mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
@composio/cli@0.4.2-beta.386
5147 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
0abc629f5d |
refactor(cli): migrate to Effect 4 (4.0.0-rc.112) (#3901)
Rebuilds the Effect v4 port on top of `next` at `effect@4.0.0-rc.112` (the newest release that clears the repository's 3-day `minimumReleaseAge` gate). The three v3-compatible preparation PRs (#4358, #4359, #4360) already landed on `next`, so this PR is now only the cutover. ## What changes - Pins `effect`, `@effect/platform-bun`, and `@effect/vitest` to exact `4.0.0-rc.112`; drops `@effect/cli`, `@effect/platform`, `@effect/platform-node`, and the `toml` override that existed only for `@effect/cli`. The `ts/vendor/effect` source oracle moves to the `effect@4.0.0-rc.112` release commit. - Services become `Context.Service` classes with explicit `Default` layers; `Either` becomes `Result`; `ParseResult` becomes `Schema.SchemaError`; platform modules come from `effect/FileSystem`, `effect/Path`, `effect/PlatformError`, `effect/unstable/process`, and `effect/unstable/http`. - The runner drives `Command.runWith` with v4's default help and error rendering. `CliError.ShowHelp` carries its own exit code, help for non-explicit invocations renders on stderr, and "Did you mean?" suggestions render. `command-introspection.ts` is gone: v4 renders the resolved command's help and the "missing value" tip itself. - `composio --version`, `composio -v`, and `composio version` print the same bare semver (`GlobalFlag.Version` is not enabled; the flag spellings are rewritten to the `version` command before parsing). - Root `--log-level` is a shared flag applied after the subcommand tree is attached, so `composio --log-level Debug <subcommand>` both parses and takes effect. - Every `Flag.boolean` carries an explicit default, because rc.112 makes boolean flags required when omitted. - A `Result` is not an `Effect` at runtime in rc.112 even though the type checker accepts `yield*` on it (the fiber dies with "Not a valid effect"); every `Result` is lifted with `Effect.fromResult`, and the skill/AGENTS guidance says so. - Every `ChildProcess.make` site passes `extendEnv: true`, because rc.112 no longer inherits the parent environment by default. - `--log-level` and `COMPOSIO_LOG_LEVEL` are exact-match on the `LogLevel` names (`All`, `Fatal`, `Error`, `Warn`, `Info`, `Debug`, `Trace`, `None`) with no case folding, per the earlier review decision; README updated. - Spawned children pass `extendEnv: true`, because rc.112's `ChildProcess` no longer inherits the parent environment by default. - ISO timestamps decode through `Schema.DateTimeUtcFromString`; `Schema.DateTimeUtc` is no longer a string codec in rc.112. - `ConfigProvider.fromEnv()` snapshots the environment at construction in v4, so providers that must observe later changes are built per read (`plugin-hint.ts`, `install.cmd.ts`, `config.ts`) and tests use a live-env provider helper. - `cli-keyring` and `json-schema-to-effect-schema` are ported alongside (the latter on `Schema.makeFilter`). - The `effect-v4` skill, the `cli-command` and `typescript-testing` references, `ts/packages/cli/AGENTS.md`, and the oxlint config are updated to the rc.112 reality. The skill's example checker (`.agents/skills/effect-v4/scripts/check-examples.mjs`, lifted from #3851) compiles every TypeScript block in the skill against the pinned packages. - The `js-yaml` overrides move to the 4.3.2 / 3.15.2 lines that GHSA-2883-xcg3-v3hh requires; `pnpm audit --prod` is clean apart from the already-ignored `extract-zip` advisory. ## Behaviour notes - `composio <unknown> --help` now prints the root help with exit 0 (v4's global `--help` handling); `composio <unknown>` without `--help` still fails with the unknown-subcommand error. ## Validation - `pnpm --filter @composio/cli typecheck` (src + test): 0 errors - `pnpm --filter @composio/cli test`: 127 files, 1325 tests pass, 1 skipped; `validate:boundaries` and `validate:skills` pass - `@composio/cli-keyring` and `@composio/json-schema-to-effect-schema` typecheck, test, and build pass - `pnpm validate:agent-skills` and `pnpm validate:skill-routing` pass (19 skills) - oxlint clean on `ts/packages/cli`, `cli-keyring`, `json-schema-to-effect-schema` - CLI bundle and standalone binary build; smoke-checked `version`, `--version`, `-v`, `--help`, unknown subcommand, unrecognized flag, missing flag value - Docker CLI e2e suites pass against an image built from this branch: `version`, `toolkits-list`, `toolkits-info`, `toolkits-search`, `setup-plugins`, `run`. `whoami` (needs an API key), `install` (needs a release dir), and `upgrade` (needs network) were not run. No changeset: `@composio/cli` is Changesets-ignored and the ported sibling packages are private. Human-facing notes are in `ts/packages/cli/CHANGELOG.md`. https://claude.ai/code/session_01AW7ZPhfZuni6PrCJ9X86DX@composio/cli@0.4.2-beta.386 |
||
|
|
a69f82d676 |
fix(sdk): run typedoc without a shell in generate-docs (SEC-899) (#4416)
## Summary
`ts/packages/core/scripts/generate-docs.ts` joined `npx typedoc` and
every discovered `src/models/*.ts` file name into one string and ran it
with `execSync`, so a model file whose name contains shell
metacharacters would execute as a command. The script runs in CI on
every push to `next` with a write-scoped app token
(`generate-sdk-docs.yml`). Reported by AppSecure as SEC-899 (command
injection via documentation generation).
Fixes SEC-899 (internal tracker).
## Changes
- Build the typedoc argument vector as an array (`buildTypeDocArgs`) and
run it with `execFileSync`, so no shell is involved.
- Skip model files whose names fall outside `[A-Za-z0-9_.-]` (with a
warning) in `discoverModelFiles`.
- Regression tests in `test/scripts/generate-docs.test.ts`:
metacharacter names are dropped, entry points stay separate arguments.
## Type of change
- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change
## How Has This Been Tested?
```
pnpm --filter @composio/core exec vitest run test/scripts/generate-docs.test.ts
Test Files 1 passed (1)
Tests 12 passed (12)
pnpm exec prettier --check ts/packages/core/scripts/generate-docs.ts ts/packages/core/test/scripts/generate-docs.test.ts
All matched files use Prettier code style!
```
Node 24.17.0 and pnpm 11.8.0 via mise.
## Screenshots (if applicable)
## Checklist
- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [x] I added a changeset if this change affects published packages (not
needed: `scripts/` is a build-time script, not part of the published
package)
## Additional context
The generated docs output is unchanged; only how typedoc is invoked
changes.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: jkomyno <alberto@composio.dev>
|
||
|
|
123905a81a |
docs: update toolkits, API spec, and meta tools data (#4414)
## Summary Automated sync of backend data into the docs site. - Trigger: `schedule` - Dispatch action: `n/a` - Source commit: `n/a` ## What changed - **Toolkit catalog** (`docs/public/data/toolkits.json`, `toolkits-list.json`) — refreshed list of available toolkits, auth schemes, and tools from the backend API - **OpenAPI specs** (`docs/public/openapi.json`, `docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) — latest v3.1 and v3.0 API specifications plus the webhook-events spec, fetched from production - **API reference pages** (`docs/content/reference/api-reference/`, `docs/content/reference/v3/api-reference/`) — regenerated index pages for both API versions - **Meta tools reference** (`docs/public/data/meta-tools.json`, `docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas and reference docs Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com> |
||
|
|
9d0cb2cf89 |
fix(cli): cap remote file downloads in tool uploads (SEC-908) (#4417)
## Summary AppSecure SEC-908 reported that remote files fetched from user-supplied URLs were read into memory with no size cap. The core SDK (`fileUtils.node.ts`, `RemoteFile.ts`, `ToolRouterSessionFileMount.ts`) and the Python SDK already stream through a 100 MiB limit. The CLI's tool-input upload path (`ts/packages/cli/src/services/tool-file-uploads.ts`) was the last remaining sink: `readFileFromUrl` still did `response.arrayBuffer()`, so a large or never-ending response could exhaust memory before the presigned upload was even requested. Fixes SEC-908 (internal tracker). ## Changes - `@composio/core` exports `readResponseBodyWithLimit` and `MAX_URL_UPLOAD_SIZE_BYTES`, next to the existing `assertSafeFileUploadPath` export, so downstream packages reuse the one bounded reader. - CLI `readFileFromUrl` uses it in place of `response.arrayBuffer()`; behaviour is unchanged below the cap. - Regression test: a response declaring a body above the cap is rejected before `createPresignedURL` is called. - Changeset for `@composio/core` (patch). `@composio/cli` is in the changeset ignore list. ## Type of change - [x] Bug fix - [ ] New feature - [ ] Refactor/Chore - [ ] Documentation - [ ] Breaking change ## How Has This Been Tested? ``` pnpm --filter @composio/core build pnpm --filter @composio/core exec vitest run test/utils/readResponseBody.test.ts Tests 4 passed (4) pnpm --filter @composio/cli exec vitest run test/src/services/tool-file-uploads.test.ts Tests 8 passed (8) pnpm exec prettier --check <touched files> pnpm exec oxlint <touched files> ``` `tsc --noEmit` on the CLI package reports the same pre-existing errors on `next` and none in the touched files. Node 24.17.0, pnpm 11.8.0 via mise. ## Screenshots (if applicable) ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [x] I ran linters/tests locally and they passed - [x] I updated documentation as needed - [x] I added tests or explain why not applicable - [x] I added a changeset if this change affects published packages ## Additional context The other files AppSecure listed for this finding were already capped on `next` (core:@composio/cli@0.4.2-beta.385 |
||
|
|
9233288b77 |
docs: add Production readiness guides and SIEM log streaming (#4412)
## Summary Add a Production readiness section with a new SIEM log collection guide. Move Managed vs custom auth, Rate limits, and Data retention into that navigation section while preserving their existing URLs. Closes https://linear.app/composio/issue/DEVREL-130/add-siem-log-streaming-documentation-to-poc-to-prod ## Changes - Document scheduled log collection, pagination within fixed time windows, checkpoints, retries, deduplication, and sensitive-data handling. - Include a cURL fetch example, a Datadog forwarding example, and Splunk HEC guidance. - Group the production guides in the Platform sidebar and remove their former sidebar entries. Rate limits links to its existing reference page; the versioned v3 reference remains unchanged. - Regenerate the semantic-search index for the new guide and verify it remains current after the navigation changes. ## Type of change - [x] Documentation ## How Has This Been Tested? From `docs/`: - `bun run test`: 542 passed. - `bun run build`, `bun run types:check`, `bun run lint:links`, and `bun run check:kb-semantic`: passed. - Navigation checks verify the new grouping, absence of duplicate entries, preserved Rate limits URL, and product switching from Data retention. - The initial SIEM guide passed `bun run build` and 90 integration tests, with one credential-dependent test skipped. Its Bash examples and JSON transformation were checked with synthetic data; no live SIEM delivery test was performed. ## Checklist - [x] Updated documentation and navigation. - [x] Updated navigation regression checks. - [x] Verified the semantic-search index. - [x] No changeset needed for this docs-only change. |
||
|
|
e4a05d2f45 | docs: group launch guides under Production readiness | ||
|
|
97c5ed9751 | docs: add SIEM log collection guide for POC to prod | ||
|
|
87d221f45d |
docs(sessions): explain experimental fast mode (#4410)
## Summary The session configuration guide doesn't explain how to enable fast mode. This adds a focused experimental section so developers can opt in with `experimental.fast_mode: true` and understand the retrieval-quality tradeoff. ## Changes - Show cURL requests to create a fast-mode session and enable or disable it on an existing session. - Mark fast mode experimental and note that tool search quality may be affected. - Document the API workaround because the current high-level TypeScript and Python session helpers don't forward this field. - Regenerate the semantic search index for the two new documentation sections. ## Validation - Checked both request bodies against the checked-in v3 OpenAPI schema and the SDK serialization paths. - Docs static tests: 542 passed; internal link validation and semantic index freshness checks passed. - Docs lint and production build (including Twoslash validation) passed. Optional authenticated toolkit fetches were skipped because no API key was set. Documentation only; no SDK changes or changeset required. |
||
|
|
a65db05b82 | docs(sessions): simplify experimental fast mode wording | ||
|
|
bec7e4871d | docs: refresh semantic index for fast mode guide | ||
|
|
ba49066bce | docs(sessions): explain experimental fast mode | ||
|
|
2956831941 |
docs: update toolkits, API spec, and meta tools data (#4402)
## Summary Automated sync of backend data into the docs site. - Trigger: `schedule` - Dispatch action: `n/a` - Source commit: `n/a` ## What changed - **Toolkit catalog** (`docs/public/data/toolkits.json`, `toolkits-list.json`) — refreshed list of available toolkits, auth schemes, and tools from the backend API - **OpenAPI specs** (`docs/public/openapi.json`, `docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) — latest v3.1 and v3.0 API specifications plus the webhook-events spec, fetched from production - **API reference pages** (`docs/content/reference/api-reference/`, `docs/content/reference/v3/api-reference/`) — regenerated index pages for both API versions - **Meta tools reference** (`docs/public/data/meta-tools.json`, `docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas and reference docs Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com> Co-authored-by: Sushmitha Mallesh <sushdec6@gmail.com> |
||
|
|
85996c4a1d |
fix(sdk): harden pusher auth and cross-origin redirect headers (#4406)
This PR:
- wraps `pysher.Pusher` in `_ComposioPusher`, whose channel-auth POST
carries a `(5, 15)` connect/read timeout and raises
`TriggerSubscriptionAuthError` (a `TriggerSubscriptionError`) on a
transport failure, a non-200, or a response without an `auth` token —
pysher 1.0.8 sent it with no timeout and turned a non-200 into a bare
`AssertionError` on the websocket thread, on every (re)subscribe
- keeps that POST a plain `requests.post(..., timeout=...)` rather than
routing it through `safe_request`: the endpoint is built from the
configured Composio API base URL, a fixed trusted host, not a value from
a response, and the SSRF guard would refuse a local dev base URL
- validates `pusher_cluster` against `^[a-z0-9-]+$` (non-empty, at most
64 chars) before pysher formats it into `ws-{cluster}.pusher.com`,
raising `InvalidPusherClusterError` that names the shape violation
without echoing the value
- replaces the `unittest.mock.MagicMock` stand-in for pysher's
connection logger with a dedicated `logging.Logger` (`NullHandler`,
`propagate=False`, disabled), so `unittest` leaves the runtime import
graph while raw frames stay out of user logs; a test asserts the module
source no longer mentions `unittest`
- strips `Authorization`, `Proxy-Authorization`, and `Cookie` from the
next hop when `ssrfSafeFetch` or `safe_request` follows a redirect to a
different origin; same-origin hops keep them. Manual redirect following
bypasses both `fetch`'s cross-origin rule and `requests`'
`rebuild_auth`, so neither guard applied it before — the gap #4387 left
out
- `@composio/slim` has no mirrored source (its build copies
`core/dist`), so the changeset covers `@composio/core` and
`@composio/slim` as patches
Verified with `pytest tests/test_triggers.py tests/test_url_safety.py
tests/test_path_join_guardrail.py` (192 passed), `ruff check` / `ruff
format --check` on the changed files, `mypy --config-file
config/mypy.ini` on the three changed modules with the noxfile's stub
pins (no issues), `vitest run test/utils/ssrfGuard.test.ts` in
`@composio/core` (42 passed), `pnpm typecheck` at the root (14 tasks
successful), and `oxlint` + `prettier --check` on the changed TypeScript
files.
