Riccardo Schirone
85ccf9b9fe
fix(program-model): drop redundant deadsnakes PPA on Ubuntu 24.04 ( #554 )
...
python3.12 ships in noble's default archive (as seed-gen/patcher already
rely on); software-properties-common + add-apt-repository ppa:deadsnakes
only added an external launchpad.net dependency for no benefit.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-18 15:53:26 +02:00
Riccardo Schirone
1b8bd65986
fix(scripts): make install_uv resilient to missing env helper ( #547 )
...
The uv installer does not always create $HOME/.local/bin/env (older
versions, or when the install is skipped), so the unconditional `source`
broke setup with `No such file or directory`. Source the helper only if
it exists, prepend $HOME/.local/bin to PATH as a fallback, and fail
loudly if `uv` is still unreachable after install.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-18 15:53:06 +02:00
Riccardo Schirone
e516fe42fb
fix(setup-local): detect existing buildx, fall back to docker-buildx pkg ( #546 )
...
The install_docker helper hardcoded `docker-buildx-plugin` (Docker's
official apt repo name), so setup-local failed on systems where Docker
was installed from Ubuntu's repos, which ship the same plugin as
`docker-buildx`. Skip the install when `docker buildx version` already
works, and probe apt-cache to pick whichever package name is available.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-18 15:52:39 +02:00
Riccardo Schirone
ec7031c5ef
fix(common): use budgeted LITELLM_API_KEY so LITELLM_MAX_BUDGET is enforced ( #550 )
...
* fix(common): use budgeted LITELLM_API_KEY for the LLM client
create_llm() authenticated with BUTTERCUP_LITELLM_KEY, which
litellm_config.yaml defines as general_settings.master_key. LiteLLM
master keys bypass all budget/rate enforcement, so LITELLM_MAX_BUDGET
had no effect — an e2e run with --budget 1 spent ~$4.77 unthrottled
with every /chat/completions returning 200.
The budgeted virtual key (llm-user, created with max_budget=
$LITELLM_MAX_BUDGET by litellm-user-keys-setup) is already plumbed:
seed-gen/patcher entrypoints export LITELLM_API_KEY from the mounted
key file. create_llm() just never read it.
Prefer LITELLM_API_KEY when set; fall back to BUTTERCUP_LITELLM_KEY so
environments without a provisioned budgeted key are unaffected.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
* chore(compose): document LITELLM_MAX_BUDGET in env.template (complements #550 )
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-18 15:52:14 +02:00
dependabot[bot]
4cc95c6659
build(deps): bump langchain-classic ( #543 )
...
Bumps the uv group with 1 update in the /patcher directory: [langchain-classic](https://github.com/langchain-ai/langchain ).
Updates `langchain-classic` from 1.0.3 to 1.0.7
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-classic==1.0.3...langchain-classic==1.0.7 )
---
updated-dependencies:
- dependency-name: langchain-classic
dependency-version: 1.0.7
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-14 08:17:19 +02:00
dependabot[bot]
fb8aa17076
build(deps): bump the uv group across 7 directories with 1 update ( #541 )
...
Bumps the uv group with 1 update in the /common directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /fuzzer directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /orchestrator directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /patcher directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /program-model directory: [urllib3](https://github.com/urllib3/urllib3 ).
Bumps the uv group with 1 update in the /seed-gen directory: [urllib3](https://github.com/urllib3/urllib3 ).
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: direct:production
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-11 19:08:41 +02:00
dependabot[bot]
683044d5df
build(deps): bump langchain-core ( #540 )
...
Bumps the uv group with 1 update in the /orchestrator directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-11 10:36:31 +02:00
dependabot[bot]
ee57d23997
build(deps): bump the uv group across 7 directories with 2 updates ( #539 )
...
Bumps the uv group with 1 update in the /common directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /fuzzer directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 2 updates in the /orchestrator directory: [langchain-core](https://github.com/langchain-ai/langchain ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /patcher directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /program-model directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /seed-gen directory: [langchain-core](https://github.com/langchain-ai/langchain ).
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `python-multipart` from 0.0.26 to 0.0.27
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
Updates `langchain-core` from 1.2.31 to 1.3.3
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.31...langchain-core==1.3.3 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: indirect
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.3.3
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-11 09:35:11 +02:00
Henrik Brodin
0f67b4812d
build(deps): bump langchain-openai to 1.1.14 and pytest to 9.0.3 ( #537 )
...
