Skip to content

chore(deps): fix the dependency audit (urllib3, litellm, pyjwt, pypdf) and cap letta - #39

Merged
wongk merged 2 commits into
mainfrom
fix/dep-audit-oct-advisories
Oct 5, 2026
Merged

wongk merged 2 commits into
mainfrom
fix/dep-audit-oct-advisories

Conversation

@wongk

@wongk wongk commented Oct 5, 2026 •

Copy link
Copy Markdown

Why

Dependency audit now fails on every PR (first seen on #38): new advisories were published since #37's run on Sep 25 against the locked urllib3, litellm, pyjwt and pypdf. Nothing in the repo changed; the advisories did.

What

  • Bumps only the four flagged packages in uv.lock: urllib3 2.7.0 → 2.8.0, litellm 1.91.0 → 1.91.5, pyjwt 2.13.0 → 2.15.1, pypdf 6.18.1 → 6.19.0.
  • litellm stays on the 1.91 line on purpose: 1.91.5 is the advisory's patch release, and the latest (1.104) changes litellm's model pricing table, which LemonCrow's cost and savings accounting reads (two tests failed on it: a model's context window and per-token price).
  • Caps the memory-server extra at letta<0.17. On Oct 4 the letta name on PyPI started shipping 0.34.x, which is "Letta Code", a terminal app, not the Letta server. Without the cap, any re-lock (including the --upgrade-package above) swaps the server for it and silently drops ~120 server dependencies from the lock. The locked version stays 0.16.8.

Verification

  • The CI audit command run locally against the new lock: No known vulnerabilities found, 8 ignored (the existing mitmproxy ignores).
  • uv lock --check passes; the lock diff is the four packages above and nothing else.
  • CI runs the full suite against the bumped versions.

wongk and others added 2 commits October 5, 2026 09:48
…cap letta below the Letta Code takeover

Co-Authored-By: lemoncrow <302591943+lemoncrow-agent[bot]@users.noreply.github.com>
…104 changes the model pricing table

Co-Authored-By: lemoncrow <302591943+lemoncrow-agent[bot]@users.noreply.github.com>
@wongk
wongk merged commit bff0d46 into main Oct 5, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant