Skip to content

[Snyk] Upgrade @langchain/openai from 1.2.7 to 1.5.3 - #1045

Open
CMiville42 wants to merge 1 commit into
mainfrom
snyk-upgrade-062e58f26b66f1cff553c0bdfd238a9c
Open

[Snyk] Upgrade @langchain/openai from 1.2.7 to 1.5.3#1045
CMiville42 wants to merge 1 commit into
mainfrom
snyk-upgrade-062e58f26b66f1cff553c0bdfd238a9c

Conversation

@CMiville42

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to upgrade @langchain/openai from 1.2.7 to 1.5.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 30 versions ahead of your current version.

  • The recommended version was released a month ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Interpretation Conflict
SNYK-JS-FASTURI-18021349
49 No Known Exploit
high severity Directory Traversal
SNYK-JS-HONONODESERVER-18170326
49 No Known Exploit
high severity Deserialization of Untrusted Data
SNYK-JS-LANGSMITH-16658749
49 No Known Exploit
medium severity Improper Check for Unusual or Exceptional Conditions
SNYK-JS-PROTOBUFJSCODEGEN-16643292
49 No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BODYPARSER-17906397
49 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-LANGSMITH-15969264
49 Proof of Concept
medium severity Insertion of Sensitive Information into Log File
SNYK-JS-LANGSMITH-16082039
49 No Known Exploit

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.

Release notes
Package name: @langchain/openai
  • 1.5.3 - 2026-06-23
  • 1.5.2 - 2026-06-22

    Patch Changes

  • 1.5.1 - 2026-06-18
  • 1.5.0 - 2026-06-17
  • 1.4.7 - 2026-05-21
  • 1.4.6 - 2026-05-18
  • 1.4.5 - 2026-04-27

    Patch Changes

  • 1.4.4 - 2026-04-10

    Patch Changes

    • Updated dependencies [988ca7d]:
      • @ langchain/openai@1.5.4
  • 1.4.3 - 2026-04-07

    Patch Changes

    • #11200 08e5888 Thanks @ hntrl! - fix(aws): normalize and safely replay Bedrock reasoning blocks

      Emit standard reasoning blocks with preserved signatures, omit incomplete signature-only reasoning during replay, and retain compatibility with legacy and redacted Bedrock reasoning.

  • 1.4.2 - 2026-04-03
  • 1.4.1 - 2026-03-31
  • 1.4.0 - 2026-03-30
  • 1.3.1 - 2026-03-24
  • 1.3.0 - 2026-03-17
  • 1.3.0-dev-1773962633795 - 2026-03-19
  • 1.3.0-dev-1773786580575 - 2026-03-17
  • 1.3.0-dev-1773785150055 - 2026-03-17
  • 1.3.0-dev-1773776071697 - 2026-03-17
  • 1.3.0-dev-1773712098100 - 2026-03-17
  • 1.3.0-dev-1773710628974 - 2026-03-17
  • 1.3.0-dev-1773709997654 - 2026-03-17
  • 1.3.0-dev-1773698445534 - 2026-03-16
  • 1.2.13 - 2026-03-11
  • 1.2.13-dev-1773345797648 - 2026-03-12
  • 1.2.12 - 2026-03-03
  • 1.2.11 - 2026-02-26
  • 1.2.10 - 2026-02-24
  • 1.2.9 - 2026-02-20
  • 1.2.8 - 2026-02-17
  • 1.2.8-dev-1771365493298 - 2026-02-17
  • 1.2.7 - 2026-02-11
from @langchain/openai GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade @langchain/openai from 1.2.7 to 1.5.3.

See this package in npm:
@langchain/openai

See this project in Snyk:
https://app.snyk.io/org/hedera-agent-kit/project/e00e6d1e-ba0f-49ee-afe5-97ee8cf7a032?utm_source=github&utm_medium=referral&page=upgrade-pr
@CMiville42

Copy link
Copy Markdown
Author

Merge Risk: Low

This is a minor version upgrade for @langchain/openai that introduces new features and improvements without documented breaking changes. Existing implementations should not require modification.

Key Changes:

  • New Features: Support has been added for several new OpenAI capabilities, including server-side tools (like web search and code interpreter), a moderateContent option for content safety, and model retry middleware for increased reliability.
  • Error Handling: The library now includes better handling for ContextOverflowError, allowing it to trigger summarization automatically.
  • Agent and Tool Improvements: Enhancements have been made to createAgent for better support of provider-specific tools and structured output schemas.

These changes are additive and provide new, optional functionality. No APIs were removed or modified in a breaking way within this version range.

Source: LangChain Official Documentation

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@CMiville42
CMiville42 requested review from a team as code owners July 28, 2026 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants