Skip to content

Dependency hardening: pin minimum safe dependency versions #642

Description

@hamizan-azman

Hi, thanks for ChatDev. Low-priority dependency-hardening note, not an active vulnerability report - a default install resolves to safe versions today.

These declarations also permit older versions with known CVEs; pinning a minimum prevents an accidental downgrade (please test compatibility):

(Low-priority dependency-hygiene note - feel free to close if not useful, happy to send a PR.)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions