Repository navigation
Update dependencies (moderate strategy) - #15
Conversation
Moderate update strategy: patch/minor bumps freely, major versions held back to avoid breaking exercises. Key updates include langchain 1.2→1.3, langchain-core 1.2→1.5, deepagents 0.4→0.7, anthropic 0.89→0.120. Fixed deprecated import paths (langchain.callbacks.manager → langchain_core.callbacks, langchain.text_splitter → langchain_text_splitters) that broke with langchain 1.3.x. Kept pinned: tree-sitter==0.21.3 (tree-sitter-languages compatibility), antlr4-python3-runtime==4.9.3 (layoutparser compatibility). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
This pull request introduces a critical security vulnerability by configuring the FilesystemBackend with
🔴 Unrestricted Filesystem Access for LLM Agent in
|
| Vulnerability | Unrestricted Filesystem Access for LLM Agent |
|---|---|
| Description | The FilesystemBackend is configured with virtual_mode=False, which according to deepagents documentation explicitly disables all path-based security guardrails. When virtual_mode=False, the root_dir parameter is not enforced as a boundary, and paths are resolved relative to the current working directory or as absolute paths. This grants the LLM agent unrestricted read/write access to the entire host filesystem, not just the intended repo directory. Combined with the FetchURLTool (which can fetch external URLs), an attacker could use prompt injection to trick the agent into reading sensitive files (credentials, configs, keys) anywhere on the filesystem or writing malicious files. |
nextgen/scripts/exercise-08/deepagent_sast_demo.py
Lines 34 to 37 in c2817a7
Comment to provide feedback on these findings.
Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]
Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing
All finding details can be found in the DryRun Security Dashboard.
There was a problem hiding this comment.
Pull request overview
This PR updates the project’s pinned Python dependencies and adjusts a handful of scripts to use the new LangChain import locations required by the upgraded LangChain ecosystem.
Changes:
- Bump a large set of pinned dependencies in
requirements.txt(LangChain ecosystem, Anthropic SDK, Redis, Torch, etc.) while keeping several major-version constraints. - Update deprecated LangChain callback/tool imports to
langchain_core.*. - Update
Languageimport to the standalonelangchain_text_splitterspackage.
Reviewed changes
Copilot reviewed 8 out of 9 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
| scripts/llm_training/view_file_tools.py | Update LangChain callback/tool imports to langchain_core. |
| scripts/llm_training/view_directory_tools.py | Update LangChain callback/tool imports to langchain_core. |
| scripts/extras/exercise-15/list_authz_decorators.py | Update Language import to langchain_text_splitters. |
| scripts/extras/exercise-11a/view_file_tools.py | Update LangChain callback/tool imports to langchain_core. |
| scripts/extras/exercise-11a/view_directory_tools.py | Update LangChain callback/tool imports to langchain_core. |
| scripts/extras/exercise-11a/custom_tool_template.py | Update LangChain callback/tool imports to langchain_core. |
| scripts/exercise-08/view_file_tools.py | Update LangChain callback/tool imports to langchain_core. |
| scripts/exercise-08/view_directory_tools.py | Update LangChain callback/tool imports to langchain_core. |
| requirements.txt | Refresh pinned dependency set and add new transitive pins. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Students don't need to see deprecation noise from langchain-community (being sunset) or RunnableWithMessageHistory (replaced by LangGraph persistence). The code still works; these are cosmetic warnings that make exercises look outdated. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 21 out of 22 changed files in this pull request and generated no new comments.
Suppressed comments (10)
scripts/llm_training/view_directory_tools.py:9
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/exercise-08/view_file_tools.py:9
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/exercise-08/view_directory_tools.py:9
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/llm_training/view_file_tools.py:9
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/extras/exercise-11a/view_file_tools.py:9
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/extras/exercise-11a/view_directory_tools.py:9
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/extras/exercise-11a/custom_tool_template.py:16
- CallbackManagerForToolRun is typically imported from langchain_core.callbacks.manager; importing it from langchain_core.callbacks can raise ImportError on langchain-core 1.5.x. This repo already uses the manager submodule elsewhere (e.g., scripts/extras/exercise-10/agentic_basic.py:10).
from langchain_core.callbacks import CallbackManagerForToolRun
scripts/exercise-00/chatbot.py:6
- Importing LangChainDeprecationWarning from langchain_core._api.deprecation relies on a private (underscore) module path and may break on future langchain-core upgrades. Add a small ImportError fallback so the script keeps working even if the warning class moves.
warnings.filterwarnings("ignore", category=DeprecationWarning, message=".*langchain-community.*")
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
scripts/exercise-05/chatbot.py:6
- Importing LangChainDeprecationWarning from langchain_core._api.deprecation relies on a private (underscore) module path and may break on future langchain-core upgrades. Add a small ImportError fallback so the script keeps working even if the warning class moves.
warnings.filterwarnings("ignore", category=DeprecationWarning, message=".*langchain-community.*")
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
scripts/exercise-00/chatbot_ollama.py:6
- Importing LangChainDeprecationWarning from langchain_core._api.deprecation relies on a private (underscore) module path and may break on future langchain-core upgrades. Add a small ImportError fallback so the script keeps working even if the warning class moves.
warnings.filterwarnings("ignore", category=DeprecationWarning, message=".*langchain-community.*")
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
deepagents 0.7 resolves skills paths through the FilesystemBackend. With virtual_mode=True, paths outside root_dir (like the skills directory) fail with path_not_found. Since these are local training exercises, virtual_mode sandboxing is unnecessary. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 26 out of 27 changed files in this pull request and generated 5 comments.