https://claude.ai/code/session_016ZuBv7JhVdSYTLYcTy2VJr
|
||
|
|
b4b9fc4a32 |
fix(json-schema-to-zod): guard schema pattern compilation (#4405)
This PR: - Adds `src/utils/compile-pattern.ts` in `@composio/json-schema-to-zod`, a shared helper that compiles `pattern` and `patternProperties` keys through `new RegExp` inside a try/catch and rethrows a typed `InvalidPatternError` (exported) that names the keyword, the pattern, and the property path (e.g. `at properties.name`), mirroring the eager `assertRegexCompiles` guard in `@composio/json-schema-to-effect-schema`. - Adds a 1024-character cap on pattern length, reported through the same error with `reason: 'too-long'`. - Chooses fail-at-conversion over degrade-with-warning: the package has no warning hook or lenient `refs` mode, its sibling packages and `oneOf` handling already throw on schema defects, and a silently dropped `pattern` would widen what a tool accepts without anyone noticing. - Threads `refs.path` into `parseString` and `parseTypelessConstraints` so the error carries the property path, and appends `patternProperties.<key>` for dynamic-key objects. - Makes `@composio/core`'s `jsonSchemaToZodSchema` include the cause message in `JsonSchemaToZodError`, so the wrapped error names the malformed property without unwrapping `cause`. - Leaves out a nested-quantifier (star-height) ReDoS heuristic on purpose: it flags linear patterns such as `^(\d+\.)*\d+$`, a wrong rejection makes `tools.get` fail for the whole tool, and it cannot be validated against the live toolkit catalog without false-positive risk. Catastrophic backtracking from a hostile `pattern` remains a known limitation; only zero-false-positive guards ship here. - Adds `test/compile-pattern.test.ts` (`(` -> `InvalidPatternError` with `SyntaxError` cause, length cap, typeless and `patternProperties` paths, `^(\d+\.)*\d+$` still compiles and enforces, valid patterns still enforced) and a core test for the wrapped message; adds a patch changeset for both packages. - Verification: `pnpm test` + `pnpm typecheck` in `ts/packages/json-schema-to-zod` (4 files, 255 tests), `pnpm test` in `ts/packages/core` (54 files, 1281 passed, 2 expected fail), root `pnpm typecheck` (14/14), `lint:packages` and Prettier clean. https://claude.ai/code/session_016ZuBv7JhVdSYTLYcTy2VJr |
||
|
|
1049942edb |
fix(py): raise requests and urllib3 floors past open advisories (#4404)
This PR: - raises the `composio` package floors to `requests>=2.32.4` and `urllib3>=2.7.0` in `python/pyproject.toml`, `python/setup.py`, and `uv.lock` - closes GHSA-9hjg-9r4m-mvj7 (`requests` `.netrc` credential leak via malicious URLs) for downstream installs; `url_safety` fetches user- and server-supplied URLs through a `trust_env` session - closes GHSA-mf9v-mfxr-j63j (decompression-bomb guard bypass in the `urllib3` streaming API that `_fetch_file_from_url` relies on for its size limit) and GHSA-qccp-gfcp-xxvc (sensitive headers forwarded across origins) - the workspace lock already resolves 2.34.2 / 2.7.0, so only the `requires-dist` specifiers change; `uv lock --check` passes and `import composio` still works - documents the advisory IDs next to each floor so the next bump has context |
||
|
|
dfdb1e286c |
docs: update Python SDK reference from source (#4380)
## Summary Auto-generated Python SDK reference docs from `python/composio/`. Regenerates pages at `docs/content/reference/sdk-reference/python/` to reflect changes in the Python package's public API (new methods, updated signatures, changed types). Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com> |
||
|
|
09ab074665 |
ci(py): add pip-audit gate for the uv lockfiles (#4394)
This PR: - adds `py.audit.yml`, the Python counterpart of `ts.audit.yml`; there was no dependency audit for the Python SDK until now - exports each tracked `uv.lock` (the root workspace plus the standalone `openai` and `claude_agent_sdk` provider projects) to pinned runtime requirements with `uv export --frozen --no-dev`, then scans them with a pinned `pip-audit --strict` - runs on lockfile and manifest changes and on a weekly schedule, so advisories that land without a commit still surface - ignores the four chromadb advisories with a comment: chromadb has no patched release, crewai pins `chromadb~=1.1.0`, and all four affect the Chroma server that `composio-crewai` never starts - with those ignores the gate is green on `next` today, which I verified locally by running the exact workflow commands |
||
|
|
08402f81bb |
docs: update toolkits, API spec, and meta tools data (#4390)
## Summary Automated sync of backend data into the docs site. - Trigger: `schedule` - Dispatch action: `n/a` - Source commit: `n/a` ## What changed - **Toolkit catalog** (`docs/public/data/toolkits.json`, `toolkits-list.json`) — refreshed list of available toolkits, auth schemes, and tools from the backend API - **OpenAPI specs** (`docs/public/openapi.json`, `docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) — latest v3.1 and v3.0 API specifications plus the webhook-events spec, fetched from production - **API reference pages** (`docs/content/reference/api-reference/`, `docs/content/reference/v3/api-reference/`) — regenerated index pages for both API versions - **Meta tools reference** (`docs/public/data/meta-tools.json`, `docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas and reference docs Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com> |
||
|
|
5e77e0de36 |
ci(dependabot): run the pip updater at the uv workspace root (#4395)
This PR:
- points Dependabot's `pip` ecosystem at `/`, where `pyproject.toml`
declares the uv workspace and `uv.lock` lives, instead of `/python` and
`/python/providers/*`
- fixes security bumps that never touched the lockfile: Dependabot's
langchain-openai bump in
|
||
|
|
988b9a1ff1 |
chore(deps): raise js-yaml and sharp override floors for new advisories (#4393)
This PR: - restores the `pnpm audit --prod --audit-level=high` gate in `ts.audit.yml`, which fails on `next` today - raises the two `js-yaml` override floors to `>=4.3.2` and `>=3.15.2` for GHSA-2883-xcg3-v3hh (`maxTotalMergeKeys` CPU exhaustion); the production path is `@composio/cli > openapi-typescript > @redocly/openapi-core` - adds a `sharp@>=0.35.4` override for the libheif advisories GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545; `sharp` is only reached through `miniflare` in the Cloudflare e2e fixtures and nothing in the repo imports it - ignores GHSA-7pqw-9j4j-h8q3, GitHub's second advisory for the already-ignored `extract-zip` symlink bug, which has no patched release either; both consumers already extract through `extractZipSafely` After the relock `pnpm audit` reports only the three documented ignores, and `pnpm audit --prod --audit-level=high` exits 0. https://claude.ai/code/session_01P1AvRSuyBh6eRtpixaPJ6g |
||
|
|
100d56866f |
fix(experimental): stamp eve durable callback descriptors (#4385)
This PR: - Closes https://github.com/ComposioHQ/composio/issues/4343 - stamps eve's durable callback descriptors on every tool `EveProvider` wraps, via the new internal `withDurableClosure(closure, callback)` helper — eve only stamps them on `defineTool` calls its build transform finds in the agent's own source, which never runs on this package inside `node_modules`, so eve discarded the whole resolver result and the agent silently lost every Composio tool - persists `{ slug, binding }` per callback, where `binding` is an id minted per `wrapTools` call and prefixed with a per-process token, and re-attaches it to that resolve's Composio executor through a module-level binding map. `executeTool` is bound to one Composio session, so a slug-only closure would have routed a call to whichever session resolved last; sessions for different users share one provider, and eve's callback registry is keyed by tool name only, so the map lives at module level rather than on the instance - covers `execute` and, when `needsApproval` is set, `approvalRequest`; the descriptor key is the global-registry symbol `Symbol.for('eve:durable-dynamic-callback')`, so no eve internal is imported and the stamp is inert on eve versions that predate the contract - adds 9 regression tests: descriptor presence