Commit Graph

5061 Commits

Author SHA1 Message Date
Alberto Schiabel 527c8947f0 chore(cli): refresh baked toolkit slugs (#4312)
## Summary
Automated refresh of the toolkit slugs the CLI knows without asking
the API, generated by
`ts/packages/cli/scripts/generate-toolkit-slugs.ts`.

Toolkits added since the last refresh currently cost users one
toolkit-list fetch (~2 s) the first time they run one of that
toolkit's tools. Merging this makes them free.

The generator refuses to write a list that is short, malformed, or
missing staple toolkits, so a bad fetch opens no PR at all.
@composio/cli@0.4.1-beta.372
2026-08-31 12:59:29 +02:00
jkomyno 26eedbf5c8 chore(cli): refresh baked toolkit slugs 2026-08-31 06:35:42 +00:00
sdkrelease[bot] 030e86e481 docs: update toolkits, API spec, and meta tools data (#4265)
## Summary
Automated sync of backend data into the docs site. Triggered by:
`schedule`.

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-08-30 12:41:55 -07:00
Soumya Medapati 09d96f914c ci(docs-agent-eval): bump pinned engine to calibrated judge (#4240)
One-line `ENGINE_REF` bump for the docs-agent-eval shim: the pin
predates the judge calibration (docs-agent-eval-ci PRs #4–#7 —
evidence-scoped scans, proxy-log ground truth, infra-vs-agent error
classification, corrected package taxonomy, renamed secret). Until this
merges, label/deployment-triggered evals run the old
false-positive-prone judge; dispatched runs already use current main.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Soumya Medapati <soumyamedapati@mac.local.meter>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-28 17:52:26 -07:00
Alberto Schiabel 64b1b85502 chore(deps): consolidate Dependabot updates (#4290)
This PR:

- supersedes https://github.com/ComposioHQ/composio/pull/4280,
https://github.com/ComposioHQ/composio/pull/4281, and
https://github.com/ComposioHQ/composio/pull/4282
- updates the Claude Code action, production dependencies, TypeScript
tooling, and experimental agent dependencies in one reviewed lockfile
refresh
- retains `@mastra/core@1.52.1` so Worker bundles do not pull in
Node-only `execa`
- aligns `ai@^7.0.79` with `@ai-sdk/mcp` and `@ai-sdk/openai` on
`@ai-sdk/provider-utils@5.0.30`
- adapts Eve approval-policy tests to its widened `ApprovalPolicy |
ApprovalConfiguration` contract
- adds the required patch changeset for the published
`@composio/experimental` TypeBox update
- verifies frozen install, package builds, workspace and example type
checks, all package tests, example validation, Oxlint, and Changesets
status
@composio/cli@0.4.1-beta.371
2026-08-28 16:33:09 +02:00
jkomyno 071bca0feb test(experimental): type Eve approval contexts 2026-08-28 15:35:52 +02:00
jkomyno 4e633d1fe4 chore(changeset): record experimental dependency update 2026-08-28 15:14:54 +02:00
jkomyno fb77efc4ba chore(experimental): update agent dependencies 2026-08-28 14:54:38 +02:00
jkomyno 9758571072 chore(deps-dev): update TypeScript tooling 2026-08-28 14:52:53 +02:00
jkomyno 02bee3b2d9 chore(deps): refresh production dependencies 2026-08-28 14:51:36 +02:00
jkomyno 6016a5eb2b build(deps): update Claude Code action 2026-08-28 14:47:23 +02:00
Alberto Schiabel 1157faf0a1 fix(providers): dereference $ref/$defs before schema translation (#4288)
This PR:
- resolves internal `$ref`/`$defs` in tool input schemas before
translation in `langchain`, `llamaindex`, `claude-agent-sdk`, `vercel`,
`google`, and `openai-agents` (`onUnresolved: 'sentinel'`)
- previously `$ref`-typed properties degraded to `z.any()` — the Zod
converter has no `$ref` branch — or were emitted as dangling references
after the root rebuild (google, openai-agents fallback)
- keeps `openai-agents`' strict-structured-outputs path untouched:
OpenAI resolves `$defs`/`$ref` natively including recursion, pinned by a
guard test
- adds per-provider `$ref` regression suites for all six providers,
including dangling-`$defs` (`GMAIL_FETCH_EMAILS`) and recursive-schema
cases
- adds a cross-provider contract test that fails when a new provider
ships without a `$ref` classification, plus property tests for
`dereferenceJsonSchema` (Python counterparts land with the Python-side
fix)
- changes the vendor-visible schema shape for `$ref`-using tools;
changeset is `minor`

## Context

The same bug was fixed locally twice before (mastra, anthropic) without
surfacing the other six providers — nothing enumerated providers and
asked the `$ref` question. The new contract test does exactly that, so
provider #11 cannot ship unclassified. Python mirrors exist already; the
Python-side provider fix follows separately.
2026-08-28 14:42:35 +02:00
jkomyno 2777545a4c test(core): make $ref contract holdout exclusive, flag polluting-key refs unresolvable 2026-08-28 14:20:23 +02:00
Alberto Schiabel ef230944ec fix(openai): stop logging MCP server URLs to stdout (#4287)
This PR:
- replaces the `console.log` in `wrapMcpServerResponse` with a redacted
`logger.debug` line (server names and count only)
- MCP URLs are user-scoped, bearer-equivalent endpoints; they previously
landed in stdout and aggregated production logs on every call
- adds a regression test asserting no stdout write and an unchanged
return shape
- treats MCP URLs already captured in existing logs as exposed;
regenerate those endpoints server-side
2026-08-28 14:17:48 +02:00
jkomyno 98f16febcd test(core,providers): restore $ref contract and property suites
Regenerate the cross-provider $ref contract test, the
dereferenceJsonSchema property tests, and the openai-agents
$ref contract lost in a session handoff, ported from their
surviving Python counterparts. The openai-agents non-strict
ratchet flips to a plain it now that the fallback dereferences;
the superseded openai-agents-ref.test.ts is removed in favor of
the richer contract file.
2026-08-28 13:34:14 +02:00
jkomyno 9447932d98 fix(providers): dereference $ref/$defs schemas before translation
jsonSchemaToZodSchema has no $ref branch, so a $ref node degrades to
z.any() for langchain, llamaindex, claude-agent-sdk, and vercel's
default path. google and openai-agents' non-strict fallback rebuild
the root from properties/required, discarding $defs while dangling
$ref pointers survive.

Dereference internal $ref/$defs before translation in all six, using
onUnresolved: 'sentinel' so a $ref into an undeclared $defs block
(e.g. GMAIL_FETCH_EMAILS) degrades to a permissive schema instead of
throwing. The mastra and anthropic providers already had this fix;
openai-agents' strict branch is untouched since OpenAI's structured
outputs support $defs/$ref natively, including recursion, and
google's rebuild still drops additionalProperties/title/root
oneOf-anyOf-allOf beyond the dangling-$ref class this fixes.
2026-08-28 11:40:49 +02:00
jkomyno 620075a5de fix(openai): stop logging MCP server URLs to stdout 2026-08-28 11:38:12 +02:00
Alberto Schiabel e5e7c04691 fix(sdk): cap automatic file downloads at 100 MiB (#4283)
This PR:

- caps automatic S3 file downloads at 100 MiB in both SDKs — these were
the only fetch paths left without a size limit, and `s3url` is a
tool-execution response field, so the body behind it is no more trusted
than a user-supplied URL (the same input the SSRF guard already defends
against)
- TypeScript: `downloadFileFromS3` buffered the whole body with
`response.arrayBuffer()`; it now reads through the existing
`readResponseBodyWithLimit` guard, overridable per call via
`maxDownloadBytes`
- Python: `FileDownloadable.download` streamed straight to disk with no
byte accounting; it now uses the same `Content-Length` pre-check plus
authoritative streamed-byte counter as its sibling
`_fetch_file_from_url`, overridable via `max_size`
- fixes two latent defects in the Python write loop found along the way:
- an `OSError` from `fd.write` (disk full, permissions) escaped the
`ErrorDownloadingFile` contract the method documents, surfacing as a raw
`OSError(28)`
- every failure left a partial file on disk that no caller was told
about; cleanup now runs on all error paths via
`_discard_partial_download()`, which suppresses cleanup failures so an
`unlink` error cannot replace the error the caller needs to see
- adds 8 regression tests (2 TypeScript, 6 Python) covering oversized
`Content-Length`, oversized streaming with no/dishonest header,
partial-file cleanup, transport and write failures, and the within-limit
success path
- not a breaking change: the caps default to the existing 100 MiB used
by both sibling paths, and both new parameters are optional

## Context

The streamed byte counter — not the `Content-Length` check — is the
authoritative limit in both SDKs, because a malicious or misconfigured
server can omit or lie in that header. The header check is only an early
abort.

Deliberately out of scope: `RemoteFile.buffer()` / `RemoteFile.blob()`
in `ts/packages/core/src/models/RemoteFile.ts` are explicit
user-initiated whole-file reads. The same `readResponseBodyWithLimit`
treatment is the natural follow-up, but they are not on the automatic
path this PR closes.
2026-08-28 10:53:56 +02:00
jkomyno 9f77e643a5 test(core): use the node: prefix for the fs import
Every other test in the package imports node builtins with the `node:`
prefix — this was the only bare `'fs'` specifier, and inconsistent with
`node:path` on the line above it.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 10:00:25 +02:00
jkomyno 28bcb190d9 refactor(python): collapse redundant download error handlers, cover both
Review follow-up on the download size cap.

`requests.exceptions.RequestException` subclasses `OSError`, so the two
handlers added for the write loop were byte-identical and the second already
subsumed the first. Collapse them into one `except OSError` and say why in a
comment, so the next reader does not re-add the redundant clause.

Route partial-file cleanup through `_discard_partial_download`, which
suppresses cleanup failures: an `OSError` from `unlink` would otherwise
replace the `ResponseTooLargeError` or transport error the caller needs.

Cover the two error paths that had no tests: a transport failure mid-stream
and a failing write both raise `ErrorDownloadingFile` and leave no partial
file behind. Without the handler the write failure escapes as a raw
`OSError(28)` — the defect these pin.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 09:54:23 +02:00
jkomyno 54d07dc5f5 fix(python): cap automatic file download size at 100 MiB
`FileDownloadable.download` streamed the response straight to disk with no
byte accounting, so an untrusted `s3url` could fill the disk. Add the same
`Content-Length` pre-check plus authoritative streamed-byte counter the
sibling `_fetch_file_from_url` already uses, capped at `_MAX_RESPONSE_SIZE`
and overridable per call via `max_size`.

Also close two gaps the write loop left open: an `OSError` from `fd.write`
(disk full, permissions) escaped the documented `ErrorDownloadingFile`
contract, and any failure left a partial file on disk that no caller was
told about. Every failure path now unlinks the partial file;
`ResponseTooLargeError` still propagates uncaught so callers see the limit.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 09:51:04 +02:00
jkomyno 8a56383b24 fix(core): cap automatic S3 download size at 100 MiB
`downloadFileFromS3` buffered the whole response with `arrayBuffer()`. The
`s3Url` it fetches is a tool-execution response field — the same untrusted
input the SSRF guard already defends against — so an oversized or endlessly
streaming body could exhaust the host process's heap.

Route the body through the existing `readResponseBodyWithLimit` guard, which
pre-checks `Content-Length` and counts streamed bytes (the header can be
absent or dishonest). The 100 MiB default matches the upload-from-URL sibling
in the same module; `maxDownloadBytes` overrides it per call.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 09:50:57 +02:00
Alberto Schiabel 3afaee05c5 Release: update version (#4177)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to next, this PR will
be updated.


# Releases
## @composio/core@0.18.0

### Minor Changes

- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.

### Patch Changes

- 449f4e1: Block automatic uploads when a sensitive directory or file
name is hidden by symlink resolution.
- 9545806: Bound the best-effort telemetry requests with a timeout so a
stalled telemetry endpoint cannot leave an SDK call pending
indefinitely.
- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- fe66cbe: Omit empty-string file-uploadable arguments from tool
execution requests instead of forwarding them to the backend, which
rejected them with "Input should be a valid dictionary or instance of
FileUploadable". This now also applies when
`dangerouslyAllowAutoUploadDownloadFiles` is off, and with it on an
empty value is no longer attempted as an upload.
- c0f1609: Fix three ComposioError subclasses
(ComposioToolVersionRequiredError, JsonSchemaToZodError,
JsonSchemaRefResolutionError) that omitted their `this.name` assignment
and therefore reported `name` as 'ComposioError' instead of their own
class name, mis-grouping distinct error types in error telemetry.
- d544006: Close a DNS-rebinding window in the SSRF guard: the address
validated by `assertSafeFetchTarget` is now the address `ssrfSafeFetch`
connects to, so a hostname is no longer resolved a second time between
the check and the connection. Each redirect hop is re-validated and
re-pinned. The request still carries the original hostname in `Host` and
TLS SNI, so certificate verification is unchanged. Hops whose effective
dispatcher is a configured route — a caller-supplied `dispatcher`, a
global `ProxyAgent`/`EnvHttpProxyAgent`, or `NODE_USE_ENV_PROXY`
env-proxy mode — keep the pre-flight check only, mirroring the Python
guard's documented proxy residual.
- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @composio/experimental@0.2.3

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/json-schema-to-zod@0.3.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/anthropic@0.11.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/claude-agent-sdk@0.11.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/cloudflare@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/google@0.10.3

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/langchain@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/llamaindex@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/mastra@0.10.4