Closes Dependabot alerts:
- #190-195: langchain-openai SSRF via DNS rebinding (GHSA-r7w7-9xr2-qq2r)
- #171-173: pytest tmpdir handling
Required transitive bumps:
- openlit 1.38 -> 1.41 (to allow openai>=2)
- pytest-asyncio 0.25 -> 1.3 (for pytest 9 compatibility)
- openai 1.109 -> 2.x (required by langchain-openai 1.1.14)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-04-28 15:21:40 +02:00
Henrik Brodin
a3d805cb35
ci: shell-quote env values in system-integration workflow ( #536 )
...
* ci: shell-quote env values for system integration tests
Two bugs in the env file step prevented the weekly System Integration
Tests from ever passing since #427 (2026-01-26):
1. The deletion regex `/^KEY=/` did not match the template's
`export KEY=replace-me` lines, leaving stale `replace-me` placeholders
in the file alongside the appended real values.
2. Appended values were not shell-quoted, so `source ./env` in
deployment/crs-architecture.sh treated whitespace and metacharacters
as shell syntax. The `OTEL_TOKEN` secret (a `Bearer <token>` header)
tripped this with `command not found` on the token component.
The same gap was a code-execution sink: a secret containing `$(...)` or
backticks would execute on the runner at source time.
Fix: strip with `(export[[:space:]]+)?` so template lines are actually
removed, and write with `printf 'export %s=%q\n'` so every value is
shell-escaped — defending against both whitespace and injection.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
* ci: drop placeholder block from ci-env.template
The placeholder lines (`export KEY=replace-me`) only existed because the
pre-rewrite step substituted into them with `sed -i "s|KEY=.*|...|"`.
The new `printf %q` write path doesn't need them, so removing them at
the source eliminates the entire delete-then-rewrite dance.
Drops `strip_var` and the for-loop. The workflow step is now: copy the
static template, then append shell-quoted assignments for every secret
the env: block injects. GHCR_AUTH is no longer defined at all, so the
`[ -n "$GHCR_AUTH" ]` warning branch in crs-architecture.sh:63 fires as
intended.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-04-27 13:06:47 +02:00
dependabot[bot]
b3e58516ac
build(deps): bump the uv group across 7 directories with 2 updates ( #535 )
...
Bumps the uv group with 1 update in the /common directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 2 updates in the /fuzzer directory: [python-dotenv](https://github.com/theskumar/python-dotenv ) and [lxml](https://github.com/lxml/lxml ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /orchestrator directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /patcher directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /program-model directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Bumps the uv group with 1 update in the /seed-gen directory: [python-dotenv](https://github.com/theskumar/python-dotenv ).
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `lxml` from 5.3.2 to 6.1.0
- [Release notes](https://github.com/lxml/lxml/releases )
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt )
- [Commits](https://github.com/lxml/lxml/compare/lxml-5.3.2...lxml-6.1.0 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.0.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
Updates `python-dotenv` from 1.0.1 to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2 )
---
updated-dependencies:
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: lxml
dependency-version: 6.1.0
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: indirect
dependency-group: uv
- dependency-name: python-dotenv
dependency-version: 1.2.2
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-27 09:26:55 +02:00
dependabot[bot]
7f8c75a49e
build(deps): bump astral-sh/setup-uv ( #534 )
...
Bumps the actions group with 1 update in the / directory: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ).
Updates `astral-sh/setup-uv` from 8.0.0 to 8.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/cec208311dfd045dd5311c1add060b2062131d57...08807647e7069bb48b6ef5acd8ec9567f424441b )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 8.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-27 09:22:32 +02:00
dependabot[bot]
ae58bb8e8a
build(deps): bump the uv group across 7 directories with 3 updates ( #533 )
...
Bumps the uv group with 1 update in the /common directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 1 update in the /fuzzer directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 2 updates in the /fuzzer_runner directory: [langchain-openai](https://github.com/langchain-ai/langchain ) and [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 1 update in the /orchestrator directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 2 updates in the /patcher directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ) and [langchain-text-splitters](https://github.com/langchain-ai/langchain ).
Bumps the uv group with 1 update in the /program-model directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Bumps the uv group with 1 update in the /seed-gen directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ).