and shape, JSON-serializability of the closure, replay of execute and approval from the closure alone, per-resolve executor isolation when sessions share a provider, hooks of the producing provider on replay, the unknown-slug and unknown-binding errors, that two fresh module instances never mint the same binding id, and one suite that loads eve 0.52.1's own `validateDurableDynamicToolCallbacks`, `replayDynamicTools`, and callback registry from the installed package to validate and replay a wrapped tool end to end. Before the change eve threw `Dynamic tool "..." callback "execute" does not have a durable descriptor` ## Context The reporter hit this on eve 0.50 as `non-serializable capture`; 0.52.1 reports the same root cause as a missing descriptor. eve exports no public durable-callback helper (tracked at vercel/eve#2967), so the provider stamps the descriptor itself rather than pinning users to an older eve. Bindings are kept for the life of the process: eve can resume a parked call at any time. A binding lives only in the process that resolved the tools, so a call parked across a restart cannot be replayed; the per-process token in the id makes the stale closure fail the lookup loudly instead of matching whichever resolve reused its counter value in the new process. Growth is one entry per `session.tools()` resolve. Docs (`/docs/providers/eve`) now state the contract, the restart limit, and the real reason the `step.started` resolver runs each step (principal re-evaluation and retry, cached per session). Also unblocks `Docs - Tests` on this branch: the catalog refresh in #4330 renamed Stripe's triggers, so the Stripe knowledge-base guide cited two dead slugs and the corpus verifier failed for any PR touching docs. The guide now cites only the renamed slug the catalog lists, and `generate-toolkits.ts` fetches trigger types with `limit=1000` so the catalog stops truncating every toolkit to its first 20 triggers. https://claude.ai/code/session_019wRk1S4Z6V6FWr4UsybGvR EOF -R ComposioHQ/composio |
||
|
|
ba85f4d183 |
fix(sdk): honor Fetch redirect semantics in both SSRF guards (#4387)
This PR: - builds on top of https://github.com/ComposioHQ/composio/pull/4271, whose commit it carries unchanged - applies the Fetch standard's redirect method/body rules in **both** SSRF guards via `_redirect_rewrite` / `redirectRewrite`: a `303` retries as a bodiless request, a `301`/`302` does the same for a `POST`, and `307`/`308` replay both - narrows `ssrfSafeFetch` to the five statuses the Fetch standard calls a redirect, so a `304` or `305` carrying a `Location` is returned to the caller instead of followed — Python already used `_REDIRECT_STATUS_CODES` - drops `params` after the first hop in `safe_request`, since `Location` carries the query for the target it names and re-appending handed a query-string credential to a target that never asked for one - purges the union of the Fetch `request-body-header` set and the two `requests` also drops, identically on both sides - blocks the IPv6 transition ranges the TypeScript CIDR list missed — 6to4 `2002::/16`, Teredo and the rest of `2001::/23`, local-use NAT64 `64:ff9b:1::/48`, `100::/64`, `2001:db8::/32`, site-local `fec0::/10` — and the IPv4/IPv6 multicast and `192.88.99.0/24` ranges Python's `is_global` missed ## Context Both guards follow redirects by hand so every hop is revalidated against the address blocklist. That also means neither inherits the method and body rewriting `fetch` and `requests` would have done, so an upload answered with a `303` was replayed — payload and all — at a result URL that expects a GET. https://github.com/ComposioHQ/composio/pull/4271 landed that rule in Python only, which left the two SDKs disagreeing on the same wire behavior. Reviewing for that divergence surfaced the redirect-status set, the `params` replay, and the address-blocklist gaps above. `2002:7f00:1::` is 6to4 for `127.0.0.1`, and it passed the TypeScript guard as a public address. Verified with `pytest python/tests/test_url_safety.py` (56 passed) and `vitest run` in `@composio/core` (54 files, 1280 passed), plus `ruff`, `tsc --noEmit`, `oxlint` and `prettier`. Fail-before confirmed: 10 of the new TypeScript cases and 5 of the new Python cases fail against the unmodified guards. Two known gaps are deliberately left out, each deserving its own change: neither guard strips `Authorization`/`Cookie` on a cross-origin redirect, and a non-seekable Python body is re-sent exhausted on a `307` where TypeScript throws a bare `TypeError` on a consumed `ReadableStream`. https://claude.ai/code/session_01SB3ZJdvoqBcRrWb2toWVrX --------- Co-authored-by: ump45nose <52391318+ump45nose@users.noreply.github.com> |
||
|
|
80867a09bc |
docs: update toolkits, API spec, and meta tools data (#4330)
## Summary Automated sync of backend data into the docs site. - Trigger: `schedule` - Dispatch action: `n/a` - Source commit: `n/a` ## What changed - **Toolkit catalog** (`docs/public/data/toolkits.json`, `toolkits-list.json`) — refreshed list of available toolkits, auth schemes, and tools from the backend API - **OpenAPI specs** (`docs/public/openapi.json`, `docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) — latest v3.1 and v3.0 API specifications plus the webhook-events spec, fetched from production - **API reference pages** (`docs/content/reference/api-reference/`, `docs/content/reference/v3/api-reference/`) — regenerated index pages for both API versions - **Meta tools reference** (`docs/public/data/meta-tools.json`, `docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas and reference docs Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com> |
||
|
|
53c024a9c8 |
fix(py): keep local results when remote multi-execute transport fails (#4386)
## Summary Follow-up to #4310. The TypeScript SDK (since #3800) catches a thrown backend call for the remote half of a mixed `COMPOSIO_MULTI_EXECUTE_TOOL` batch and turns it into one failure entry per remote slug, so completed local results are not lost. The Python SDK still let the exception escape `_route_multi_execute`, discarding every local result that had already run. This ports the TypeScript behavior so both SDKs return the same shape on a remote transport failure. Fixes # ## Changes - Catch the remote future's exception in `_route_multi_execute` and keep `str(error)`, falling back to `Remote tool execution failed` when the message is empty (same fallback as TS). - Synthesize `{response: {successful: False, data: {}, error}, tool_slug, error}` for each remote index and merge them in original request order. - Recompute `total_count` / `success_count` / `error_count` on transport failure, as TS does. - Add two regression tests mirroring the TS cases in `customToolRouting.test.ts`: local results preserved with per-tool remote errors, and the empty-message fallback. ## Type of change - [x] Bug fix - [ ] New feature - [ ] Refactor/Chore - [ ] Documentation - [ ] Breaking change ## How Has This Been Tested? - `uv run --locked --group dev pytest tests/test_custom_tools.py -q`: 87 passed. - `uv run --locked --group dev nox -s chk`: ruff and mypy clean. - Without the source change, the new `test_remote_transport_failure_keeps_local_results` raises `RuntimeError: remote unavailable` out of `_route_multi_execute`. ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [x] I ran linters/tests locally and they passed - [ ] I updated documentation as needed - [x] I added tests or explain why not applicable - [ ] I added a changeset if this change affects published packages (Python does not use Changesets) ## Additional context TypeScript reference: `ts/packages/core/src/models/ToolRouterSession.ts`, the `remoteErrorMessage` branch, and the test "should preserve successful local results when remote transport fails". https://claude.ai/code/session_01PAXMbiZd3qPoJ8Z9uPvEAb EOF -R ComposioHQ/composio |
||
|
|
2c4339a859 |
fix(python): preserve mixed multi-execute result order (#4310)
## Summary `ToolRouterSession._route_multi_execute` currently concatenates remote results before local results and assigns new indexes from that concatenated list. For a request such as `[LOCAL_TOOL, REMOTE_TOOL]`, callers receive `[REMOTE_TOOL, LOCAL_TOOL]`, so code that correlates `results[index]` with the requested tools can use the wrong result. This brings the Python implementation in line with the merged TypeScript behavior in [#3800](https://github.com/ComposioHQ/composio/pull/3800): preserve each tool's original request index, restore that order after local/remote execution, and then assign contiguous result indexes. Fixes # ## Changes - Preserve the original index on locally executed result entries. - Map remote sub-batch results back to their original request indexes before merging. - Sort the merged results by original index and re-index them sequentially. - Update the mixed local/remote regression test to assert request order and indexes. ## Type of change - [x] Bug fix - [ ] New feature - [ ] Refactor/Chore - [ ] Documentation - [ ] Breaking change ## How Has This Been Tested? - `uv run --locked --group dev pytest tests/test_custom_tools.py -q` — 69 passed. - `uv run --locked --group dev nox -s tst -- tests/test_custom_tools.py` — 69 passed. - `uv run --locked --group dev ruff --config config/ruff.toml check composio/core/models/tool_router_session.py tests/test_custom_tools.py` — passed. - Ruff format check on both changed files — passed. - Verified the regression test fails on the pre-fix implementation and passes after the fix. ## Screenshots (if applicable) Not applicable. ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [x] I ran linters/tests locally and they passed - [ ] I updated documentation as needed - [x] I added tests or explain why not applicable - [ ] I added a changeset if this change affects published packages ## Additional context This change is limited to Python multi-execute result ordering. All-local and all-remote fast paths remain unchanged. No changeset is needed because this repository does not use Changesets for Python package changes. Signed-off-by: CoralGarden52 <2193436736@qq.com> |
||
|
|
705591451c |
chore(deps): upgrade CI actions and every outdated dependency (#4381)
This PR: - upgrades every CI action to its latest release (only `changesets/action` had one: v2.1.1 -> v2.1.2, SHA-pinned) and every outdated dependency across the pnpm workspace, the docs bun workspace, and all three `uv.lock` files - moves zod to 4.5.4 everywhere first-party — catalog, docs, `@composio/json-schema-to-zod`, `@composio/claude-agent-sdk` and the zod-v4 e2e fixtures; the `*-zod-v3` fixtures stay on 3.25.76 because that is what they exercise - moves `@mastra/core` 1.52.1 -> 1.53.0, which is the ceiling rather than a preference: bisecting `ts/examples/mastra`'s `cf:dry-run` shows 1.54.0 moved the workspace/sandbox subsystem behind `@mastra/core/agent`, which drags execa (-> `npm-run-path` -> `unicorn-magic`) into the Workers bundle where esbuild cannot link it. `@mastra/mcp` is capped at 1.17.2 for the same reason — 1.17.3 wants `@mastra/core` >=1.64. The docs bun workspace mirrors that cap as an explicit devDependency plus `overrides` entry, because bun does not apply overrides to auto-installed peers - clears every production advisory that has a published fix, so the audit gate can run without `--ignore`, which does not filter a single run: it writes the advisory into `auditConfig` and exits 0 whatever else is outstanding, so the gate was passing over nine advisories - `qs` -> >=6.16.0, `fast-uri` -> >=3.1.6, `toml` -> the 4.x line, all via overrides in the existing `# temporary: … drop when` style - `extract-zip` (GHSA-jmr9-qjv8-65gv) has no fixed version to move to — 2.0.1 is the newest release and GitHub records `first_patched_version` as null — so it moves to `auditConfig.ignoreGhsas` pointing at the `extractZipSafely` mitigation that already covers it - GHSA-866g-f22w-33x8 (`@ai-sdk/provider-utils` 3.x, low) also has nothing to move to: the advisory names 3.0.98 as patched but the 3.x line stopped at 3.0.30 and GitHub records no fixed version. It only enters the tree through `@mastra/core`, which is a peer or dev dependency of every published package, so all flagged paths are private examples and e2e fixtures. It goes in `ignoreGhsas` with that rationale so the un-levelled `pnpm audit --prod` step stops posting a warning comment on every PR - widens `@composio/anthropic`'s `@anthropic-ai/sdk` peer range to include `^0.124.0`, the line its devDependency now tests against (for a `0.x` caret, `^0.120.0` excluded it); the package is in the changeset for that reason - adapts three call sites that upstream broke: `eve` 0.52 moved `ApprovalContext` to `eve/tools/approval`, `@pierre/diffs` 1.4 gave `FileDiffProps` a second type parameter, and `fumadocs-openapi` 11.4 fixed the undeclared-tag drop that a docs guard test asserted (the guard now also asserts the page positively, so it cannot pass vacuously) - drops the stale `hono` `minimumReleaseAgeExclude` entry (its comment said to after 2026-08-06) and adds an `undici` `peerDependencyRules` allowance for openai 7.10's new optional peer ## Context Some upgrades were deliberately declined, each for a reason recorded next to the pin: - `vitest`/`@vitest/ui` stay on 4.1.11 — `@cloudflare/vitest-pool-workers@0.22.0` (latest) peers on `vitest ^4.1.0` - `undici` stays on `^7` in core — `pinnedDispatcher.node.ts` documents that Node's `fetch` rejects undici 8 dispatchers - the `pnpm` catalog entry stays on `^11` to match the mise-owned toolchain - `eve` stays on 0.27.6 in docs — 0.52 changes the `defineAgent` model definition and the `useEveAgent` helpers, so `agent/agent.ts` and `components/eve-chat.tsx` fail `types:check`; migrating the docs agent is its own PR - `@earendil-works/pi-coding-agent` stays on 0.84.4 — 0.85.x imports `@earendil-works/pi-server` without declaring it, so `test/pi.test.ts` fails to load `declareOperationTags` is kept as a safety net rather than retired, even though `fumadocs-openapi` 11.4 makes it redundant: removing it changes how specs are normalised at sync time and is worth its own PR. Verified locally: `pnpm build:packages`, `pnpm typecheck`, `pnpm test`, `pnpm typecheck:examples`, `pnpm lint:examples`, `turbo cf:dry-run --filter='./ts/examples/*'`, `pnpm peers check`, `pnpm audit --prod --audit-level=high` (exit 0), frozen-lockfile installs for pnpm and bun, docs `types:check` + 542 static tests, and Python `make chk` + `make tst` (1790 passed). https://claude.ai/code/session_018evFic47PFPXuB95uRE1aw EOF -R ComposioHQ/composio@composio/cli@0.4.2-beta.384 |
||
|
|
0fb479b8f1 |
Merge commit from fork
* fix(cli): escape generated source metadata * test(cli): execute generated Python regression * fix(cli): order Python fallback assignments --------- Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>@composio/cli@0.4.2-beta.383 |
||
|
|
7d36de8c0a |
fix(python-sdk): isolate default provider per Composio instance (#4370)
Construct a fresh OpenAIProvider per SDK instance instead of sharing a module-level singleton whose execute_tool binding was overwritten by the last-constructed instance, silently routing tool execution through the wrong client/API key. Regression test in tests/test_sdk.py. Fixes #4369 Co-authored-by: Adesh Deshmukh <adeshkd123@gmail.com> Claude-Session: https://claude.ai/code/session_015YPz5SzeScR9TkgoRi2p1F EOF -R ComposioHQ/composio |
||
|
|
85d4923507 |
fix(python): dereference $ref/$defs in Google provider (#4297)
## Summary The Python Vertex AI Google provider rebuilt tool parameter schemas from `properties` and `required` without resolving internal `$ref`/`$defs` references first. As a result, referenced properties were sent as dangling references and could not be interpreted by Vertex AI. This change dereferences internal schema references before the existing Google-specific translation. It follows the provider behavior fixed in [TypeScript PR #4288](https://github.com/ComposioHQ/composio/pull/4288). ## Changes - Dereference Google provider input schemas with the existing `dereference_json_schema` helper. - Use the resolved schema when extracting properties and required fields. - Add a regression test covering a property defined through `$ref`/`$defs`. ## Type of change - [x] Bug fix - [ ] New feature - [ ] Refactor/Chore - [ ] Documentation - [ ] Breaking change ## How Has This Been Tested? - `pytest tests/test_google_provider.py tests/test_json_schema.py tests/test_provider.py -q -k 'not TestLangchainReservedKeywords and not TestLangchainFreeFormObjectArguments'` — 59 passed, 4 skipped, 5 deselected. - `ruff check --config config/ruff.toml providers/google/composio_google/provider.py tests/test_google_provider.py` — passed. - `ruff format --check providers/google/composio_google/provider.py tests/test_google_provider.py` — passed. - `mypy --config-file config/mypy.ini providers/google/composio_google/provider.py tests/test_google_provider.py` — passed. ## Screenshots (if applicable) Not applicable. ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [x] I ran linters/tests locally and they passed - [x] I updated documentation as needed - [x] I added tests or explain why not applicable - [x] I added a changeset if this change affects published TypeScript packages ## Additional context This is a Python-only provider fix; no TypeScript changeset is required. No existing issue was found for the Python provider, so this PR includes the minimal reproduction and regression test directly. --------- Co-authored-by: jkomyno <alberto@composio.dev> |
||
|
|
5803b4544b |
fix(docs): accept Mercury data refresh events (#4345)
## Summary - accept `mercury-production-deploy` alongside the Apollo deployment event - log the correct source commit for Apollo and Mercury dispatches - preserve compatibility with Apollo’s legacy `hermes_commit` payload - show the dispatch action and source commit in generated data PRs ## Companion PR - ComposioHQ/mercury#26701 sends the event after a successful production registry sync. ## Verification - `bun test tests/static/docs-data-workflow.test.ts` (6 passed) - `bunx oxlint tests/static/docs-data-workflow.test.ts` - `bunx prettier --check ../.github/workflows/docs-update-data.yml tests/static/docs-data-workflow.test.ts` - `actionlint .github/workflows/docs-update-data.yml` - `bun test tests/static` reached 541 passes. One unrelated analytics test failed because Bun could not bind its ephemeral local server with `EADDRINUSE`; rerunning that test reproduced the same local environment failure. |
||
|
|
230f81a737 |
refactor(cli): import @effect/platform modules by subpath (#4360)
This PR: - rebases onto `next` now that https://github.com/ComposioHQ/composio/pull/4358 and https://github.com/ComposioHQ/composio/pull/4359 are merged - rewrites every `@effect/platform` and `@effect/platform-bun` barrel import under `ts/packages/cli` (155 statements in 112 files) as a per-module namespace import, e.g. `import * as FileSystem from '@effect/platform/FileSystem'` - adds both barrels to the `no-restricted-imports` lists for `ts/packages/cli/src`, with messages pointing at the subpath form - updates the boundary guidance in `ts/packages/cli/AGENTS.md` and the `cli-command` skill to the subpath form ## Context Both barrels are pure namespace re-exports (60 and 19 modules), so this is import-only with no runtime change. Effect v4 spreads these modules across `effect` (`FileSystem`, `Path`, `PlatformError`), `effect/unstable/http`, and `effect/unstable/process`; with per-module imports the port becomes a scripted path rewrite instead of hand-splitting each barrel line. Third of three preparation PRs. ## Validation - `pnpm --filter @composio/cli typecheck` and oxlint clean; a probe barrel import in `src/` is rejected by the new rule - `pnpm --filter @composio/cli test`: 127 files, 1318 tests pass, 1 skipped@composio/cli@0.4.2-beta.382 |
||
|
|
e633a7bdf2 |
docs: update guides for SDK changes (#4365)
## Summary
Automated docs update triggered by SDK source changes on `next`.
- Claude reviewed the SDK diff and updated guides, FAQs, or examples
that reference changed APIs or features.
- The docs `@composio/*` dependencies were realigned to their latest
published releases so Twoslash snippets and example apps validate
against versions users can actually install.
## Review checklist
- [ ] Changes accurately reflect the new SDK behavior
- [ ] No unrelated docs were modified
- [ ] Code examples are correct and complete
- [ ] If a documented feature is not published yet, the Twoslash build
will fail — wait for the release instead of working around it
Generated by Claude Code via GitHub Actions.
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
|
||
|
|
f5ff810f2e |
refactor(cli): define services with Context.Tag and thread argv explicitly (#4359)
This PR: - builds on top of https://github.com/ComposioHQ/composio/pull/4358 - replaces the eleven `Effect.Service` files (fourteen services) with `Context.Tag` classes that export a `<Name>Shape` type and an explicit `static readonly Default` layer built from a `make<Name>` constructor - removes the three `accessors: true` declarations; nothing in `src/` used a generated accessor, and the one test that did now yields the service - builds test doubles with `Service.of({ ... })` instead of `new Service({ ... })`, and types helper parameters with the `Shape` types where the class had been used as a type - passes the normalized argv from `bin.ts` into `runCli` and through `cli-main.ts` instead of mutating `process.argv` and reading it back in five places - documents the service pattern in `ts/packages/cli/AGENTS.md` ## Context Effect v4 replaces `Effect.Service` with `Context.Service`, which generates neither a `.Default` layer nor accessors; with the explicit-layer shape already on v3, the port turns each service into a one-line rename. `Command.runWith` in `effect/unstable/cli` takes user arguments explicitly, so `cli-main.ts` now receives argv rather than re-reading process state. Second of three preparation PRs. ## Validation - `pnpm --filter @composio/cli typecheck`, `validate:boundaries`, and oxlint clean - `pnpm --filter @composio/cli test`: 127 files, 1319 tests pass, 1 skipped@composio/cli@0.4.2-beta.381 |
||
|
|
20aaa95c96 |
ci(ts): verify packed provider compatibility (#4355)
This PR: - adds a clean consumer harness that packs core, its internal JSON Schema dependency, and all ten TypeScript providers - verifies tarball contents, npm installation, named public exports, consumer typechecking, provider construction, and a credential-free `wrapTool` conversion - covers the current workspace core, one verified minimum-core lane per provider, and the packed workspace core presented as `1.0.0-beta.0` - preserves existing 0.x minimum peer ranges while recording the verified floors separately for the future breaking release - additively accepts core 1.0 prereleases without claiming stable 1.x support yet - widens the Anthropic and OpenAI Agents peer ranges to include the upstream versions already used by this repository - runs the gate in TypeScript CI and immediately before Changesets publishing The release guard fails before publication and its regression test verifies build -> compatibility -> publish ordering plus failure propagation. ## Non-breaking scope No public API is removed or renamed, and the existing 0.x core peer floors remain unchanged. All peer-range changes are additive. The gate reports the nine floor corrections that should be made with the planned breaking release. ## Validation - `pnpm run check:provider-compatibility` (12 packed consumer lanes) - `pnpm run test:provider-compatibility` - `pnpm run test:release-workflow` - `pnpm run build:packages` (19 packages) - focused TypeScript compile and Oxlint checks - Prettier, Changesets validation, and `git diff --check` |
||
|
|
61c3cb6481 |
chore(cli): refresh baked toolkit slugs (#4372)
## Summary Automated refresh of the toolkit slugs the CLI knows without asking the API, generated by `ts/packages/cli/scripts/generate-toolkit-slugs.ts`. Toolkits added since the last refresh currently cost users one toolkit-list fetch (~2 s) the first time they run one of that toolkit's tools. Merging this makes them free. The generator refuses to write a list that is short, malformed, or missing staple toolkits, so a bad fetch opens no PR at all. Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>@composio/cli@0.4.2-beta.380 |
||
|
|
d4077ba415 |
chore(cli): trim unused Effect packages and unify version output (#4358)
This PR: - drops the eight `@effect/*` satellite devDependencies and `@effect/platform-node-shared` from `@composio/cli`; none is imported by the CLI, its tests, or its scripts, and the `@effect/platform-node-shared` catalog entry goes with them - makes `--log-level` fall back to `COMPOSIO_LOG_LEVEL` when the flag is absent (`Option.orElse` instead of `Option.zipLeft`, which discarded the env value) and adds a precedence test - rewrites `composio --version` and `composio -v` to the `version` command before parsing, so the three spellings share one handler and print identical output (the framework built-in used to add a trailing blank line); CI and the installer keep using `composio --version` ## Context First of three preparation PRs for the Effect v4 port; https://github.com/ComposioHQ/composio/pull/3901 is the reference port. Each lands v3-compatible groundwork that the port otherwise has to redo on top of a large diff: the manifest, catalog, and lockfile were three of the conflicting files in that PR, and its review had accepted Effect v4's default `composio v<semver>` banner for `--version`. Owning the flag in argv normalization keeps `--version` output stable across the framework change instead. ## Validation - `pnpm --filter @composio/cli typecheck` and oxlint clean - `pnpm --filter @composio/cli test`: 127 files, 1318 tests pass, 1 skipped; `version`, `--version`, and `-v` are asserted byte-identical - The Docker install e2e suite was not run locally; `cli.install-e2e.yml` runs it on this PR@composio/cli@0.4.2-beta.379 |
||
|
|
2573c64d97 |
Release: update version (#4285)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to next, this PR will be updated. # Releases ## @composio/claude-agent-sdk@0.12.0 ### Minor Changes -@e2e-tests/node-tool-router-pagination@0.0.2 @composio/claude-agent-sdk@0.12.0 @composio/langchain@0.11.0 langchain-example@0.1.11 @composio/json-schema-to-zod@0.3.2 google-example@0.1.2 llamaindex-example@0.1.2 @composio/json-schema-to-effect-schema@0.1.1 @composio/llamaindex@0.11.0 mastra-example@0.1.2 @composio/google@0.11.0 file-handling-example@0.1.2 mcp-example@0.1.2 @composio/experimental@0.2.4 @composio/openai-agents@0.11.0 modifiers-example@0.1.11 error-handling-example@0.1.11 @composio/openai@0.12.2 openai-example@0.1.11 connected-accounts-example@0.1.11 @e2e-tests/node-custom-tools@0.0.2 @composio/slim@0.18.1 session-management-example@0.1.2 json-schema-to-zod-example@0.1.2 anthropic-example@0.1.2 tool-router-example@1.0.12 @composio/vercel@0.12.0 @composio/core@0.18.1 @e2e-tests/node-claude-agent-sdk@0.0.2 @e2e-tests/node-tool-router-files@0.0.2 vercel-example@0.1.11 @e2e-tests/cf-workers-tool-router-ai@0.0.2 @e2e-tests/cf-workers-basic@0.0.2 toolkits-example@0.1.11 @e2e-tests/node-mastra-tool-router-zod-v4@0.0.2 @e2e-tests/node-mastra-tool-router-zod-v3@0.0.2 tools-example@0.1.2 versioning-example@0.1.2 @e2e-tests/node-json-schema-to-zod-v3@0.0.2 @e2e-tests/cf-workers-files@0.0.2 triggers-example@0.1.2 @e2e-tests/node-json-schema-to-zod-v4@0.0.2 |
||
|
|
684a392816 |
chore(python): prepare 0.21.1 release (#4361)
## Summary - bump the Python SDK and all provider package versions to `0.21.1` - regenerate the root `uv.lock` from the updated workspace metadata - keep the existing coordinated changelog as the release authority ## Verification - `pnpm test:release-workflow` - `make build` (26 artifacts) - `python -m twine check python/dist/*`py@0.21.1 |
||
|
|
1ab8b3c683 |
fix(toolchain): pin stable Bun 1.4.1 binaries (#4357)
This PR: - replaces the temporary Bun canary pin with the signed stable `1.4.1` platform packages - restores Linux ARM64 cross-compilation, which blocked the CLI beta workflow after https://github.com/ComposioHQ/composio/pull/4315 - preserves immutable per-platform tarballs and checksums through mise's HTTP backend - keeps the declared revision aligned with `bun --revision` ## Verification - both macOS platform binaries pass `codesign --verify --strict` - `pnpm test:toolchain` - `pnpm test:release-workflow` - `pnpm build:packages` - `pnpm --filter @composio/cli build:binary:cross --target bun-linux-arm64` - `taplo fmt --check mise.toml` - `git diff --check`@composio/cli@0.4.1 @composio/cli@0.4.1-beta.377 |
||
|
|
cfeada600d |
docs(changelog): document September CLI and SDK releases (#4350)
This PR: - prepares the coordinated September 4 changelog for CLI `0.4.1`, Python SDK `0.21.1`, and the TypeScript SDK release - gives DevRel one customer-facing source for credential security, file transfers, JSON Schema behavior, and custom-tool routing - records the TypeScript provider and schema-converter package matrix, including the releases added after #4316 merged - adds the `@composio/core` `0.18.1` row that the refreshed release PR #4285 now requires - corrects the download-limit guidance and documents the fallback for a `$ref` without matching `$defs` The listed versions are coordinated release targets. They are not all published yet, so this changelog and the release PRs still need to be sequenced together. ## Verification - `pnpm exec prettier --check docs/content/changelog/09-04-26-cli-and-sdk-releases.mdx` - `cd docs && bun run types:check` - `cd docs && bun run lint:links` - `cd docs && bun run test` (541 passed) - `pnpm test:release-workflow` |
||
|
|
0d4383c4f7 |
fix(docs): isolate product theme from next-themes storage, switcher link fixes (#4349)
## Summary Applies the top findings from a multi-reviewer code review of #4335 (which merged before these could land on the PR branch). Four validated findings, all small and behavior-preserving outside the fixes themselves: - **Cross-tab theme fight (P1):** #4335 routed the product-derived theme through next-themes' shared `theme` localStorage key -- written by the root layout's inline head script on every hard load and by `setTheme` on every client switch. next-themes listens for cross-tab storage events on that key, so two docs tabs on different products (Platform dark / For You light) silently repaint each other with no self-heal (the provider effect's deps are `[product, setTheme]`, so the flipped tab never corrects). The product theme is derived state, not a preference: this PR applies it directly to the document element (`applyProductTheme`) and passes `forcedTheme: initialTheme` from the server-resolved product so hydration cannot flip a stale stored value. No `theme` localStorage writes remain anywhere. - **theme-color meta (P2):** the two `prefers-color-scheme`-keyed metas meant mobile browser chrome mismatched the forced page theme (white chrome over dark Platform pages for light-OS users). Now a single meta keyed to the product theme. - **Switcher current-option href (P2):** the popover option marked `aria-current="page"` resolved to the product landing route, so middle-click, hover status bar, and copy-link all pointed at the wrong URL. It now hrefs the current pathname. - **Explore-card aria-label (P3):** `aria-label` replaced the link's accessible name, so the product description inside the card was not announced. Dropped; heading + description now form the name. ## Changes - `docs/app/layout.tsx` -- inline script no longer writes localStorage (pre-paint class priming unchanged); single product-keyed `theme-color` meta; `forcedTheme: initialTheme` on `RootProvider`. - `docs/components/docs-product-context.tsx` -- `setTheme`/`useTheme` removed; new `applyProductTheme` used in the product effect and the flushSync commit. - `docs/components/product-switcher.tsx` -- `destination = isCurrent ? pathname : docsProductDestination(...)`. - `docs/components/home-surfaces.tsx` -- Explore-card `aria-label` removed. - `docs/tests/static/product-navigation.test.ts` -- pins the new invariants (`applyProductTheme`, `forcedTheme: initialTheme`, and a negative assertion that `localStorage.setItem('theme'` stays out). ## Testing - `bun test tests/static/` -- 541 pass / 0 fail - `bun run types:check` -- clean - `bun run lint` -- only pre-existing warnings (`home-surfaces.tsx:102` `no-img-element` is in `ForYouVisual`, untouched) - Worth a manual check: two tabs on different products no longer repaint each other (static tests cannot prove cross-tab storage isolation) ## Notes - Docs-only change; no changeset required. - Review context: follow-up to #4335. Remaining review findings (navigation state-machine races, theme-scope design call, decision record) are tracked separately. |
||
|
|
ab289d6224 |
fix(sdk): preserve primitive JSON Schema semantics (#4316)
## Summary - preserve boolean, empty, null, type-array, enum, const, and scalar-constraint semantics across every Python conversion entry point - intersect Zod enum and const values with declared types and constraints, including compound JSON values - default unversioned exact validation to Draft 7 and apply inclusive and numeric exclusive bounds independently - run one byte-identical corpus through Python, Zod, and Effect so accepted and rejected inputs stay aligned - keep exact JSON Schema acceptance separate from Pydantic default materialization ## Review follow-up (second push) - Python: exact Draft 7 acceptance now wraps all three entry points (`json_schema_to_pydantic_type`, `json_schema_to_model`, `pydantic_model_from_param_schema`), so they can no longer disagree - Python: draft-4 boolean `exclusiveMinimum`/`exclusiveMaximum` (OpenAPI 3.0 style) no longer crash conversion — exact validation falls back to Draft 4, and the library input is translated to the numeric spelling - Python: ECMA-only regex patterns (look-around) no longer crash pydantic model builds — Rust-incompatible patterns fall back to Python `re` - Python: type arrays with sibling constraints no longer raise `TypeError` on valid input — constraints are scoped per member before the library sees them - Python: integral floats satisfy `integer`, `const` intersects `enum`, annotation-only schemas accept anything, and an optional property with an empty `enum` tolerates absence - Zod: typeless scalar constraints apply per instance type, and string lengths count Unicode code points instead of UTF-16 code units - Effect: draft-4 boolean exclusive bounds are enforced instead of silently ignored - `multipleOf` uses decimal scaling in all three converters (declared `divergesFromJsonSchema` on the corpus case) - shared corpus grows by 13 primitive cases; new property-based tests check acceptance against real Draft 7 oracles (hypothesis + `jsonschema` in Python, fast-check + Ajv in TypeScript) ## Verification - Python `make chk` (ruff + mypy) - Python pytest: 1,572 passed (5 langchain-extra tests need an env this sandbox lacks; unchanged from base) - `@composio/json-schema-to-zod`: 187 passed incl. 300-run fast-check property test; typecheck + build - `@composio/json-schema-to-effect-schema`: 133 passed; typecheck - `@composio/core` corpus ingress tests: 61 passed - shared Python/TypeScript corpus files are byte-identical (shasum-verified) - `git diff --check` ## Contributor context This replaces four narrow proposals after independent local reproduction: - [#4301](https://github.com/ComposioHQ/composio/pull/4301) · [Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4301) - [#4302](https://github.com/ComposioHQ/composio/pull/4302) · [Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4302) - [#4303](https://github.com/ComposioHQ/composio/pull/4303) · [Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4303) - [#4307](https://github.com/ComposioHQ/composio/pull/4307) · [Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4307) --------- Co-authored-by: simpleqt <89645338+simpleqt@users.noreply.github.com> |
||
|
|
abefd6962f |
feat(docs): add product context switcher (#4335)
## Summary Add a product context switcher that separates the docs into two paths just like the Dashboard: - Composio For You, for connecting apps to existing AI clients - Composio Platform, for building agents with the SDK The selected product controls the docs sidebar and persists across navigation. Product-specific URLs set the matching context, while shared pages remain open when readers switch products. https://github.com/user-attachments/assets/e3f6905d-7238-43a2-a51e-145a01688c04 ## Changes - Define product labels, landing pages, route ownership, sidebar groups, and equivalent destinations in one configuration. - Build separate Fumadocs page trees for For You and Platform. - Add an accessible product switcher and a separate home link to the site header. - Force dark mode for Platform and light mode for For You, with no separate theme toggle. - Update the homepage cards to select the matching product. - Add a reduced-motion-aware transition with a 1.5-second navigation timeout. - Test route classification, destination mapping, complete page-tree coverage, and switcher semantics. ## Testing - `bun test tests/static/ --reporter=dot` — 541 passed - `bun run types:check` - `bun run lint` - `bun run build` - Tested both product directions in the local docs site. - Verified that the home link works, Platform stays dark, For You stays light, and shared Security pages remain open when switching products. ## Notes This is a docs-only change and does not require a changeset. |
||
|
|
33434bbe93 | Merge branch 'next' into bdo/add-context-switcher | ||
|
|
4e08394e67 |
chore(code-owners): add brendan as a codeowner for docs (#4342)
## Summary Explain the motivation and context for this change. Link to any related issues. Fixes # ## Changes - - ## Type of change - [ ] Bug fix - [ ] New feature - [ ] Refactor/Chore - [ ] Documentation - [ ] Breaking change ## How Has This Been Tested? Describe the tests you ran and instructions so reviewers can reproduce. Include any relevant config/versions. ## Screenshots (if applicable) ## Checklist - [ ] I have read the Code of Conduct and this PR adheres to it - [ ] I ran linters/tests locally and they passed - [ ] I updated documentation as needed - [ ] I added tests or explain why not applicable - [ ] I added a changeset if this change affects published packages ## Additional context |
||
|
|
0fbed5273b |
docs(auth): clarify managed OAuth app coverage (#4322)
## Summary Clarifies that the managed auth page covers OAuth apps, not every credential type. Fixes # ## Changes - Renames the page and tabs around managed OAuth. - Explains the difference between OAuth app credentials and user authorization. - Clarifies how toolkits with multiple authentication methods appear. - Keeps the browser and agent-readable versions consistent. - Replaces the API-key-based PostHog example with Gmail. ## Type of change - [ ] Bug fix - [ ] New feature - [ ] Refactor/Chore - [x] Documentation - [ ] Breaking change ## How Has This Been Tested? Describe the tests you ran and instructions so reviewers can reproduce. Include any relevant config/versions. ## Screenshots (if applicable) ## Checklist - [ ] I have read the Code of Conduct and this PR adheres to it - [ ] I ran linters/tests locally and they passed - [ ] I updated documentation as needed - [ ] I added tests or explain why not applicable - [ ] I added a changeset if this change affects published packages ## Additional context |
||
|
|
7dd5832ded | chore(docs): rebuild KB semantic artifact | ||
|
|
985d0d0777 | docs(auth): clarify managed OAuth app coverage | ||
|
|
027b773b36 |
docs: update Python SDK reference from source (#4339)
## Summary Auto-generated Python SDK reference docs from `python/composio/`. Regenerates pages at `docs/content/reference/sdk-reference/python/` to reflect changes in the Python package's public API (new methods, updated signatures, changed types). Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com> |
||
|
|
eb951dff34 |
docs: update guides for SDK changes (#4274)
## Summary
Automated docs update triggered by SDK source changes on `next`.
- Claude reviewed the SDK diff and updated guides, FAQs, or examples
that reference changed APIs or features.
- The docs `@composio/*` dependencies were realigned to their latest
published releases so Twoslash snippets and example apps validate
against versions users can actually install.
## Review checklist
- [ ] Changes accurately reflect the new SDK behavior
- [ ] No unrelated docs were modified
- [ ] Code examples are correct and complete
- [ ] If a documented feature is not published yet, the Twoslash build
will fail — wait for the release instead of working around it
Generated by Claude Code via GitHub Actions.
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
|