Open
Conversation
Collaborator
|
@cym3118288-afk thanks so much for this, would you be able to run "pre-commit run --all-files" and push the It should have diskcache in it: |
Author
|
sure ,I will give it a try later |
Codecov Report❌ Patch coverage is
... and 20 files with indirect coverage changes 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
AG2 has a hard dependency on
diskcachewhich is affected by CVE-2025-69872(CVSS 9.8 Critical) - an unsafe pickle deserialization vulnerability. This
blocks deployments in security-sensitive environments using vulnerability
scanners like Aquasec, Snyk, or Trivy.
Solution
This PR makes
diskcachean **optional dependency** and changes the defaultcache backend to
InMemoryCache.Changes
diskcachefrom core dependencies inpyproject.tomldiskcacheas optional dependencyag2\[diskcache]DiskCacheto raise helpful error when diskcache not installedcache\_factorydefault fallback toInMemoryCacheMigration Path
Users have three options:
pip install ag2\[diskcache]Breaking Changes
now use InMemoryCache (no persistence between runs). To restore previous
behavior:
pip install ag2\[diskcache]Security Impact
✅ Resolves CVE-2025-69872
✅ Security scanners will no longer flag ag2
✅ Safe for deployment in security-sensitive environments