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langchain-openai` from 1.1.12 to 1.1.14
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.1.12...langchain-openai==1.1.14 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langchain-text-splitters` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-text-splitters==1.1.1...langchain-text-splitters==1.1.2 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
Updates `langsmith` from 0.6.5 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.6.5...v0.7.31 )
---
updated-dependencies:
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langchain-openai
dependency-version: 1.1.14
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langchain-text-splitters
dependency-version: 1.1.2
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-27 09:08:43 +02:00
dependabot[bot]
db794fa1c7
build(deps): bump the uv group across 7 directories with 2 updates ( #531 )
...
Bumps the uv group with 2 updates in the /common directory: [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 2 updates in the /fuzzer directory: [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /fuzzer_runner directory: [pytest](https://github.com/pytest-dev/pytest ).
Bumps the uv group with 1 update in the /orchestrator directory: [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /patcher directory: [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 2 updates in the /program-model directory: [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Bumps the uv group with 1 update in the /seed-gen directory: [python-multipart](https://github.com/Kludex/python-multipart ).
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `pytest` from 8.3.5 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
---
updated-dependencies:
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:development
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-20 10:03:24 +02:00
dependabot[bot]
9ad65cf91c
build(deps): bump the actions group with 3 updates ( #532 )
...
Bumps the actions group with 3 updates: [actions/cache](https://github.com/actions/cache ), [actions/upload-artifact](https://github.com/actions/upload-artifact ) and [docker/build-push-action](https://github.com/docker/build-push-action ).
Updates `actions/cache` from 5.0.4 to 5.0.5
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae )
Updates `actions/upload-artifact` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a )
Updates `docker/build-push-action` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...bcafcacb16a39f128d818304e6c9c0c18556b85f )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: 5.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: actions/upload-artifact
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: docker/build-push-action
dependency-version: 7.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-20 09:44:52 +02:00
dependabot[bot]
c7c47eba55
build(deps): bump docker/login-action in the actions group ( #521 )
...
Bumps the actions group with 1 update: [docker/login-action](https://github.com/docker/login-action ).
Updates `docker/login-action` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/b45d80f862d83dbcd57f89517bcf500b2ab88fb2...4907a6ddec9925e35a0a9e82d7399ccc52663121 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-13 10:00:27 +02:00
dependabot[bot]
6703c453e8
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /patcher ( #520 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:06:55 +02:00
dependabot[bot]
ec41f764cd
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /common ( #518 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:06:48 +02:00
dependabot[bot]
a854399a12
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /fuzzer_runner ( #517 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:06:37 +02:00
dependabot[bot]
8b36cb86ea
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /orchestrator ( #519 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:06:28 +02:00
dependabot[bot]
0276f04eb8
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /common ( #515 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:05:43 +02:00
dependabot[bot]
c8196929ee
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /fuzzer ( #516 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:05:24 +02:00
dependabot[bot]
5add488707
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /fuzzer ( #514 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:03:33 +02:00
dependabot[bot]
07386f6bc7
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /seed-gen ( #513 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:03:13 +02:00
dependabot[bot]
5239596045
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /patcher ( #512 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:02:56 +02:00
dependabot[bot]
e3c2ccc1bf
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /orchestrator ( #511 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:02:33 +02:00
dependabot[bot]
3340b93491
build(deps): bump langchain-core from 1.2.23 to 1.2.28 in /program-model ( #510 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.23 to 1.2.28.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.23...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:02:15 +02:00
dependabot[bot]
ea0a3e1cae
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /program-model ( #509 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:01:57 +02:00
dependabot[bot]
f62ba9cfad
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /seed-gen ( #508 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:01:41 +02:00
dependabot[bot]
b0b460b501
build(deps): bump cryptography from 46.0.6 to 46.0.7 in /fuzzer_runner ( #507 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:01:24 +02:00
dependabot[bot]
db9532728d
build(deps): bump the actions group with 2 updates ( #505 )
...
Bumps the actions group with 2 updates: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) and [codecov/codecov-action](https://github.com/codecov/codecov-action ).
Updates `astral-sh/setup-uv` from 7.6.0 to 8.0.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/37802adc94f370d6bfd71619e3f0bf239e1f3b78...cec208311dfd045dd5311c1add060b2062131d57 )
Updates `codecov/codecov-action` from 5.5.2 to 6.0.0
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/671740ac38dd9b0130fbe1cec585b89eea48d3de...57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 8.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: codecov/codecov-action
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:01:05 +02:00
dependabot[bot]
d98c7a5e71
build(deps): bump aiohttp from 3.13.3 to 3.13.4 in /patcher ( #504 )
...
