Commit Graph

5085 Commits

Author SHA1 Message Date
Alberto Schiabel 1d31c80eff fix(sdk): keep credentials private in storage and logs (#4318)
## Summary

- write CLI user data, pending login sessions, and agent identities
through one atomic `0600` helper
- repair `0644` credential files created by older CLI versions before
reading them
- redact credential-shaped structured values from CLI user-context
diagnostics
- redact secret-shaped text at both TypeScript and Python SDK log-output
boundaries, including Pusher `auth` responses and exception tracebacks
- preserve Python logger compatibility: errors remain untruncated,
disabled levels remain lazy, and malformed placeholders cannot expose
arguments

## Local reproduction

Under the normal `022` umask, `next` created a plaintext credential file
with mode `0644`. The pre-fix CLI user-context and TypeScript SDK debug
paths also emitted sentinel credentials. The private atomic writer
changes an existing `0644` target to `0600`, and the upgrade tests now
prove all three legacy credential files are tightened without changing
their contents.

## Verification

- CLI permission upgrade tests: 31 passed across user data, pending
login, and agent identity paths
- CLI source and test typechecks passed
- TypeScript core logging, redaction, and Pusher tests: 17 passed
- TypeScript core source and type-test typechecks passed
- Python logging regression tests: 5 passed
- focused Ruff, Prettier, Oxlint, and `git diff --check` passed

The focused CLI runner needed a temporary local alias for the
pre-existing missing `#ssrf_guard` mapping in the CLI Vitest config. The
alias was removed after verification and is not part of this PR.

## Contributor context

Credit to **Syed Anas Mohiuddin**, independent security researcher, for
reporting the legacy CLI credential-file permission issue.

Supersedes [#4300](https://github.com/ComposioHQ/composio/pull/4300) ·
[Glen review](https://app.tryglen.com/ComposioHQ/composio/pull/4300).
The implementation also covers agent credentials, retains atomic writes,
and applies redaction at the shared SDK logging boundary.
@composio/cli@0.4.1-beta.374
2026-09-03 01:45:11 +02:00
palash-c 36785a38fc docs: Hobby / Pro / Enterprise plans + pass-through premium tools (#4141)
## Summary

Composio's new pricing went live on Aug 15, 2026: **Hobby** ($0) /
**Pro** ($29/mo) / **Enterprise** (custom). This PR updates the public
docs to describe only the current offering and reprices premium tools as
pass-through (provider cost + 5% platform fee).

## Principle

- Docs describe the **current** plans only (Hobby / Pro / Enterprise).
No Starter/Growth tables, no dual documentation.
- Where a legacy note is genuinely useful (rate limits), exactly one
sentence pointing pre-Aug-15 customers to
https://composio.dev/pricing/legacy.
- **Link to https://composio.dev/pricing instead of repeating numbers**,
so future price changes are a one-place edit.

## Files changed

- `docs/content/toolkits/pro-tools.mdx` — replaced the "3x the cost"
line and the Totally Free / Ridiculously Cheap / Serious Business tier
table with pass-through pricing copy: paid third-party providers,
provider price + 5% platform fee (no markup), per-call prices on the
pricing page's "Premium tools" section, Hobby includes up to $2/mo of
premium tool usage, prices depend on provider and can change with
advance notice. Retitled the page from "Pro Tools" to "Premium Tools"
(matches the pricing page and avoids confusion with the new Pro plan).
URL slug `/toolkits/pro-tools` is unchanged so no links break. Rest of
the page (what counts as a premium tool, rate limits) intact.
- `docs/content/reference/rate-limits.mdx` +
`docs/content/reference/v3/rate-limits.mdx` (manual copies, updated
identically) — plan table now Hobby 2,000 req/min · Pro 10,000 req/min ·
Enterprise Custom (kept the doc's existing per-minute unit and "Custom"
wording for Enterprise). No legacy/grandfathering note — docs describe
current plans only; grandfathered customers are served by the dashboard
and composio.dev/pricing/legacy.
- `docs/app/llms.mdx/[[...slug]]/route.ts`,
`docs/components/toolkits/toolkits-landing.tsx` — label text "Pro Tools"
→ "Premium Tools" (link targets unchanged).

## Not changed / notes for reviewers

- `docs/content/docs/common-faq.mdx` no longer exists on `next` (removed
in the sessions-first rewrite, #3637); a grep for self-host / on-prem
across `docs/content` found **no** page advertising self-hosting as an
Enterprise feature, so nothing to remove there.
- Grep sweep (case-insensitive) over `docs/content` for: Starter, Growth
plan/tier, Ridiculously, Serious Business, Totally Free, on-prem,
self-host(ed), $229, $599, 20k tool calls, 200k, per seat, per-seat, 3x
the cost. All customer-facing hits were in the three files above and are
fixed. Left alone:
- `changelog/*` — historical entries (self-hosted Supabase/PostHog
instances, "self-hosted deployments need backend version X"); these
refer to third-party instances or historical SDK notes, not to an
Enterprise plan feature.
- `docs/auth-configuration/custom-auth-configs.mdx:23`,
`docs/authentication/custom-app-vs-managed-app.mdx:30` — "self-hosted"
refers to the *customer's* self-hosted third-party app (e.g. Salesforce
subdomain), unrelated to Composio plans.
- `docs/configuring-sessions.mdx`, `docs/sandbox/remote.mdx` —
"Sandboxes are not billed today" note; not part of this change, flagging
in case sandbox billing status changed with the new pricing.
- `pro-tools.mdx` "Rate limits" table: **fixed in `421789d90`** —
dropped the "Standard Tool Calls" column (100/min · 5,000/min
contradicted `reference/rate-limits.mdx`), kept only the
premium-execution limiter mapped to plan names (Hobby 1,000/hr · Pro
10,000/hr · Enterprise Custom) with a note that it is separate from the
org API limit. Also added Pro's premium allowance bullet.

## Validation

- `bun run lint` (oxlint): passes; only pre-existing warnings in
untouched files.
- `bun run lint:links` (`scripts/validate-links.ts`): 0 errors.

## Related PRs

- landing: https://github.com/ComposioHQ/landing/pull/289
- platform: https://github.com/ComposioHQ/platform/pull/12078
- dashboard: https://github.com/ComposioHQ/dashboard/pull/1326

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01P3JgWs8DcjeQTRKoJd8gmQ

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-03 00:03:05 +02:00
Alberto Schiabel f08d7614f0 fix(docs): remove unavailable Go SDK setup (#4334)
This PR:
- closes #4323
- removes the unsupported Go SDK setup from the harness integration
example
- removes the dead `ComposioHQ/composio-go` link that breaks the nightly
external-link sweep
- verifies both internal and external docs link validation
2026-09-02 14:34:58 +02:00
sdkrelease[bot] f0ca056795 docs: update toolkits, API spec, and meta tools data (#4309)
## Summary
Automated sync of backend data into the docs site. Triggered by:
`schedule`.

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-09-01 14:48:38 -07:00
Saransh Rana 961b0a0418 security: fix Parameter finding #91 (CWE-94) - identifier guard in ts-builders codegen (#4324)
## What the vulnerability was

The CLI's TypeScript generator wrote API-supplied tool and trigger slugs
straight into generated `.ts` files at two places where the slug becomes
**code**, not data:

- **object-literal property keys** (`PropertyValue.write`), and
- **type-declaration names** (`TypeDeclaration.write`).

Slugs are unconstrained strings (`ToolAsEnum = Schema.String`, no
character allowlist) and the threat model treats API responses as
untrusted. So a crafted slug could close the key and inject arbitrary
top-level TypeScript, which then executes when the generated SDK is
imported or built. That is remote code execution on the developer or CI
host running `composio ts generate`.

The sibling `Property` builder already got this right: it tests
`isValidJsIdentifier` and falls back to a JSON-encoded computed key.
`PropertyValue` and `TypeDeclaration` simply lacked the same guard.

## Why this change addresses it

- `PropertyValue` now applies the exact guard `Property` uses. A name
that is not a valid identifier becomes a quoted computed key
(`["..."]`), so everything it contains is parsed as a string, never as
an expression.
- `TypeDeclaration` refuses a non-identifier name with a `TypeError`. A
type name has no quoted or computed form, so quoting is not available
and failing loudly is the only safe option. The guard sits after the
existing early return for a string type body, which never writes the
name.

Output is byte-identical for every name that is already a valid
identifier, so no existing generation changes. The CLI codegen snapshots
contain only identifier-shaped slugs
(`GITHUB_ACCEPT_A_REPOSITORY_INVITATION_INPUT`) and no computed keys,
and they are unchanged.

Worth noting on the throw: the two sinks differ in exposure.
`typeDeclaration` receives the full `tool.slug` (for example
`GITHUB_FOO`), which is identifier-shaped in practice. `propertyValue`
receives `stripPrefix(tool.slug)`, which can plausibly start with a
digit for real data and now gets safely quoted rather than throwing. Any
name that would now throw was already producing syntactically invalid
TypeScript, so this converts a confusing downstream compile error into a
clear codegen error.

## Tests

**Exploit tests**, not behaviour-pinning. Nine new tests across the two
files.

The key one builds the generated object literal from a malicious slug,
evaluates it, and asserts the injected IIFE did not run:

```ts
const evaluated = new Function(`return { ${out} };`)() as Record<string, unknown>;
expect(Object.keys(evaluated)).toEqual([malicious]);
expect((globalThis as Record<string, unknown>).__PWNED__).toBeUndefined();
```

Each test was confirmed to fail against the unpatched builders and pass
after the change. On the vulnerable code the generator emits `["k"]: (()
=> { globalThis.__PWNED__ = 1; })(), ["SEND"]: "SLACK_SEND"`, which is
the payload as live code.

Existing behaviour is also pinned: valid identifier keys, well-known
symbols, optional properties, generic parameters, doc comments, and the
string-type-body short circuit.

## What was not verified

- **No end-to-end run of `composio ts generate` against a real or
malicious API response.** The fix and its tests are at the builder
layer. The call sites in
`ts/packages/cli/src/generation/typescript/generate-toolkit-sources.ts`
were read to confirm they pass attacker-controlled slugs into these
builders, but were not exercised.
- **No model-layer slug validation was added.** The finding also
suggests validating slugs against `^[A-Za-z0-9_]+$` at the model layer.
That is deliberately out of scope here: it would change what the CLI
accepts from the API and belongs in a separate, human-reviewed change.
This PR closes the two injection sinks only.
- **The `TypeDeclaration` throw is a new failure mode.** If any live
toolkit ships a slug that is not a valid identifier, codegen will now
fail loudly for it instead of emitting broken TypeScript. No such slug
appears in the repo's fixtures, but the full set of production slugs was
not enumerated.
- Python codegen was not reviewed. This finding and fix are
TypeScript-only.

## Testing performed

Clean-HEAD baseline captured before any edit: full monorepo `pnpm run
test` green, 26/26 turbo tasks, exit 0.

After the change, the same full suite is green, 26/26 tasks, exit 0.
`@composio/ts-builders` goes from 131 to 140 tests, all passing.
`@composio/cli` unchanged at 1304 passed. 20 example packages validated.
No new failures and no snapshot churn.

## Finding

Parameter finding #91 (CWE-94), validated live at
`abc8e038218305cab7f3373b82a37144fa15e630`.
Linear: https://linear.app/composio/issue/SEC-579

parameter-finding: kcy19unq784bp2z34b3299w0

Co-authored-by: Saransh <saranshrana@Saranshs-MacBook-Pro.local>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-01 10:50:42 +02:00
Soham Basu cedefcb1be ci(docs): refresh support knowledge from dispatches (#4277)
## Summary

- listen for `support-knowledge-updated` repository dispatches and
validate the dispatched commit against upstream `main`
- coalesce delayed or out-of-order events to the newest mainline commit
that changed a `public.md` leaf
- ignore customer-safe-only and repository-maintenance changes without
advancing public snapshot provenance
- serialize refresh runs with latest-wins concurrency so overlapping
events cannot race on the shared proposal branch
- preserve the existing semantic artifact across atomic imports so
unchanged vectors can be reused
- fail dispatched refreshes when `source_commit` is missing, upstream
access is unavailable, or source ancestry cannot be verified
- keep a six-hour reconciliation run as a self-healing backstop for
missed events and docs-side semantic drift
- keep source-resolution logic in a dedicated script tested directly
against temporary Git histories
- update the durable public KB decision record and executable workflow
regression coverage

## Verification

- `bun run test` — 533 tests passed
- `bun run types:check` — passed
- `bun run lint` — passed with pre-existing warnings only
- `bun run lint:links` — 0 errors
- `bash -n scripts/resolve-kb-refresh-source.sh` — passed
- exact isolated import of support-knowledge `3103ed2` — 132 public
guides, 135 generated files, 0 customer-safe leaves, no `sourceCommit`
frontmatter
- semantic reuse check — 850 of 944 vectors reused; 94 embeddings
required

No generated KB corpus files are included in this PR; the first
successful refresh will propose them separately on
`docs/auto-update-kb`.
2026-08-31 22:24:27 -07:00
Soham Basu 43a6c391ba ci(docs): refresh support knowledge from dispatches 2026-08-31 21:40:51 -07:00
Soham Basu abc8e03821 fix(docs): stop repinning generated KB pages (#4258)
## Stack

1. **This PR** removes noisy per-page `sourceCommit` frontmatter
2. #4277 makes validated support-knowledge dispatches the primary
refresh path

Merge this PR first. Keep `codex/remove-kb-source-commit-frontmatter`
until #4277 is retargeted to `next`.

## Why

Every support-knowledge repin rewrote all generated KB pages because
each page duplicated the upstream commit in frontmatter. That made small
refreshes look much larger than their actual content changes.

## What changed

- remove per-page `sourceCommit` from generated KB frontmatter and its
schema
- keep the source pin centrally in `docs/kb/manifest.json`
- keep semantic/eval artifact provenance unchanged
- add a regression test proving a commit-only repin produces
byte-identical generated pages
- regenerate 126 guides (each generated diff is only the one-line
removal)

## Verification

- 523 static tests
- typecheck, lint, link validation, and production build
- semantic artifact current: 888 records
2026-08-31 21:39:29 -07:00
Soham Basu 0d14aede89 fix(docs): avoid repinning unchanged KB pages 2026-08-31 21:18:22 -07:00
Alberto Schiabel 28378595a1 fix(providers/anthropic): re-export AnthropicTool, InputSchema, and CacheControlEphemeral types (#4286) (#4295)
## Summary
- Re-exports `AnthropicTool`, `InputSchema`, and `CacheControlEphemeral`
types from `@composio/anthropic` entry point
(`ts/packages/providers/anthropic/src/index.ts`).
- Allows TypeScript users to import schema types directly without
reaching into internal paths.

## Test Plan
- Verified index exports in `@composio/anthropic`.
2026-08-31 13:07:19 +02:00
Alberto Schiabel 4feb29f804 docs: Add Harness Integration example (#4291)
## Summary
Explain the motivation and context for this change. Link to any related
issues.

Fixes #

## Changes
- 
- 

## Type of change
- [ ] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?
Describe the tests you ran and instructions so reviewers can reproduce.
Include any relevant config/versions.

## Screenshots (if applicable)

## Checklist
- [ ] I have read the Code of Conduct and this PR adheres to it
- [ ] I ran linters/tests locally and they passed
- [ ] I updated documentation as needed
- [ ] I added tests or explain why not applicable
- [ ] I added a changeset if this change affects published packages

## Additional context
2026-08-31 13:05:46 +02:00
Alberto Schiabel bf200e2a09 fix(cli): stop spinner from scrolling endlessly in narrow terminals (#4262)
## Summary
`composio upgrade` (and any other command with a long spinner message)
scrolls endlessly in terminals narrower than the message, printing the
spinner line hundreds of times instead of animating in place:

```
◐  New version available:
◓  New version available:
◑  New version available:
◒  New version available:
... (hundreds of lines while the binary downloads)
```

Root cause is in `@clack/prompts` (present in the published `1.7.0` and
in the vendored submodule): the spinner's `clearPrevMessage` computes
how many lines to erase by re-wrapping the **raw message**, but each
frame actually renders `${frame} ${message}${dots}` — three prefix
columns plus up to three animated dots that the erase math never sees.
Once those extras push the rendered frame across a wrap boundary, the
erase under-counts by a line and every 80ms tick leaks one. The upgrade
message (`New version available: @composio/cli@x.y.z (current:
@composio/cli@a.b.c). Downloading...`) is ~90 columns, so any narrower
terminal triggers it.

This fixes it downstream in `TerminalUI` by clamping live spinner
messages (start and `message()` updates) to a single terminal row —
truncated with an ellipsis using the same `getColumns` width source
clack wraps with — so the redraw arithmetic cannot diverge. Stop/error
messages are single writes with no redraw loop and stay untouched.

## Changes
- `terminal-ui.ts`: add `clampSpinnerMessage` (newline-collapse + width
clamp, ANSI-bearing messages left alone) and apply it to
`withSpinner`/`useMakeSpinner` start messages and live
`SpinnerHandle.message` updates.
- `terminal-ui.test.ts`: unit tests for the clamp behavior plus a
fake-timer regression test that renders a live frame at 40 columns with
the real upgrade message and asserts it no longer wraps.

## Type of change
- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?
- `pnpm --filter @composio/cli test` — 124 files, 1297 passed / 1
skipped, plus `validate:skills` and `validate:boundaries` green.
- `pnpm --filter @composio/cli typecheck` — clean for these files (ran
on node 22 locally, so CI on the pinned toolchain is the authoritative
pass).
- Reproduced the original failure on macOS with the released CLI 0.3.2
upgrading to 0.4.0 in a narrow terminal pane.

## Screenshots (if applicable)
VHS recordings at a 43-column terminal (an every-tick leak width for
this message), driving the real `makeTerminalUI.useMakeSpinner` —
baseline from `next` on the left, this PR on the right:

| Before (`next`) | After (this PR) |
| --- | --- |
| ![spinner leaks a line on every 80ms redraw tick, scrolling "New
version available:"
endlessly](https://raw.githubusercontent.com/sjd9021/composio/assets/cli-spinner-repro/before.gif)
| ![spinner message clamped to one row, animating in
place](https://raw.githubusercontent.com/sjd9021/composio/assets/cli-spinner-repro/after.gif)
|

## Checklist
- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [x] I added a changeset if this change affects published packages
(`@composio/cli` is in the changeset ignore list, so none needed)

## Additional context
The same erase under-count exists upstream in `bombshell-dev/clack`
`packages/prompts/src/spinner.ts` (`clearPrevMessage` wraps
`_prevMessage`, the raw message, while the write path wraps the
frame-prefixed output). Worth an upstream issue/PR too, but this keeps
the CLI correct regardless of the pinned clack version. No VHS
recording: internal rendering fix, no documented workflow change.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
@composio/cli@0.4.1-beta.373
2026-08-31 13:05:10 +02:00
Alberto Schiabel 7da1397017 Merge branch 'next' into fix/cli-spinner-narrow-terminal-scroll 2026-08-31 13:02:18 +02:00
jkomyno 41019972e1 fix(cli): harden spinner message clamping
Keep live spinner updates within both Clack's construction-time width and the current terminal width, so resizing wider cannot reintroduce wrapped frames while narrower terminals remain clamped.

Segment messages by grapheme cluster before measuring display width so keycap and joined emoji cannot be under-counted or split.
2026-08-31 13:00:11 +02:00
Alberto Schiabel 527c8947f0 chore(cli): refresh baked toolkit slugs (#4312)
## Summary
Automated refresh of the toolkit slugs the CLI knows without asking
the API, generated by
`ts/packages/cli/scripts/generate-toolkit-slugs.ts`.

Toolkits added since the last refresh currently cost users one
toolkit-list fetch (~2 s) the first time they run one of that
toolkit's tools. Merging this makes them free.

The generator refuses to write a list that is short, malformed, or
missing staple toolkits, so a bad fetch opens no PR at all.
@composio/cli@0.4.1-beta.372
2026-08-31 12:59:29 +02:00
jkomyno 26eedbf5c8 chore(cli): refresh baked toolkit slugs 2026-08-31 06:35:42 +00:00
sdkrelease[bot] 030e86e481 docs: update toolkits, API spec, and meta tools data (#4265)
## Summary
Automated sync of backend data into the docs site. Triggered by:
`schedule`.

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-08-30 12:41:55 -07:00
Brendan O'Leary 972b44c737 Merge branch 'next' into bdo/add-harness-integration-example 2026-08-29 09:26:35 -04:00
jkomyno 6b135d1606 refactor(cli): start clamped spinners in one place
Both spinner entry points constructed a clack spinner on stderr and
started it with a clamped message, and useMakeSpinner built a throwaway
lambda purely to relay that same clamp into createClackSpinnerHandle.

Give makeTerminalUI a startSpinner helper that both entry points call,
and let createClackSpinnerHandle take the output stream it clamps
against instead of a pre-bound closure. Behaviour is unchanged.

Claude-Session: https://claude.ai/code/session_0191yFPnWgJnzPPnCYrVm6X7
2026-08-29 12:30:09 +02:00
teddiesloco f438422df0 fix(providers/anthropic): re-export AnthropicTool, InputSchema, and CacheControlEphemeral types (#4286) 2026-08-29 12:34:04 +07:00
Soumya Medapati 09d96f914c ci(docs-agent-eval): bump pinned engine to calibrated judge (#4240)
One-line `ENGINE_REF` bump for the docs-agent-eval shim: the pin
predates the judge calibration (docs-agent-eval-ci PRs #4–#7 —
evidence-scoped scans, proxy-log ground truth, infra-vs-agent error
classification, corrected package taxonomy, renamed secret). Until this
merges, label/deployment-triggered evals run the old
false-positive-prone judge; dispatched runs already use current main.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Soumya Medapati <soumyamedapati@mac.local.meter>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-28 17:52:26 -07:00
Brendan O'Leary 2c9c19e3fb Update toolkit 2026-08-28 15:56:45 -04:00
Sushmitha Mallesh 4f4fddddb9 Merge branch 'next' into bdo/add-harness-integration-example 2026-08-28 11:29:36 -07:00
Brendan O'Leary 582b837fd1 Apply updates from Soham's feedback 2026-08-28 13:20:51 -04:00
jkomyno 4e45d7fabe fix(cli): clamp spinner messages by display width
Follow-ups from review of the narrow-terminal spinner fix.

- Budget and truncate by display columns instead of UTF-16 code units.
  Clack wraps the rendered frame by width, so a CJK message sat under a
  `.length` budget and wrapped anyway, reinstating the leak. Walking whole
  code points also keeps the cut off a surrogate pair.
- Drop MIN_SPINNER_MESSAGE_COLUMNS. The 8-column floor exceeded the row
  below ~15 columns and restored the scroll it was meant to prevent. The
  budget now degrades to the ellipsis, so the one-row invariant holds
  wherever it can hold at all.
- Cover the paths production actually drives: live `message()` updates and
  `withSpinner`'s start message. Reverting either clamp previously left the
  whole suite green.
- Advance fake timers past clack's dot animation so the three dot columns
  SPINNER_RENDER_OVERHEAD reserves are exercised, and run these cases
  through `it.live` per the package's Effect test convention.
- Add the CHANGELOG entry this user-facing fix needs; `@composio/cli` is
  changeset-ignored, so release notes go there directly.

Claude-Session: https://claude.ai/code/session_0191yFPnWgJnzPPnCYrVm6X7
2026-08-28 18:39:48 +02:00
Brendan O'Leary c0eddf0fce Phrasing updates 2026-08-28 11:03:04 -04:00
Brendan O'Leary 19a6219d9b Add first draft of harness integration example 2026-08-28 10:58:46 -04:00
Alberto Schiabel 64b1b85502 chore(deps): consolidate Dependabot updates (#4290)
This PR:

- supersedes https://github.com/ComposioHQ/composio/pull/4280,
https://github.com/ComposioHQ/composio/pull/4281, and
https://github.com/ComposioHQ/composio/pull/4282
- updates the Claude Code action, production dependencies, TypeScript
tooling, and experimental agent dependencies in one reviewed lockfile
refresh
- retains `@mastra/core@1.52.1` so Worker bundles do not pull in
Node-only `execa`
- aligns `ai@^7.0.79` with `@ai-sdk/mcp` and `@ai-sdk/openai` on
`@ai-sdk/provider-utils@5.0.30`
- adapts Eve approval-policy tests to its widened `ApprovalPolicy |
ApprovalConfiguration` contract
- adds the required patch changeset for the published
`@composio/experimental` TypeBox update
- verifies frozen install, package builds, workspace and example type
checks, all package tests, example validation, Oxlint, and Changesets
status
@composio/cli@0.4.1-beta.371
2026-08-28 16:33:09 +02:00
jkomyno 071bca0feb test(experimental): type Eve approval contexts 2026-08-28 15:35:52 +02:00
jkomyno 4e633d1fe4 chore(changeset): record experimental dependency update 2026-08-28 15:14:54 +02:00
jkomyno fb77efc4ba chore(experimental): update agent dependencies 2026-08-28 14:54:38 +02:00
jkomyno 9758571072 chore(deps-dev): update TypeScript tooling 2026-08-28 14:52:53 +02:00
jkomyno 02bee3b2d9 chore(deps): refresh production dependencies 2026-08-28 14:51:36 +02:00
jkomyno 6016a5eb2b build(deps): update Claude Code action 2026-08-28 14:47:23 +02:00
Alberto Schiabel 1157faf0a1 fix(providers): dereference $ref/$defs before schema translation (#4288)
This PR:
- resolves internal `$ref`/`$defs` in tool input schemas before
translation in `langchain`, `llamaindex`, `claude-agent-sdk`, `vercel`,
`google`, and `openai-agents` (`onUnresolved: 'sentinel'`)
- previously `$ref`-typed properties degraded to `z.any()` — the Zod
converter has no `$ref` branch — or were emitted as dangling references
after the root rebuild (google, openai-agents fallback)
- keeps `openai-agents`' strict-structured-outputs path untouched:
OpenAI resolves `$defs`/`$ref` natively including recursion, pinned by a
guard test
- adds per-provider `$ref` regression suites for all six providers,
including dangling-`$defs` (`GMAIL_FETCH_EMAILS`) and recursive-schema
cases
- adds a cross-provider contract test that fails when a new provider
ships without a `$ref` classification, plus property tests for
`dereferenceJsonSchema` (Python counterparts land with the Python-side
fix)
- changes the vendor-visible schema shape for `$ref`-using tools;
changeset is `minor`

## Context

The same bug was fixed locally twice before (mastra, anthropic) without
surfacing the other six providers — nothing enumerated providers and
asked the `$ref` question. The new contract test does exactly that, so
provider #11 cannot ship unclassified. Python mirrors exist already; the
Python-side provider fix follows separately.
2026-08-28 14:42:35 +02:00
jkomyno 2777545a4c test(core): make $ref contract holdout exclusive, flag polluting-key refs unresolvable 2026-08-28 14:20:23 +02:00
Alberto Schiabel ef230944ec fix(openai): stop logging MCP server URLs to stdout (#4287)
This PR:
- replaces the `console.log` in `wrapMcpServerResponse` with a redacted
`logger.debug` line (server names and count only)
- MCP URLs are user-scoped, bearer-equivalent endpoints; they previously
landed in stdout and aggregated production logs on every call
- adds a regression test asserting no stdout write and an unchanged
return shape
- treats MCP URLs already captured in existing logs as exposed;
regenerate those endpoints server-side
2026-08-28 14:17:48 +02:00
jkomyno 98f16febcd test(core,providers): restore $ref contract and property suites
Regenerate the cross-provider $ref contract test, the
dereferenceJsonSchema property tests, and the openai-agents
$ref contract lost in a session handoff, ported from their
surviving Python counterparts. The openai-agents non-strict
ratchet flips to a plain it now that the fallback dereferences;
the superseded openai-agents-ref.test.ts is removed in favor of
the richer contract file.
2026-08-28 13:34:14 +02:00
jkomyno 9447932d98 fix(providers): dereference $ref/$defs schemas before translation
jsonSchemaToZodSchema has no $ref branch, so a $ref node degrades to
z.any() for langchain, llamaindex, claude-agent-sdk, and vercel's
default path. google and openai-agents' non-strict fallback rebuild
the root from properties/required, discarding $defs while dangling
$ref pointers survive.

Dereference internal $ref/$defs before translation in all six, using
onUnresolved: 'sentinel' so a $ref into an undeclared $defs block
(e.g. GMAIL_FETCH_EMAILS) degrades to a permissive schema instead of
throwing. The mastra and anthropic providers already had this fix;
openai-agents' strict branch is untouched since OpenAI's structured
outputs support $defs/$ref natively, including recursion, and
google's rebuild still drops additionalProperties/title/root
oneOf-anyOf-allOf beyond the dangling-$ref class this fixes.
2026-08-28 11:40:49 +02:00
jkomyno 620075a5de fix(openai): stop logging MCP server URLs to stdout 2026-08-28 11:38:12 +02:00
Alberto Schiabel e5e7c04691 fix(sdk): cap automatic file downloads at 100 MiB (#4283)
This PR:

- caps automatic S3 file downloads at 100 MiB in both SDKs — these were
the only fetch paths left without a size limit, and `s3url` is a
tool-execution response field, so the body behind it is no more trusted
than a user-supplied URL (the same input the SSRF guard already defends
against)
- TypeScript: `downloadFileFromS3` buffered the whole body with
`response.arrayBuffer()`; it now reads through the existing
`readResponseBodyWithLimit` guard, overridable per call via
`maxDownloadBytes`
- Python: `FileDownloadable.download` streamed straight to disk with no
byte accounting; it now uses the same `Content-Length` pre-check plus
authoritative streamed-byte counter as its sibling
`_fetch_file_from_url`, overridable via `max_size`
- fixes two latent defects in the Python write loop found along the way:
- an `OSError` from `fd.write` (disk full, permissions) escaped the
`ErrorDownloadingFile` contract the method documents, surfacing as a raw
`OSError(28)`
- every failure left a partial file on disk that no caller was told
about; cleanup now runs on all error paths via
`_discard_partial_download()`, which suppresses cleanup failures so an
`unlink` error cannot replace the error the caller needs to see
- adds 8 regression tests (2 TypeScript, 6 Python) covering oversized
`Content-Length`, oversized streaming with no/dishonest header,
partial-file cleanup, transport and write failures, and the within-limit
success path
- not a breaking change: the caps default to the existing 100 MiB used
by both sibling paths, and both new parameters are optional

## Context

The streamed byte counter — not the `Content-Length` check — is the
authoritative limit in both SDKs, because a malicious or misconfigured
server can omit or lie in that header. The header check is only an early
abort.

Deliberately out of scope: `RemoteFile.buffer()` / `RemoteFile.blob()`
in `ts/packages/core/src/models/RemoteFile.ts` are explicit
user-initiated whole-file reads. The same `readResponseBodyWithLimit`
treatment is the natural follow-up, but they are not on the automatic
path this PR closes.
2026-08-28 10:53:56 +02:00
jkomyno 9f77e643a5 test(core): use the node: prefix for the fs import
Every other test in the package imports node builtins with the `node:`
prefix — this was the only bare `'fs'` specifier, and inconsistent with
`node:path` on the line above it.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 10:00:25 +02:00
jkomyno 28bcb190d9 refactor(python): collapse redundant download error handlers, cover both
Review follow-up on the download size cap.

`requests.exceptions.RequestException` subclasses `OSError`, so the two
handlers added for the write loop were byte-identical and the second already
subsumed the first. Collapse them into one `except OSError` and say why in a
comment, so the next reader does not re-add the redundant clause.

Route partial-file cleanup through `_discard_partial_download`, which
suppresses cleanup failures: an `OSError` from `unlink` would otherwise
replace the `ResponseTooLargeError` or transport error the caller needs.

Cover the two error paths that had no tests: a transport failure mid-stream
and a failing write both raise `ErrorDownloadingFile` and leave no partial
file behind. Without the handler the write failure escapes as a raw
`OSError(28)` — the defect these pin.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 09:54:23 +02:00
jkomyno 54d07dc5f5 fix(python): cap automatic file download size at 100 MiB
`FileDownloadable.download` streamed the response straight to disk with no
byte accounting, so an untrusted `s3url` could fill the disk. Add the same
`Content-Length` pre-check plus authoritative streamed-byte counter the
sibling `_fetch_file_from_url` already uses, capped at `_MAX_RESPONSE_SIZE`
and overridable per call via `max_size`.

