Files
Magnus Müller d4b9e30188 Remove litellm from dependencies (supply chain attack CVE)
litellm versions 1.82.7 and 1.82.8 were backdoored on March 24, 2026
by TeamPCP via a compromised Trivy CI/CD pipeline. browser-use 0.12.3
shipped litellm>=1.82.2 (unpinned) as a core dependency, exposing
~6,900 users to the backdoored versions during the 4-hour window.

This commit:
- Removes litellm entirely from pyproject.toml (core and optional)
- Keeps ChatLiteLLM wrapper intact with a docstring noting
  `pip install litellm` is required separately
- litellm is already lazy-imported inside methods, so users who
  don't use ChatLiteLLM are never affected

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-24 20:29:44 -07:00
..
2026-03-16 13:30:29 -07:00
2026-03-16 13:30:29 -07:00