fleet-memory/hindsight-integrations
Derek Bouius 8a2388a48f
security: bump litellm to >=1.83.0 (#912)
Fixes Dependabot alerts:
- GHSA-jjhc-v7c2-5hh6 (critical): Authentication bypass via OIDC userinfo
  cache key collision (CVE-2026-35030)
- GHSA-53mr-6c8q-9789 (high): related litellm vulnerability

Updates both hindsight-api-slim and hindsight-integrations/litellm to
require litellm >=1.83.0. The previous upper cap (<=1.82.6) was set due
to the 1.82.7/1.82.8 supply chain compromise, which has since been yanked
from PyPI; 1.83.0 was published from the new secure CI/CD v2 pipeline
and is safe.

The uv.lock diffs are large because the current uv version (0.9.11)
upgrades the lockfile format (adds revision=3 and upload-time fields);
only litellm itself changes version (1.81.10/1.80.10 -> 1.83.0).

All 68 tests in hindsight-integrations/litellm pass against 1.83.0.
2026-04-07 16:54:24 +02:00
..
ag2 fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00
agno fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00
ai-sdk fix: resolve all Dependabot security alerts (#702) 2026-03-26 13:15:36 +01:00
autogen release(autogen): v0.1.1 2026-04-01 17:51:46 +02:00
chat fix: resolve all Dependabot security alerts (#702) 2026-03-26 13:15:36 +01:00
claude-code Fix trailing commas in openclaw.plugin.json and add JSON manifest CI tests (#774) 2026-03-30 16:55:06 +02:00
codex release(codex): v0.2.0 2026-03-30 17:50:02 +02:00
crewai fix: resolve remaining Dependabot security alerts (#833) 2026-04-01 17:22:38 +02:00
hermes fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00
langgraph fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00
litellm security: bump litellm to >=1.83.0 (#912) 2026-04-07 16:54:24 +02:00
llamaindex fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00
nemoclaw fix: resolve all Dependabot security alerts (#702) 2026-03-26 13:15:36 +01:00
openclaw feat(openclaw): JSONL-backed retain queue for external API resilience (#740) 2026-04-01 18:06:57 +02:00
opencode feat: add OpenCode persistent memory plugin (#853) 2026-04-07 10:11:57 +02:00
paperclip fix: add paperclip and opencode to changelog generator (#903) 2026-04-07 10:25:53 +02:00
pydantic-ai fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00
strands fix(deps): address critical and high severity security vulnerabilities (#827) 2026-04-01 09:20:34 +02:00