Fixes Dependabot alerts: - GHSA-jjhc-v7c2-5hh6 (critical): Authentication bypass via OIDC userinfo cache key collision (CVE-2026-35030) - GHSA-53mr-6c8q-9789 (high): related litellm vulnerability Updates both hindsight-api-slim and hindsight-integrations/litellm to require litellm >=1.83.0. The previous upper cap (<=1.82.6) was set due to the 1.82.7/1.82.8 supply chain compromise, which has since been yanked from PyPI; 1.83.0 was published from the new secure CI/CD v2 pipeline and is safe. The uv.lock diffs are large because the current uv version (0.9.11) upgrades the lockfile format (adds revision=3 and upload-time fields); only litellm itself changes version (1.81.10/1.80.10 -> 1.83.0). All 68 tests in hindsight-integrations/litellm pass against 1.83.0.
69 lines
1.9 KiB
TOML
69 lines
1.9 KiB
TOML
[project]
|
|
name = "hindsight-litellm"
|
|
version = "0.5.0"
|
|
description = "Universal LLM memory integration via LiteLLM - works with 100+ providers"
|
|
readme = "README.md"
|
|
requires-python = ">=3.10"
|
|
license = { text = "MIT" }
|
|
authors = [
|
|
{ name = "Vectorize", email = "support@vectorize.io" }
|
|
]
|
|
keywords = [
|
|
"ai",
|
|
"memory",
|
|
"llm",
|
|
"litellm",
|
|
"openai",
|
|
"anthropic",
|
|
"groq",
|
|
"langchain",
|
|
"agents",
|
|
"hindsight",
|
|
]
|
|
classifiers = [
|
|
"Development Status :: 4 - Beta",
|
|
"Intended Audience :: Developers",
|
|
"License :: OSI Approved :: MIT License",
|
|
"Programming Language :: Python :: 3",
|
|
"Programming Language :: Python :: 3.10",
|
|
"Programming Language :: Python :: 3.11",
|
|
"Programming Language :: Python :: 3.12",
|
|
"Topic :: Scientific/Engineering :: Artificial Intelligence",
|
|
]
|
|
|
|
dependencies = [
|
|
"litellm>=1.83.0", # 1.82.7/1.82.8 had a supply chain compromise (yanked); 1.83.0+ also fixes GHSA-jjhc-v7c2-5hh6 / GHSA-53mr-6c8q-9789
|
|
# Transitive dependency security fixes
|
|
"aiohttp>=3.13.3", # Multiple DoS vulnerabilities
|
|
"filelock>=3.20.3", # TOCTOU race condition
|
|
"urllib3>=2.6.3", # Decompression-bomb safeguards bypass
|
|
"requests>=2.33.0", # Insecure temp file reuse in extract_zipped_paths()
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
dev = [
|
|
"pytest>=7.0.0",
|
|
"pytest-asyncio>=0.21.0",
|
|
"pytest-mock>=3.10.0",
|
|
]
|
|
|
|
[project.urls]
|
|
Homepage = "https://github.com/vectorize-io/hindsight"
|
|
Documentation = "https://github.com/vectorize-io/hindsight/tree/main/hindsight-integrations/litellm"
|
|
Repository = "https://github.com/vectorize-io/hindsight"
|
|
|
|
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["hindsight_litellm"]
|
|
|
|
[tool.pytest.ini_options]
|
|
asyncio_mode = "auto"
|
|
testpaths = ["tests"]
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
"pytest>=9.0.2",
|
|
]
|