Files
John Kennedyandopen-swe[bot] f5ee2b65f4 chore(chroma): bump Pygments security constraint (#40162)
Chroma's development lock still selected Pygments 2.20.0, which is
affected by a published security advisory. Raise the existing transitive
dependency constraint to 2.21.0 and refresh the lockfile so development
and CI environments select the patched release.

The other recently reported Chroma lockfile dependencies were already
updated on `master`, are no longer present in the current uv dependency
graph, or do not yet have a compatible patched release.

This contribution was prepared with an AI coding agent.

Made by [Open
SWE](https://openswe.vercel.app/agents/867a14a4-e0cb-53ec-bf1a-70edcb54e89e)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-02 19:03:27 -07:00

135 lines
3.7 KiB
TOML

[build-system]
requires = ["hatchling"]
build-backend = "hatchling.build"
[project]
name = "langchain-chroma"
version = "1.1.0"
description = "An integration package connecting Chroma and LangChain."
license = { text = "MIT" }
readme = "README.md"
classifiers = [
"Development Status :: 5 - Production/Stable",
"Intended Audience :: Developers",
"License :: OSI Approved :: MIT License",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Topic :: Scientific/Engineering :: Artificial Intelligence",
]
requires-python = ">=3.10.0,<4.0.0"
dependencies = [
"langchain-core>=1.4.7,<2.0.0",
"numpy>=1.26.0; python_version < '3.13'",
"numpy>=2.1.0; python_version >= '3.13'",
"chromadb>=1.5.5,<2.0.0",
]
[project.urls]
Homepage = "https://docs.langchain.com/oss/python/integrations/providers/chroma"
Documentation = "https://reference.langchain.com/python/integrations/langchain_chroma/"
Repository = "https://github.com/langchain-ai/langchain"
Issues = "https://github.com/langchain-ai/langchain/issues"
Changelog = "https://github.com/langchain-ai/langchain/releases?q=%22langchain-chroma%22"
Twitter = "https://x.com/langchain_oss"
Slack = "https://www.langchain.com/join-community"
Reddit = "https://www.reddit.com/r/LangChain/"
[dependency-groups]
test = [
"pytest>=9.0.3,<10.0.0",
"pytest-mock>=3.10.0,<4.0.0",
"pytest-benchmark",
"pytest-watcher>=0.3.4,<1.0.0",
"pytest-asyncio>=1.3.0,<2.0.0",
"pytest-socket>=0.7.0,<1.0.0",
"pytest-xdist>=3.6.1,<4.0.0",
"freezegun>=1.2.2,<2.0.0",
"syrupy>=5.0.0,<6.0.0",
"langchain-tests>=1.1.9,<2.0.0",
]
test_integration = []
lint = [
"ruff>=0.13.1,<0.14.0",
]
dev = []
typing = [
"mypy>=2.1.0,<2.2.0",
"types-requests>=2.31.0,<3.0.0",
]
[tool.uv.sources]
langchain-core = { path = "../../core", editable = true }
langchain-tests = { path = "../../standard-tests", editable = true }
[tool.uv]
constraint-dependencies = ["urllib3>=2.6.3", "pygments>=2.21.0"]
[tool.mypy]
disallow_untyped_defs = true
[tool.ruff.format]
docstring-code-format = true
[tool.ruff.lint]
select = [ "ALL" ]
ignore = [
"COM812", # Messes with the formatter
"PLC0415", # Import top of file
"FIX002", # TODO
"TD002", # TODO
"TD003", # TODO
"PLR0912", # Too many branches
"PLR0913", # Too many arguments
"C901", # Too complex
# TODO
"ANN204",
"ANN401",
"TRY201",
"ARG002",
"N803",
"TC002",
"TC003",
"TRY300",
"N806",
]
unfixable = ["B028"] # People should intentionally tune the stacklevel
[tool.coverage.run]
omit = ["tests/*"]
[tool.pytest.ini_options]
addopts = " --strict-markers --strict-config --durations=5"
markers = [
"requires: mark tests as requiring a specific library",
"compile: mark placeholder test used to compile integration tests without running them",
]
asyncio_mode = "auto"
[tool.ruff.lint.pydocstyle]
convention = "google"
ignore-var-parameters = true # ignore missing documentation for *args and **kwargs parameters
[tool.ruff.lint.flake8-tidy-imports]
ban-relative-imports = "all"
[tool.ruff.lint.per-file-ignores]
"tests/**" = ["D"]
[tool.ruff.lint.extend-per-file-ignores]
"tests/**/*.py" = [
"S101", # Tests need assertions
"S311", # Standard pseudo-random generators are not suitable for cryptographic purposes
"SLF001", # Private member access in tests
"PLR2004", # Comparison to magic number
"PT011", # Exception too broad
"BLE001", # Blind except
]
"scripts/*.py" = [
"INP001", # Not a package
]