dependabot[bot]
fb8aa17076
build(deps): bump the uv group across 7 directories with 1 update ( #541 )
...
Bumps the uv group with 1 update in the /common directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /fuzzer directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /orchestrator directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /patcher directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /program-model directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /seed-gen directory: [urllib3](https://github.com/urllib3/urllib3 ).
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: direct:production
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-11 19:08:41 +02:00
dependabot[bot]
ee57d23997
build(deps): bump the uv group across 7 directories with 2 updates ( #539 )
...
Bumps the uv group with 1 update in the /common directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /fuzzer directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 2 updates in the /orchestrator directory: [langchain-core](https://github.com/langchain-ai/langchain ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /patcher directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /program-model directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /seed-gen directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `python-multipart` from 0.0.26 to 0.0.27
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: indirect
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-11 09:35:11 +02:00
dependabot[bot]
b3e58516ac
build(deps): bump the uv group across 7 directories with 2 updates ( #535 )
...
Bumps the uv group with 1 update in the /common directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 2 updates in the /fuzzer directory: [python-dotenv](https://github.com/theskumar/python-dotenv ) and [lxml](https://github.com/lxml/lxml ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /orchestrator directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /patcher directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /program-model directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /seed-gen directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `lxml` from 5.3.2 to 6.1.0
- [Release notes](https://github.com/lxml/lxml/releases )
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt )
- [Commits](https://github.com/lxml/lxml/compare/lxml-5.3.2...lxml-6.1.0 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.0.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.0.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
---
updated-dependencies:
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: lxml
dependency-version: 6.1.0
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-27 09:26:55 +02:00
dependabot[bot]
ae58bb8e8a
build(deps): bump the uv group across 7 directories with 3 updates ( #533 )
...
Bumps the uv group with 1 update in the /common directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 1 update in the /fuzzer directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 2 updates in the /fuzzer_runner directory: [langchain-openai](https://github.com/langchain-ai/langchain ) and [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 1 update in the /orchestrator directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 2 updates in the /patcher directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ) and [langchain-text-splitters](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /program-model directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 1 update in the /seed-gen directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langchain-openai` from 1.1.12 to 1.1.14
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.1.12...langchain-openai==1.1.14 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langchain-text-splitters` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-text-splitters==1.1.1...langchain-text-splitters==1.1.2 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
---
updated-dependencies:
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langchain-openai
dependency-version: 1.1.14
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langchain-text-splitters
dependency-version: 1.1.2
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-27 09:08:43 +02:00
dependabot[bot]
db794fa1c7
build(deps): bump the uv group across 7 directories with 2 updates ( #531 )
...
Bumps the uv group with 2 updates in the /common directory: [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 2 updates in the /fuzzer directory: [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [pytest](https://github.com/pytest-dev/pytest ).
Bumps the uv group with 1 update in the /orchestrator directory: [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /patcher directory: [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 2 updates in the /program-model directory: [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /seed-gen directory: [python-multipart](https://github.com/Kludex/python-multipart ).
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
---
updated-dependencies:
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-20 10:03:24 +02:00
dependabot[bot]
a854399a12
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /fuzzer_runner ( #517 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:06:37 +02:00
dependabot[bot]
b0b460b501
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /fuzzer_runner ( #507 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:01:24 +02:00
Henrik Brodin
a20170e6c6
build(deps): bump langchain-core and cryptography for security fixes ( #502 )
...
Upgrade langchain-core ~=1.2.22 (resolves to 1.2.23) to fix high-severity
path traversal in legacy load_prompt functions (GHSA dependabot alerts).
Upgrade cryptography to 46.0.6 to fix low-severity incomplete DNS name
constraint enforcement.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-30 09:34:17 +02:00
Henrik Brodin
04469d6a53
build(deps): bump requests from 2.32.5 to 2.33.0 across all components ( #497 )
...
Consolidates Dependabot PRs #491-#496 into a single update.
Updates lock files for common, fuzzer, fuzzer_runner, orchestrator,
patcher, program-model, and seed-gen. Also bumps the orchestrator
pyproject.toml constraint from ~=2.32.3 to ~=2.33.0.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-27 10:00:04 +01:00
Henrik Brodin
385ea5ce93
Update langchain ecosystem and transitive dependencies ( #490 )
...
* build(deps): update langchain ecosystem and transitive dependencies
Upgrade dependencies across all components:
- langchain-core: 0.3.x -> 1.2.21
- langgraph: 0.6.x -> 1.0.10+
- langgraph-checkpoint: 3.x -> 4.0.1
- langchain: 0.3.x -> 1.2.x, langchain-openai: 0.3.x -> 1.1.x,
langchain-community: 0.3.x -> 0.4.x (ecosystem alignment)
- langfuse: 2.59.x -> 4.0.1 (compat with langchain 1.x)
- openlit: 1.36.x -> 1.38.x (remove langgraph ToolNode workaround)
- pydantic-settings: 2.7.x -> 2.10.x (langchain-community requirement)
- openai: 1.100.x -> 1.109.x (langchain-openai requirement)
- orjson: 3.11.5 -> 3.11.7
- PyJWT: 2.10.1 -> 2.12.1
- pyasn1: 0.6.2 -> 0.6.3
Code changes for langchain 1.x compatibility:
- common/llm.py: update imports for langchain-core and langfuse 4.x
- seed-gen/task.py: update langchain.prompts -> langchain_core.prompts
- Move langfuse to common[full] optional deps to avoid protobuf
conflict with clusterfuzz in fuzzer_runner
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* fix(ci): fix import sorting and ignore unfixed pygments CVE
- Sort imports in seed-gen/task.py to satisfy ruff I001
- Add CVE-2026-4539 (pygments ReDoS, no fix available) to pip-audit
ignore list in CI workflow
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* fix(ci): remove stale pip-audit ignores for orjson and protobuf
CVE-2025-67221 (orjson) and CVE-2026-0994 (protobuf) are fixed in the
versions now pinned in our lockfiles (orjson 3.11.7, protobuf 6.33.5).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* refactor: move langfuse import to top level in llm.py
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-27 09:33:50 +01:00
Henrik Brodin
b5aa20d0b4
build(deps): bump cryptography from 46.0.3 to 46.0.5 in remaining components ( #471 )
...
Bump cryptography to 46.0.5 in common, orchestrator, patcher,
program-model, seed-gen, and fuzzer_runner lock files to match
the fuzzer component which was already updated in #470 .
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-11 10:53:29 +01:00
Ronald Eytchison
3c3ae36a11
Fix fuzzer-runner missing transitive dependency and add tests ( #459 )
...
* Use openlit <1.36.6
Openlit >=1.36.6 has a bug with langgraph instrumentation.
Also add a test to seed-gen for when openlit is enabled
* Link to issue
* Fix CoverageBot.run_task and add test cases
* Add setuptools as an explicit dependency
This is because a transitive dependency via clusterfuzz depends on it
* Appease ruff
2026-01-27 23:13:53 +01:00
Ronald Eytchison
a31b670a2e
Fix: Use Openlit <1.36.6 to avoid bug with langgraph instrumentation ( #457 )
...
* Use openlit <1.36.6
Openlit >=1.36.6 has a bug with langgraph instrumentation.
Also add a test to seed-gen for when openlit is enabled
* Link to issue
2026-01-27 16:28:41 -05:00
Henrik Brodin
42fb0c126d
build(deps): pin protobuf to 3.20.3 in fuzzer_runner for OSS-Fuzz compatibility ( #456 )
...
Add uv constraint-dependencies to prevent protobuf from being updated
beyond 3.20.3, which is required for compatibility with OSS-Fuzz
infrastructure.
This prevents dependabot from creating PRs like #453 that would break
the fuzzer runner.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-27 22:25:04 +01:00
Henrik Brodin
b94a23eedb
build(deps): update openlit and pydantic to unblock mcp upgrade ( #455 )
...