---
updated-dependencies:
- dependency-name: aiohttp
dependency-version: 3.13.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 09:00:28 +02:00
dependabot[bot]
946d5ba6d9
build(deps): bump pygments from 2.19.2 to 2.20.0 in /orchestrator ( #503 )
...
Bumps [pygments](https://github.com/pygments/pygments ) from 2.19.2 to 2.20.0.
- [Release notes](https://github.com/pygments/pygments/releases )
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES )
- [Commits](https://github.com/pygments/pygments/compare/2.19.2...2.20.0 )
---
updated-dependencies:
- dependency-name: pygments
dependency-version: 2.20.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-30 23:16:09 +02:00
Henrik Brodin
a20170e6c6
build(deps): bump langchain-core and cryptography for security fixes ( #502 )
...
Upgrade langchain-core ~=1.2.22 (resolves to 1.2.23) to fix high-severity
path traversal in legacy load_prompt functions (GHSA dependabot alerts).
Upgrade cryptography to 46.0.6 to fix low-severity incomplete DNS name
constraint enforcement.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-30 09:34:17 +02:00
dependabot[bot]
54acdcef42
build(deps): bump cryptography from 46.0.5 to 46.0.6 in /patcher ( #501 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.5 to 46.0.6.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-30 08:26:11 +02:00
dependabot[bot]
3519f1d729
build(deps): bump cryptography from 46.0.5 to 46.0.6 in /fuzzer ( #500 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.5 to 46.0.6.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-30 08:25:39 +02:00
dependabot[bot]
6d869033b6
build(deps): bump langchain-core from 1.2.21 to 1.2.22 in /common ( #499 )
...
Bumps [langchain-core](https://github.com/langchain-ai/langchain ) from 1.2.21 to 1.2.22.
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.21...langchain-core==1.2.22 )
---
updated-dependencies:
- dependency-name: langchain-core
dependency-version: 1.2.22
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-30 08:24:44 +02:00
dependabot[bot]
8d0048f577
build(deps): bump the actions group across 1 directory with 8 updates ( #498 )
...
Bumps the actions group with 8 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) | `7.3.1` | `7.6.0` |
| [actions/cache](https://github.com/actions/cache ) | `5.0.3` | `5.0.4` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) | `3.12.0` | `4.0.0` |
| [docker/login-action](https://github.com/docker/login-action ) | `3.7.0` | `4.0.0` |
| [docker/metadata-action](https://github.com/docker/metadata-action ) | `5.10.0` | `6.0.0` |
| [docker/build-push-action](https://github.com/docker/build-push-action ) | `6.19.2` | `7.0.0` |
| [dorny/paths-filter](https://github.com/dorny/paths-filter ) | `3.0.2` | `4.0.1` |
| [actions/download-artifact](https://github.com/actions/download-artifact ) | `8.0.0` | `8.0.1` |
Updates `astral-sh/setup-uv` from 7.3.1 to 7.6.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/5a095e7a2014a4212f075830d4f7277575a9d098...37802adc94f370d6bfd71619e3f0bf239e1f3b78 )
Updates `actions/cache` from 5.0.3 to 5.0.4
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/cdf6c1fa76f9f475f3d7449005a359c84ca0f306...668228422ae6a00e4ad889ee87cd7109ec5666a7 )
Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/8d2750c68a42422c14e847fe6c8ac0403b4cbd6f...4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd )
Updates `docker/login-action` from 3.7.0 to 4.0.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...b45d80f862d83dbcd57f89517bcf500b2ab88fb2 )
Updates `docker/metadata-action` from 5.10.0 to 6.0.0
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](https://github.com/docker/metadata-action/compare/c299e40c65443455700f0fdfc63efafe5b349051...030e881283bb7a6894de51c315a6bfe6a94e05cf )
Updates `docker/build-push-action` from 6.19.2 to 7.0.0
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/10e90e3645eae34f1e60eeb005ba3a3d33f178e8...d08e5c354a6adb9ed34480a06d141179aa583294 )
Updates `dorny/paths-filter` from 3.0.2 to 4.0.1
- [Release notes](https://github.com/dorny/paths-filter/releases )
- [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md )
- [Commits](https://github.com/dorny/paths-filter/compare/de90cc6fb38fc0963ad72b210f1f284cd68cea36...fbd0ab8f3e69293af611ebaee6363fc25e6d187d )
Updates `actions/download-artifact` from 8.0.0 to 8.0.1
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3...3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 7.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: actions/cache
dependency-version: 5.0.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: docker/setup-buildx-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/login-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/metadata-action
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: docker/build-push-action
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: dorny/paths-filter
dependency-version: 4.0.1
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/download-artifact
dependency-version: 8.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-27 10:28:42 +01:00
Henrik Brodin
04469d6a53
build(deps): bump requests from 2.32.5 to 2.33.0 across all components ( #497 )
...
