Commit Graph

5147 Commits

Author SHA1 Message Date
Alberto Schiabel 0abc629f5d refactor(cli): migrate to Effect 4 (4.0.0-rc.112) (#3901)
Rebuilds the Effect v4 port on top of `next` at `effect@4.0.0-rc.112`
(the newest release that clears the repository's 3-day
`minimumReleaseAge` gate). The three v3-compatible preparation PRs
(#4358, #4359, #4360) already landed on `next`, so this PR is now only
the cutover.

## What changes

- Pins `effect`, `@effect/platform-bun`, and `@effect/vitest` to exact
`4.0.0-rc.112`; drops `@effect/cli`, `@effect/platform`,
`@effect/platform-node`, and the `toml` override that existed only for
`@effect/cli`. The `ts/vendor/effect` source oracle moves to the
`effect@4.0.0-rc.112` release commit.
- Services become `Context.Service` classes with explicit `Default`
layers; `Either` becomes `Result`; `ParseResult` becomes
`Schema.SchemaError`; platform modules come from `effect/FileSystem`,
`effect/Path`, `effect/PlatformError`, `effect/unstable/process`, and
`effect/unstable/http`.
- The runner drives `Command.runWith` with v4's default help and error
rendering. `CliError.ShowHelp` carries its own exit code, help for
non-explicit invocations renders on stderr, and "Did you mean?"
suggestions render. `command-introspection.ts` is gone: v4 renders the
resolved command's help and the "missing value" tip itself.
- `composio --version`, `composio -v`, and `composio version` print the
same bare semver (`GlobalFlag.Version` is not enabled; the flag
spellings are rewritten to the `version` command before parsing).
- Root `--log-level` is a shared flag applied after the subcommand tree
is attached, so `composio --log-level Debug <subcommand>` both parses
and takes effect.
- Every `Flag.boolean` carries an explicit default, because rc.112 makes
boolean flags required when omitted.
- A `Result` is not an `Effect` at runtime in rc.112 even though the
type checker accepts `yield*` on it (the fiber dies with "Not a valid
effect"); every `Result` is lifted with `Effect.fromResult`, and the
skill/AGENTS guidance says so.
- Every `ChildProcess.make` site passes `extendEnv: true`, because
rc.112 no longer inherits the parent environment by default.
- `--log-level` and `COMPOSIO_LOG_LEVEL` are exact-match on the
`LogLevel` names (`All`, `Fatal`, `Error`, `Warn`, `Info`, `Debug`,
`Trace`, `None`) with no case folding, per the earlier review decision;
README updated.
- Spawned children pass `extendEnv: true`, because rc.112's
`ChildProcess` no longer inherits the parent environment by default.
- ISO timestamps decode through `Schema.DateTimeUtcFromString`;
`Schema.DateTimeUtc` is no longer a string codec in rc.112.
- `ConfigProvider.fromEnv()` snapshots the environment at construction
in v4, so providers that must observe later changes are built per read
(`plugin-hint.ts`, `install.cmd.ts`, `config.ts`) and tests use a
live-env provider helper.
- `cli-keyring` and `json-schema-to-effect-schema` are ported alongside
(the latter on `Schema.makeFilter`).
- The `effect-v4` skill, the `cli-command` and `typescript-testing`
references, `ts/packages/cli/AGENTS.md`, and the oxlint config are
updated to the rc.112 reality. The skill's example checker
(`.agents/skills/effect-v4/scripts/check-examples.mjs`, lifted from
#3851) compiles every TypeScript block in the skill against the pinned
packages.
- The `js-yaml` overrides move to the 4.3.2 / 3.15.2 lines that
GHSA-2883-xcg3-v3hh requires; `pnpm audit --prod` is clean apart from
the already-ignored `extract-zip` advisory.

## Behaviour notes

- `composio <unknown> --help` now prints the root help with exit 0 (v4's
global `--help` handling); `composio <unknown>` without `--help` still
fails with the unknown-subcommand error.

## Validation

- `pnpm --filter @composio/cli typecheck` (src + test): 0 errors
- `pnpm --filter @composio/cli test`: 127 files, 1325 tests pass, 1
skipped; `validate:boundaries` and `validate:skills` pass
- `@composio/cli-keyring` and `@composio/json-schema-to-effect-schema`
typecheck, test, and build pass
- `pnpm validate:agent-skills` and `pnpm validate:skill-routing` pass
(19 skills)
- oxlint clean on `ts/packages/cli`, `cli-keyring`,
`json-schema-to-effect-schema`
- CLI bundle and standalone binary build; smoke-checked `version`,
`--version`, `-v`, `--help`, unknown subcommand, unrecognized flag,
missing flag value
- Docker CLI e2e suites pass against an image built from this branch:
`version`, `toolkits-list`, `toolkits-info`, `toolkits-search`,
`setup-plugins`, `run`. `whoami` (needs an API key), `install` (needs a
release dir), and `upgrade` (needs network) were not run.

No changeset: `@composio/cli` is Changesets-ignored and the ported
sibling packages are private. Human-facing notes are in
`ts/packages/cli/CHANGELOG.md`.

https://claude.ai/code/session_01AW7ZPhfZuni6PrCJ9X86DX
@composio/cli@0.4.2-beta.386
2026-09-10 17:47:14 +02:00
Saransh Rana a69f82d676 fix(sdk): run typedoc without a shell in generate-docs (SEC-899) (#4416)
## Summary
`ts/packages/core/scripts/generate-docs.ts` joined `npx typedoc` and
every discovered `src/models/*.ts` file name into one string and ran it
with `execSync`, so a model file whose name contains shell
metacharacters would execute as a command. The script runs in CI on
every push to `next` with a write-scoped app token
(`generate-sdk-docs.yml`). Reported by AppSecure as SEC-899 (command
injection via documentation generation).

Fixes SEC-899 (internal tracker).

## Changes
- Build the typedoc argument vector as an array (`buildTypeDocArgs`) and
run it with `execFileSync`, so no shell is involved.
- Skip model files whose names fall outside `[A-Za-z0-9_.-]` (with a
warning) in `discoverModelFiles`.
- Regression tests in `test/scripts/generate-docs.test.ts`:
metacharacter names are dropped, entry points stay separate arguments.

## Type of change
- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?
```
pnpm --filter @composio/core exec vitest run test/scripts/generate-docs.test.ts
 Test Files  1 passed (1)
      Tests  12 passed (12)
pnpm exec prettier --check ts/packages/core/scripts/generate-docs.ts ts/packages/core/test/scripts/generate-docs.test.ts
All matched files use Prettier code style!
```
Node 24.17.0 and pnpm 11.8.0 via mise.

## Screenshots (if applicable)

## Checklist
- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [x] I added a changeset if this change affects published packages (not
needed: `scripts/` is a build-time script, not part of the published
package)

## Additional context
The generated docs output is unchanged; only how typedoc is invoked
changes.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-09-10 17:14:47 +02:00
sdkrelease[bot] 123905a81a docs: update toolkits, API spec, and meta tools data (#4414)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-09-10 15:57:38 +02:00
Saransh Rana 9d0cb2cf89 fix(cli): cap remote file downloads in tool uploads (SEC-908) (#4417)
## Summary
AppSecure SEC-908 reported that remote files fetched from user-supplied
URLs were read into memory with no size cap. The core SDK
(`fileUtils.node.ts`, `RemoteFile.ts`, `ToolRouterSessionFileMount.ts`)
and the Python SDK already stream through a 100 MiB limit. The CLI's
tool-input upload path
(`ts/packages/cli/src/services/tool-file-uploads.ts`) was the last
remaining sink: `readFileFromUrl` still did `response.arrayBuffer()`, so
a large or never-ending response could exhaust memory before the
presigned upload was even requested.

Fixes SEC-908 (internal tracker).

## Changes
- `@composio/core` exports `readResponseBodyWithLimit` and
`MAX_URL_UPLOAD_SIZE_BYTES`, next to the existing
`assertSafeFileUploadPath` export, so downstream packages reuse the one
bounded reader.
- CLI `readFileFromUrl` uses it in place of `response.arrayBuffer()`;
behaviour is unchanged below the cap.
- Regression test: a response declaring a body above the cap is rejected
before `createPresignedURL` is called.
- Changeset for `@composio/core` (patch). `@composio/cli` is in the
changeset ignore list.

## Type of change
- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?
```
pnpm --filter @composio/core build
pnpm --filter @composio/core exec vitest run test/utils/readResponseBody.test.ts
 Tests  4 passed (4)
pnpm --filter @composio/cli exec vitest run test/src/services/tool-file-uploads.test.ts
 Tests  8 passed (8)
pnpm exec prettier --check <touched files>
pnpm exec oxlint <touched files>
```
`tsc --noEmit` on the CLI package reports the same pre-existing errors
on `next` and none in the touched files. Node 24.17.0, pnpm 11.8.0 via
mise.

## Screenshots (if applicable)

## Checklist
- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [x] I added a changeset if this change affects published packages

## Additional context
The other files AppSecure listed for this finding were already capped on
`next` (core: ecd0861, 8a56383; python: 54d07dc); this PR closes the
residual.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
@composio/cli@0.4.2-beta.385
2026-09-10 15:57:13 +02:00
Brendan O'Leary 9233288b77 docs: add Production readiness guides and SIEM log streaming (#4412)
## Summary
Add a Production readiness section with a new SIEM log collection guide.
Move Managed vs custom auth, Rate limits, and Data retention into that
navigation section while preserving their existing URLs.

Closes
https://linear.app/composio/issue/DEVREL-130/add-siem-log-streaming-documentation-to-poc-to-prod

## Changes
- Document scheduled log collection, pagination within fixed time
windows, checkpoints, retries, deduplication, and sensitive-data
handling.
- Include a cURL fetch example, a Datadog forwarding example, and Splunk
HEC guidance.
- Group the production guides in the Platform sidebar and remove their
former sidebar entries. Rate limits links to its existing reference
page; the versioned v3 reference remains unchanged.
- Regenerate the semantic-search index for the new guide and verify it
remains current after the navigation changes.

## Type of change
- [x] Documentation

## How Has This Been Tested?
From `docs/`:
- `bun run test`: 542 passed.
- `bun run build`, `bun run types:check`, `bun run lint:links`, and `bun
run check:kb-semantic`: passed.
- Navigation checks verify the new grouping, absence of duplicate
entries, preserved Rate limits URL, and product switching from Data
retention.
- The initial SIEM guide passed `bun run build` and 90 integration
tests, with one credential-dependent test skipped. Its Bash examples and
JSON transformation were checked with synthetic data; no live SIEM
delivery test was performed.

## Checklist
- [x] Updated documentation and navigation.
- [x] Updated navigation regression checks.
- [x] Verified the semantic-search index.
- [x] No changeset needed for this docs-only change.
2026-09-09 17:16:24 -07:00
Brendan O'Leary e4a05d2f45 docs: group launch guides under Production readiness 2026-09-09 16:36:52 -07:00
Brendan O'Leary 97c5ed9751 docs: add SIEM log collection guide for POC to prod 2026-09-09 16:11:56 -07:00
Tri 87d221f45d docs(sessions): explain experimental fast mode (#4410)
## Summary

The session configuration guide doesn't explain how to enable fast mode.
This adds a focused experimental section so developers can opt in with
`experimental.fast_mode: true` and understand the retrieval-quality
tradeoff.

## Changes

- Show cURL requests to create a fast-mode session and enable or disable
it on an existing session.
- Mark fast mode experimental and note that tool search quality may be
affected.
- Document the API workaround because the current high-level TypeScript
and Python session helpers don't forward this field.

- Regenerate the semantic search index for the two new documentation
sections.

## Validation

- Checked both request bodies against the checked-in v3 OpenAPI schema
and the SDK serialization paths.
- Docs static tests: 542 passed; internal link validation and semantic
index freshness checks passed.
- Docs lint and production build (including Twoslash validation) passed.
Optional authenticated toolkit fetches were skipped because no API key
was set.

Documentation only; no SDK changes or changeset required.
2026-09-09 14:13:35 -07:00
Tridhatri Vallamkondu a65db05b82 docs(sessions): simplify experimental fast mode wording 2026-09-09 14:01:52 -07:00
Tridhatri Vallamkondu bec7e4871d docs: refresh semantic index for fast mode guide 2026-09-09 13:58:06 -07:00
Tridhatri Vallamkondu ba49066bce docs(sessions): explain experimental fast mode 2026-09-09 13:53:46 -07:00
sdkrelease[bot] 2956831941 docs: update toolkits, API spec, and meta tools data (#4402)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
Co-authored-by: Sushmitha Mallesh <sushdec6@gmail.com>
2026-09-09 21:30:15 +02:00
Alberto Schiabel 85996c4a1d fix(sdk): harden pusher auth and cross-origin redirect headers (#4406)
This PR:

- wraps `pysher.Pusher` in `_ComposioPusher`, whose channel-auth POST
carries a `(5, 15)` connect/read timeout and raises
`TriggerSubscriptionAuthError` (a `TriggerSubscriptionError`) on a
transport failure, a non-200, or a response without an `auth` token —
pysher 1.0.8 sent it with no timeout and turned a non-200 into a bare
`AssertionError` on the websocket thread, on every (re)subscribe
- keeps that POST a plain `requests.post(..., timeout=...)` rather than
routing it through `safe_request`: the endpoint is built from the
configured Composio API base URL, a fixed trusted host, not a value from
a response, and the SSRF guard would refuse a local dev base URL
- validates `pusher_cluster` against `^[a-z0-9-]+$` (non-empty, at most
64 chars) before pysher formats it into `ws-{cluster}.pusher.com`,
raising `InvalidPusherClusterError` that names the shape violation
without echoing the value
- replaces the `unittest.mock.MagicMock` stand-in for pysher's
connection logger with a dedicated `logging.Logger` (`NullHandler`,
`propagate=False`, disabled), so `unittest` leaves the runtime import
graph while raw frames stay out of user logs; a test asserts the module
source no longer mentions `unittest`
- strips `Authorization`, `Proxy-Authorization`, and `Cookie` from the
next hop when `ssrfSafeFetch` or `safe_request` follows a redirect to a
different origin; same-origin hops keep them. Manual redirect following
bypasses both `fetch`'s cross-origin rule and `requests`'
`rebuild_auth`, so neither guard applied it before — the gap #4387 left
out
- `@composio/slim` has no mirrored source (its build copies
`core/dist`), so the changeset covers `@composio/core` and
`@composio/slim` as patches

Verified with `pytest tests/test_triggers.py tests/test_url_safety.py
tests/test_path_join_guardrail.py` (192 passed), `ruff check` / `ruff
format --check` on the changed files, `mypy --config-file
config/mypy.ini` on the three changed modules with the noxfile's stub
pins (no issues), `vitest run test/utils/ssrfGuard.test.ts` in
`@composio/core` (42 passed), `pnpm typecheck` at the root (14 tasks
successful), and `oxlint` + `prettier --check` on the changed TypeScript
files.

https://claude.ai/code/session_016ZuBv7JhVdSYTLYcTy2VJr
2026-09-09 21:29:18 +02:00
Alberto Schiabel b4b9fc4a32 fix(json-schema-to-zod): guard schema pattern compilation (#4405)
This PR:

- Adds `src/utils/compile-pattern.ts` in `@composio/json-schema-to-zod`,
a shared helper that compiles `pattern` and `patternProperties` keys
through `new RegExp` inside a try/catch and rethrows a typed
`InvalidPatternError` (exported) that names the keyword, the pattern,
and the property path (e.g. `at properties.name`), mirroring the eager
`assertRegexCompiles` guard in `@composio/json-schema-to-effect-schema`.
- Adds a 1024-character cap on pattern length, reported through the same
error with `reason: 'too-long'`.
- Chooses fail-at-conversion over degrade-with-warning: the package has
no warning hook or lenient `refs` mode, its sibling packages and `oneOf`
handling already throw on schema defects, and a silently dropped
`pattern` would widen what a tool accepts without anyone noticing.
- Threads `refs.path` into `parseString` and `parseTypelessConstraints`
so the error carries the property path, and appends
`patternProperties.<key>` for dynamic-key objects.
- Makes `@composio/core`'s `jsonSchemaToZodSchema` include the cause
message in `JsonSchemaToZodError`, so the wrapped error names the
malformed property without unwrapping `cause`.
- Leaves out a nested-quantifier (star-height) ReDoS heuristic on
purpose: it flags linear patterns such as `^(\d+\.)*\d+$`, a wrong
rejection makes `tools.get` fail for the whole tool, and it cannot be
validated against the live toolkit catalog without false-positive risk.
Catastrophic backtracking from a hostile `pattern` remains a known
limitation; only zero-false-positive guards ship here.
- Adds `test/compile-pattern.test.ts` (`(` -> `InvalidPatternError` with
`SyntaxError` cause, length cap, typeless and `patternProperties` paths,
`^(\d+\.)*\d+$` still compiles and enforces, valid patterns still
enforced) and a core test for the wrapped message; adds a patch
changeset for both packages.
- Verification: `pnpm test` + `pnpm typecheck` in
`ts/packages/json-schema-to-zod` (4 files, 255 tests), `pnpm test` in
`ts/packages/core` (54 files, 1281 passed, 2 expected fail), root `pnpm
typecheck` (14/14), `lint:packages` and Prettier clean.

https://claude.ai/code/session_016ZuBv7JhVdSYTLYcTy2VJr
2026-09-09 19:53:07 +02:00
Alberto Schiabel 1049942edb fix(py): raise requests and urllib3 floors past open advisories (#4404)
This PR:

- raises the `composio` package floors to `requests>=2.32.4` and
`urllib3>=2.7.0` in `python/pyproject.toml`, `python/setup.py`, and
`uv.lock`
- closes GHSA-9hjg-9r4m-mvj7 (`requests` `.netrc` credential leak via
malicious URLs) for downstream installs; `url_safety` fetches user- and
server-supplied URLs through a `trust_env` session
- closes GHSA-mf9v-mfxr-j63j (decompression-bomb guard bypass in the
`urllib3` streaming API that `_fetch_file_from_url` relies on for its
size limit) and GHSA-qccp-gfcp-xxvc (sensitive headers forwarded across
origins)
- the workspace lock already resolves 2.34.2 / 2.7.0, so only the
`requires-dist` specifiers change; `uv lock --check` passes and `import
composio` still works
- documents the advisory IDs next to each floor so the next bump has
context
2026-09-09 18:37:25 +02:00
sdkrelease[bot] dfdb1e286c docs: update Python SDK reference from source (#4380)
## Summary
Auto-generated Python SDK reference docs from `python/composio/`.

Regenerates pages at `docs/content/reference/sdk-reference/python/` to
reflect changes in the Python package's public API (new methods, updated
signatures, changed types).

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-09-09 16:04:07 +02:00
Alberto Schiabel 09ab074665 ci(py): add pip-audit gate for the uv lockfiles (#4394)
This PR:

- adds `py.audit.yml`, the Python counterpart of `ts.audit.yml`; there
was no dependency audit for the Python SDK until now
- exports each tracked `uv.lock` (the root workspace plus the standalone
`openai` and `claude_agent_sdk` provider projects) to pinned runtime
requirements with `uv export --frozen --no-dev`, then scans them with a
pinned `pip-audit --strict`
- runs on lockfile and manifest changes and on a weekly schedule, so
advisories that land without a commit still surface
- ignores the four chromadb advisories with a comment: chromadb has no
patched release, crewai pins `chromadb~=1.1.0`, and all four affect the
Chroma server that `composio-crewai` never starts
- with those ignores the gate is green on `next` today, which I verified
locally by running the exact workflow commands
2026-09-09 16:03:44 +02:00
sdkrelease[bot] 08402f81bb docs: update toolkits, API spec, and meta tools data (#4390)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-09-09 15:58:04 +02:00
Alberto Schiabel 5e77e0de36 ci(dependabot): run the pip updater at the uv workspace root (#4395)
This PR:

- points Dependabot's `pip` ecosystem at `/`, where `pyproject.toml`
declares the uv workspace and `uv.lock` lives, instead of `/python` and
`/python/providers/*`
- fixes security bumps that never touched the lockfile: Dependabot's
langchain-openai bump in ec24c54ff edited only `python/pyproject.toml`,
and Dependabot alert 439 for that package is still open against a pin
that has been at 1.6.0 since 2026-08-24
- keeps explicit directories for the four providers that are not
workspace members (`autogen`, `claude_agent_sdk`, `langgraph`,
`llamaindex`) so they keep getting updates on their own manifests
- leaves the `tomli` and `ag2` ignores and the grouping untouched

Follow-up worth a look, out of scope here: `python/providers/openai` is
a workspace member but also carries its own `uv.lock`, which uv ignores
when it resolves the workspace from the root.
2026-09-09 15:57:39 +02:00
Alberto Schiabel 988b9a1ff1 chore(deps): raise js-yaml and sharp override floors for new advisories (#4393)
This PR:

- restores the `pnpm audit --prod --audit-level=high` gate in
`ts.audit.yml`, which fails on `next` today
- raises the two `js-yaml` override floors to `>=4.3.2` and `>=3.15.2`
for GHSA-2883-xcg3-v3hh (`maxTotalMergeKeys` CPU exhaustion); the
production path is `@composio/cli > openapi-typescript >
@redocly/openapi-core`
- adds a `sharp@>=0.35.4` override for the libheif advisories
GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545; `sharp` is only reached
through `miniflare` in the Cloudflare e2e fixtures and nothing in the
repo imports it
- ignores GHSA-7pqw-9j4j-h8q3, GitHub's second advisory for the
already-ignored `extract-zip` symlink bug, which has no patched release
either; both consumers already extract through `extractZipSafely`

After the relock `pnpm audit` reports only the three documented ignores,
and `pnpm audit --prod --audit-level=high` exits 0.

https://claude.ai/code/session_01P1AvRSuyBh6eRtpixaPJ6g
2026-09-09 15:56:32 +02:00
Alberto Schiabel 100d56866f fix(experimental): stamp eve durable callback descriptors (#4385)
This PR:

- Closes https://github.com/ComposioHQ/composio/issues/4343
- stamps eve's durable callback descriptors on every tool `EveProvider`
wraps, via the new internal `withDurableClosure(closure, callback)`
helper — eve only stamps them on `defineTool` calls its build transform
finds in the agent's own source, which never runs on this package inside
`node_modules`, so eve discarded the whole resolver result and the agent
silently lost every Composio tool
- persists `{ slug, binding }` per callback, where `binding` is an id
minted per `wrapTools` call and prefixed with a per-process token, and
re-attaches it to that resolve's Composio executor through a
module-level binding map. `executeTool` is bound to one Composio
session, so a slug-only closure would have routed a call to whichever
session resolved last; sessions for different users share one provider,
and eve's callback registry is keyed by tool name only, so the map lives
at module level rather than on the instance
- covers `execute` and, when `needsApproval` is set, `approvalRequest`;
the descriptor key is the global-registry symbol
`Symbol.for('eve:durable-dynamic-callback')`, so no eve internal is
imported and the stamp is inert on eve versions that predate the
contract
- adds 9 regression tests: descriptor presence and shape,
JSON-serializability of the closure, replay of execute and approval from
the closure alone, per-resolve executor isolation when sessions share a
provider, hooks of the producing provider on replay, the unknown-slug
and unknown-binding errors, that two fresh module instances never mint
the same binding id, and one suite that loads eve 0.52.1's own
`validateDurableDynamicToolCallbacks`, `replayDynamicTools`, and
callback registry from the installed package to validate and replay a
wrapped tool end to end. Before the change eve threw `Dynamic tool "..."
callback "execute" does not have a durable descriptor`

## Context

The reporter hit this on eve 0.50 as `non-serializable capture`; 0.52.1
reports the same root cause as a missing descriptor. eve exports no
public durable-callback helper (tracked at vercel/eve#2967), so the
provider stamps the descriptor itself rather than pinning users to an
older eve.