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 3c3b4da: `MastraProvider({ strict: true })` now keeps optional
parameters instead of dropping them: every property becomes required and
optional ones accept `null`, matching the OpenAI providers, and a `null`
argument the tool's own schema does not accept is dropped before
execution. Tools whose schema strict mode cannot express keep their
original schema with a warning.
## @composio/openai@0.12.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.
## @composio/openai-agents@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 9692db5: `OpenAIAgentsProvider({ strict: true })` now takes effect:
tools are registered with `strict: true` and a schema normalized for
OpenAI structured outputs (every property required, optional ones accept
`null`), a `null` argument the tool's own schema does not accept is
dropped before execution, and tools whose schema strict mode cannot
express are registered without strict mode with a warning. The option
was previously ignored.
## @composio/vercel@0.11.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.
## @composio/slim@0.18.0

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/cf-workers-basic@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/cf-workers-files@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/cf-workers-tool-router-ai@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## @e2e-tests/node-claude-agent-sdk@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/claude-agent-sdk@0.11.1
## @e2e-tests/node-custom-tools@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/node-json-schema-to-zod-v3@0.0.1

### Patch Changes

- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/node-json-schema-to-zod-v4@0.0.1

### Patch Changes

- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/node-mastra-tool-router-zod-v3@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## @e2e-tests/node-mastra-tool-router-zod-v4@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## @e2e-tests/node-tool-router-files@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/node-tool-router-pagination@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## anthropic-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/anthropic@0.11.1
  - @composio/claude-agent-sdk@0.11.1
## cloudflare-wrangler-example@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## connected-accounts-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## error-handling-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## file-handling-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## google-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/google@0.10.3
## json-schema-to-zod-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## langchain-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/langchain@0.10.2
## llamaindex-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/llamaindex@0.10.2
## mastra-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## mcp-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## modifiers-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## openai-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [9692db5]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/openai-agents@0.10.2
  - @composio/openai@0.12.1
## session-management-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## tool-router-example@1.0.11

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [9692db5]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/claude-agent-sdk@0.11.1
  - @composio/openai-agents@0.10.2
  - @composio/vercel@0.11.2
## toolkits-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## tools-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## triggers-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## vercel-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## versioning-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
py@0.21.0 @e2e-tests/node-custom-tools@0.0.1 @e2e-tests/cli-agent-signin@0.0.0 @composio/cloudflare@0.10.2 @composio/core@0.18.0 openai-example@0.1.10 @composio/claude-agent-sdk@0.11.1 @e2e-tests/node-tool-router-files@0.0.1 @composio/anthropic@0.11.1 versioning-example@0.1.1 modifiers-example@0.1.10 @composio/experimental@0.2.3 @e2e-tests/node-tool-router-pagination@0.0.1 @composio/google@0.10.3 @e2e-tests/node-openai-zod4-compat@0.0.0 mcp-example@0.1.1 @composio/json-schema-to-zod@0.3.1 @composio/langchain@0.10.2 @e2e-tests/node-vercel-ai-sdk-v6@0.0.0 @composio/llamaindex@0.10.2 mastra-example@0.1.1 vercel-example@0.1.10 @composio/mastra@0.10.4 @composio/openai-agents@0.10.2 @composio/openai@0.12.1 llamaindex-example@0.1.1 @e2e-tests/node-mastra-tool-router-zod-v4@0.0.1 @composio/slim@0.18.0 @e2e-tests/node-mastra-tool-router-zod-v3@0.0.1 @composio/vercel@0.11.2 langchain-example@0.1.10 triggers-example@0.1.1 @e2e-tests/cf-workers-basic@0.0.1 @e2e-tests/node-json-schema-to-zod-v4@0.0.1 @e2e-tests/cf-workers-files@0.0.1 json-schema-to-zod-example@0.1.1 @e2e-tests/node-typescript-mjs-import-nodenext@0.0.0 @e2e-tests/cf-workers-tool-router-ai@0.0.1 @e2e-tests/utils@0.0.0 tool-router-example@1.0.11 google-example@0.1.1 @e2e-tests/cli-install@0.0.0 @e2e-tests/cli-run@0.0.0 @e2e-tests/cli-setup-plugins@0.0.0 @e2e-tests/cli-toolkits-info@0.0.0 file-handling-example@0.1.1 @e2e-tests/cli-toolkits-list@0.0.0 @e2e-tests/cli-toolkits-search@0.0.0 @e2e-tests/cli-upgrade@0.0.0 @e2e-tests/cli-version@0.0.0 error-handling-example@0.1.10 @e2e-tests/cli-whoami@0.0.0 @e2e-tests/deno-esm-basic@0.0.0 @e2e-tests/node-cjs-basic@0.0.0 session-management-example@0.1.1 connected-accounts-example@0.1.10 @e2e-tests/node-claude-agent-sdk@0.0.1 tools-example@0.1.1 cloudflare-wrangler-example@0.0.1 @e2e-tests/node-vercel-ai-sdk-v7@0.0.0 @e2e-tests/node-esm-basic@0.0.0 @e2e-tests/node-file-roundtrip@0.0.0 toolkits-example@0.1.10 anthropic-example@0.1.1 @e2e-tests/node-json-schema-to-zod-v3@0.0.1
2026-08-27 20:19:15 +02:00
sdkrelease[bot] dbe5a63965 Release: update version 2026-08-27 18:07:50 +00:00
Alberto Schiabel e2270d12d0 chore(sdk): prepare Python 0.21.0 and TypeScript 0.18.0 (#4272)
This PR:

- unblocks https://github.com/ComposioHQ/composio/pull/4177 by
documenting TypeScript `@composio/core` `0.18.0`
- bumps Python `composio` and all 12 provider distributions from
`0.20.0` to `0.21.0`
- keeps `python/composio/__version__.py` and the pinned `uv.lock`
aligned with package metadata
- adds the combined customer-facing changelog for strict tool schemas,
safer file transfers, and runtime reliability updates
- records the Node.js 22.22.3 minimum for the TypeScript release

## Release sequence

1. Merge this PR into `next`.
2. Merge #4177 after its release-workflow check turns green; Changesets
publishes the TypeScript packages to npm.
3. Tag the resulting `next` commit as `py@0.21.0` to publish the Python
core and provider packages to PyPI.

## Verification

- `pnpm test:release-workflow`
- `mise exec -- uv lock --check`
- `make chk`
- `make build`
- `uv tool run twine check dist/*` (26 artifacts)
- `bun run test` in `docs/` (527 tests)
2026-08-27 20:05:43 +02:00
jkomyno 3cbc7556f5 chore(sdk): prepare Python 0.21.0 and TypeScript 0.18.0 2026-08-27 19:27:19 +02:00
Alberto Schiabel 82ca7384d5 fix(errors): set this.name on three ComposioError subclasses (#4128)
## What

`ComposioError` (`errors/ComposioError.ts`) assigns `name` as a class
field (`public name = 'ComposioError'`). Under the package tsconfig
(es2022 -> `useDefineForClassFields`), each subclass must reassign
`this.name` in its constructor or it inherits the base value. ~30
sibling subclasses do this; three omitted it:

- `ComposioToolVersionRequiredError` (`errors/ToolErrors.ts`)
- `JsonSchemaToZodError` (`errors/ValidationErrors.ts`)
- `JsonSchemaRefResolutionError` (`errors/ValidationErrors.ts`)

So `new JsonSchemaToZodError().name === 'ComposioError'`, and the same
for the other two. All three are thrown on real paths (`Tools.ts`,
`jsonSchema.ts`), and `error.name` is forwarded to error telemetry
(`telemetry/Telemetry.ts`), so these distinct error types silently
mis-group under the base name; any consumer branching on `err.name ===
'<ClassName>'` never matches.

## Fix

Add the missing `this.name = '<ClassName>'` at the end of each of the
three constructors, matching the established sibling pattern.
Runtime-only; no type or public-API change. (The two `PusherErrors`
subclasses set `name` via a class field, which already resolves
correctly, so they are intentionally left untouched.)

## Tests

Adds `test/errors/errorNames.test.ts` asserting each of the three
reports its own class name and is `instanceof ComposioError`. Verified
fails-before / passes-after; full `@composio/core` suite green (1095
tests), plus `tsc`, oxlint, and prettier clean.
2026-08-27 19:17:18 +02:00
Alberto Schiabel 08306f8bc1 Merge branch 'next' into fix/error-subclass-names 2026-08-27 18:51:36 +02:00
Alberto Schiabel b71471c6ef fix(telemetry): bound telemetry requests with an AbortSignal timeout (#4127)
## What

`TelemetryService.sendMetric` and `sendErrorLog` issue `await
fetch(...)` with no timeout. If the telemetry endpoint stalls, the await
never settles. Both are awaited on the SDK's telemetry path
(`Telemetry.ts` batch-processor callback, `sendMetric`, and
`sendErrorTelemetry`), so a stalled telemetry endpoint can leave an SDK
call pending indefinitely — which the existing `catch` comment says must
never happen ("telemetry failures should never affect SDK calls").

## Fix

Wrap both requests in a private `postWithTimeout` helper that bounds
each best-effort request with an `AbortController` + `setTimeout` (3s)
and clears the timer in `.finally()`. This mirrors the already-merged
bound on the background npm version check in `utils/version.ts` (#4027),
including the hand-rolled-timer-over-`AbortSignal.timeout` rationale: an
uncleared timer pins the workerd request context open for the full
timeout on every successful send. On timeout the abort rejects `fetch`,
which the existing `catch` swallows exactly as it already swallowed
network errors, so the best-effort / never-throws contract is unchanged.

## Tests

Adds a `TelemetryService network bounding` suite (mirrors
`version.test.ts`): asserts each method passes an `AbortSignal` and
clears its timer on success, and that a never-responding endpoint
resolves to `undefined` without throwing. Verified fails-before /
passes-after; full `@composio/core` suite green (1092 tests), plus
`tsc`, oxlint, and prettier all clean.
2026-08-27 18:29:23 +02:00
Alberto Schiabel 3c7b938bd1 Merge branch 'next' into fix/telemetry-request-timeout 2026-08-27 18:27:32 +02:00
jkomyno cf42328040 fix(telemetry): clear timeout on serialization errors 2026-08-27 18:23:38 +02:00
Alberto Schiabel b20ca59d91 fix(openai): keep optional parameters under strict mode instead of dropping them (#4257)
This PR:

- builds on top of https://github.com/ComposioHQ/composio/pull/4209 by
@AseemPrasad, keeping its recursive `toStrictJsonSchema()` and Python
parity while changing the mechanism so strict mode stops deleting
parameters
- keeps every optional parameter under `strict: true`: properties become
required and optional ones accept `null` (the emulation OpenAI
documents), instead of dropping 42% of parameters across the 930-tool
corpus; `type` arrays stay as they are, so nullable objects stay
nullable
- sends tools whose schema strict mode cannot express (objects with
arbitrary keys, `allOf`, `prefixItems`, dangling `$ref`s, non-object
roots) with `strict: false` and a warning naming the tool and path,
instead of narrowing them to empty closed objects
- adds `omitNullToolArguments()`: the strict providers drop a `null`
argument only where the tool's own schema rejects it, so nullable fields
keep an explicit `null`
- keeps local `$ref`/`$defs` (recursion included) under strict mode
instead of inlining them
- brings the Python `OpenAIResponsesProvider(strict=True)` to parity:
emits `strict`, calls the base initializer, mirrors the rewrite and null
omission
- makes Mastra and openai-agents use the same strict semantics
(`OpenAIAgentsProvider({ strict: true })` previously had no effect)
- pins the behavior with a shared `strict-cases.json` corpus
(byte-identical TypeScript/Python copies) plus edge-case regression
tests enumerated independently with a second model

## Context

OpenAI's structured-outputs contract accepts `"type": ["string",
"null"]` and rejects `type` next to `anyOf`. Validated against OpenAI's
own `toStrictJsonSchema` converter over the 930 real tool schemas in
`ts/packages/cli/test/__mocks__/tools.json`: the previous approach was
accepted for 930/930 tools but only after removing 1,682 properties;
this one emits strict schemas for 816 tools (all accepted, no property
lost, idempotent) and downgrades the 114 tools that use free-form or
map-style parameters.

https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-27 16:05:56 +02:00
jkomyno 013f753195 chore(docs): rebuild KB semantic artifact 2026-08-27 15:53:22 +02:00
jkomyno f37c6fbec3 docs(strict-mode): correct provider support details 2026-08-27 15:51:18 +02:00
jkomyno 92b0e423e8 chore(docs): rebuild KB semantic artifact 2026-08-27 15:44:29 +02:00
jkomyno a93e8df547 docs(providers): clarify strict schema behavior 2026-08-27 15:41:46 +02:00
jkomyno 9feca8f95d fix(json-schema): accept document-root references in strict mode 2026-08-27 15:39:38 +02:00
jkomyno 507c4fe3a8 fix(python): preserve explicit empty tool schemas 2026-08-27 15:38:27 +02:00
jkomyno d9ea7bbb90 chore(docs): rebuild KB semantic artifact 2026-08-27 15:29:29 +02:00
Alberto Schiabel 81631f83f4 Merge branch 'next' into fix/strict-mode-keep-optional-parameters 2026-08-27 15:14:24 +02:00
Alberto Schiabel 64db269a33 fix(deps-dev): bump langchain-openai from 1.4.3 to 1.6.0 in /python in the pip-version group across 1 directory (#4196)
Bumps the pip-version group with 1 update in the /python directory:
[langchain-openai](https://github.com/langchain-ai/langchain).

Updates `langchain-openai` from 1.4.3 to 1.6.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchain/releases">langchain-openai's
releases</a>.</em></p>
<blockquote>
<h2>langchain-openai==1.6.0</h2>
<p>Changes since langchain-openai==1.5.2</p>
<p>release(openai): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39762">#39762</a>)
feat(core): add standard model exception types (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39538">#39538</a>)
fix(openai): raise clear error on unexpected response type in
<code>_create_chat_result</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39731">#39731</a>)</p>
<h2>langchain-openai==1.5.2</h2>
<p>Changes since langchain-openai==1.5.1</p>
<p>release(openai): 1.5.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39719">#39719</a>)
fix(openai): preserve reasoning item boundaries (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39278">#39278</a>)
release(openai): 1.5.2a1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39709">#39709</a>)
feat(openai): extract gateway metadata from response headers when
available (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39706">#39706</a>)
chore(openai): update snapshots (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39657">#39657</a>)
fix(openai): support o-series models in
<code>get_num_tokens_from_messages</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38710">#38710</a>)</p>
<h2>langchain-openai==1.5.2a1</h2>
<p>Initial release</p>
<p>release(openai): 1.5.2a1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39709">#39709</a>)
feat(openai): extract gateway metadata from response headers when
available (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39706">#39706</a>)
chore(openai): update snapshots (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39657">#39657</a>)
fix(openai): support o-series models in
<code>get_num_tokens_from_messages</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38710">#38710</a>)
release(openai): 1.5.1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39653">#39653</a>)
fix(openai): preserve streamed encrypted reasoning (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39635">#39635</a>)
chore(infra): support langsmith gateway in CI (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39651">#39651</a>)
release(openai): 1.5.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39629">#39629</a>)
feat(openai): support openai 3.0 SDK (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39613">#39613</a>)
chore(partners): bump langgraph floor in openai and huggingface
lockfiles (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39617">#39617</a>)
release(openai): 1.4.3 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39485">#39485</a>)
fix(openai): filter invalid tool calls from content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39366">#39366</a>)
chore(openai): update guidance for responses API for OpenAI-compatible
providers (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39327">#39327</a>)
chore(openai): update docstring for
<code>include_response_headers</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39326">#39326</a>)
release(openai): 1.4.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39322">#39322</a>)
fix(openai): handle <code>ContextWindowExceededError</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39300">#39300</a>)
chore: bump the minor-and-patch group across 3 directories with 7
updates (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39187">#39187</a>)
fix(openai): filter langchain-generated content block IDs (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39209">#39209</a>)
fix(openai): preserve Responses <code>text</code> options (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39204">#39204</a>)
fix(openai): redact MCP <code>authorization</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39155">#39155</a>)
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39050">#39050</a>)
release(openai): 1.4.1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39045">#39045</a>)
feat(anthropic,fireworks,openai): support langsmith gateway through env
var (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38742">#38742</a>)
fix(openai): correct <code>gpt-5.3-chat-latest</code> profile (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39009">#39009</a>)
release(openai): 1.4.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38983">#38983</a>)
chore: bump pillow from 12.2.0 to 12.3.0 in /libs/partners/openai (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38999">#38999</a>)
feat(core): add <code>reasoning_effort</code> as a standard chat model
parameter (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38887">#38887</a>)
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38797">#38797</a>)
release(openai): 1.3.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38785">#38785</a>)
feat(openai): support explicit prompt caching (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38762">#38762</a>)</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchain/commit/3478c28ef21435162cb67abbd2aaef67c7cd8981"><code>3478c28</code></a>
release(anthropic): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39763">#39763</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/420dfc94516f57a4d8662132a55bc532afbc6045"><code>420dfc9</code></a>
release(openai): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39762">#39762</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/85602c3676fbd51e098a01d7c66638719f529f84"><code>85602c3</code></a>
release(core): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39760">#39760</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/5c3538e83a24eaf819ecec066773a232dcd4a8e6"><code>5c3538e</code></a>
fix(core): resolve postponed annotations in
`StructuredTool._injected_args_ke...</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/9984a87fa5a6971c76cb12fc75b37ed74286b740"><code>9984a87</code></a>
feat(core): add standard model exception types (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39538">#39538</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/b3e9eef13c23c3a048f9846e1592b658f85f5f94"><code>b3e9eef</code></a>
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39751">#39751</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/ded2a1fb3c06a9562d9079e42099020ecaca4060"><code>ded2a1f</code></a>
fix(core): allow deserializing <code>RunnablePick</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39753">#39753</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/04ae7447d72e61841905a41b309856c5191452fb"><code>04ae744</code></a>
fix(core): make <code>convert_to_openai_function</code> handle callables
and non-dict ma...</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/37f266278d780cd7ebdfbf1891ba92066192d687"><code>37f2662</code></a>
feat(langchain): support custom token_counter in
ContextEditingMiddleware (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/3">#3</a>...</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/2019bf5ebe50324c548f67c2666a804343f9b772"><code>2019bf5</code></a>
fix(openai): raise clear error on unexpected response type in
`_create_chat_r...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchain/compare/langchain-openai==1.4.3...langchain-openai==1.6.0">compare
view</a></li>
</ul>
</details>
<br />
2026-08-27 15:13:51 +02:00
Alberto Schiabel 5de192a5b8 docs: update TypeScript SDK reference from source (#4260)
## Summary
Auto-generated TypeScript SDK reference docs from
`ts/packages/core/src/`.