Consolidates Dependabot PRs #491-#496 into a single update.
Updates lock files for common, fuzzer, fuzzer_runner, orchestrator,
patcher, program-model, and seed-gen. Also bumps the orchestrator
pyproject.toml constraint from ~=2.32.3 to ~=2.33.0.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-27 10:00:04 +01:00
Henrik Brodin
385ea5ce93
Update langchain ecosystem and transitive dependencies ( #490 )
...
* build(deps): update langchain ecosystem and transitive dependencies
Upgrade dependencies across all components:
- langchain-core: 0.3.x -> 1.2.21
- langgraph: 0.6.x -> 1.0.10+
- langgraph-checkpoint: 3.x -> 4.0.1
- langchain: 0.3.x -> 1.2.x, langchain-openai: 0.3.x -> 1.1.x,
langchain-community: 0.3.x -> 0.4.x (ecosystem alignment)
- langfuse: 2.59.x -> 4.0.1 (compat with langchain 1.x)
- openlit: 1.36.x -> 1.38.x (remove langgraph ToolNode workaround)
- pydantic-settings: 2.7.x -> 2.10.x (langchain-community requirement)
- openai: 1.100.x -> 1.109.x (langchain-openai requirement)
- orjson: 3.11.5 -> 3.11.7
- PyJWT: 2.10.1 -> 2.12.1
- pyasn1: 0.6.2 -> 0.6.3
Code changes for langchain 1.x compatibility:
- common/llm.py: update imports for langchain-core and langfuse 4.x
- seed-gen/task.py: update langchain.prompts -> langchain_core.prompts
- Move langfuse to common[full] optional deps to avoid protobuf
conflict with clusterfuzz in fuzzer_runner
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* fix(ci): fix import sorting and ignore unfixed pygments CVE
- Sort imports in seed-gen/task.py to satisfy ruff I001
- Add CVE-2026-4539 (pygments ReDoS, no fix available) to pip-audit
ignore list in CI workflow
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* fix(ci): remove stale pip-audit ignores for orjson and protobuf
CVE-2025-67221 (orjson) and CVE-2026-0994 (protobuf) are fixed in the
versions now pinned in our lockfiles (orjson 3.11.7, protobuf 6.33.5).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* refactor: move langfuse import to top level in llm.py
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
2026-03-27 09:33:50 +01:00
dependabot[bot]
55a4c64a19
build(deps): bump the actions group with 3 updates ( #478 )
...
Bumps the actions group with 3 updates: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ), [actions/upload-artifact](https://github.com/actions/upload-artifact ) and [actions/download-artifact](https://github.com/actions/download-artifact ).
Updates `astral-sh/setup-uv` from 7.3.0 to 7.3.1
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/eac588ad8def6316056a12d4907a9d4d84ff7a3b...5a095e7a2014a4212f075830d4f7277575a9d098 )
Updates `actions/upload-artifact` from 6.0.0 to 7.0.0
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/b7c566a772e6b6bfb58ed0dc250532a479d7789f...bbbca2ddaa5d8feaa63e36b76fdaad77386f024f )
Updates `actions/download-artifact` from 7.0.0 to 8.0.0
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/37930b1c2abaa49bbe596cd826c3c89aef350131...70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 7.3.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: actions/upload-artifact
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/download-artifact
dependency-version: 8.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 09:48:36 +01:00
dependabot[bot]
d9e7d0b60b
build(deps): bump docker/build-push-action in the actions group ( #476 )
...
Bumps the actions group with 1 update: [docker/build-push-action](https://github.com/docker/build-push-action ).
Updates `docker/build-push-action` from 6.18.0 to 6.19.2
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/263435318d21b8e681c14492fe198d362a7d2c83...10e90e3645eae34f1e60eeb005ba3a3d33f178e8 )
---
updated-dependencies:
- dependency-name: docker/build-push-action
dependency-version: 6.19.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-02 08:53:41 +01:00
Akshith G
1adc774d33
docs: add Colima and docker-buildx setup instructions for macOS ( #474 )
...
macOS users using Colima instead of Docker Desktop were hitting
missing buildx errors and had no documentation to guide them.
Add Colima as a supported Docker runtime, document buildx
installation, and ensure setup-local installs buildx automatically.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-23 09:15:34 -08:00
dependabot[bot]
ed723f40de
build(deps): bump astral-sh/setup-uv in the actions group ( #473 )
...
Bumps the actions group with 1 update: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ).
Updates `astral-sh/setup-uv` from 7.2.0 to 7.3.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](https://github.com/astral-sh/setup-uv/compare/61cb8a9741eeb8a550a1b8544337180c0fc8476b...eac588ad8def6316056a12d4907a9d4d84ff7a3b )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 09:55:09 +01:00
Ronald Eytchison
77a3e77936
Create minikube config for a large machine (16 CPU, 128 GB) ( #469 )
...
* Create minikube config for a large machine (16 CPU, 128 GB)
* Address PR feedback and scale services
- Increase redis memory
- Disable redis in-memory backups to conserve memory
- Increase build bot replicas
- Increase dind CPU/Memory given build bot scaling
- Set reasonable limits for merger-bot and pov-reproducer
- increase coverage bot memory
* Configure /dev/shm size for corpus tmpfs
2026-02-12 08:32:55 -05:00
Henrik Brodin
fb9a40cfc9
docs: add Redis testing guidance to CLAUDE.md ( #472 )
...
Many component test suites require a running Redis instance.
Document how to start a temporary Redis container via Docker
so these tests are not skipped or left failing.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-11 10:53:44 +01:00
Henrik Brodin
b5aa20d0b4
build(deps): bump cryptography from 46.0.3 to 46.0.5 in remaining components ( #471 )
...
Bump cryptography to 46.0.5 in common, orchestrator, patcher,
program-model, seed-gen, and fuzzer_runner lock files to match
the fuzzer component which was already updated in #470 .
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-11 10:53:29 +01:00
dependabot[bot]
e6aa09c831
build(deps): bump cryptography from 46.0.3 to 46.0.5 in /fuzzer ( #470 )
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 46.0.3 to 46.0.5.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.3...46.0.5 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-11 08:58:31 +01:00
dependabot[bot]
7f10615d76
build(deps): bump the actions group with 2 updates ( #466 )
...
Bumps the actions group with 2 updates: [actions/cache](https://github.com/actions/cache ) and [docker/login-action](https://github.com/docker/login-action ).
Updates `actions/cache` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/8b402f58fbc84540c8b491a91e594a4576fec3d7...cdf6c1fa76f9f475f3d7449005a359c84ca0f306 )
Updates `docker/login-action` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/5e57cd118135c172c3672efd75eb46360885c0ef...c94ce9fb468520275223c153574b00df6fe4bcc9 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: 5.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: docker/login-action
dependency-version: 3.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-09 09:12:28 +01:00
Henrik Brodin
09f2980ff9
Add optional tmpfs storage for fuzzing corpus ( #461 )
...
* Add optional tmpfs storage for fuzzing corpus
Add support for storing the node-local fuzzing corpus in tmpfs (RAM-based
filesystem) for improved I/O performance during fuzzing operations.
Key changes:
- Add CORPUS_TMPFS_PATH environment variable to configure tmpfs location
- Add cross-filesystem safe operations (copy+delete fallback for EXDEV)
- Update Corpus class to use tmpfs path when enabled while maintaining
correct remote path calculation for rsync synchronization
- Add Helm chart configuration using /dev/shm (requires no host setup)
- Update fuzzer-bot, coverage-bot, merger-bot, seed-gen deployments
The feature is disabled by default. Enable by setting
global.volumes.corpusTmpfs.enabled=true in values.yaml.
Uses hostPath to /dev/shm/buttercup-corpus which is available on
Linux systems without requiring any Kubernetes host configuration.
2026-02-06 20:10:45 +01:00