peer @langchain/core@"^1.0.0" from @langchain/[email protected]
npm error node_modules/@langchain/community
npm error   @langchain/community@"^1.0.0" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry
npm error this command with --force or --legacy-peer-deps
npm error to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /tmp/renovate/cache/others/npm/_logs/2025-11-14T13_09_53_355Z-eresolve-report.txt
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2025-11-14T13_09_53_355Z-debug-0.log

@github-actions github-actions bot enabled auto-merge (squash) November 14, 2025 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by WhiteSource

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants