mirror of
https://github.com/open-webui/open-webui.git
synced 2026-07-23 09:10:55 -05:00
* chore: bump Python backend dependencies, drop unused peewee Minor/patch + reviewed major bumps across requirements.txt, requirements-min.txt, pyproject.toml and uv.lock; playwright image bumped in docker-compose.playwright.yaml. peewee/peewee-migrate removed (zero imports). Security-relevant: cryptography 46->48, authlib 1.6.10->1.7.2, PyJWT 2.11->2.13, requests 2.33.1->2.34.2, RestrictedPython 8.1->8.2, pillow 12.1.1->12.2.0. Reviewed majors: redis 7->8, pymilvus ->2.6.14, azure-search-documents 11->12, chardet 5->7, unstructured 0.18->0.22, pycrdt 0.12->0.13. Testing: - Resolution: `uv lock` resolves the full bumped set with no conflicts; uv.lock regenerated to match (peewee dropped, every pin including azure-search-documents==12.0.0 resolves). - Per-dependency contract tests (external tests repo, unit/deps/): 105 files, 2205 passed / 6 skipped, ruff-clean. One file per dependency pins the symbols, signatures and behaviour the backend actually uses, so an API removal/rename in a bumped version fails loudly instead of at runtime. Offline/deterministic. - End-to-end embed->retrieve test driving transformers + sentence-transformers + chromadb together through Open WebUI's real RAG path (cached model, in-memory chroma, semantic retrieval asserted). - Install/startup/health resolution gate added to the dep-bump workflow and the integration suite (uv/pip resolve + uvicorn /health + Playwright dev visibility). - Bugs surfaced while testing each got an isolated fix branch + regression test: Mistral OCR aiohttp FilePayload (#25779), chroma has_collection (#25780), aiocache per-user model-cache key (security), otel semconv deprecation, pydub/audioop <3.13 note. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Bump python-multipart 0.0.22 -> 0.0.27 (CVE-2026-42561, CVE-2026-40347) 0.0.22 is affected by two DoS CVEs in the multipart parser that Starlette/FastAPI run for every multipart/form-data request, so any authenticated user hitting an upload endpoint can trigger them: - CVE-2026-42561: unbounded part-header count/size -> CPU exhaustion (fixed 0.0.27) - CVE-2026-40347: large multipart preamble/epilogue DoS (fixed 0.0.26) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
58 lines
956 B
Plaintext
58 lines
956 B
Plaintext
# Minimal requirements for backend to run
|
|
# WIP: use this as a reference to build a minimal docker image
|
|
|
|
fastapi==0.136.3
|
|
uvicorn[standard]==0.41.0
|
|
pydantic==2.13.4
|
|
python-multipart==0.0.27
|
|
itsdangerous==2.2.0
|
|
|
|
python-socketio==5.16.2
|
|
python-jose==3.5.0
|
|
cryptography
|
|
bcrypt==5.0.0
|
|
argon2-cffi==25.1.0
|
|
PyJWT[crypto]==2.13.0
|
|
authlib==1.7.2
|
|
|
|
requests==2.34.2
|
|
aiohttp==3.13.5 # do not update to 3.13.3 - broken
|
|
async-timeout
|
|
aiocache
|
|
aiofiles
|
|
starlette-compress==1.7.1
|
|
Brotli==1.2.0
|
|
brotlicffi==1.2.0.1
|
|
httpx[socks,http2,zstd,cli,brotli]==0.28.1
|
|
starsessions[redis]==2.2.1
|
|
|
|
sqlalchemy==2.0.50
|
|
aiosqlite==0.22.1
|
|
psycopg[binary]==3.3.4
|
|
alembic==1.18.4
|
|
|
|
pycrdt==0.13.1
|
|
redis
|
|
|
|
APScheduler==3.11.2
|
|
RestrictedPython==8.2
|
|
|
|
loguru==0.7.3
|
|
asgiref==3.11.1
|
|
|
|
mcp==1.27.2
|
|
openai
|
|
|
|
langchain==1.2.10
|
|
langchain-community==0.4.2
|
|
langchain-classic==1.0.7
|
|
langchain-text-splitters==1.1.2
|
|
|
|
fake-useragent==2.2.0
|
|
|
|
chromadb==1.5.9
|
|
black==26.5.1
|
|
pydub
|
|
chardet==7.4.3
|
|
beautifulsoup4
|