mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
@composio/cli@0.4.1-beta.373
1278 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
7da1397017 | Merge branch 'next' into fix/cli-spinner-narrow-terminal-scroll | ||
|
|
41019972e1 |
fix(cli): harden spinner message clamping
Keep live spinner updates within both Clack's construction-time width and the current terminal width, so resizing wider cannot reintroduce wrapped frames while narrower terminals remain clamped. Segment messages by grapheme cluster before measuring display width so keycap and joined emoji cannot be under-counted or split. |
||
|
|
26eedbf5c8 | chore(cli): refresh baked toolkit slugs | ||
|
|
6b135d1606 |
refactor(cli): start clamped spinners in one place
Both spinner entry points constructed a clack spinner on stderr and started it with a clamped message, and useMakeSpinner built a throwaway lambda purely to relay that same clamp into createClackSpinnerHandle. Give makeTerminalUI a startSpinner helper that both entry points call, and let createClackSpinnerHandle take the output stream it clamps against instead of a pre-bound closure. Behaviour is unchanged. Claude-Session: https://claude.ai/code/session_0191yFPnWgJnzPPnCYrVm6X7 |
||
|
|
4e45d7fabe |
fix(cli): clamp spinner messages by display width
Follow-ups from review of the narrow-terminal spinner fix. - Budget and truncate by display columns instead of UTF-16 code units. Clack wraps the rendered frame by width, so a CJK message sat under a `.length` budget and wrapped anyway, reinstating the leak. Walking whole code points also keeps the cut off a surrogate pair. - Drop MIN_SPINNER_MESSAGE_COLUMNS. The 8-column floor exceeded the row below ~15 columns and restored the scroll it was meant to prevent. The budget now degrades to the ellipsis, so the one-row invariant holds wherever it can hold at all. - Cover the paths production actually drives: live `message()` updates and `withSpinner`'s start message. Reverting either clamp previously left the whole suite green. - Advance fake timers past clack's dot animation so the three dot columns SPINNER_RENDER_OVERHEAD reserves are exercised, and run these cases through `it.live` per the package's Effect test convention. - Add the CHANGELOG entry this user-facing fix needs; `@composio/cli` is changeset-ignored, so release notes go there directly. Claude-Session: https://claude.ai/code/session_0191yFPnWgJnzPPnCYrVm6X7 |
||
|
|
071bca0feb | test(experimental): type Eve approval contexts | ||
|
|
fb77efc4ba | chore(experimental): update agent dependencies | ||
|
|
9758571072 | chore(deps-dev): update TypeScript tooling | ||
|
|
02bee3b2d9 | chore(deps): refresh production dependencies | ||
|
|
1157faf0a1 |
fix(providers): dereference $ref/$defs before schema translation (#4288)
This PR: - resolves internal `$ref`/`$defs` in tool input schemas before translation in `langchain`, `llamaindex`, `claude-agent-sdk`, `vercel`, `google`, and `openai-agents` (`onUnresolved: 'sentinel'`) - previously `$ref`-typed properties degraded to `z.any()` — the Zod converter has no `$ref` branch — or were emitted as dangling references after the root rebuild (google, openai-agents fallback) - keeps `openai-agents`' strict-structured-outputs path untouched: OpenAI resolves `$defs`/`$ref` natively including recursion, pinned by a guard test - adds per-provider `$ref` regression suites for all six providers, including dangling-`$defs` (`GMAIL_FETCH_EMAILS`) and recursive-schema cases - adds a cross-provider contract test that fails when a new provider ships without a `$ref` classification, plus property tests for `dereferenceJsonSchema` (Python counterparts land with the Python-side fix) - changes the vendor-visible schema shape for `$ref`-using tools; changeset is `minor` ## Context The same bug was fixed locally twice before (mastra, anthropic) without surfacing the other six providers — nothing enumerated providers and asked the `$ref` question. The new contract test does exactly that, so provider #11 cannot ship unclassified. Python mirrors exist already; the Python-side provider fix follows separately. |
||
|
|
2777545a4c | test(core): make $ref contract holdout exclusive, flag polluting-key refs unresolvable | ||
|
|
98f16febcd |
test(core,providers): restore $ref contract and property suites
Regenerate the cross-provider $ref contract test, the dereferenceJsonSchema property tests, and the openai-agents $ref contract lost in a session handoff, ported from their surviving Python counterparts. The openai-agents non-strict ratchet flips to a plain it now that the fallback dereferences; the superseded openai-agents-ref.test.ts is removed in favor of the richer contract file. |
||
|
|
9447932d98 |
fix(providers): dereference $ref/$defs schemas before translation
jsonSchemaToZodSchema has no $ref branch, so a $ref node degrades to z.any() for langchain, llamaindex, claude-agent-sdk, and vercel's default path. google and openai-agents' non-strict fallback rebuild the root from properties/required, discarding $defs while dangling $ref pointers survive. Dereference internal $ref/$defs before translation in all six, using onUnresolved: 'sentinel' so a $ref into an undeclared $defs block (e.g. GMAIL_FETCH_EMAILS) degrades to a permissive schema instead of throwing. The mastra and anthropic providers already had this fix; openai-agents' strict branch is untouched since OpenAI's structured outputs support $defs/$ref natively, including recursion, and google's rebuild still drops additionalProperties/title/root oneOf-anyOf-allOf beyond the dangling-$ref class this fixes. |
||
|
|
620075a5de | fix(openai): stop logging MCP server URLs to stdout | ||
|
|
9f77e643a5 |
test(core): use the node: prefix for the fs import
Every other test in the package imports node builtins with the `node:` prefix — this was the only bare `'fs'` specifier, and inconsistent with `node:path` on the line above it. Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z |
||
|
|
8a56383b24 |
fix(core): cap automatic S3 download size at 100 MiB
`downloadFileFromS3` buffered the whole response with `arrayBuffer()`. The `s3Url` it fetches is a tool-execution response field — the same untrusted input the SSRF guard already defends against — so an oversized or endlessly streaming body could exhaust the host process's heap. Route the body through the existing `readResponseBodyWithLimit` guard, which pre-checks `Content-Length` and counts streamed bytes (the header can be absent or dishonest). The 100 MiB default matches the upload-from-URL sibling in the same module; `maxDownloadBytes` overrides it per call. Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z |
||
|
|
dbe5a63965 | Release: update version | ||
|
|
08306f8bc1 | Merge branch 'next' into fix/error-subclass-names | ||
|
|
3c7b938bd1 | Merge branch 'next' into fix/telemetry-request-timeout | ||
|
|
cf42328040 | fix(telemetry): clear timeout on serialization errors | ||
|
|
f37c6fbec3 | docs(strict-mode): correct provider support details | ||
|
|
a93e8df547 | docs(providers): clarify strict schema behavior | ||
|
|
9feca8f95d | fix(json-schema): accept document-root references in strict mode | ||
|
|
81631f83f4 | Merge branch 'next' into fix/strict-mode-keep-optional-parameters | ||
|
|
7ad88415c7 |
fix(cli): stop spinner from scrolling endlessly in narrow terminals
Clack's spinner erases the previous frame by re-wrapping the raw message, but each frame actually renders three extra prefix columns plus up to three animated dots. Once those extras push the rendered frame across a wrap boundary — e.g. the ~90-column upgrade message in a narrower terminal — the erase under-counts lines and every 80ms tick leaks one, scrolling 'New version available: …' forever. Clamp live spinner messages (start and message updates) to a single terminal row so the redraw arithmetic cannot diverge. Stop/error messages are single writes and stay untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
c0880764cf | fix(docs): escape pipes in generated text | ||
|
|
8fe03eff47 |
test(json-schema): add strict-mode edge cases enumerated with a second model
Extends strict-cases.json to 68 cases with shapes enumerated independently (single-element and three-member type arrays, null-only and null-carrying enum/const properties, nested compositions, nullable objects in arrays, tuple and boolean items, conditional and dependency keywords, oneOf beside anyOf, boolean and malformed properties, $ref siblings and chains, legacy definitions next to $defs, non-string required entries, ten-level nesting) plus null-omission pairs for nullable, composed and $ref-typed arguments. Checks in the generator that derives the pinned JSON. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
b47d5137c2 |
fix(core): report every construct strict mode cannot rewrite
Tuple-form items, boolean subschemas, malformed properties, oneOf left beside anyOf, and the conditional and dependency keywords (not, if, then, else, dependencies, dependentSchemas, propertyNames, contains, additionalItems, unevaluatedItems, unevaluatedProperties) are now reported as unsupported so the tool is sent without strict mode instead of with a schema the API rejects. A root typed ["object"] is accepted, and an enum or const that already includes null is not wrapped again. omitNullToolArguments now follows the anyOf/oneOf branch that matches an argument's shape, so nulls inside an object sent for a composed property are reconciled against that branch. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
678ac7260a | fix(docs): complete generated string escaping | ||
|
|
3ca07210d3 |
test(json-schema): drive strict-mode cases from a shared corpus
strict-cases.json (one byte-identical copy per language, next to object-cases.json) pins the exact strict schema or the reported incompatibilities for 44 shapes: optional widening at every depth, nullable type arrays, compositions, enum/const wrapping, annotation stripping, keyword-named and prototype-named properties, dynamic-key and free-form objects, allOf/prefixItems, $defs recursion, dangling and external refs, malformed required, non-object roots, plus null-omission argument pairs. The TypeScript suite pins the implementation and the Python suite checks parity against the same file. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
991c57af80 |
fix(core): keep properties named like prototype keys under strict mode
toStrictJsonSchema assigned rewritten property schemas by name, so a property called __proto__ set the prototype of the properties map instead of being stored and disappeared from the strict schema. Own properties are now defined explicitly, matching the other schema walkers in this module. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
9692db5c0a |
fix(openai-agents): honor the strict option
OpenAIAgentsProvider accepted { strict } but always registered tools with
strict: false and additionalProperties: true. Strict mode now registers
tools with strict: true and a schema normalized by toStrictJsonSchema
(optional parameters required-nullable), drops null arguments the tool
schema rejects before execution, and registers tools strict mode cannot
express without strict mode with a warning.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
|
||
|
|
3c3b4dae94 |
fix(mastra): keep optional parameters under strict mode
MastraProvider strict mode used the root-only, input-mutating removeNonRequiredProperties, so "strict" meant something different from the OpenAI providers. It now runs the same toStrictJsonSchema rewrite: optional parameters become required-nullable, tools strict mode cannot express keep their original schema with a warning, and null arguments the tool schema rejects are dropped before execution. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
e6fb9f9d32 |
feat(core): keep $defs recursion under strict mode
OpenAI structured outputs support local $ref pointers, including recursive definitions, so toStrictJsonSchema no longer inlines them: $defs and definitions are normalized where they are declared, an optional $ref property is widened with an anyOf null branch, and external or dangling $refs are reported as unsupported. omitNullToolArguments follows local $refs when deciding whether a null is accepted. The Vercel provider still inlines definitions before converting to Zod, which does not follow $ref. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
fb30e8f299 |
fix(vercel): keep optional parameters available under strict mode
VercelProvider strict mode now widens optional parameters to nullable instead of dropping them, keeps the original schema for tools strict mode cannot express, and drops null arguments the tool schema rejects before execution. The README and docs page described the old dropping behavior. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
6a7ddbad06 |
fix(openai): send tools strict mode cannot express without strict
OpenAIResponsesProvider emits the strict schema and strict: true only when the rewrite is lossless; otherwise the tool keeps its original schema with strict: false and a warning names the tool and path. Tools without parameters get a canonical empty closed object. Null arguments the tool schema rejects are dropped before execution. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
4f69975475 |
fix(core): keep optional parameters under strict mode instead of dropping them
toStrictJsonSchema now follows the contract OpenAI documents for structured outputs: every property becomes required and optional ones are widened to accept null, so the model keeps every parameter it could pass before. Type arrays stay as they are (the API accepts them and rejects type next to anyOf), so nullable objects stay nullable. Constructs strict mode cannot express (objects with arbitrary keys, allOf, prefixItems, unresolved $refs, non-object roots) are reported in `unsupported` instead of being narrowed. omitNullToolArguments drops a null argument only where the tool's own schema rejects it, so nullable fields keep an explicit null. The keyword taxonomy shared by the three schema walkers now lives in one place. Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com> Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs |
||
|
|
18944df9eb |
fix(cli): verify codex-acp tarballs against the lockfile before packaging them (#4217)
# Description Found by the scheduled security audit while reviewing the CLI release pipeline. `ts/packages/cli/scripts/_acp-adapters.ts` downloads four `@zed-industries/codex-acp-<platform>` tarballs directly from the registry at release-build time — it has to, because `pnpm` only installs the optional dependency matching the runner's own platform while the archive must name all four. Those bytes were then extracted, `chmod 0755`'d, and packaged inside the published `composio` CLI archive **without being checked against any known hash**. That made the codex-acp binaries the one dependency in the release that received none of the integrity verification `pnpm install --frozen-lockfile` applies to everything else, despite `pnpm-lock.yaml` already pinning a `sha512` for each of them: ``` '@zed-industries/codex-acp-linux-x64@0.16.0': resolution: {integrity: sha512-xs5zZBLpJuciEbZNx6ZSNL0qCa9h3i/zWpj40sp6QtF+L4Ow/7qzHdBzboGhHdcz1jrLedfZeRFDA2Elj8TLMA==} ``` Distribution is `curl -fsSL https://composio.dev/install | sh`, so anything that reached those bytes between the registry and the archive would ship executable to every CLI user inside an otherwise-signed release. ## What changed New `scripts/_tarball-integrity.ts`: - `parseLockfileIntegrity` — maps every `name@version` in `pnpm-lock.yaml` to its recorded hash. Line-based rather than a YAML parse: the shape being read is two adjacent lines, and this keeps a build script free of a YAML dependency. - `expectedIntegrityFor` — returns the pinned hash, and **throws** for a package the lockfile never resolved. - `assertBytesMatchIntegrity` — Web Crypto digest compared against the pinned value; the algorithm is read from the expected string so a lockfile that moves off sha512 keeps working. - `findLockfilePath` / `loadLockfileIntegrity` — walk up from the script rather than resolving a fixed `../../..`. `_acp-adapters.ts` now looks the hash up *before* the download and verifies the archive bytes before extracting them. Two deliberate choices: - **Checked against the lockfile, not the registry's `dist.integrity`** — whoever can serve the tarball can serve the metadata that vouches for it. - **Fail-closed throughout** — a missing lockfile, or a package absent from it, aborts the build rather than packaging unverified bytes. Scope is limited to the integrity gap. The `@zed-industries/codex-acp*` family is deprecated upstream ("replaced by `@agentclientprotocol/codex-acp`") and pinned at `0.16.0`; migrating it is a separate call for whoever owns the ACP integration. # How did I test this PR **Unit — 16 new tests, all passing:** ``` $ vitest run test/src/scripts/tarball-integrity.test.ts Test Files 1 passed (1) Tests 16 passed (16) ``` Covers quoted scoped keys and unquoted bare keys, resolutions carrying no integrity, `snapshots:` repeats, a package absent from the lockfile, a version pinned under a different number, tampered bytes, a single flipped byte, an uncomputable algorithm, sha256 as well as sha512, and the upward lockfile walk (including the no-lockfile-anywhere case). One test asserts this repository actually pins a hash for all four packaged codex-acp binaries. **Live end-to-end against the real registry** — the real 74,914,872-byte `@zed-industries/codex-acp-linux-x64@0.16.0` tarball, downloaded and run through the same code path the build uses: ``` downloaded 74914872 bytes from https://registry.npmjs.org/@zed-industries/codex-acp-linux-x64/-/codex-acp-linux-x64-0.16.0.tgz PASS: real tarball matches the lockfile pin PASS: tampered rejected — TarballIntegrityError: Integrity mismatch for @zed-industries/codex-acp-linux-x64@0.16.0. PASS: unpinned version refused — TarballIntegrityError: @zed-industries/codex-acp-linux-x64@0.99.0 has no integrity hash in pnpm-lock.yaml; refusing to package unverified bytes. ``` So the check passes on genuine bytes, rejects a single flipped byte in a 75 MB archive, and refuses a version the lockfile does not pin. **Lint / types / boundaries:** - `oxlint` on all three files — clean. (First draft used `node:crypto`; `no-restricted-imports` bans it, so the digest went to Web Crypto.) - `prettier --check` — clean. - `tsc --noEmit` — no errors in any of the three changed files. This sandbox has 820 pre-existing errors from an unbuilt workspace (only 7 of 70 projects installed); `test/src/scripts/release-artifacts.test.ts` fails to import here for the same reason, on `next` as well as on this branch. - `pnpm run validate:boundaries` — `lint boundaries OK: 4 registered disables across 4 files` (unchanged; `scripts/` and `test/` sit outside the `src/` Effect boundary policy). # Security - **Grype** — `grype dir:ts/packages/cli/scripts --only-fixed --fail-on medium` → `No vulnerabilities found`. - **Socket** — could not run. `doppler secrets get SOCKET_API_TOKEN --plain --project hermes --config dev_zen` returns empty in this cron sandbox, so `socket ci` exits with `Auth Error`. Reporting rather than skipping silently; this change adds no dependency, so the dependency-alert surface is unchanged. - No new dependencies, no new network destinations. The one behavioural change is a fail-closed integrity check on bytes that were previously trusted unverified. Origin: cron-48e51eab745f / [zen-cron-44e260352d1a](https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a) Triggered by: saransh@composio.dev | Source: unknown Session: https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a |
||
|
|
9e958948c5 |
fix(core): block sensitive upload paths hidden behind a symlinked directory (#4218)
# Description
Found by the scheduled security audit, while checking whether a test
failure on my other PR was pre-existing. It was — and the reason it
fails is a real gap in a shipped security control.
`isBlockedSensitiveFileUploadPath` (the GHSA-hp3h-89pf-5q58 denylist)
matched deny segments **only against the symlink-resolved path**. That
catches a benign name pointing at a secret — `~/innocent-name ->
~/nested/.aws/creds`, which the existing test covers — but misses the
inverse:
| Layout | Written path | Resolved path | Blocked before? |
|---|---|---|---|
| `~/innocent -> ~/.aws/creds` | no `.aws` | **`.aws`** | yes |
| `~/.claude -> /state/claude` | **`.claude`** | no `.claude` | **no** |
`~/.claude/settings.json` resolves to `/state/claude/settings.json`,
which has no `.claude` segment, so it sailed through — and `.claude` is
on the denylist precisely because it *"may contain API keys and project
context read by assistants"*.
This layout is not exotic. Dotfile managers (chezmoi, stow, yadm) and
containerised home directories produce it routinely — Composio's own
agent sandbox image has `/home/zen/.claude -> /state/claude`. For every
user in that shape the control was silently inactive, which is the worst
failure mode for a denylist: no error, no warning, upload proceeds.
The same hiding trick applies to the basename check (`~/.env ->
/state/plain-config`), so that path is fixed too.
## Why CI never caught this
`ts/packages/core/test/utils/sensitiveFileUploadPaths.test.ts` **already
asserts** the blocked behaviour:
```ts
expect(isBlockedSensitiveFileUploadPath(path.join(os.homedir(), '.claude', 'settings.json'))).toBe(true);
```
That assertion has been failing on `next` on any machine where
`~/.claude` is a symlink. It passes in CI only because `~/.claude` does
not exist on the runners: `existsSync` is false, no `realpath` runs, and
the written path keeps its `.claude` segment. The test is
environment-dependent, so green CI was never evidence the control
worked.
## The fix
The TypeScript `normalizePath` helper now returns both the written and
resolved segments, and the segment scan and basename check each consider
both. The Python guard now applies the same rule. Either path can carry
the denied name, so both SDKs inspect both forms.
# How did I test this PR
**The TypeScript fix is gated by tests — 3 fail without it, 13/13 pass
with it.**
Without the `src` change (test file only):
```
× blocks common credential directory segments
× blocks a sensitive directory that is itself a symlink to a plain path
× blocks a denied basename whose symlink target is named innocuously
Tests 3 failed | 10 passed (13)
```
With the fix:
```
Test Files 1 passed (1)
Tests 13 passed (13)
```
Note the first of those three is the **pre-existing** assertion quoted
above — this PR turns it green rather than adding it.
Three tests added, each building a real symlink in a temp dir:
- sensitive directory that is itself a symlink to a plain path (the
`~/.claude -> /state/claude` case), asserting both
`isBlockedSensitiveFileUploadPath` and that `assertSafeFileUploadPath`
throws
- denied basename whose symlink target is named innocuously (`.env ->
plain-config`)
- **negative case**: an ordinary file reached through a symlinked
directory (`docs/document.pdf`) is still allowed, so the fix does not
over-block
The Python parity change adds the same three cases. Before the Python
source change, the sensitive written directory and basename both
returned `False`; with the fix, all 11 focused Python tests pass.
**Full verification:**
| Command | Result |
|---|---|
| `vitest run` in `ts/packages/core` | **48 files, 1114 tests passed** |
| `pnpm typecheck` (workspace) | **14/14 tasks successful**, exit 0 |
| `oxlint` on both changed files | exit 0, clean |
| `prettier --check` on both changed files | "All matched files use
Prettier code style!" |
| `nox -s chk` in `python/` | Ruff and mypy passed |
| `nox -s tst` in `python/` | **1339 passed, 33 skipped**, exit 0 |
# Security
- No dependency changes, no new network calls, no new imports. The diff
is limited to the equivalent TypeScript and Python guards, their tests,
and the required `@composio/core` patch changeset.
- This **strengthens** an existing control and cannot weaken it: the
previous match set is a strict subset of the new one, so nothing that
was blocked before is allowed now. The added negative test pins that the
widening does not over-block ordinary files.
- **Grype** — `grype dir:ts/packages/core --only-fixed --fail-on medium`
→ reported below.
- **Socket** — could not run; `doppler secrets get SOCKET_API_TOKEN
--plain --project hermes --config dev_zen` returns empty in this cron
sandbox, so `socket ci` exits `Auth Error`. Reporting rather than
skipping silently.
- Unrelated pre-existing note: the repo's `pnpm audit --prod` comment
flags `extract-zip <=2.0.1` with `Patched versions >=2.0.2`, a version
that does not exist on npm. Details in #4217.
Origin: cron-48e51eab745f /
[zen-cron-44e260352d1a](https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a)
Triggered by: saransh@composio.dev | Source: unknown
Session:
https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a
|
||
|
|
52f8861c95 |
docs(gemini): update to use gemini 3.7 and new models (#4244)
## Summary Updates docs and sample scripts to use latest Gemini models. ## Changes - Vertex & Gemini sample scripts updated - Plus accompanying markdown ## Type of change - [ ] Bug fix - [ ] New feature - [ ] Refactor/Chore - [x] Documentation - [ ] Breaking change ## How Has This Been Tested? Visual inspection ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [x] I ran linters/tests locally and they passed - [x] I updated documentation as needed - [ ] I added tests or explain why not applicable - [ ] I added a changeset if this change affects published packages ## Additional context |
||
|
|
f174b28c3a |
fix(sdk): omit empty file-uploadable arguments from tool execution (#4238)
This PR: - closes https://github.com/ComposioHQ/composio/issues/4233 - stops forwarding `""` for a `file_uploadable` parameter (e.g. Gmail `attachment`) to the backend, which rejected it with `Input should be a valid dictionary or instance of FileUploadable` - Python: parameterizes the upload walker on a `leaf` handler and adds `FileHelper.drop_empty_file_uploads()`, run on both `Tools.execute` paths when `dangerously_allow_auto_upload_download_files` is off (the default) - TypeScript: moves the walker into the runtime-neutral `walkFileUploadableLeaves()` with a `DELETE_VALUE` sentinel and `dropEmptyFileUploads()`, so the flag-off path also works on edge runtimes; with the flag on, `''` is no longer attempted as an upload (previously threw `Either path or blob must be provided`) - TypeScript: `schemaHasFileProperty()` now looks through `$defs`/`definitions`, so the flag-off pass (and the existing one-shot warning) fire for `$ref`-based file schemas - keeps each SDK's existing `null` semantics: Python omits `None` as before, TypeScript still passes `null` through for schemas with a `null` variant - adds regression tests for both SDKs and a `@composio/core` changeset ## Context Reproduced against staging with `composio==0.16.0` and the current SDK: the live `GMAIL_CREATE_EMAIL_DRAFT` schema is `anyOf[FileUploadable, array[FileUploadable]]` with no `null` variant, and `""` yields the exact error from the issue on `no_auth` file tools (`TEXT_TO_PDF_UPLOAD_FILE`). With this change the backend sees the parameter as not provided, matching what the playground UI sends. |
||
|
|
96c6260b8c | Merge branch 'next' into 37f-docs | ||
|
|
e3d2c093e3 | docs(gemini): update to use gemini 3.7 and new models | ||
|
|
765d67ad65 | fix(ts): preserve proxy compatibility suppression | ||
|
|
a61ad27940 | fix(ts): preprocess session file uploads | ||
|
|
505d8914ad |
fix(core): keep @ts-ignore on deprecated proxy param
|
||
|
|
fe66cbeb77 |
fix(sdk): omit empty file-uploadable arguments from tool execution
Both SDKs forwarded "" for a file_uploadable parameter (e.g. Gmail attachment) verbatim to the backend, which rejected it with a Pydantic validation error. Python only dropped it inside the opt-in auto-upload walker; TypeScript never did, and with auto-upload on it tried to upload the empty string. Run a schema-aware, upload-free pass on the default execute path that omits empty file values, and reuse the same walker for staging when auto-upload is enabled. Closes #4233 |
||
|
|
994b2f2fff | Merge branch next into chore/changesets-v3-migration | ||
|
|
96d6c87705 |
fix(deps): bump the npm-production group across 1 directory with 26 updates (#4231)
Bumps the npm-production group with 26 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript) | `0.3.233` | `0.3.239` | | [@mastra/mcp](https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp) | `1.16.0` | `1.17.1` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.256` | `6.0.263` | | [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.117.1` | `0.120.0` | | [@google/genai](https://github.com/googleapis/js-genai) | `2.17.1` | `2.18.0` | | [@langchain/core](https://github.com/langchain-ai/langchainjs) | `1.2.8` | `1.2.9` | | [@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core) | `1.4.10` | `1.4.12` | | [@langchain/openai](https://github.com/langchain-ai/langchainjs) | `1.5.8` | `1.5.10` | | [langchain](https://github.com/langchain-ai/langchainjs) | `1.5.9` | `1.5.10` | | [@openai/agents](https://github.com/openai/openai-agents-js) | `0.16.0` | `0.17.0` | | [@langchain/anthropic](https://github.com/langchain-ai/langchainjs) | `1.5.6` | `1.5.8` | | [@langchain/mcp-adapters](https://github.com/langchain-ai/langchainjs) | `1.1.3` | `1.1.4` | | [@agentclientprotocol/sdk](https://github.com/agentclientprotocol/typescript-sdk) | `1.3.0` | `1.4.0` | | [typebox](https://github.com/sinclairzx81/typebox) | `1.3.14` | `1.3.16` | | [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) | `2.0.32` | `2.0.34` | | [@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai) | `4.0.42` | `4.0.45` | | [@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers) | `0.21.3` | `0.22.0` | | [@cloudflare/workers-types](https://github.com/cloudflare/workerd) | `5.20260815.1` | `5.20260821.1` | | [@mastra/core](https://github.com/mastra-ai/mastra/tree/HEAD/packages/core) | `1.52.1` | `1.61.0` | | [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.26.0` | `1.30.0` | | [@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun) | `1.3.14` | `1.4.0` | | [@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui) | `4.1.10` | `4.1.11` | | [pnpm](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm) | `11.21.0` | `11.22.0` | | [publint](https://github.com/publint/publint/tree/HEAD/packages/publint) | `0.3.23` | `0.3.24` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `4.1.11` | | [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler) | `4.123.0` | `4.125.0` | Updates `@anthropic-ai/claude-agent-sdk` from 0.3.233 to 0.3.239 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/anthropics/claude-agent-sdk-typescript/releases">@anthropic-ai/claude-agent-sdk's releases</a>.</em></p> <blockquote> <h2>v0.3.239</h2> <h2>What's changed</h2> <ul> <li><code>total_cost_usd</code> / <code>modelUsage.costUSD</code> now include the 1.1× US-only-inference (data residency) multiplier when the response reports <code>inference_geo: "us"</code></li> <li>A result held back for background subagents in one-shot mode now reports <code>total_cost_usd</code>, <code>duration_api_ms</code> and <code>modelUsage</code> as of its release, not the turn-end snapshot</li> <li>Fixed <code>SYSTEM_PROMPT_DYNAMIC_BOUNDARY</code> in an array <code>systemPrompt</code> being sent to the model as literal text on Bedrock, Vertex, Foundry, and gateway providers</li> <li>A repeated <code>initialize</code> on a running process is now followed by a <code>background_tasks_changed</code> snapshot of the live background tasks, so reconnecting hosts see work that is still running</li> </ul> <h2>Update</h2> <pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.239 # or yarn add @anthropic-ai/claude-agent-sdk@0.3.239 # or pnpm add @anthropic-ai/claude-agent-sdk@0.3.239 # or bun add @anthropic-ai/claude-agent-sdk@0.3.239 </code></pre> <h2>v0.3.238</h2> <h2>What's changed</h2> <ul> <li>Added <code>is_backgrounded</code> and <code>spawn_depth</code> to <code>task_started</code> events for subagent tasks (<code>is_backgrounded</code> also on background Bash tasks)</li> <li>Added <code>suppressOriginalPrompt</code> to <code>UserPromptExpansion</code> hook output, matching <code>UserPromptSubmit</code></li> <li>Added <code>command_lifecycle</code> state <code>refused</code>: a cross-session peer message the session's receive-side policy declines now reports this terminal state instead of producing no lifecycle frames</li> <li>Fixed SDK hook callbacks silently not applying after a host re-sends <code>initialize</code> to an already-running CLI; the response now reports <code>hooks_applied</code></li> <li>Fixed <code>CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true</code> not keeping <code>prompt_suggestion</code> messages on when the account is near, but not over, its usage limit</li> <li>Changed <code>vcs_state_changed</code> push events to emit one event per pushed branch</li> </ul> <h2>Update</h2> <pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.238 # or yarn add @anthropic-ai/claude-agent-sdk@0.3.238 # or pnpm add @anthropic-ai/claude-agent-sdk@0.3.238 # or bun add @anthropic-ai/claude-agent-sdk@0.3.238 </code></pre> <h2>v0.3.237</h2> <h2>What's changed</h2> <ul> <li>Updated to parity with Claude Code v2.1.237</li> </ul> <h2>Update</h2> <pre lang="sh"><code></tr></table> </code></pre> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md">@anthropic-ai/claude-agent-sdk's changelog</a>.</em></p> <blockquote> <h2>0.3.239</h2> <ul> <li><code>total_cost_usd</code> / <code>modelUsage.costUSD</code> now include the 1.1× US-only-inference (data residency) multiplier when the response reports <code>inference_geo: "us"</code></li> <li>A result held back for background subagents in one-shot mode now reports <code>total_cost_usd</code>, <code>duration_api_ms</code> and <code>modelUsage</code> as of its release, not the turn-end snapshot</li> <li>Fixed <code>SYSTEM_PROMPT_DYNAMIC_BOUNDARY</code> in an array <code>systemPrompt</code> being sent to the model as literal text on Bedrock, Vertex, Foundry, and gateway providers</li> <li>A repeated <code>initialize</code> on a running process is now followed by a <code>background_tasks_changed</code> snapshot of the live background tasks, so reconnecting hosts see work that is still running</li> </ul> <h2>0.3.238</h2> <ul> <li>Added <code>is_backgrounded</code> and <code>spawn_depth</code> to <code>task_started</code> events for subagent tasks (<code>is_backgrounded</code> also on background Bash tasks)</li> <li>Added <code>suppressOriginalPrompt</code> to <code>UserPromptExpansion</code> hook output, matching <code>UserPromptSubmit</code></li> <li>Added <code>command_lifecycle</code> state <code>refused</code>: a cross-session peer message the session's receive-side policy declines now reports this terminal state instead of producing no lifecycle frames</li> <li>Fixed SDK hook callbacks silently not applying after a host re-sends <code>initialize</code> to an already-running CLI; the response now reports <code>hooks_applied</code></li> <li>Fixed <code>CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true</code> not keeping <code>prompt_suggestion</code> messages on when the account is near, but not over, its usage limit</li> <li>Changed <code>vcs_state_changed</code> push events to emit one event per pushed branch</li> </ul> <h2>0.3.237</h2> <ul> <li>Updated to parity with Claude Code v2.1.237</li> </ul> <h2>0.3.236</h2> <ul> <li><code>PostToolUse</code> hooks can return <code>hookSpecificOutput.classifierContext</code>, a short host-asserted note about a tool call's result that the auto mode permission classifier reads alongside that result</li> </ul> <h2>0.3.235</h2> <ul> <li>Updated to parity with Claude Code v2.1.235</li> </ul> <h2>0.3.234</h2> <ul> <li>Removed unused <code>bypass_permissions_disabled</code> from <code>ExitReason</code> type; the value was never emitted — TypeScript consumers with an explicit <code>case</code> branch get a compile error on upgrade (runtime unaffected)</li> <li>Updated the <code>ApiKeySource</code> type to include the values <code>system/init</code> actually reports (<code>ANTHROPIC_API_KEY</code>, <code>apiKeyHelper</code>, <code>/login managed key</code>, <code>none</code>)</li> <li><code>vcs_state_changed</code> events report the directory the shell finished in (an inner <code>cd</code> is reflected)</li> <li>A peer <code>origin</code> injected by the host may declare the sending session's permission class (<code>fromMode</code>) so a same-class message is delivered to a recipient that runs without asking</li> <li><code>SDKSystemMessage</code> (<code>system</code>/<code>init</code>) gains an optional <code>effort</code> field: the session's applied effort level, or <code>null</code> when none is sent. Set on Remote Control bridge init frames</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/ae7e3dd656244b67e8634c33b3137775ae5a3fcd"><code>ae7e3dd</code></a> chore: Update CHANGELOG.md</li> <li><a href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/c4fdbe3a4309f7165a4c3bee179c155d0422ff4c"><code>c4fdbe3</code></a> chore: Update CHANGELOG.md</li> <li><a href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/591a180a197a73ce90042a6f97a7c59c100d2c3a"><code>591a180</code></a> chore: Update CHANGELOG.md</li> <li><a href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/d933c997f2282179582d97c562b4d3451e74c0ee"><code>d933c99</code></a> chore: Update CHANGELOG.md</li> <li><a href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/076593f6db4357c3a050a5ed19c39ba1217eab3a"><code>076593f</code></a> chore: Update CHANGELOG.md</li> <li><a href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/a616205d6cb7c2f5907120f660f6391310918369"><code>a616205</code></a> chore: Update CHANGELOG.md</li> <li>See full diff in <a href="https://github.com/anthropics/claude-agent-sdk-typescript/compare/v0.3.233...v0.3.239">compare view</a></li> </ul> </details> <br /> Updates `@mastra/mcp` from 1.16.0 to 1.17.1 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/mastra-ai/mastra/blob/main/packages/mcp/CHANGELOG.md">@mastra/mcp's changelog</a>.</em></p> <blockquote> <h2>1.17.1</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fixed MCP tool listing when a tool has no input schema. (<a href="https://redirect.github.com/mastra-ai/mastra/pull/21861">#21861</a>)</p> </li> <li> <p>Fixed <code>Cannot find package '@modelcontextprotocol/sdk'</code> when importing <code>@mastra/mcp</code> in projects that skip automatic peer installation (e.g. npm with <code>--legacy-peer-deps</code>), by declaring the MCP SDK v1 peer required by <code>@modelcontextprotocol/ext-apps</code> as a direct dependency. (<a href="https://redirect.github.com/mastra-ai/mastra/pull/21999">#21999</a>)</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/mastra-ai/mastra/commit/88d14cac008582a618fecc3d5c7fd3bdf4f6ddc3"><code>88d14ca</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/480e491588bd6a7a1c9ee4407590ad625dd33952"><code>480e491</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/acc3471de5f3fde8027ee4e355af292b2bc1bc30"><code>acc3471</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/b6a771ef23d203ddb348efca8065eff65def8191"><code>b6a771e</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/3bb88ddf07fb98f3cd16d3bff94e51cd3b45d011"><code>3bb88dd</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/d23e75d57cc7cf5b9bfdbee896bf5a6a2484fed7"><code>d23e75d</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/c8faa4e1cfebaec56b65e754e90b9fe46d153359"><code>c8faa4e</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/d378d7511f71309ed61a8f6b93cd0361dc6cb70f"><code>d378d75</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/26d40160ff7f7d8bf95fee2039a52cbc83863533"><code>26d4016</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/7c60df5c7872343fbac5c3e5b1175c8076a5abfd"><code>7c60df5</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/f2031a47445e8f67a89ba1309036816f97ab7a65"><code>f2031a4</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/cad42082e6aa1776168a94914f523334be45d929"><code>cad4208</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/8e529d4ac754efef04b225841349e0da9edf89a6"><code>8e529d4</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/57c51035a2a36e3df3c4f32f46bb789a66ed5946"><code>57c5103</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/038b7b405cb4ac25ab3f3031334111b1f87ac112"><code>038b7b4</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/4132d61f8367077120ee9e6420d3224dffd93c93"><code>4132d61</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/d378d7511f71309ed61a8f6b93cd0361dc6cb70f"><code>d378d75</code></a>]:</p> <ul> <li><code>@mastra/core</code><a href="https://github.com/1"><code>@1</code></a>.61.0</li> </ul> </li> </ul> <h2>1.17.1-alpha.1</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fixed <code>Cannot find package '@modelcontextprotocol/sdk'</code> when importing <code>@mastra/mcp</code> in projects that skip automatic peer installation (e.g. npm with <code>--legacy-peer-deps</code>), by declaring the MCP SDK v1 peer required by <code>@modelcontextprotocol/ext-apps</code> as a direct dependency. (<a href="https://redirect.github.com/mastra-ai/mastra/pull/21999">#21999</a>)</p> </li> <li> <p>Updated dependencies:</p> <ul> <li><code>@mastra/core</code><a href="https://github.com/1"><code>@1</code></a>.61.0-alpha.4</li> </ul> </li> </ul> <h2>1.17.1-alpha.0</h2> <h3>Patch Changes</h3> <ul> <li> <p>Fixed MCP tool listing when a tool has no input schema. (<a href="https://redirect.github.com/mastra-ai/mastra/pull/21861">#21861</a>)</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/mastra-ai/mastra/commit/88d14cac008582a618fecc3d5c7fd3bdf4f6ddc3"><code>88d14ca</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/038b7b405cb4ac25ab3f3031334111b1f87ac112"><code>038b7b4</code></a>, <a href="https://github.com/mastra-ai/mastra/commit/4132d61f8367077120ee9e6420d3224dffd93c93"><code>4132d61</code></a>]:</p> <ul> <li><code>@mastra/core</code><a href="https://github.com/1"><code>@1</code></a>.60.1-alpha.0</li> </ul> </li> </ul> <h2>1.17.0</h2> <h3>Minor Changes</h3> <ul> <li> <p>MCP tools served over HTTP now see the authenticated caller. When an MCP server runs behind a Mastra server with <code>server.auth</code> configured, the resolved user is bridged into <code>extra.authInfo</code> automatically, on both the streamable HTTP and SSE transports. Previously <code>extra.authInfo</code> was always undefined because the request handed to the MCP transport was rebuilt without the auth data. (<a href="https://redirect.github.com/mastra-ai/mastra/pull/21689">#21689</a>)</p> <p><strong>Custom verification</strong></p> <p>If your own middleware verifies the caller, build the auth info yourself with the new <code>server.mcpOptions.setRequestAuth</code> hook:</p> <pre lang="ts"><code>export const mastra = new Mastra({ mcpServers: { myServer }, server: { middleware: [verifyBearerToken], mcpOptions: { setRequestAuth: (req, requestContext) => { const payload = requestContext.get('bearerPayload'); req.auth = { token: payload.token, clientId: payload.sub, scopes: payload.scope.split(' ') }; }, }, </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/mastra-ai/mastra/commit/ce66f918f0e27984772b524220e87be0e69cebe3"><code>ce66f91</code></a> chore: version - exit prerelease mode</li> <li><a href="https://github.com/mastra-ai/mastra/commit/cc6549590e54065c70721a2b4af025c91550792b"><code>cc65495</code></a> chore: version packages (alpha) (<a href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/22001">#22001</a>)</li> <li><a href="https://github.com/mastra-ai/mastra/commit/1d41dd06a001c6fee3aab1cdf1ec759f2070df3e"><code>1d41dd0</code></a> fix(mcp): declare <code>@modelcontextprotocol/sdk</code> v1 as a direct dependency (<a href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21999">#21999</a>)</li> <li><a href="https://github.com/mastra-ai/mastra/commit/8c6990aefc426c68a63560328bef4033f9ae8f77"><code>8c6990a</code></a> chore: version packages</li> <li><a href="https://github.com/mastra-ai/mastra/commit/64cd7ac22c2c7a6e6b533a4b3a9ede432700f1fb"><code>64cd7ac</code></a> fix(mcp): list tools without input schemas (<a href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21861">#21861</a>)</li> <li><a href="https://github.com/mastra-ai/mastra/commit/c23d44525cb59f271fca8978bbaae05b7b6b3b9e"><code>c23d445</code></a> chore: version - exit prerelease mode</li> <li><a href="https://github.com/mastra-ai/mastra/commit/86bde188a70540ebe849bd8a77594d88ffb77e2f"><code>86bde18</code></a> chore: version packages (alpha) (<a href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21734">#21734</a>)</li> <li><a href="https://github.com/mastra-ai/mastra/commit/39ba1b9ce256a9a910a16f125cc6a59588185bfe"><code>39ba1b9</code></a> feat(mcp): elicitation on the 2026-07-28 protocol leg via multi round-trip re...</li> <li><a href="https://github.com/mastra-ai/mastra/commit/0f53aeb119158bd9f83bd8ef667f1f675740e8f0"><code>0f53aeb</code></a> feat(mcp): opt-in MCP protocol revision 2026-07-28 behind a protocolVersion f...</li> <li><a href="https://github.com/mastra-ai/mastra/commit/9f626699ac4422352721b2a3ca95ed5543763294"><code>9f62669</code></a> chore: version packages (alpha) (<a href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21597">#21597</a>)</li> <li>Additional commits viewable in <a href="https://github.com/mastra-ai/mastra/commits/@mastra/mcp@1.17.1/packages/mcp">compare view</a></li> </ul> </details> <br /> Updates `ai` from 6.0.256 to 6.0.263 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vercel/ai/blob/ai@6.0.263/packages/ai/CHANGELOG.md">ai's changelog</a>.</em></p> <blockquote> <h2>6.0.263</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [1e70580] <ul> <li><code>@ai-sdk/gateway</code><a href="https://github.com/3"><code>@3</code></a>.0.179</li> </ul> </li> </ul> <h2>6.0.262</h2> <h3>Patch Changes</h3> <ul> <li>30526e9: Prevent exceptions in streaming <code>onChunk</code> and <code>onError</code> callbacks from terminating the stream or masking provider errors.</li> <li>Updated dependencies [7de3226]</li> <li>Updated dependencies [504da15] <ul> <li><code>@ai-sdk/gateway</code><a href="https://github.com/3"><code>@3</code></a>.0.178</li> </ul> </li> </ul> <h2>6.0.261</h2> <h3>Patch Changes</h3> <ul> <li>f1afbf9: Fix array-backed language model mocks to return configured results in order from the first call.</li> </ul> <h2>6.0.260</h2> <h3>Patch Changes</h3> <ul> <li>98c656f: fix: reject <code>streamObject</code> result promises and report failed completion when the provider stream errors</li> <li>b253d52: Filter preliminary tool outputs when <code>ignoreIncompleteToolCalls</code> is enabled.</li> <li>9e15cb4: Prevent automatic tool execution when a model call ends with an unsafe finish reason.</li> </ul> <h2>6.0.259</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [def7999] <ul> <li><code>@ai-sdk/gateway</code><a href="https://github.com/3"><code>@3</code></a>.0.177</li> </ul> </li> </ul> <h2>6.0.258</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [96304fc] <ul> <li><code>@ai-sdk/gateway</code><a href="https://github.com/3"><code>@3</code></a>.0.176</li> </ul> </li> </ul> <h2>6.0.257</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [000b243] <ul> <li><code>@ai-sdk/gateway</code><a href="https://github.com/3"><code>@3</code></a>.0.175</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vercel/ai/commit/23e4c50cf56b0a9fca260098b731b1f730fd6254"><code>23e4c50</code></a> Version Packages (<a href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19261">#19261</a>)</li> <li><a href="https://github.com/vercel/ai/commit/b55c2a9941725e0723a0abb0dc26a00baddab59b"><code>b55c2a9</code></a> Version Packages (<a href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19212">#19212</a>)</li> <li><a href="https://github.com/vercel/ai/commit/30526e9ec8265181756c24ac6e8ff41b17d4366f"><code>30526e9</code></a> [v6.0] fix: contain streaming callback exceptions without interrupting consum...</li> <li><a href="https://github.com/vercel/ai/commit/d3f6cc9591a5482656decf88ee5cd08cdfaddc58"><code>d3f6cc9</code></a> Version Packages (<a href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19191">#19191</a>)</li> <li><a href="https://github.com/vercel/ai/commit/f1afbf981dc66ea4ca290d778232b96640b6c14a"><code>f1afbf9</code></a> [v6.0] fix: return array-backed mock language model results in configured ord...</li> <li><a href="https://github.com/vercel/ai/commit/bb5526fc0b981bcb2c95accde20bf93b1b317de2"><code>bb5526f</code></a> Version Packages (<a href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19131">#19131</a>)</li> <li><a href="https://github.com/vercel/ai/commit/9e15cb48a5f82f8e241ed71ad28918341ae5b16a"><code>9e15cb4</code></a> [v6.0] fix: automatic tools executing after unsafe model finish reasons (<a href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19120">#19120</a>)</li> <li><a href="https://github.com/vercel/ai/commit/b253d5245e9cd29a59811d1a18677c63c9a77f93"><code>b253d52</code></a> [v6.0] fix: omit preliminary tool outputs when ignoring incomplete tool calls...</li> <li><a href="https://github.com/vercel/ai/commit/98c656f768f0ae3a887b4251340f397d878ce5de"><code>98c656f</code></a> [v6.0] fix: settle streamObject results and report provider stream failures w...</li> <li><a href="https://github.com/vercel/ai/commit/815515120857394d2a3d3979a399f2cf4380a80f"><code>8155151</code></a> Version Packages (<a href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19079">#19079</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vercel/ai/commits/ai@6.0.263/packages/ai">compare view</a></li> </ul> </details> <br /> Updates `@anthropic-ai/sdk` from 0.117.1 to 0.120.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@anthropic-ai/sdk's releases</a>.</em></p> <blockquote> <h2>sdk: v0.120.0</h2> <h2>0.120.0 (2026-08-19)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.119.0...sdk-v0.120.0">sdk-v0.119.0...sdk-v0.120.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> managed agents web search config and self hosted sandbox memory (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ba8ec50ffe31e10781971a942d54289439307424">ba8ec50</a>)</li> </ul> <h3>Chores</h3> <ul> <li><strong>internal:</strong> use a single pnpm workspace lockfile (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3c32145d2bc4d53888c6c6857c9af216eec95fb9">3c32145</a>)</li> </ul> <h2>sdk: v0.119.0</h2> <h2>0.119.0 (2026-08-19)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.118.0...sdk-v0.119.0">sdk-v0.118.0...sdk-v0.119.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> Files and Skills APIs are now GA; add computer use and browser use toolsets (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab41aa32b92a7964b35beb42a6be5b0bec1dd735">ab41aa3</a>)</li> </ul> <h2>sdk: v0.118.0</h2> <h2>0.118.0 (2026-08-18)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.118.0">sdk-v0.117.1...sdk-v0.118.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> additions to files and memory stores (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/fdc03790dc3e7fb0352298382f8a9603e92e19c2">fdc0379</a>)</li> <li><strong>api:</strong> updates to skill, files, and user profiles (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/671e6b187f475b5a7a797adbbe5b908bd74d3935">671e6b1</a>)</li> <li><strong>client:</strong> add helpers for accessing the workspace ID in response headers (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/28aa5afe3284bcdc2cc35264f6f4d8dd762e186f">28aa5af</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>api:</strong> remove unsupported mid_conv_system content block (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ae6ca9403125b5a0effb22c9d9c65804a99a80bd">ae6ca94</a>)</li> <li><strong>session-runner:</strong> retry tool-result sends for at least the lease TTL (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7dc632557bfea8475aab8345e27469f02faa6a5a">7dc6325</a>)</li> </ul> <h3>Chores</h3> <ul> <li><strong>internal:</strong> bump zod to 4.4.3 (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/334">#334</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/faa5b7b841a31967ee4679423c22802d4e70c79f">faa5b7b</a>)</li> <li><strong>internal:</strong> remove leftover prism references (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a163b960ce982ffb2827a0e95a5ae05a1120aa51">a163b96</a>)</li> <li>stop shipping the v0.50 migration guide and migrate CLI (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/53992d708ba024c25adabc864fe0268cc065865d">53992d7</a>)</li> </ul> <h3>Documentation</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@anthropic-ai/sdk's changelog</a>.</em></p> <blockquote> <h2>0.120.0 (2026-08-19)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.119.0...sdk-v0.120.0">sdk-v0.119.0...sdk-v0.120.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> managed agents web search config and self hosted sandbox memory (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ba8ec50ffe31e10781971a942d54289439307424">ba8ec50</a>)</li> </ul> <h3>Chores</h3> <ul> <li><strong>internal:</strong> use a single pnpm workspace lockfile (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3c32145d2bc4d53888c6c6857c9af216eec95fb9">3c32145</a>)</li> </ul> <h2>0.119.0 (2026-08-19)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.118.0...sdk-v0.119.0">sdk-v0.118.0...sdk-v0.119.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> Files and Skills APIs are now GA; add computer use and browser use toolsets (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab41aa32b92a7964b35beb42a6be5b0bec1dd735">ab41aa3</a>)</li> </ul> <h2>0.118.0 (2026-08-18)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.118.0">sdk-v0.117.1...sdk-v0.118.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> additions to files and memory stores (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/fdc03790dc3e7fb0352298382f8a9603e92e19c2">fdc0379</a>)</li> <li><strong>api:</strong> updates to skill, files, and user profiles (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/671e6b187f475b5a7a797adbbe5b908bd74d3935">671e6b1</a>)</li> <li><strong>client:</strong> add helpers for accessing the workspace ID in response headers (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/28aa5afe3284bcdc2cc35264f6f4d8dd762e186f">28aa5af</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>api:</strong> remove unsupported mid_conv_system content block (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ae6ca9403125b5a0effb22c9d9c65804a99a80bd">ae6ca94</a>)</li> <li><strong>session-runner:</strong> retry tool-result sends for at least the lease TTL (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7dc632557bfea8475aab8345e27469f02faa6a5a">7dc6325</a>)</li> </ul> <h3>Chores</h3> <ul> <li><strong>internal:</strong> bump zod to 4.4.3 (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/334">#334</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/faa5b7b841a31967ee4679423c22802d4e70c79f">faa5b7b</a>)</li> <li><strong>internal:</strong> remove leftover prism references (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a163b960ce982ffb2827a0e95a5ae05a1120aa51">a163b96</a>)</li> <li>stop shipping the v0.50 migration guide and migrate CLI (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/53992d708ba024c25adabc864fe0268cc065865d">53992d7</a>)</li> </ul> <h3>Documentation</h3> <ul> <li><strong>tools:</strong> warn that blocking tool bodies stall the worker heartbeat (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/299">#299</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/908fdb5d9de8809190bdcf9d14a8319e80d8f31c">908fdb5</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bfa9197f0182084941052be9752c948638421601"><code>bfa9197</code></a> chore: release main</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bc167f3c8fe36137c5594a3776e9677d493e6618"><code>bc167f3</code></a> feat(api): managed agents web search config and self hosted sandbox memory</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/83fd8981a7b11321257027c817755305cc0a4b59"><code>83fd898</code></a> chore(internal): use a single pnpm workspace lockfile (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7fe6dd50d509bb68eb0981ad1f7ad046984b426e"><code>7fe6dd5</code></a> remove internal ticket references from changelog- <a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/360">#360</a></li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/c67e4e2d2329d25ba057f5e60c6dec3b2f33ba97"><code>c67e4e2</code></a> chore: release main</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/50fc0dba920417d641734f4abef51627c4785380"><code>50fc0db</code></a> feat(api): Files and Skills APIs are now GA; add computer use and browser use...</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/18ea26d324911c3236f2ce762dd0c87f04d038d3"><code>18ea26d</code></a> chore: release main</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/6ed9ddd8924924d20ff4610b83668754629f9478"><code>6ed9ddd</code></a> feat(api): updates to skill, files, and user profiles</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/91921f5f0410a8caa638a85b0d38a8102d7e3c91"><code>91921f5</code></a> fix(session-runner): retry tool-result sends for at least the lease TTL (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/142adcc2b864940a72464e41b63cc5733f38187b"><code>142adcc</code></a> docs(tools): warn that blocking tool bodies stall the worker heartbeat (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/299">#299</a>)</li> <li>Additional commits viewable in <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.120.0">compare view</a></li> </ul> </details> <br /> Updates `@google/genai` from 2.17.1 to 2.18.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/googleapis/js-genai/releases">@google/genai's releases</a>.</em></p> <blockquote> <h2>v2.18.0</h2> <h2><a href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">2.18.0</a> (2026-08-19)</h2> <h3>Features</h3> <ul> <li>Add <code>mode</code> enum (<code>VERBATIM</code>, <code>SMART</code>) to <code>AudioTranscriptionConfig</code> and <code>TranscriptionConfig</code>. (<a href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709">4c5208b</a>)</li> <li>Add enable_data_retention to ToolParallelAiSearch, Add step_count to ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (<a href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab">f52c208</a>)</li> <li>Add IDLE state to live connection status enum and mark REQUIRES_ACTION as deprecated. (<a href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857">2f110f2</a>)</li> <li>add video resolution and extension task parameters (<a href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d">39b2a2d</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>fix examples (<a href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8">3f631be</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md">@google/genai's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">2.18.0</a> (2026-08-19)</h2> <h3>Features</h3> <ul> <li>Add <code>mode</code> enum (<code>VERBATIM</code>, <code>SMART</code>) to <code>AudioTranscriptionConfig</code> and <code>TranscriptionConfig</code>. (<a href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709">4c5208b</a>)</li> <li>Add enable_data_retention to ToolParallelAiSearch, Add step_count to ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (<a href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab">f52c208</a>)</li> <li>Add IDLE state to live connection status enum and mark REQUIRES_ACTION as deprecated. (<a href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857">2f110f2</a>)</li> <li>add video resolution and extension task parameters (<a href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d">39b2a2d</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>fix examples (<a href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8">3f631be</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/googleapis/js-genai/commit/128781fdfec5d33f24d8305d90964f3b75b0774f"><code>128781f</code></a> chore(main): release 2.18.0 (<a href="https://redirect.github.com/googleapis/js-genai/issues/1856">#1856</a>)</li> <li><a href="https://github.com/googleapis/js-genai/commit/67f4cf7c48059de776d2841a5cf5129361a97c49"><code>67f4cf7</code></a> chore: Internal Changes</li> <li><a href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857"><code>2f110f2</code></a> feat: Add IDLE state to live connection status enum and mark REQUIRES_ACTION ...</li> <li><a href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8"><code>3f631be</code></a> fix: fix examples</li> <li><a href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709"><code>4c5208b</code></a> feat: Add <code>mode</code> enum (<code>VERBATIM</code>, <code>SMART</code>) to <code>AudioTranscriptionConfig</code> and...