litellm/ui
yucheng-berri 3ddffa3da8
fix(deps): bump osv-flagged dependencies to clear known CVEs (#31122)
Scoped to the customer-shipped dependencies on this line: cryptography 48.0.1,
python-multipart 0.0.32, pypdf 6.13.3, and semantic-router >=0.1.15,<1.0 (the
pinned 0.1.12 is yanked, CVE-2026-42208); mlflow is loosened to >=3.11.1,<4.0 so
cryptography can move, and the dashboard js-yaml 4.2.0 and ws 8.21.0 overrides are
bumped. uv.lock and package-lock.json are regenerated on this line. The
osv-scanner.toml and osv-scan.yml hunks are dropped (absent on 1.85.x), and the
non-shipping CI/test stack (langchain, langgraph, vcrpy, aiohttp) is left out.
semantic-router >=0.1.15,<1.0 is content-verified present on
litellm_internal_staging (via aggregator f49707bc66) and matches the 1.84.x
backport of this PR (1a56faa750).

(cherry picked from commit a8a1472428)
2026-06-23 21:44:31 -07:00
..
litellm-dashboard fix(deps): bump osv-flagged dependencies to clear known CVEs (#31122) 2026-06-23 21:44:31 -07:00