Also close two gaps the write loop left open: an `OSError` from `fd.write`
(disk full, permissions) escaped the documented `ErrorDownloadingFile`
contract, and any failure left a partial file on disk that no caller was
told about. Every failure path now unlinks the partial file;
`ResponseTooLargeError` still propagates uncaught so callers see the limit.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 09:51:04 +02:00
jkomyno 8a56383b24 fix(core): cap automatic S3 download size at 100 MiB
`downloadFileFromS3` buffered the whole response with `arrayBuffer()`. The
`s3Url` it fetches is a tool-execution response field — the same untrusted
input the SSRF guard already defends against — so an oversized or endlessly
streaming body could exhaust the host process's heap.

Route the body through the existing `readResponseBodyWithLimit` guard, which
pre-checks `Content-Length` and counts streamed bytes (the header can be
absent or dishonest). The 100 MiB default matches the upload-from-URL sibling
in the same module; `maxDownloadBytes` overrides it per call.

Claude-Session: https://claude.ai/code/session_01K1hH9PMmd6KPKdkACX553z
2026-08-28 09:50:57 +02:00
Alberto Schiabel 3afaee05c5 Release: update version (#4177)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to next, this PR will
be updated.


# Releases
## @composio/core@0.18.0

### Minor Changes

- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.

### Patch Changes

- 449f4e1: Block automatic uploads when a sensitive directory or file
name is hidden by symlink resolution.
- 9545806: Bound the best-effort telemetry requests with a timeout so a
stalled telemetry endpoint cannot leave an SDK call pending
indefinitely.
- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- fe66cbe: Omit empty-string file-uploadable arguments from tool
execution requests instead of forwarding them to the backend, which
rejected them with "Input should be a valid dictionary or instance of
FileUploadable". This now also applies when
`dangerouslyAllowAutoUploadDownloadFiles` is off, and with it on an
empty value is no longer attempted as an upload.
- c0f1609: Fix three ComposioError subclasses
(ComposioToolVersionRequiredError, JsonSchemaToZodError,
JsonSchemaRefResolutionError) that omitted their `this.name` assignment
and therefore reported `name` as 'ComposioError' instead of their own
class name, mis-grouping distinct error types in error telemetry.
- d544006: Close a DNS-rebinding window in the SSRF guard: the address
validated by `assertSafeFetchTarget` is now the address `ssrfSafeFetch`
connects to, so a hostname is no longer resolved a second time between
the check and the connection. Each redirect hop is re-validated and
re-pinned. The request still carries the original hostname in `Host` and
TLS SNI, so certificate verification is unchanged. Hops whose effective
dispatcher is a configured route — a caller-supplied `dispatcher`, a
global `ProxyAgent`/`EnvHttpProxyAgent`, or `NODE_USE_ENV_PROXY`
env-proxy mode — keep the pre-flight check only, mirroring the Python
guard's documented proxy residual.
- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @composio/experimental@0.2.3

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/json-schema-to-zod@0.3.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/anthropic@0.11.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/claude-agent-sdk@0.11.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/cloudflare@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/google@0.10.3

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/langchain@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/llamaindex@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/mastra@0.10.4

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 3c3b4da: `MastraProvider({ strict: true })` now keeps optional
parameters instead of dropping them: every property becomes required and
optional ones accept `null`, matching the OpenAI providers, and a `null`
argument the tool's own schema does not accept is dropped before
execution. Tools whose schema strict mode cannot express keep their
original schema with a warning.
## @composio/openai@0.12.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.
## @composio/openai-agents@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 9692db5: `OpenAIAgentsProvider({ strict: true })` now takes effect:
tools are registered with `strict: true` and a schema normalized for
OpenAI structured outputs (every property required, optional ones accept
`null`), a `null` argument the tool's own schema does not accept is
dropped before execution, and tools whose schema strict mode cannot
express are registered without strict mode with a warning. The option
was previously ignored.
## @composio/vercel@0.11.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.
## @composio/slim@0.18.0

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/cf-workers-basic@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/cf-workers-files@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/cf-workers-tool-router-ai@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## @e2e-tests/node-claude-agent-sdk@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/claude-agent-sdk@0.11.1
## @e2e-tests/node-custom-tools@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/node-json-schema-to-zod-v3@0.0.1

### Patch Changes

- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/node-json-schema-to-zod-v4@0.0.1

### Patch Changes

- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/node-mastra-tool-router-zod-v3@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## @e2e-tests/node-mastra-tool-router-zod-v4@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## @e2e-tests/node-tool-router-files@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/node-tool-router-pagination@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## anthropic-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/anthropic@0.11.1
  - @composio/claude-agent-sdk@0.11.1
## cloudflare-wrangler-example@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## connected-accounts-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## error-handling-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## file-handling-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## google-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/google@0.10.3
## json-schema-to-zod-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## langchain-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/langchain@0.10.2
## llamaindex-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/llamaindex@0.10.2
## mastra-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## mcp-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## modifiers-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## openai-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [9692db5]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/openai-agents@0.10.2
  - @composio/openai@0.12.1
## session-management-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## tool-router-example@1.0.11

