diff --git a/CONTRIBUTING.md b/.github/CONTRIBUTING.md similarity index 100% rename from CONTRIBUTING.md rename to .github/CONTRIBUTING.md diff --git a/CLAUDE.md b/CLAUDE.md new file mode 100644 index 000000000..f9dabdc62 --- /dev/null +++ b/CLAUDE.md @@ -0,0 +1,55 @@ +# AGENTS Instructions + +This repository is a monorepo. Each library lives in a subdirectory under `libs/`. + +When you modify code in any library, run the following commands in that library's directory before creating a pull request: + +- `make format` – run code formatters +- `make lint` – run the linter +- `make test` – execute the test suite + +To run a particular test file or to pass additional pytest options you can specify the `TEST` variable: + +``` +TEST=path/to/test.py make test +``` + +Other pytest arguments can also be supplied inside the `TEST` variable. + +## Libraries + +The repository contains several Python and JavaScript/TypeScript libraries. +Below is a high-level overview: + +- **checkpoint** – base interfaces for LangGraph checkpointers. +- **checkpoint-postgres** – Postgres implementation of the checkpoint saver. +- **checkpoint-sqlite** – SQLite implementation of the checkpoint saver. +- **cli** – official command-line interface for LangGraph. +- **langgraph** – core framework for building stateful, multi-actor agents. +- **prebuilt** – high-level APIs for creating and running agents and tools. +- **sdk-js** – JS/TS SDK for interacting with the LangGraph REST API. +- **sdk-py** – Python SDK for the LangGraph Server API. + +### Dependency map + +The diagram below lists downstream libraries for each production dependency as +declared in that library's `pyproject.toml` (or `package.json`). + +```text +checkpoint +├── checkpoint-postgres +├── checkpoint-sqlite +├── prebuilt +└── langgraph + +prebuilt +└── langgraph + +sdk-py +├── langgraph +└── cli + +sdk-js (standalone) +``` + +Changes to a library may impact all of its dependents shown above. diff --git a/security.md b/security.md deleted file mode 100644 index 22e50057d..000000000 --- a/security.md +++ /dev/null @@ -1,61 +0,0 @@ -# Security Policy - -## Reporting OSS Vulnerabilities - -LangChain is partnered with [huntr by Protect AI](https://huntr.com/) to provide -a bounty program for our open source projects. - -Please report security vulnerabilities associated with the LangChain -open source projects by visiting the following link: - -[https://huntr.com/bounties/disclose/](https://huntr.com/bounties/disclose/?target=https%3A%2F%2Fgithub.com%2Flangchain-ai%2Flangchain&validSearch=true) - -Before reporting a vulnerability, please review: - -1) In-Scope Targets and Out-of-Scope Targets below. -2) The [langchain-ai/langchain](https://github.com/langchain-ai/langchain) monorepo structure. -3) LangChain [security guidelines](https://python.langchain.com/docs/security) to - understand what we consider to be a security vulnerability vs. developer - responsibility. - -### In-Scope Targets - -The following packages and repositories are eligible for bug bounties: - -- langchain-core -- langchain (see exceptions) -- langchain-community (see exceptions) -- langgraph -- langserve - -### Out of Scope Targets - -All out of scope targets defined by huntr as well as: - -- **langchain-experimental**: This repository is for experimental code and is not - eligible for bug bounties, bug reports to it will be marked as interesting or waste of - time and published with no bounty attached. -- **tools**: Tools in either langchain or langchain-community are not eligible for bug - bounties. This includes the following directories - - langchain/tools - - langchain-community/tools - - Please review our [security guidelines](https://python.langchain.com/docs/security) - for more details, but generally tools interact with the real world. Developers are - expected to understand the security implications of their code and are responsible - for the security of their tools. -- Code documented with security notices. This will be decided done on a case by - case basis, but likely will not be eligible for a bounty as the code is already - documented with guidelines for developers that should be followed for making their - application secure. -- Any LangSmith related repositories or APIs see below. - -## Reporting LangSmith Vulnerabilities - -Please report security vulnerabilities associated with LangSmith by email to `security@langchain.dev`. - -- LangSmith site: -- SDK client: - -### Other Security Concerns - -For any other security concerns, please contact us at `security@langchain.dev`.