Regenerates pages at `docs/content/reference/sdk-reference/typescript/`
to reflect changes in the core package's public API (new methods,
updated signatures, changed types).
2026-08-27 15:09:03 +02:00
Alberto Schiabel e02bb58aa0 docs: update toolkits, API spec, and meta tools data (#4189)
## Summary
Automated sync of backend data into the docs site. Triggered by:
`schedule`.

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs
2026-08-27 14:10:39 +02:00
Sushmithamallesh ca8661e961 docs: update toolkits and API data 2026-08-26 20:46:13 +00:00
jkomyno 0a0095ea82 docs: auto-generate TypeScript SDK reference 2026-08-26 18:10:48 +00:00
Alberto Schiabel 14797bbee6 fix(docs): complete generated string escaping (#4256)
This PR:

- fixes CodeQL alerts
[#48](https://github.com/ComposioHQ/composio/security/code-scanning/48),
[#49](https://github.com/ComposioHQ/composio/security/code-scanning/49),
[#50](https://github.com/ComposioHQ/composio/security/code-scanning/50),
[#51](https://github.com/ComposioHQ/composio/security/code-scanning/51),
[#88](https://github.com/ComposioHQ/composio/security/code-scanning/88),
and
[#89](https://github.com/ComposioHQ/composio/security/code-scanning/89)
- encodes Markdown table delimiters as HTML entities without consuming
existing backslashes
- serializes generated YAML frontmatter strings with `JSON.stringify()`
- escapes existing backslashes before adding MDX metacharacter escapes
in the core docs generator
- adds regression coverage for Markdown tables, YAML frontmatter, and
MDX text
- verifies 38 focused docs tests, docs type-checking and lint, core
type-checking, all 1,123 core tests, and changeset validation
2026-08-26 20:09:14 +02:00
jkomyno c0880764cf fix(docs): escape pipes in generated text 2026-08-26 19:55:59 +02:00
Alberto Schiabel 1862d91faf fix(py): isolate incompatible provider dependencies (#4254)
## Summary

- stop installing the independently distributed Autogen adapter into the
shared CrewAI/LangChain/LangGraph unit-test environment
- run the Autogen import guard and signature regressions in their own
matrix environment
- align the local `tst` nox session with the compatible shared provider
set and add `tst_autogen` for isolated Autogen coverage

## Root cause

`autogen-core==0.7.5` requires `protobuf~=5.29.3`, while CrewAI's
current telemetry dependency chain requires
`googleapis-common-protos>=1.75.1`, whose generated modules require
`protobuf>=6.33.5`.

The packages are independently distributed adapters and are not tested
together, but the workflow installed both into one virtual environment.
Because the installs were sequential, installing Autogen last downgraded
`protobuf` to `5.29.6` and left the already-installed Google modules
unusable:

```text
google.protobuf.runtime_version.VersionError: Detected incompatible Protobuf Gencode/Runtime versions when loading google/rpc/error_details.proto: gencode 6.33.5 runtime 5.29.6.
```

## Regression coverage

The shared suite intentionally skips Autogen because loading it
alongside CrewAI creates the incompatible protobuf environment. CI now
runs these existing regressions in the isolated Autogen environment
instead:

- `test_autogen_signature_honors_skip_defaults`
- `test_autogen_signature_preserves_default`

Developers can reproduce that boundary with `nox -s tst_autogen`.

## Verification

- reproduced the downgrade after the Autogen provider installation
- shared provider environment imports `google.rpc.error_details_pb2`
with `protobuf==6.33.6`
- isolated Autogen environment imports `composio_autogen` with
`protobuf==5.29.6`
- isolated Autogen regressions: 2 passed
- Python unit suite: 1,355 passed, 35 skipped
- Ruff and mypy: passed
- agent-skill and skill-routing validators: passed
- Prettier and `git diff --check`: passed

No Changeset is required: this only changes CI and test-environment
setup.
2026-08-26 19:48:32 +02:00
jkomyno 78fb09efdf test(py): preserve isolated Autogen regression coverage 2026-08-26 19:40:26 +02:00
jkomyno c5690031d3 fix(py): isolate incompatible provider dependencies 2026-08-26 19:40:26 +02:00