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [9692db5]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/claude-agent-sdk@0.11.1
  - @composio/openai-agents@0.10.2
  - @composio/vercel@0.11.2
## toolkits-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## tools-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## triggers-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## vercel-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## versioning-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
py@0.21.0 @e2e-tests/node-custom-tools@0.0.1 @e2e-tests/cli-agent-signin@0.0.0 @composio/cloudflare@0.10.2 @composio/core@0.18.0 openai-example@0.1.10 @composio/claude-agent-sdk@0.11.1 @e2e-tests/node-tool-router-files@0.0.1 @composio/anthropic@0.11.1 versioning-example@0.1.1 modifiers-example@0.1.10 @composio/experimental@0.2.3 @e2e-tests/node-tool-router-pagination@0.0.1 @composio/google@0.10.3 @e2e-tests/node-openai-zod4-compat@0.0.0 mcp-example@0.1.1 @composio/json-schema-to-zod@0.3.1 @composio/langchain@0.10.2 @e2e-tests/node-vercel-ai-sdk-v6@0.0.0 @composio/llamaindex@0.10.2 mastra-example@0.1.1 vercel-example@0.1.10 @composio/mastra@0.10.4 @composio/openai-agents@0.10.2 @composio/openai@0.12.1 llamaindex-example@0.1.1 @e2e-tests/node-mastra-tool-router-zod-v4@0.0.1 @composio/slim@0.18.0 @e2e-tests/node-mastra-tool-router-zod-v3@0.0.1 @composio/vercel@0.11.2 langchain-example@0.1.10 triggers-example@0.1.1 @e2e-tests/cf-workers-basic@0.0.1 @e2e-tests/node-json-schema-to-zod-v4@0.0.1 @e2e-tests/cf-workers-files@0.0.1 json-schema-to-zod-example@0.1.1 @e2e-tests/node-typescript-mjs-import-nodenext@0.0.0 @e2e-tests/cf-workers-tool-router-ai@0.0.1 @e2e-tests/utils@0.0.0 tool-router-example@1.0.11 google-example@0.1.1 @e2e-tests/cli-install@0.0.0 @e2e-tests/cli-run@0.0.0 @e2e-tests/cli-setup-plugins@0.0.0 @e2e-tests/cli-toolkits-info@0.0.0 file-handling-example@0.1.1 @e2e-tests/cli-toolkits-list@0.0.0 @e2e-tests/cli-toolkits-search@0.0.0 @e2e-tests/cli-upgrade@0.0.0 @e2e-tests/cli-version@0.0.0 error-handling-example@0.1.10 @e2e-tests/cli-whoami@0.0.0 @e2e-tests/deno-esm-basic@0.0.0 @e2e-tests/node-cjs-basic@0.0.0 session-management-example@0.1.1 connected-accounts-example@0.1.10 @e2e-tests/node-claude-agent-sdk@0.0.1 tools-example@0.1.1 cloudflare-wrangler-example@0.0.1 @e2e-tests/node-vercel-ai-sdk-v7@0.0.0 @e2e-tests/node-esm-basic@0.0.0 @e2e-tests/node-file-roundtrip@0.0.0 toolkits-example@0.1.10 anthropic-example@0.1.1 @e2e-tests/node-json-schema-to-zod-v3@0.0.1
2026-08-27 20:19:15 +02:00
sdkrelease[bot] dbe5a63965 Release: update version 2026-08-27 18:07:50 +00:00
Alberto Schiabel e2270d12d0 chore(sdk): prepare Python 0.21.0 and TypeScript 0.18.0 (#4272)
This PR:

- unblocks https://github.com/ComposioHQ/composio/pull/4177 by
documenting TypeScript `@composio/core` `0.18.0`
- bumps Python `composio` and all 12 provider distributions from
`0.20.0` to `0.21.0`
- keeps `python/composio/__version__.py` and the pinned `uv.lock`
aligned with package metadata
- adds the combined customer-facing changelog for strict tool schemas,
safer file transfers, and runtime reliability updates
- records the Node.js 22.22.3 minimum for the TypeScript release

## Release sequence

1. Merge this PR into `next`.
2. Merge #4177 after its release-workflow check turns green; Changesets
publishes the TypeScript packages to npm.
3. Tag the resulting `next` commit as `py@0.21.0` to publish the Python
core and provider packages to PyPI.

## Verification

- `pnpm test:release-workflow`
- `mise exec -- uv lock --check`
- `make chk`
- `make build`
- `uv tool run twine check dist/*` (26 artifacts)
- `bun run test` in `docs/` (527 tests)
2026-08-27 20:05:43 +02:00
jkomyno 3cbc7556f5 chore(sdk): prepare Python 0.21.0 and TypeScript 0.18.0 2026-08-27 19:27:19 +02:00
Alberto Schiabel 82ca7384d5 fix(errors): set this.name on three ComposioError subclasses (#4128)
## What

`ComposioError` (`errors/ComposioError.ts`) assigns `name` as a class
field (`public name = 'ComposioError'`). Under the package tsconfig
(es2022 -> `useDefineForClassFields`), each subclass must reassign
`this.name` in its constructor or it inherits the base value. ~30
sibling subclasses do this; three omitted it:

- `ComposioToolVersionRequiredError` (`errors/ToolErrors.ts`)
- `JsonSchemaToZodError` (`errors/ValidationErrors.ts`)
- `JsonSchemaRefResolutionError` (`errors/ValidationErrors.ts`)

So `new JsonSchemaToZodError().name === 'ComposioError'`, and the same
for the other two. All three are thrown on real paths (`Tools.ts`,
`jsonSchema.ts`), and `error.name` is forwarded to error telemetry
(`telemetry/Telemetry.ts`), so these distinct error types silently
mis-group under the base name; any consumer branching on `err.name ===
'<ClassName>'` never matches.

## Fix

Add the missing `this.name = '<ClassName>'` at the end of each of the
three constructors, matching the established sibling pattern.
Runtime-only; no type or public-API change. (The two `PusherErrors`
subclasses set `name` via a class field, which already resolves
correctly, so they are intentionally left untouched.)

## Tests

Adds `test/errors/errorNames.test.ts` asserting each of the three
reports its own class name and is `instanceof ComposioError`. Verified
fails-before / passes-after; full `@composio/core` suite green (1095
tests), plus `tsc`, oxlint, and prettier clean.
2026-08-27 19:17:18 +02:00