</li> <li><a href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab"><code>f52c208</code></a> feat: Add enable_data_retention to ToolParallelAiSearch, Add step_count to Re...</li> <li><a href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d"><code>39b2a2d</code></a> feat: add video resolution and extension task parameters</li> <li>See full diff in <a href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">compare view</a></li> </ul> </details> <br /> Updates `@langchain/core` from 1.2.8 to 1.2.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchainjs/releases">@langchain/core's releases</a>.</em></p> <blockquote> <h2><code>@langchain/core</code><a href="https://github.com/1"><code>@1</code></a>.2.9</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11402">#11402</a> <a href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a> Thanks <a href="https://github.com/thushanth-bengre-langchain"><code>@thushanth-bengre-langchain</code></a>! - Fix ChatVertexAI/ChatGoogle content blocks: include <code>tool_call</code> blocks from <code>message.tool_calls</code> and skip spurious empty <code>text</code> blocks in <code>contentBlocks</code>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a> chore: version packages (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a> fix(google-common): release endpoint routing fix as patch (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a> feat(google): add gateway support for genai (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a> chore(langchain): update langgraph deps (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a> fix(anthropic): round-trip tool search server-tool result blocks (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a> fix(openai): drop Gemini functionCall content blocks in Chat Completions mess...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a> fix(google-genai): throw ContentBlockedError when Gemini candidate has no con...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a> fix(openai): retain cache_write_tokens, update to v7 sdk (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11399">#11399</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/5ff9179e25f594d7cd21e176fdadd953190375c5"><code>5ff9179</code></a> fix(google-genai): guard streaming chunks when candidate has no content (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/10742">#10742</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a> fix(core): include tool_call blocks and skip empty text blocks in ChatVertexA...</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.8...@langchain/core@1.2.9">compare view</a></li> </ul> </details> <br /> Updates `@langchain/langgraph` from 1.4.10 to 1.4.12 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langgraphjs/releases">@langchain/langgraph's releases</a>.</em></p> <blockquote> <h2><code>@langchain/langgraph</code><a href="https://github.com/1"><code>@1</code></a>.4.12</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2714">#2714</a> <a href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a> Thanks <a href="https://github.com/hntrl"><code>@hntrl</code></a>! - Update checkpoint integrations to require the patched checkpoint serializer release.</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>]:</p> <ul> <li><code>@langchain/langgraph-checkpoint</code><a href="https://github.com/1"><code>@1</code></a>.1.5</li> </ul> </li> </ul> <h2><code>@langchain/langgraph</code><a href="https://github.com/1"><code>@1</code></a>.4.11</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2706">#2706</a> <a href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a> Thanks <a href="https://github.com/zduric-langchain"><code>@zduric-langchain</code></a>! - fix(langgraph): dedupe merged callback handlers by identity</p> <p><code>mergeCallbacks</code> concatenated <code>handlers</code> and <code>inheritableHandlers</code> while deduping <code>tags</code>, so a handler inherited by both the ambient and the explicit config picked up an extra registration at every graph boundary. With tracing on, a nested <code>streamMode: "messages"</code> run delivered every token twice.</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/langchain-ai/langgraphjs/commit/3ce9f8d11dd64b1d091a25162603c49e6f4a426f"><code>3ce9f8d</code></a>, <a href="https://github.com/langchain-ai/langgraphjs/commit/51b42020f7c730a15193aa907056881e3d961924"><code>51b4202</code></a>, <a href="https://github.com/langchain-ai/langgraphjs/commit/a86f813954e010fbf30711c37baa5c53444613d5"><code>a86f813</code></a>]:</p> <ul> <li><code>@langchain/langgraph-sdk</code><a href="https://github.com/1"><code>@1</code></a>.9.30</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md">@langchain/langgraph's changelog</a>.</em></p> <blockquote> <h2>1.4.12</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2714">#2714</a> <a href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a> Thanks <a href="https://github.com/hntrl"><code>@hntrl</code></a>! - Update checkpoint integrations to require the patched checkpoint serializer release.</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>]:</p> <ul> <li><code>@langchain/langgraph-checkpoint</code><a href="https://github.com/1"><code>@1</code></a>.1.5</li> </ul> </li> </ul> <h2>1.4.11</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2706">#2706</a> <a href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a> Thanks <a href="https://github.com/zduric-langchain"><code>@zduric-langchain</code></a>! - fix(langgraph): dedupe merged callback handlers by identity</p> <p><code>mergeCallbacks</code> concatenated <code>handlers</code> and <code>inheritableHandlers</code> while deduping <code>tags</code>, so a handler inherited by both the ambient and the explicit config picked up an extra registration at every graph boundary. With tracing on, a nested <code>streamMode: "messages"</code> run delivered every token twice.</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/langchain-ai/langgraphjs/commit/3ce9f8d11dd64b1d091a25162603c49e6f4a426f"><code>3ce9f8d</code></a>, <a href="https://github.com/langchain-ai/langgraphjs/commit/51b42020f7c730a15193aa907056881e3d961924"><code>51b4202</code></a>, <a href="https://github.com/langchain-ai/langgraphjs/commit/a86f813954e010fbf30711c37baa5c53444613d5"><code>a86f813</code></a>]:</p> <ul> <li><code>@langchain/langgraph-sdk</code><a href="https://github.com/1"><code>@1</code></a>.9.30</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langgraphjs/commit/6530ba9b4c577c560422d9c9de18914e67411d9d"><code>6530ba9</code></a> chore: version packages (<a href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2715">#2715</a>)</li> <li><a href="https://github.com/langchain-ai/langgraphjs/commit/c3b27a997c682a64f65904b2a97a5ee4d6e741b0"><code>c3b27a9</code></a> fix(checkpoint): narrow re-constructable types in JsonPlusSerializer (<a href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2709">#2709</a>)</li> <li><a href="https://github.com/langchain-ai/langgraphjs/commit/659d628d196f6b1ba7aa46b30293c31ff5715cf4"><code>659d628</code></a> chore: version packages (<a href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2704">#2704</a>)</li> <li><a href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a> fix(langgraph): dedupe merged callback handlers by identity (<a href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2706">#2706</a>)</li> <li>See full diff in <a href="https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.12/libs/langgraph-core">compare view</a></li> </ul> </details> <br /> Updates `@langchain/openai` from 1.5.8 to 1.5.10 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchainjs/releases">@langchain/openai's releases</a>.</em></p> <blockquote> <h2><code>@langchain/openai</code><a href="https://github.com/1"><code>@1</code></a>.5.10</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11419">#11419</a> <a href="https://github.com/langchain-ai/langchainjs/commit/c26c87e41bccd01111e170c32ba1e5eec94ba3a6"><code>c26c87e</code></a> Thanks <a href="https://github.com/chiliec"><code>@chiliec</code></a>! - fix(openai): send content null (not []) for tool-call-only v1 assistant messages</li> </ul> <h2><code>@langchain/openai</code><a href="https://github.com/1"><code>@1</code></a>.5.9</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11399">#11399</a> <a href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a> Thanks <a href="https://github.com/gethin-langchain"><code>@gethin-langchain</code></a>! - update to v7 openai sdk</p> </li> <li> <p><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11403">#11403</a> <a href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a> Thanks <a href="https://github.com/thushanth-bengre-langchain"><code>@thushanth-bengre-langchain</code></a>! - Drop Gemini-native <code>functionCall</code> content blocks (already carried in <code>tool_calls</code>) when converting messages to Chat Completions API params, fixing requests that fail when a <code>ChatGoogleGenerativeAI</code> message is passed to <code>ChatOpenAI</code> (e.g. a cross-provider handoff in LangGraph).</p> </li> <li> <p><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11399">#11399</a> <a href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a> Thanks <a href="https://github.com/gethin-langchain"><code>@gethin-langchain</code></a>! - Map OpenAI's <code>cache_write_tokens</code> to <code>cache_creation</code> in <code>usage_metadata.input_token_details</code>, mirroring the existing <code>cached_tokens</code> -> <code>cache_read</code> mapping across the Chat Completions and Responses APIs. Previously, prompt cache-write token counts were silently dropped.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchainjs/commit/d5264a180b2dd121d5fba54e9272d34352875d7b"><code>d5264a1</code></a> chore: version packages (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11427">#11427</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/c26c87e41bccd01111e170c32ba1e5eec94ba3a6"><code>c26c87e</code></a> fix(openai): send content null (not []) for tool-call-only v1 assistant messa...