mirror of
https://github.com/browser-use/browser-use.git
synced 2026-09-14 19:59:47 +08:00
d4b9e30188
litellm versions 1.82.7 and 1.82.8 were backdoored on March 24, 2026 by TeamPCP via a compromised Trivy CI/CD pipeline. browser-use 0.12.3 shipped litellm>=1.82.2 (unpinned) as a core dependency, exposing ~6,900 users to the backdoored versions during the 4-hour window. This commit: - Removes litellm entirely from pyproject.toml (core and optional) - Keeps ChatLiteLLM wrapper intact with a docstring noting `pip install litellm` is required separately - litellm is already lazy-imported inside methods, so users who don't use ChatLiteLLM are never affected Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>