pip-audit flagged the 46.0.7 pin: wheels before 48.0.1 statically link a vulnerable OpenSSL. 48.0.1 is the fix version.
23 lines
1 KiB
Text
23 lines
1 KiB
Text
langgraph==1.2.6
|
|
# Durable SQLite checkpointer for the R720 agent-team Plane-2 pipeline (design D9).
|
|
langgraph-checkpoint-sqlite==3.1.0
|
|
langchain-anthropic==1.4.6
|
|
langchain-openai==1.3.2
|
|
langchain-google-genai==4.2.5
|
|
langchain-community==0.4.2
|
|
composio-langgraph==0.15.0
|
|
python-dotenv==1.2.2
|
|
# WS1 agent-team HTTP API (agent_team/api.py): FastAPI app + uvicorn ASGI server.
|
|
fastapi==0.136.1
|
|
uvicorn==0.46.0
|
|
# GitHub App installation-token minting for the agent-team P3 dispatcher
|
|
# (agent_team/github_app.py): RS256 JWT (PyJWT) signed with the App private key,
|
|
# exchanged for a short-lived installation token. cryptography backs RS256.
|
|
PyJWT==2.13.0
|
|
# >=48.0.1: earlier wheels statically link a vulnerable OpenSSL (GHSA-537c-gmf6-5ccf).
|
|
cryptography==48.0.1
|
|
# Runtime HTTP client for the agent-team P3 App-dispatch seams
|
|
# (github_app.mint_installation_token, dispatcher.app_workflow_dispatcher,
|
|
# dispatcher.app_run_locator) and the CI fetcher/transport. Pinned first-class
|
|
# (was previously relied on only as a transitive dep of langchain-community).
|
|
requests==2.34.2
|