Update dependency constraints to allow mcp 1.26.0:
- common: openlit ==1.35.0 -> ~=1.36.0
- orchestrator: pydantic ~=2.10.5 -> ~=2.11.0
The mcp upgrade was blocked because:
1. openlit 1.35.0 constrained openai-agents to older versions
2. pydantic <2.11.0 blocked mcp 1.23.0+ (requires pydantic>=2.11.0)
Resulting upgrades:
- mcp: 1.12.4 -> 1.26.0
- openlit: 1.35.0 -> 1.36.7
- pydantic: 2.10.6 -> 2.11.10
- openai-agents: 0.2.8 -> 0.3.3
Closes #450
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-27 14:15:53 +01:00
Henrik Brodin
ddb25601a9
build(deps): add fuzzer_runner dependency updates ( #451 )
...
Updates pyasn1 0.6.1 → 0.6.2 and urllib3 2.5.0 → 2.6.3 in fuzzer_runner.
These updates are from Dependabot PRs #448 and #449 .
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-27 13:31:22 +01:00
Riccardo Schirone
47f38b8863
fix: apply ruff import sorting fixes to all source files
...
Run `ruff check --fix` across all components to fix I001 import sorting
violations in src/ and test/ directories.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-26 15:17:12 +01:00
Dan Guido
0206c0f6e1
chore: update Python dependencies and pyproject.toml configs
...
Update dependencies across all components:
- Update ruff to v0.12.0
- Add ty (Astral type checker) as dev dependency
- Standardize pyproject.toml configurations
- Regenerate uv.lock files
Components updated:
- common
- orchestrator
- fuzzer
- fuzzer_runner
- patcher
- program-model
- seed-gen
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-26 11:44:48 +01:00
Dan Guido
95875b4ec5
fix: apply shellcheck and shfmt fixes to all shell scripts
...
Apply automated fixes from shellcheck and shfmt to all shell scripts:
- Quote variables to prevent word splitting and globbing
- Use $(...) instead of backticks for command substitution
- Add proper shebang and set -euo pipefail where missing
- Fix array handling and iteration patterns
- Consistent indentation (4 spaces)
- Remove unnecessary curly braces and simplify expressions
Files fixed:
- deployment/*.sh
- scripts/*.sh
- orchestrator/scripts/*.sh
- fuzzer_runner/runner.sh
- protoc.sh
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com >
2026-01-26 11:13:16 +01:00
Henrik Brodin
1d83c2daf4
Improve fuzzer logging ( #416 )
...
To help when integrating new harnesses with buttercup, this provides
more detailed logging about harness execution and exit.
2026-01-21 13:03:00 +01:00
Riccardo Schirone
143a59c236
fuzzer_runner: split fuzzer's dependencies ( #320 )
...
Before this commit, the fuzzer dependend on clusterfuzz, which uses
protobuf 3.20. Since fuzzer-bot depended on common subpackage as well
and also common (and the other packages) require protobuf, we had to use
protobuf 3.20 everywhere. This old dependency however means that a lot
of packages can't be used in their "newer" versions, because they depend
on newer protobuf versions.
This commit splits the fuzzer into a separate fuzzer-runner that is
executed in a separate process inside a separate venv. fuzzer-runner
executes the clusterfuzz-heavy operations (e.g. fuzzing) and isolates the
clusterfuzz dependency, so that the rest of the system can use newer
protobuf version.
* split `fuzzer-bot` in `fuzzer-runner` and `fuzzer-bot`
* have a "full" optional dependency group in `common`, including `openlit`
and `protobuf`, so that `fuzzer-runner` can use the lite version of `common`
without bringing those heavy deps
* move `FuzzConfiguration`/`BuildConfiguration` in a separate common file
that doesn't require to load all protobuf files. Again, in this way
other components can just depend on the `common` "lite" version and not
require protobuf stuff
* add `fuzzer-runner` as a separate venv inside the `fuzzer-bot` container
* add `RunnerProxy` class in fuzzer package to provide an interface to
interact with the fuzzer-runner binary.
2025-09-10 09:52:08 +02:00