Out of Scope
libs/sdk-js — Moved to external
langchain-ai/langgraphjs repository; no source in this
repo
libs/checkpoint-conformance — Conformance test suite
only; not shipped code
- LangGraph Server /
langgraph-api — Closed-source server
runtime; not in this repo
- LangChain Core (
langchain-core) — Upstream dependency;
separate threat model
- User application code — Tools, prompts, model selection, deployment
infrastructure
- LLM provider behavior — Model output content and safety
- LangSmith platform — Observability/tracing backend
- Tests, benchmarks, documentation — Not shipped code