Suppressed comments (11)
scripts/exercise-01/prompt_engineering.py:4
- This warning filter matches by message only and will suppress any warning category whose text matches, which can hide non-deprecation warnings. Since the PR notes this is a deprecation noise issue, restrict the filter to
DeprecationWarning(and/or the specific LangChain warning class) to reduce accidental masking.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/exercise-02/building_with_context.py:4
- This warning filter matches by message only and will suppress any warning category whose text matches, which can hide non-deprecation warnings. Restrict it to
DeprecationWarningto keep the suppression narrowly scoped to the intended deprecation noise.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/exercise-04/embed_and_store.py:4
- This warning filter matches by message only and will suppress any warning category whose text matches, which can hide non-deprecation warnings. If the goal is to silence the LangChain community deprecation message, constrain this to
DeprecationWarning.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/exercise-05/load_guide.py:3
- This warning filter matches by message only and will suppress any warning category whose text matches. Since this is intended to quiet deprecation output, constrain it to
DeprecationWarningto avoid masking other warnings.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/exercise-05/chatbot_prompti_prevention_example.py:12
- This warning filter matches by message only and will suppress any warning category whose text matches. Restrict it to
DeprecationWarningso non-deprecation warnings aren’t accidentally hidden.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/extras/exercise-03/dynamic_context.py:4
- This warning filter matches by message only and will suppress any warning category whose text matches. Constrain it to
DeprecationWarningto keep the suppression narrowly targeted.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/extras/exercise-07/agentic_basic.py:2
- This warning filter matches by message only and will suppress any warning category whose text matches. If the intent is only to remove the langchain-community deprecation noise, constrain it to
DeprecationWarningto avoid hiding other warnings.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/extras/exercise-10/agentic_basic.py:2
- This warning filter matches by message only and will suppress any warning category whose text matches. Restrict it to
DeprecationWarningso other warnings aren’t accidentally masked.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/extras/exercise-12/profile_app.py:4
- This warning filter matches by message only and will suppress any warning category whose text matches. Constrain it to
DeprecationWarningto avoid masking other warnings.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/extras/exercise-15/list_authz_decorators.py:4
- This warning filter matches by message only and will suppress any warning category whose text matches. If the goal is to quiet the langchain-community deprecation output, constrain it to
DeprecationWarning.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
scripts/extras/exercise-24/multi_retriever_routing.py:18
- This warning filter matches by message only and will suppress any warning category whose text matches. Restrict it to
DeprecationWarningto avoid accidentally hiding other warnings while still silencing the deprecation noise noted in the PR.
warnings.filterwarnings("ignore", message=".*langchain-community.*")
Agent step output files are generated at runtime when exercises are run — they shouldn't be in version control. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Use langchain_core.callbacks.manager (not langchain_core.callbacks) for CallbackManagerForToolRun — matches the convention in the rest of the repo. Also remove unused Language import in exercise-15. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 30 out of 32 changed files in this pull request and generated no new comments.
Suppressed comments (8)
scripts/llm_training/audit.py:31
- Setting virtual_mode=False appears to disable the FilesystemBackend sandbox, allowing the agent to access files outside repo_path. Repo docs describe virtual_mode=True as a security best practice (e.g., docs/REACT_TO_DEEPAGENT_MIGRATION.md:202, docs/DEEPAGENT_TRANSITION_GUIDE.md:343). Use virtual_mode=True (or gate it behind an explicit opt-out env var) to avoid unintended local file exposure.
scripts/extras/exercise-23/deepagent_skills_demo.py:68 - Setting virtual_mode=False appears to disable the FilesystemBackend sandbox, allowing the agent to access files outside repo_path. Repo docs describe virtual_mode=True as a security best practice (e.g., docs/REACT_TO_DEEPAGENT_MIGRATION.md:202, docs/DEEPAGENT_TRANSITION_GUIDE.md:343). Use virtual_mode=True (or gate it behind an explicit opt-out env var) to avoid unintended local file exposure.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/extras/exercise-23/deepagent_sast_demo.py:38
- Setting virtual_mode=False appears to disable the FilesystemBackend sandbox, allowing the agent to access files outside repo_path. Repo docs describe virtual_mode=True as a security best practice (e.g., docs/REACT_TO_DEEPAGENT_MIGRATION.md:202, docs/DEEPAGENT_TRANSITION_GUIDE.md:343). Use virtual_mode=True (or gate it behind an explicit opt-out env var) to avoid unintended local file exposure.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/extras/exercise-11a/deepagent_security_assessment.py:34
- Setting virtual_mode=False appears to disable the FilesystemBackend sandbox, allowing the agent to access files outside repo_path. Repo docs describe virtual_mode=True as a security best practice (e.g., docs/REACT_TO_DEEPAGENT_MIGRATION.md:202, docs/DEEPAGENT_TRANSITION_GUIDE.md:343). Use virtual_mode=True (or gate it behind an explicit opt-out env var) to avoid unintended local file exposure.
scripts/exercise-08/deepagent_sast_demo.py:34 - Setting virtual_mode=False appears to disable the FilesystemBackend sandbox, allowing the agent to access files outside repo_path. Repo docs describe virtual_mode=True as a security best practice (e.g., docs/REACT_TO_DEEPAGENT_MIGRATION.md:202, docs/DEEPAGENT_TRANSITION_GUIDE.md:343). Use virtual_mode=True (or gate it behind an explicit opt-out env var) to avoid unintended local file exposure.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/exercise-00/chatbot.py:6
- This imports LangChainDeprecationWarning from a private module path (langchain_core._api.*). That can break even on patch/minor LangChain updates and would prevent the script from starting. Guard the import so warning suppression is best-effort and the script still runs if the internal path changes.
warnings.filterwarnings("ignore", category=DeprecationWarning, message=".*langchain-community.*")
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
scripts/exercise-00/chatbot_ollama.py:6
- This imports LangChainDeprecationWarning from a private module path (langchain_core._api.*). That can break even on patch/minor LangChain updates and would prevent the script from starting. Guard the import so warning suppression is best-effort and the script still runs if the internal path changes.
warnings.filterwarnings("ignore", category=DeprecationWarning, message=".*langchain-community.*")
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
scripts/exercise-05/chatbot.py:6
- This imports LangChainDeprecationWarning from a private module path (langchain_core._api.*). That can break even on patch/minor LangChain updates and would prevent the script from starting. Guard the import so warning suppression is best-effort and the script still runs if the internal path changes.
warnings.filterwarnings("ignore", category=DeprecationWarning, message=".*langchain-community.*")
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 30 out of 32 changed files in this pull request and generated no new comments.
Suppressed comments (8)
scripts/llm_training/audit.py:30
- Setting
virtual_mode=Falseallows the agent filesystem tool to potentially access paths outsideroot_dir(e.g., via..traversal), which can expose local machine secrets when running this script. Repo docs describevirtual_mode=Trueas the security best practice for restricting access toroot_dir.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/extras/exercise-11a/deepagent_security_assessment.py:31
virtual_mode=Falsemay allow filesystem tool access outsiderepo_path, which can unintentionally expose local files to the agent. This script previously documentedvirtual_mode=Trueas the recommended security setting; consider keeping that default.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/extras/exercise-23/deepagent_skills_demo.py:68
- With
virtual_mode=False, the agent’s filesystem backend may allow access outsiderepo_path, increasing the risk of unintended local file disclosure. The repo documentation recommendsvirtual_mode=Trueto restrict access toroot_dir.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/extras/exercise-23/deepagent_sast_demo.py:38
- Using
virtual_mode=Falsecan allow the agent to read files outside the cloned repo directory, which is risky when running security-analysis agents locally (it can leak host secrets). Prefervirtual_mode=Trueto restrict access toroot_dir.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/exercise-08/deepagent_sast_demo.py:34
virtual_mode=Falsecan permit access outsideroot_dir, which is a security footgun for an agent that reads local files. Prefervirtual_mode=Trueso the agent is constrained torepo_path.
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
scripts/exercise-00/chatbot.py:6
LangChainDeprecationWarningis imported fromlangchain_core._api.deprecation(a private/unstable module path). This can break on future LangChain upgrades and cause the script to fail at import time. Consider guarding the import and falling back toDeprecationWarning.
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
scripts/exercise-00/chatbot_ollama.py:6
LangChainDeprecationWarningis imported fromlangchain_core._api.deprecation(a private/unstable module path). A minor LangChain refactor could break this and prevent the script from starting. Guard the import and fall back toDeprecationWarning.
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
scripts/exercise-05/chatbot.py:6
- This imports
LangChainDeprecationWarningfromlangchain_core._api.deprecation, which is a private module path and may change between LangChain versions, breaking the script. Guard the import and fall back toDeprecationWarningto keep the warning filter stable across upgrades.
from langchain_core._api.deprecation import LangChainDeprecationWarning
warnings.filterwarnings("ignore", category=LangChainDeprecationWarning)
|
Very good catch DryRun! Except this one is intentional but ya... hella insecure. |
Summary
langchain.callbacks.manager→langchain_core.callbacks,langchain.text_splitter→langchain_text_splitters)Constraints Applied
Test Results
tree_sitter_languages.get_language('ruby'))Notes
langchain-communityshows a DeprecationWarning (being sunset in favor of standalone packages) — informational only, still works🤖 Generated with Claude Code