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/041a75581666a7fd551e6df62226dcf873be50cc"><code>041a755</code></a> fix(anthropic): preserve generic tool_search_tool_result blocks (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11421">#11421</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a> chore: version packages (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a> fix(google-common): release endpoint routing fix as patch (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a> feat(google): add gateway support for genai (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a> chore(langchain): update langgraph deps (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a> fix(anthropic): round-trip tool search server-tool result blocks (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a> fix(openai): drop Gemini functionCall content blocks in Chat Completions mess...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a> fix(google-genai): throw ContentBlockedError when Gemini candidate has no con...</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchainjs/compare/@langchain/openai@1.5.8...@langchain/openai@1.5.10">compare view</a></li> </ul> </details> <br /> Updates `langchain` from 1.5.9 to 1.5.10 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchainjs/releases">langchain's releases</a>.</em></p> <blockquote> <h2>langchain@1.5.10</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11412">#11412</a> <a href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a> Thanks <a href="https://github.com/hntrl"><code>@hntrl</code></a>! - chore(langgraph): update langgraph deps to track serialization fix</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a> chore: version packages (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a> fix(google-common): release endpoint routing fix as patch (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a> feat(google): add gateway support for genai (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a> chore(langchain): update langgraph deps (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a> fix(anthropic): round-trip tool search server-tool result blocks (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a> fix(openai): drop Gemini functionCall content blocks in Chat Completions mess...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a> fix(google-genai): throw ContentBlockedError when Gemini candidate has no con...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a> fix(openai): retain cache_write_tokens, update to v7 sdk (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11399">#11399</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/5ff9179e25f594d7cd21e176fdadd953190375c5"><code>5ff9179</code></a> fix(google-genai): guard streaming chunks when candidate has no content (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/10742">#10742</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a> fix(core): include tool_call blocks and skip empty text blocks in ChatVertexA...</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchainjs/compare/langchain@1.5.9...langchain@1.5.10">compare view</a></li> </ul> </details> <br /> Updates `@openai/agents` from 0.16.0 to 0.17.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/openai/openai-agents-js/releases">@openai/agents's releases</a>.</em></p> <blockquote> <h2>v0.17.0</h2> <h2>Key Changes</h2> <h3>Output-guardrail replay safety</h3> <p>Serialized output-bearing approval checkpoints now fail closed with <code>UserError</code> when the SDK cannot prove which response owns a pending terminal tool output. Continue with the live <code>RunState</code> when possible, or start a new run from safe input instead of replaying ambiguous serialized items. When an output guardrail rejects a completed function-tool result used as final output, the SDK replaces rejected content in SDK-owned replay surfaces with <code>Output withheld by an output guardrail.</code>, sanitizes current guardrail metadata, and preserves earlier accepted history. This does not undo external tool side effects or erase application-owned copies.</p> <h3>Complete guardrail batch results</h3> <p>Guardrails started in the same batch now settle before the runner surfaces a tripwire or execution failure. Completed sibling results remain available in run state while further run processing is halted.</p> <h3>Explicit OpenAI client configuration</h3> <p><code>OpenAIProvider</code> now rejects <code>organization</code> or <code>project</code> when <code>openAIClient</code> is also supplied because provider-level values cannot modify an already-created client. Configure these values when constructing the <code>OpenAI</code> client, then pass that client through <code>openAIClient</code>.</p> <h2>What's Changed</h2> <ul> <li>fix(core): redact blocked tool outputs and aliases from replay state by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1712">openai/openai-agents-js#1712</a></li> <li>fix(openai): reject ignored explicit-client options by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1718">openai/openai-agents-js#1718</a></li> </ul> <h3>Documentation & Other Changes</h3> <ul> <li>docs: v01.6.1 release by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1696">openai/openai-agents-js#1696</a></li> <li>docs: fix access token typo in connectors example by <a href="https://github.com/Chair403"><code>@Chair403</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1716">openai/openai-agents-js#1716</a></li> <li>fix: keep Codex verification for development sandboxed by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1707">openai/openai-agents-js#1707</a></li> <li>chore: update versions by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1717">openai/openai-agents-js#1717</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Chair403"><code>@Chair403</code></a> made their first contribution in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1716">openai/openai-agents-js#1716</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/openai/openai-agents-js/compare/v0.16.1...v0.17.0">https://github.com/openai/openai-agents-js/compare/v0.16.1...v0.17.0</a></p> <h2>v0.16.1</h2> <h2>What's Changed</h2> <ul> <li>feat(core): add model call timeouts by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1679">openai/openai-agents-js#1679</a></li> <li>feat(sandbox): add run-scoped sandbox working directories by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1683">openai/openai-agents-js#1683</a></li> <li>feat(sandbox): allow Docker sandboxes to disable networking by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1695">openai/openai-agents-js#1695</a></li> <li>feat(extensions): add Modal sandbox resource options by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1693">openai/openai-agents-js#1693</a></li> <li>fix(core): honor exact call approval decisions by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1694">openai/openai-agents-js#1694</a></li> <li>fix(sandbox): validate view_image raster content by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1704">openai/openai-agents-js#1704</a></li> <li>fix(sandbox): validate dynamic compaction ratios by <a href="https://github.com/sylvesterkaczmarek"><code>@sylvesterkaczmarek</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1691">openai/openai-agents-js#1691</a></li> <li>fix(sandbox): trace effective run-scoped sandbox paths by <a href="https://github.com/sylvesterkaczmarek"><code>@sylvesterkaczmarek</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1697">openai/openai-agents-js#1697</a></li> </ul> <h3>Documentation & Other Changes</h3> <ul> <li>docs: prepare v0.16.0 release documentation by <a href="https://github.com/seratch"><code>@seratch</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1646">openai/openai-agents-js#1646</a></li> <li>docs: document Agent.clone list property sharing by <a href="https://github.com/thegoodengineer"><code>@thegoodengineer</code></a> in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1705">openai/openai-agents-js#1705</a></li> <li>chore: update versions by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/openai/openai-agents-js/pull/1688">openai/openai-agents-js#1688</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/openai/openai-agents-js/commit/0319b657e64e0c132629fe9ed4d524f7cde93445"><code>0319b65</code></a> chore: update versions (<a href="https://redirect.github.com/openai/openai-agents-js/issues/1717">#1717</a>)</li> <li><a href="https://github.com/openai/openai-agents-js/commit/d80736ace3c8ac32c41ba2b353a3e64ed31354b3"><code>d80736a</code></a> fix(openai): reject ignored explicit-client options (<a href="https://redirect.github.com/openai/openai-agents-js/issues/1718">#1718</a>)</li> <li><a href="https://github.com/openai/openai-agents-js/commit/b9ecb03ede8845fd8e2da74667242b7d2cf3d7c3"><code>b9ecb03</code></a> docs: fix access token typo in connectors example (<a href="https://redirect.github.com/openai/openai-agents-js/issues/1716">#1716</a>)</li> <li><a href="https://github.com/openai/openai-agents-js/commit/33fe55c62e5a0535766f8adbac63430593b7acd9"><code>33fe55c</code></a> fix(core): redact blocked tool outputs and aliases from replay state (<a href="https://redirect.github.com/openai/openai-agents-js/issues/1712">#1712</a>)</li> <li><a href="https://github.com/openai/openai-agents-js/commit/2d68a10f8c1593f37a8e291e7bce00634ba3e5dd"><code>2d68a10</code></a> test: remove flaky example process-group test</li> <li><a href="https://github.com/openai/openai-agents-js/commit/dcbb1e7ba9bcf5ce50052a2a8d287c94d1d84daf"><code>dcbb1e7</code></a> chore: move example and integration runners out of skills</li> <li><a href="https://github.com/openai/openai-agents-js/commit/272... _Description has been truncated_ --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: jkomyno <alberto@composio.dev> |
||
|
|
700327c2a6 | Merge branch 'next' into chore/changesets-v3-migration |