SWIRL Community 4.5.0.1
π SWIRL Community 4.5.0.1 β Security Patch
This release re-freezes Python dependencies to clear ~30 vulnerabilities reported by Docker Scout. No SWIRL application code changed.
β PLEASE STAR OUR REPO: https://github.com/swirlai/swirl-search
π PLEASE VISIT OUR WEBSITE: https://www.swirlaiconnect.com/
Updates
nltk 3.9.2 β 3.9.4β CVE-2025-14009 (CVSS 10.0)litellm 1.83.0 β 1.83.10β CVE-2026-42208 (CVSS 9.3)
Plus 26 high-severity CVEs across Django, urllib3, cryptography, ujson, pyOpenSSL, lxml, PyJWT, pyasn1, azure-core, cbor2, protobuf, orjson, and previously-transitive wheel + jaraco.context.
Some upstream constraints forced additional version moves:
openai 2.9.0 β 2.24.0β required bylitellm 1.83.10snowflake-connector-python 3.17.3 β 4.5.0β required forcffi 2.0.0(whichcryptography 46.0.5requires)cffi 1.17.1 β 2.0.0
The OpenAI integration path has been re-validated against both OpenAI and Anthropic models via LiteLLM.
Deferred
twisted 25.5.0 β 26.4.0β fix is currently only available as a release candidate (26.4.0rc2). Will be picked up in 4.5.1 / 4.6 once26.4.0final ships. The associated CVE-2026-42304 (CVSS 7.5) is acknowledged but does not affect the SWIRL request path in normal deployment.