Bindings are kept for the life of the process: eve can resume a parked
call at any time. A binding lives only in the process that resolved the
tools, so a call parked across a restart cannot be replayed; the
per-process token in the id makes the stale closure fail the lookup
loudly instead of matching whichever resolve reused its counter value in
the new process. Growth is one entry per `session.tools()` resolve.

Docs (`/docs/providers/eve`) now state the contract, the restart limit,
and the real reason the `step.started` resolver runs each step
(principal re-evaluation and retry, cached per session).

Also unblocks `Docs - Tests` on this branch: the catalog refresh in
#4330 renamed Stripe's triggers, so the Stripe knowledge-base guide
cited two dead slugs and the corpus verifier failed for any PR touching
docs. The guide now cites only the renamed slug the catalog lists, and
`generate-toolkits.ts` fetches trigger types with `limit=1000` so the
catalog stops truncating every toolkit to its first 20 triggers.

https://claude.ai/code/session_019wRk1S4Z6V6FWr4UsybGvR


EOF -R ComposioHQ/composio
2026-09-08 20:51:33 +02:00
Alberto Schiabel ba85f4d183 fix(sdk): honor Fetch redirect semantics in both SSRF guards (#4387)
This PR:

- builds on top of https://github.com/ComposioHQ/composio/pull/4271,
whose commit it carries unchanged
- applies the Fetch standard's redirect method/body rules in **both**
SSRF guards via `_redirect_rewrite` / `redirectRewrite`: a `303` retries
as a bodiless request, a `301`/`302` does the same for a `POST`, and
`307`/`308` replay both
- narrows `ssrfSafeFetch` to the five statuses the Fetch standard calls
a redirect, so a `304` or `305` carrying a `Location` is returned to the
caller instead of followed — Python already used
`_REDIRECT_STATUS_CODES`
- drops `params` after the first hop in `safe_request`, since `Location`
carries the query for the target it names and re-appending handed a
query-string credential to a target that never asked for one
- purges the union of the Fetch `request-body-header` set and the two
`requests` also drops, identically on both sides
- blocks the IPv6 transition ranges the TypeScript CIDR list missed —
6to4 `2002::/16`, Teredo and the rest of `2001::/23`, local-use NAT64
`64:ff9b:1::/48`, `100::/64`, `2001:db8::/32`, site-local `fec0::/10` —
and the IPv4/IPv6 multicast and `192.88.99.0/24` ranges Python's
`is_global` missed

## Context

Both guards follow redirects by hand so every hop is revalidated against
the address blocklist. That also means neither inherits the method and
body rewriting `fetch` and `requests` would have done, so an upload
answered with a `303` was replayed — payload and all — at a result URL
that expects a GET.

https://github.com/ComposioHQ/composio/pull/4271 landed that rule in
Python only, which left the two SDKs disagreeing on the same wire
behavior. Reviewing for that divergence surfaced the redirect-status
set, the `params` replay, and the address-blocklist gaps above.
`2002:7f00:1::` is 6to4 for `127.0.0.1`, and it passed the TypeScript
guard as a public address.

Verified with `pytest python/tests/test_url_safety.py` (56 passed) and
`vitest run` in `@composio/core` (54 files, 1280 passed), plus `ruff`,
`tsc --noEmit`, `oxlint` and `prettier`. Fail-before confirmed: 10 of
the new TypeScript cases and 5 of the new Python cases fail against the
unmodified guards.

Two known gaps are deliberately left out, each deserving its own change:
neither guard strips `Authorization`/`Cookie` on a cross-origin
redirect, and a non-seekable Python body is re-sent exhausted on a `307`
where TypeScript throws a bare `TypeError` on a consumed
`ReadableStream`.

https://claude.ai/code/session_01SB3ZJdvoqBcRrWb2toWVrX

---------

Co-authored-by: ump45nose <52391318+ump45nose@users.noreply.github.com>
2026-09-08 20:51:12 +02:00
sdkrelease[bot] 80867a09bc docs: update toolkits, API spec, and meta tools data (#4330)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-09-08 18:14:20 +02:00
Alberto Schiabel 53c024a9c8 fix(py): keep local results when remote multi-execute transport fails (#4386)
## Summary

Follow-up to #4310. The TypeScript SDK (since #3800) catches a thrown
backend call for the remote half of a mixed
`COMPOSIO_MULTI_EXECUTE_TOOL` batch and turns it into one failure entry
per remote slug, so completed local results are not lost. The Python SDK
still let the exception escape `_route_multi_execute`, discarding every
local result that had already run.

This ports the TypeScript behavior so both SDKs return the same shape on
a remote transport failure.

Fixes #

## Changes

- Catch the remote future's exception in `_route_multi_execute` and keep
`str(error)`, falling back to `Remote tool execution failed` when the
message is empty (same fallback as TS).
- Synthesize `{response: {successful: False, data: {}, error},
tool_slug, error}` for each remote index and merge them in original
request order.
- Recompute `total_count` / `success_count` / `error_count` on transport
failure, as TS does.
- Add two regression tests mirroring the TS cases in
`customToolRouting.test.ts`: local results preserved with per-tool
remote errors, and the empty-message fallback.

## Type of change

- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?

- `uv run --locked --group dev pytest tests/test_custom_tools.py -q`: 87
passed.
- `uv run --locked --group dev nox -s chk`: ruff and mypy clean.
- Without the source change, the new
`test_remote_transport_failure_keeps_local_results` raises
`RuntimeError: remote unavailable` out of `_route_multi_execute`.

## Checklist

- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [ ] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [ ] I added a changeset if this change affects published packages
(Python does not use Changesets)

## Additional context

TypeScript reference:
`ts/packages/core/src/models/ToolRouterSession.ts`, the
`remoteErrorMessage` branch, and the test "should preserve successful
local results when remote transport fails".

https://claude.ai/code/session_01PAXMbiZd3qPoJ8Z9uPvEAb
EOF -R ComposioHQ/composio
2026-09-08 18:11:25 +02:00
CoralGarden52 2c4339a859 fix(python): preserve mixed multi-execute result order (#4310)
## Summary

`ToolRouterSession._route_multi_execute` currently concatenates remote
results before local results and assigns new indexes from that
concatenated list. For a request such as `[LOCAL_TOOL, REMOTE_TOOL]`,
callers receive `[REMOTE_TOOL, LOCAL_TOOL]`, so code that correlates
`results[index]` with the requested tools can use the wrong result.

This brings the Python implementation in line with the merged TypeScript
behavior in [#3800](https://github.com/ComposioHQ/composio/pull/3800):
preserve each tool's original request index, restore that order after
local/remote execution, and then assign contiguous result indexes.

Fixes #

## Changes

- Preserve the original index on locally executed result entries.
- Map remote sub-batch results back to their original request indexes
before merging.
- Sort the merged results by original index and re-index them
sequentially.
- Update the mixed local/remote regression test to assert request order
and indexes.

## Type of change

- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?

- `uv run --locked --group dev pytest tests/test_custom_tools.py -q` —
69 passed.
- `uv run --locked --group dev nox -s tst -- tests/test_custom_tools.py`
— 69 passed.
- `uv run --locked --group dev ruff --config config/ruff.toml check
composio/core/models/tool_router_session.py tests/test_custom_tools.py`
— passed.
- Ruff format check on both changed files — passed.
- Verified the regression test fails on the pre-fix implementation and
passes after the fix.

## Screenshots (if applicable)

Not applicable.

## Checklist

- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [ ] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [ ] I added a changeset if this change affects published packages

## Additional context

This change is limited to Python multi-execute result ordering.
All-local and all-remote fast paths remain unchanged. No changeset is
needed because this repository does not use Changesets for Python
package changes.

Signed-off-by: CoralGarden52 <2193436736@qq.com>
2026-09-08 16:28:24 +02:00
Alberto Schiabel 705591451c chore(deps): upgrade CI actions and every outdated dependency (#4381)
This PR:

- upgrades every CI action to its latest release (only
`changesets/action` had one: v2.1.1 -> v2.1.2, SHA-pinned) and every
outdated dependency across the pnpm workspace, the docs bun workspace,
and all three `uv.lock` files
- moves zod to 4.5.4 everywhere first-party — catalog, docs,
`@composio/json-schema-to-zod`, `@composio/claude-agent-sdk` and the
zod-v4 e2e fixtures; the `*-zod-v3` fixtures stay on 3.25.76 because
that is what they exercise
- moves `@mastra/core` 1.52.1 -> 1.53.0, which is the ceiling rather
than a preference: bisecting `ts/examples/mastra`'s `cf:dry-run` shows
1.54.0 moved the workspace/sandbox subsystem behind
`@mastra/core/agent`, which drags execa (-> `npm-run-path` ->
`unicorn-magic`) into the Workers bundle where esbuild cannot link it.
`@mastra/mcp` is capped at 1.17.2 for the same reason — 1.17.3 wants
`@mastra/core` >=1.64. The docs bun workspace mirrors that cap as an
explicit devDependency plus `overrides` entry, because bun does not
apply overrides to auto-installed peers
- clears every production advisory that has a published fix, so the
audit gate can run without `--ignore`, which does not filter a single
run: it writes the advisory into `auditConfig` and exits 0 whatever else
is outstanding, so the gate was passing over nine advisories
- `qs` -> >=6.16.0, `fast-uri` -> >=3.1.6, `toml` -> the 4.x line, all
via overrides in the existing `# temporary: … drop when` style
- `extract-zip` (GHSA-jmr9-qjv8-65gv) has no fixed version to move to —
2.0.1 is the newest release and GitHub records `first_patched_version`
as null — so it moves to `auditConfig.ignoreGhsas` pointing at the
`extractZipSafely` mitigation that already covers it
- GHSA-866g-f22w-33x8 (`@ai-sdk/provider-utils` 3.x, low) also has
nothing to move to: the advisory names 3.0.98 as patched but the 3.x
line stopped at 3.0.30 and GitHub records no fixed version. It only
enters the tree through `@mastra/core`, which is a peer or dev
dependency of every published package, so all flagged paths are private
examples and e2e fixtures. It goes in `ignoreGhsas` with that rationale
so the un-levelled `pnpm audit --prod` step stops posting a warning
comment on every PR
- widens `@composio/anthropic`'s `@anthropic-ai/sdk` peer range to
include `^0.124.0`, the line its devDependency now tests against (for a
`0.x` caret, `^0.120.0` excluded it); the package is in the changeset
for that reason
- adapts three call sites that upstream broke: `eve` 0.52 moved
`ApprovalContext` to `eve/tools/approval`, `@pierre/diffs` 1.4 gave
`FileDiffProps` a second type parameter, and `fumadocs-openapi` 11.4
fixed the undeclared-tag drop that a docs guard test asserted (the guard
now also asserts the page positively, so it cannot pass vacuously)
- drops the stale `hono` `minimumReleaseAgeExclude` entry (its comment
said to after 2026-08-06) and adds an `undici` `peerDependencyRules`
allowance for openai 7.10's new optional peer

## Context

Some upgrades were deliberately declined, each for a reason recorded
next to the pin:

- `vitest`/`@vitest/ui` stay on 4.1.11 —
`@cloudflare/vitest-pool-workers@0.22.0` (latest) peers on `vitest
^4.1.0`
- `undici` stays on `^7` in core — `pinnedDispatcher.node.ts` documents
that Node's `fetch` rejects undici 8 dispatchers
- the `pnpm` catalog entry stays on `^11` to match the mise-owned
toolchain
- `eve` stays on 0.27.6 in docs — 0.52 changes the `defineAgent` model
definition and the `useEveAgent` helpers, so `agent/agent.ts` and
`components/eve-chat.tsx` fail `types:check`; migrating the docs agent
is its own PR
- `@earendil-works/pi-coding-agent` stays on 0.84.4 — 0.85.x imports
`@earendil-works/pi-server` without declaring it, so `test/pi.test.ts`
fails to load

`declareOperationTags` is kept as a safety net rather than retired, even
though `fumadocs-openapi` 11.4 makes it redundant: removing it changes
how specs are normalised at sync time and is worth its own PR.

Verified locally: `pnpm build:packages`, `pnpm typecheck`, `pnpm test`,
`pnpm typecheck:examples`, `pnpm lint:examples`, `turbo cf:dry-run
--filter='./ts/examples/*'`, `pnpm peers check`, `pnpm audit --prod
--audit-level=high` (exit 0), frozen-lockfile installs for pnpm and bun,
docs `types:check` + 542 static tests, and Python `make chk` + `make
tst` (1790 passed).

https://claude.ai/code/session_018evFic47PFPXuB95uRE1aw
EOF -R ComposioHQ/composio
@composio/cli@0.4.2-beta.384
2026-09-08 16:15:34 +02:00
Alberto Schiabel 0fb479b8f1 Merge commit from fork
* fix(cli): escape generated source metadata

* test(cli): execute generated Python regression

* fix(cli): order Python fallback assignments

---------

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
@composio/cli@0.4.2-beta.383
2026-09-08 14:59:48 +02:00
Adesh Deshmukh 7d36de8c0a fix(python-sdk): isolate default provider per Composio instance (#4370)
Construct a fresh OpenAIProvider per SDK instance instead of sharing a
module-level singleton whose execute_tool binding was overwritten by the
last-constructed instance, silently routing tool execution through the
wrong client/API key. Regression test in tests/test_sdk.py.

Fixes #4369

Co-authored-by: Adesh Deshmukh <adeshkd123@gmail.com>
Claude-Session: https://claude.ai/code/session_015YPz5SzeScR9TkgoRi2p1F
EOF -R ComposioHQ/composio
2026-09-08 13:33:10 +02:00
CoralGarden52 85d4923507 fix(python): dereference $ref/$defs in Google provider (#4297)
## Summary

The Python Vertex AI Google provider rebuilt tool parameter schemas from
`properties` and `required` without resolving internal `$ref`/`$defs`
references first. As a result, referenced properties were sent as
dangling references and could not be interpreted by Vertex AI.

This change dereferences internal schema references before the existing
Google-specific translation. It follows the provider behavior fixed in
[TypeScript PR #4288](https://github.com/ComposioHQ/composio/pull/4288).

## Changes

- Dereference Google provider input schemas with the existing
`dereference_json_schema` helper.
- Use the resolved schema when extracting properties and required
fields.
- Add a regression test covering a property defined through
`$ref`/`$defs`.

## Type of change

- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?

- `pytest tests/test_google_provider.py tests/test_json_schema.py
tests/test_provider.py -q -k 'not TestLangchainReservedKeywords and not
TestLangchainFreeFormObjectArguments'` — 59 passed, 4 skipped, 5
deselected.
- `ruff check --config config/ruff.toml
providers/google/composio_google/provider.py
tests/test_google_provider.py` — passed.
- `ruff format --check providers/google/composio_google/provider.py
tests/test_google_provider.py` — passed.
- `mypy --config-file config/mypy.ini
providers/google/composio_google/provider.py
tests/test_google_provider.py` — passed.

## Screenshots (if applicable)

Not applicable.

## Checklist

- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [x] I added a changeset if this change affects published TypeScript
packages

## Additional context

This is a Python-only provider fix; no TypeScript changeset is required.
No existing issue was found for the Python provider, so this PR includes
the minimal reproduction and regression test directly.

---------

Co-authored-by: jkomyno <alberto@composio.dev>
2026-09-07 16:00:20 +02:00
Brendan O'Leary 5803b4544b fix(docs): accept Mercury data refresh events (#4345)
## Summary

- accept `mercury-production-deploy` alongside the Apollo deployment
event
- log the correct source commit for Apollo and Mercury dispatches
- preserve compatibility with Apollo’s legacy `hermes_commit` payload
- show the dispatch action and source commit in generated data PRs

## Companion PR

- ComposioHQ/mercury#26701 sends the event after a successful production
registry sync.

## Verification

- `bun test tests/static/docs-data-workflow.test.ts` (6 passed)
- `bunx oxlint tests/static/docs-data-workflow.test.ts`
- `bunx prettier --check ../.github/workflows/docs-update-data.yml
tests/static/docs-data-workflow.test.ts`
- `actionlint .github/workflows/docs-update-data.yml`
- `bun test tests/static` reached 541 passes. One unrelated analytics
test failed because Bun could not bind its ephemeral local server with
`EADDRINUSE`; rerunning that test reproduced the same local environment
failure.
2026-09-07 15:14:52 +02:00
Alberto Schiabel 230f81a737 refactor(cli): import @effect/platform modules by subpath (#4360)
This PR:

- rebases onto `next` now that
https://github.com/ComposioHQ/composio/pull/4358 and
https://github.com/ComposioHQ/composio/pull/4359 are merged
- rewrites every `@effect/platform` and `@effect/platform-bun` barrel
import under `ts/packages/cli` (155 statements in 112 files) as a
per-module namespace import, e.g. `import * as FileSystem from
'@effect/platform/FileSystem'`
- adds both barrels to the `no-restricted-imports` lists for
`ts/packages/cli/src`, with messages pointing at the subpath form
- updates the boundary guidance in `ts/packages/cli/AGENTS.md` and the
`cli-command` skill to the subpath form

## Context

Both barrels are pure namespace re-exports (60 and 19 modules), so this
is import-only with no runtime change. Effect v4 spreads these modules
across `effect` (`FileSystem`, `Path`, `PlatformError`),
`effect/unstable/http`, and `effect/unstable/process`; with per-module
imports the port becomes a scripted path rewrite instead of
hand-splitting each barrel line. Third of three preparation PRs.

## Validation

- `pnpm --filter @composio/cli typecheck` and oxlint clean; a probe
barrel import in `src/` is rejected by the new rule
- `pnpm --filter @composio/cli test`: 127 files, 1318 tests pass, 1
skipped
@composio/cli@0.4.2-beta.382
2026-09-07 15:14:15 +02:00
sdkrelease[bot] e633a7bdf2 docs: update guides for SDK changes (#4365)
## Summary
Automated docs update triggered by SDK source changes on `next`.

- Claude reviewed the SDK diff and updated guides, FAQs, or examples
  that reference changed APIs or features.
- The docs `@composio/*` dependencies were realigned to their latest
  published releases so Twoslash snippets and example apps validate
  against versions users can actually install.

