Skip to content

Commit b740d01

Browse files
security: require Python 3.10+, dropping a vulnerable resolution branch (#14)
* security: require Python 3.10+, dropping a vulnerable resolution branch #11 closed the critical langchain-core advisory, but had a side effect worth correcting. langchain-core 1.6.1 requires Python 3.10+, while this package still declared `requires-python = ">=3.9"`. uv therefore split the resolution, pinning an older set for the 3.9 branch: urllib3 2.6.3 (python < 3.10) vs 2.7.0 (>= 3.10) requests 2.32.5 (python < 3.10) vs 2.34.2 (>= 3.10) orjson 3.11.5 (python < 3.10) vs 3.12.0 (>= 3.10) Anyone installing under 3.9 got the left-hand column, which carries three high and one medium advisory: urllib3 2.6.3 GHSA-mf9v-mfxr-j63j decompression-bomb bypass high urllib3 2.6.3 GHSA-qccp-gfcp-xxvc headers forwarded cross-origin high orjson 3.11.5 GHSA-hx9q-6w63-j58v unbounded recursion high requests 2.32.5 GHSA-gc5v-m9x4-r6x2 insecure temp file reuse medium Raising `requires-python` to >=3.10 collapses the split. It is also honest: the package's primary dependency dropped 3.9, so claiming 3.9 support was already inaccurate. - `requires-python` >=3.9 -> >=3.10 - removed the `Programming Language :: Python :: 3.9` classifier - CI matrix 3.9-3.13 -> 3.10-3.13 ## Verification Every dual resolution is gone except `websockets` (16.1.1 / 17.1), and neither of those carries an advisory. Single resolutions now: langchain-core 1.6.1 urllib3 2.7.0 requests 2.34.2 orjson 3.12.0 h11 0.16.0 `uv sync --frozen --all-groups` clean; imports resolve and VectorizeRetriever still has BaseRetriever in its MRO; urllib3 2.7.0 and requests 2.34.2 confirmed at runtime. Claude-Session: https://claude.ai/code/session_01SK2htrNEFAj2VuxKWqFavo * fix: lint the matrix Pythons, clear anyio, adopt 3.10 annotations Three things this PR needed to go green and to close the critical anyio alert (#23, GHSA-82r6-8w77-94w6): - lint.yml declared a 3.9/3.13 matrix but setup-python read python-version-file instead, so it installed the newest release (3.14), which pyo3-ffi 0.22 cannot build against. Use the matrix, and drop 3.9 to match requires-python >=3.10. - Re-lock anyio. With 3.9 gone the resolution no longer splits, so the only anyio is 4.15.1. Before, the 3.9 branch was pinned to a vulnerable 4.12.1 because anyio's fixed releases require Python 3.10+. - ruff's UP045 now applies (Optional[str] -> str | None) since the minimum is 3.10; applied with ruff --fix. Verified locally on 3.10 and 3.13: ruff format --check, ruff check, mypy all pass. pytest needs VECTORIZE_TOKEN and a paid-plan account (CI fails with UPGRADE_REQUIRED), so it is environmental and unchanged by this PR. Claude-Session: https://claude.ai/code/session_014J7s5yzoVEqoZ8LmnD8bQd
1 parent 4a9c777 commit b740d01

5 files changed

Lines changed: 74 additions & 638 deletions

File tree

‎.github/workflows/lint.yml‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717
working-directory: ./langchain
1818
strategy:
1919
matrix:
20-
python-version: ['3.9', '3.13']
20+
python-version: ['3.10', '3.13']
2121
steps:
2222
- uses: actions/checkout@v4
2323
with:
@@ -30,7 +30,10 @@ jobs:
3030
- name: "Set up Python"
3131
uses: actions/setup-python@v5
3232
with:
33-
python-version-file: "langchain/pyproject.toml"
33+
# Use the matrix version. Reading pyproject's requires-python made
34+
# setup-python pick the newest release (3.14), which pyo3-ffi 0.22
35+
# cannot build against, so the matrix was never actually tested.
36+
python-version: ${{ matrix.python-version }}
3437
- name: Restore uv cache
3538
uses: actions/cache@v4
3639
with:

‎.github/workflows/python_test.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717
working-directory: ./langchain
1818
strategy:
1919
matrix:
20-
python-version: ['3.9', '3.10', '3.11', '3.12', '3.13']
20+
python-version: ['3.10', '3.11', '3.12', '3.13']
2121
steps:
2222
- uses: actions/checkout@v4
2323
with:

‎langchain/langchain_vectorize/retrievers.py‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
from __future__ import annotations
44

5-
from typing import TYPE_CHECKING, Any, Literal, Optional
5+
from typing import TYPE_CHECKING, Any, Literal
66

77
from langchain_core.documents import Document
88
from langchain_core.retrievers import BaseRetriever
@@ -109,9 +109,9 @@ def format_docs(docs):
109109
"""The Vectorize API token."""
110110
environment: Literal["prod", "dev", "local", "staging"] = "prod"
111111
"""The Vectorize API environment."""
112-
organization: Optional[str] = None
112+
organization: str | None = None
113113
"""The Vectorize organization ID."""
114-
pipeline_id: Optional[str] = None
114+
pipeline_id: str | None = None
115115
"""The Vectorize pipeline ID."""
116116
num_results: int = 5
117117
"""The number of documents to return."""

‎langchain/pyproject.toml‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords = ["langchain", "vectorize", "retrieval", "search"]
77
authors = [
88
{ name = "Vectorize", email = "contact@vectorize.io" },
99
]
10-
requires-python = ">=3.9"
10+
requires-python = ">=3.10"
1111
dependencies = [
1212
"langchain-core>=0.3.45",
1313
"vectorize-client>=0.4.0",
@@ -17,7 +17,6 @@ classifiers = [
1717
"Intended Audience :: Developers",
1818
"Topic :: Software Development :: Build Tools",
1919
"License :: OSI Approved :: MIT License",
20-
"Programming Language :: Python :: 3.9",
2120
"Programming Language :: Python :: 3.10",
2221
"Programming Language :: Python :: 3.11",
2322
"Programming Language :: Python :: 3.12",

0 commit comments

Comments
 (0)