Skip to content

fix(predict-rlm): bump aiohttp parent dependencies#45

Merged
magix022 merged 1 commit into
mainfrom
fix/aiohttp-vulnerability-parent-bumps
Jun 19, 2026
Merged

fix(predict-rlm): bump aiohttp parent dependencies#45
magix022 merged 1 commit into
mainfrom
fix/aiohttp-vulnerability-parent-bumps

Conversation

@magix022

@magix022 magix022 commented Jun 19, 2026

Copy link
Copy Markdown
Collaborator

Rationale

aiohttp is pulled in through upstream LM integration dependencies. Updating the parent dependency minimums prevents vulnerable aiohttp releases from being selected when consumers resolve the affected dependency paths.

Summary

  • Bump dspy minimum from 3.1.2 to 3.2.1.
  • Bump litellm minimum for the codex-lm extra from 1.50 to 1.89.2.

@magix022 magix022 merged commit 18d87b8 into main Jun 19, 2026
15 of 16 checks passed
@magix022 magix022 deleted the fix/aiohttp-vulnerability-parent-bumps branch June 19, 2026 15:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants