INTPYTHON-825 LangGraph-Checkpoint CVE fix #263
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue Key
Summary
This PR addresses a critical security vulnerability found in langgraph-checkpoint's serializer, "JsonSerializer". It is described in detail here: RCE in json mode of JsonPlusSerializer.
Changes in this PR
The primary change was to bump to "langggraph-checkpoint >= 3.0".
The base checkpointer removed dumps/loads in preference of typed versions. We had previously only used the defaults so a few changes were made to update to these.
Test Plan
This change does not change any of our API so no changes to tests were made. All pass. INTPYTHON-826 will add tests of the serialization types once we expose them.
Screenshots (optional)
Checklist
Checklist for Author
Checklist for Reviewer {@primary_reviewer}