Skip to content

chore: dependabot security batch 2026 02 16#269

Merged
robodev-r2d2 merged 9 commits intomainfrom
chore/dependabot-security-batch-2026-02-16
Feb 16, 2026
Merged

chore: dependabot security batch 2026 02 16#269
robodev-r2d2 merged 9 commits intomainfrom
chore/dependabot-security-batch-2026-02-16

Conversation

@a-klos
Copy link
Member

@a-klos a-klos commented Feb 16, 2026

This pull request primarily updates dependencies and cleans up metadata in the project. The most significant change is the removal of the "peer": true property from many entries in package-lock.json, which simplifies package metadata and may improve compatibility and installation consistency. Additionally, there are minor version bumps for dependencies in both Python and JavaScript projects.

Dependency updates:

  • Upgraded the docling dependency in pyproject.toml from version 2.71.0 to 2.73.1, ensuring access to the latest features and fixes.
  • Updated the qs package in package-lock.json from version 6.14.1 to 6.14.2, which may include bug fixes or improvements.

Metadata cleanup in JavaScript dependencies:

These changes are mostly maintenance-related and should not impact application functionality, but will help keep dependencies current and metadata accurate.

dependabot bot and others added 9 commits February 11, 2026 15:13
Bumps [langchain-core](https://github.com/langchain-ai/langchain) from 1.2.6 to 1.2.11.
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.2.6...langchain-core==1.2.11)

---
updated-dependencies:
- dependency-name: langchain-core
  dependency-version: 1.2.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [langchain-core](https://github.com/langchain-ai/langchain) from 1.2.6 to 1.2.11.
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.2.6...langchain-core==1.2.11)

---
updated-dependencies:
- dependency-name: langchain-core
  dependency-version: 1.2.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [langchain-core](https://github.com/langchain-ai/langchain) from 1.2.6 to 1.2.11.
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.2.6...langchain-core==1.2.11)

---
updated-dependencies:
- dependency-name: langchain-core
  dependency-version: 1.2.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.14.1 to 6.14.2.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.14.1...v6.14.2)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.14.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@robodev-r2d2 robodev-r2d2 merged commit 0057f9b into main Feb 16, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments