Skip to content

Modify LiteLLM dependency constraints for compromised packages - #2512

Closed
nsphung wants to merge 1 commit into
ag2ai:mainfrom
nsphung:patch-1
Closed

Modify LiteLLM dependency constraints for compromised packages#2512
nsphung wants to merge 1 commit into
ag2ai:mainfrom
nsphung:patch-1

Conversation

@nsphung

@nsphung nsphung commented Mar 24, 2026

Copy link
Copy Markdown

Updated litellm dependency to exclude specific versions due to security issues.

Why are these changes needed?

Pinned upper bound for litellm[proxy] to avoid compromised versions 1.82.7 / 1.82.8

Related issue number

Details on BerriAI/litellm#24518

Replicated like on langchain-ai/langchain-litellm#103

Checks

Updated litellm dependency to exclude specific versions due to security issues.
@CLAassistant

CLAassistant commented Mar 24, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@marklysze

Copy link
Copy Markdown
Collaborator

@nsphung thank you for highlighting this and suggesting the change. As the litellm version in the interop-crewai extra is already restricted to 1.76.3 or below, the affected LiteLLM packages won't be retrieved.

It is very useful to have this PR as evidence of this issue but at this stage we won't merge into main.

Thank you!

@marklysze marklysze closed this Mar 25, 2026
@marklysze marklysze changed the title Modify litellm dependency constraints Modify LiteLLM dependency constraints for compromised packages Mar 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants