{"data":{"ecosystem":"pypi","name":"dspy","url":"https://aisecwatch.com/packages/pypi/dspy","latestVersion":"3.4.0","firstReleaseAt":"2024-04-14T22:02:23.271Z","repository":"https://github.com/stanfordnlp/dspy","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-04-14T22:02:23.271Z","integratedVersion":"0.0.1","sdks":["dspy"],"path":[]},"authority":{"profile":["http","mcp_tools"],"fromDependencies":["pypi:mcp","pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"anthropic","versionSpec":"<1.0.0,>=0.18.0","scope":"extra:anthropic"},{"ecosystem":"pypi","name":"datasets","versionSpec":">=2.14.6","scope":"extra:test-extras"},{"ecosystem":"pypi","name":"gepa","versionSpec":"==0.1.4","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-core","versionSpec":">=0.3.0","scope":"extra:langchain"},{"ecosystem":"pypi","name":"litellm","versionSpec":">=1.65.8","scope":"runtime"},{"ecosystem":"pypi","name":"mcp","versionSpec":null,"scope":"extra:mcp"},{"ecosystem":"pypi","name":"openai","versionSpec":">=1.66.2","scope":"runtime"},{"ecosystem":"pypi","name":"weaviate-client","versionSpec":"<4.22.0,>=4.5.4","scope":"extra:weaviate"},{"ecosystem":"pypi","name":"anyio","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"build","versionSpec":">=1.0.3","scope":"extra:dev"},{"ecosystem":"pypi","name":"cachetools","versionSpec":">=5.5.0","scope":"runtime"},{"ecosystem":"pypi","name":"cloudpickle","versionSpec":">=3.1.2","scope":"runtime"},{"ecosystem":"pypi","name":"datamodel-code-generator","versionSpec":">=0.26.3","scope":"extra:dev"},{"ecosystem":"pypi","name":"deno","versionSpec":"<3.0.0,>=2.4.5","scope":"extra:deno"},{"ecosystem":"pypi","name":"diskcache","versionSpec":">=5.6.0","scope":"runtime"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"<0.140.7","scope":"extra:dev"},{"ecosystem":"pypi","name":"json-repair","versionSpec":">=0.54.2","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.26.0","scope":"extra:numpy"},{"ecosystem":"pypi","name":"optuna","versionSpec":">=3.4.0","scope":"extra:optuna"},{"ecosystem":"pypi","name":"orjson","versionSpec":">=3.9.0","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":">=2.1.1","scope":"extra:test-extras"},{"ecosystem":"pypi","name":"pillow","versionSpec":">=10.1.0","scope":"extra:dev"},{"ecosystem":"pypi","name":"pre-commit","versionSpec":">=3.7.0","scope":"extra:dev"},{"ecosystem":"pypi","name":"pydantic","versionSpec":">=2.11.0","scope":"runtime"},{"ecosystem":"pypi","name":"pytest","versionSpec":">=6.2.5","scope":"extra:dev"},{"ecosystem":"pypi","name":"pytest-asyncio","versionSpec":">=0.26.0","scope":"extra:dev"},{"ecosystem":"pypi","name":"pytest-mock","versionSpec":">=3.12.0","scope":"extra:dev"},{"ecosystem":"pypi","name":"pytest-xdist","versionSpec":">=3.5.0","scope":"extra:dev"},{"ecosystem":"pypi","name":"regex","versionSpec":">=2023.10.3","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":">=2.31.0","scope":"runtime"},{"ecosystem":"pypi","name":"ruff","versionSpec":">=0.3.0","scope":"extra:dev"},{"ecosystem":"pypi","name":"tenacity","versionSpec":">=8.2.3","scope":"runtime"},{"ecosystem":"pypi","name":"tqdm","versionSpec":">=4.66.1","scope":"runtime"},{"ecosystem":"pypi","name":"typesafe-sdk","versionSpec":"<1.0.0,>=0.6.0","scope":"extra:typesafe"}],"advisories":[{"id":"b2d1d938-b056-4faa-b8b3-0ca3424d94f7","url":"https://aisecwatch.com/issues/b2d1d938-b056-4faa-b8b3-0ca3424d94f7","cveId":"CVE-2025-12695","title":"CVE-2025-12695: The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build…","headline":"DSPy sandbox configuration allows arbitrary file read via PythonInterpreter","severity":"medium","publishedAt":"2025-11-04T19:15:34.087Z","affected":["dspy@<= 3.0.3"],"epssScore":0.00338,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:48:40.720Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}