You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
[0.4.0] - 2026-08-30
Added
AGENTS.md, GEMINI.md, and CLAUDE.md files to provide context and instructions to AI Coding Assistants [GS-303].
SAST testing [GS-315].
AWS_SSL_CERTIFICATE_ARN_BE envvar to the .env.example file [GS-328].
Changed:
Remove all references to fynapp on ai_conversations_conversion.py
Enhance comments about how to specify the C0301 and E501 line-too-long lint conditions on config.py
License changed to MIT [FA-244].
Replace Github Gemini code review with SonarQube and Claude code review [GS-336].
Modify Makefile to allow optional arguments for twine upload during production publish, e.g. "--verbosity" [GS-327].
Update version to 0.4.0 in package.json, pyproject.toml, and setup.py [GS-327].
Security
Upgrade langchain to "^1.3.14", langchain-openai to "^1.4.1", langchain-core to "^1.5.2", langchain-community to "^0.4.2", to fix security vulnerabilities [GS-219].
Allocation of Resources Without Limits or Throttling [High Severity], SNYK-PYTHON-AIOHTTP-14871876, SNYK-PYTHON-AIOHTTP-14871877, SNYK-PYTHON-AIOHTTP-15873732, SNYK-PYTHON-BROTLICFFI-14172734
Regular Expression Denial of Service (ReDoS) [High Severity], SNYK-PYTHON-LANGCHAINCLASSIC-14914754
Deserialization of Untrusted Data [High Severity], SNYK-PYTHON-LANGGRAPH-15433492, SNYK-PYTHON-LANGGRAPHCHECKPOINT-15353408, SNYK-PYTHON-LANGGRAPHCHECKPOINT-15433491
h2: Duplicate Host header could facilitate request smuggling
Upgrade pytest to "^9.1.1", pytest-cov to "^7.1.0", twine to "^7.0.0", fastapi to "^0.140.13", pytest-mock to "^3.15.1", to fix security vulnerabilities [GS-219].
Upgrade ddgs to "^9.14.4" to fix security vulnerabilities [GS-219].
Pin "urllib3" to "^2.7.0" to fix "urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API" security vulnerability [GS-219].
Pin starlette to "^1.3.1" to fix "Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks" security vulnerability (only for development dependencies) [GS-219].
Pin aiohttp to "^3.14.3" to fix "Allocation of Resources Without Limits or Throttling [High Severity][https://security.snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871876]" security vulnerability. This must be removed once aiohttp is greater than "^3.14.3" by its dependers [GS-219].
Upgrade cryptography to "^50.0.0" to fix security vulnerabilities [GS-219].
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
Upgrade pyjwt to "^2.13.0" to fix security vulnerabilities [GS-219].