Fixes Dependabot alerts: - GHSA-jjhc-v7c2-5hh6 (critical): Authentication bypass via OIDC userinfo cache key collision (CVE-2026-35030) - GHSA-53mr-6c8q-9789 (high): related litellm vulnerability Updates both hindsight-api-slim and hindsight-integrations/litellm to require litellm >=1.83.0. The previous upper cap (<=1.82.6) was set due to the 1.82.7/1.82.8 supply chain compromise, which has since been yanked from PyPI; 1.83.0 was published from the new secure CI/CD v2 pipeline and is safe. The uv.lock diffs are large because the current uv version (0.9.11) upgrades the lockfile format (adds revision=3 and upload-time fields); only litellm itself changes version (1.81.10/1.80.10 -> 1.83.0). All 68 tests in hindsight-integrations/litellm pass against 1.83.0. |
||
|---|---|---|
| .. | ||
| ag2 | ||
| agno | ||
| ai-sdk | ||
| autogen | ||
| chat | ||
| claude-code | ||
| codex | ||
| crewai | ||
| hermes | ||
| langgraph | ||
| litellm | ||
| llamaindex | ||
| nemoclaw | ||
| openclaw | ||
| opencode | ||
| paperclip | ||
| pydantic-ai | ||
| strands | ||