## Review checklist
- [ ] Changes accurately reflect the new SDK behavior
- [ ] No unrelated docs were modified
- [ ] Code examples are correct and complete
- [ ] If a documented feature is not published yet, the Twoslash build
      will fail — wait for the release instead of working around it

Generated by Claude Code via GitHub Actions.

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-09-07 12:35:12 +02:00
Alberto Schiabel f5ff810f2e refactor(cli): define services with Context.Tag and thread argv explicitly (#4359)
This PR:

- builds on top of https://github.com/ComposioHQ/composio/pull/4358
- replaces the eleven `Effect.Service` files (fourteen services) with
`Context.Tag` classes that export a `<Name>Shape` type and an explicit
`static readonly Default` layer built from a `make<Name>` constructor
- removes the three `accessors: true` declarations; nothing in `src/`
used a generated accessor, and the one test that did now yields the
service
- builds test doubles with `Service.of({ ... })` instead of `new
Service({ ... })`, and types helper parameters with the `Shape` types
where the class had been used as a type
- passes the normalized argv from `bin.ts` into `runCli` and through
`cli-main.ts` instead of mutating `process.argv` and reading it back in
five places
- documents the service pattern in `ts/packages/cli/AGENTS.md`

## Context

Effect v4 replaces `Effect.Service` with `Context.Service`, which
generates neither a `.Default` layer nor accessors; with the
explicit-layer shape already on v3, the port turns each service into a
one-line rename. `Command.runWith` in `effect/unstable/cli` takes user
arguments explicitly, so `cli-main.ts` now receives argv rather than
re-reading process state. Second of three preparation PRs.

## Validation

- `pnpm --filter @composio/cli typecheck`, `validate:boundaries`, and
oxlint clean
- `pnpm --filter @composio/cli test`: 127 files, 1319 tests pass, 1
skipped
@composio/cli@0.4.2-beta.381
2026-09-07 12:34:13 +02:00
Alberto Schiabel 20aaa95c96 ci(ts): verify packed provider compatibility (#4355)
This PR:

- adds a clean consumer harness that packs core, its internal JSON
Schema dependency, and all ten TypeScript providers
- verifies tarball contents, npm installation, named public exports,
consumer typechecking, provider construction, and a credential-free
`wrapTool` conversion
- covers the current workspace core, one verified minimum-core lane per
provider, and the packed workspace core presented as `1.0.0-beta.0`
- preserves existing 0.x minimum peer ranges while recording the
verified floors separately for the future breaking release
- additively accepts core 1.0 prereleases without claiming stable 1.x
support yet
- widens the Anthropic and OpenAI Agents peer ranges to include the
upstream versions already used by this repository
- runs the gate in TypeScript CI and immediately before Changesets
publishing

The release guard fails before publication and its regression test
verifies build -> compatibility -> publish ordering plus failure
propagation.

## Non-breaking scope

No public API is removed or renamed, and the existing 0.x core peer
floors remain unchanged. All peer-range changes are additive. The gate
reports the nine floor corrections that should be made with the planned
breaking release.

## Validation

- `pnpm run check:provider-compatibility` (12 packed consumer lanes)
- `pnpm run test:provider-compatibility`
- `pnpm run test:release-workflow`
- `pnpm run build:packages` (19 packages)
- focused TypeScript compile and Oxlint checks
- Prettier, Changesets validation, and `git diff --check`
2026-09-07 12:33:53 +02:00
sdkrelease[bot] 61c3cb6481 chore(cli): refresh baked toolkit slugs (#4372)
## Summary
Automated refresh of the toolkit slugs the CLI knows without asking
the API, generated by
`ts/packages/cli/scripts/generate-toolkit-slugs.ts`.

Toolkits added since the last refresh currently cost users one
toolkit-list fetch (~2 s) the first time they run one of that
toolkit's tools. Merging this makes them free.

The generator refuses to write a list that is short, malformed, or
missing staple toolkits, so a bad fetch opens no PR at all.

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
@composio/cli@0.4.2-beta.380
2026-09-07 12:33:27 +02:00
Alberto Schiabel d4077ba415 chore(cli): trim unused Effect packages and unify version output (#4358)
This PR:

- drops the eight `@effect/*` satellite devDependencies and
`@effect/platform-node-shared` from `@composio/cli`; none is imported by
the CLI, its tests, or its scripts, and the
`@effect/platform-node-shared` catalog entry goes with them
- makes `--log-level` fall back to `COMPOSIO_LOG_LEVEL` when the flag is
absent (`Option.orElse` instead of `Option.zipLeft`, which discarded the
env value) and adds a precedence test
- rewrites `composio --version` and `composio -v` to the `version`
command before parsing, so the three spellings share one handler and
print identical output (the framework built-in used to add a trailing
blank line); CI and the installer keep using `composio --version`

## Context

First of three preparation PRs for the Effect v4 port;
https://github.com/ComposioHQ/composio/pull/3901 is the reference port.
Each lands v3-compatible groundwork that the port otherwise has to redo
on top of a large diff: the manifest, catalog, and lockfile were three
of the conflicting files in that PR, and its review had accepted Effect
v4's default `composio v<semver>` banner for `--version`. Owning the
flag in argv normalization keeps `--version` output stable across the
framework change instead.

## Validation

- `pnpm --filter @composio/cli typecheck` and oxlint clean
- `pnpm --filter @composio/cli test`: 127 files, 1318 tests pass, 1
skipped; `version`, `--version`, and `-v` are asserted byte-identical
- The Docker install e2e suite was not run locally;
`cli.install-e2e.yml` runs it on this PR
@composio/cli@0.4.2-beta.379
2026-09-05 00:22:11 +02:00
sdkrelease[bot] 2573c64d97 Release: update version (#4285)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to next, this PR will
be updated.


# Releases
## @composio/claude-agent-sdk@0.12.0

### Minor Changes

- 9447932: Dereference internal $ref/$defs in tool input schemas before
provider translation, so properties reachable only through a reference
keep their types and validation instead of degrading to untyped (z.any)
or being emitted as a dangling reference.

This changes the JSON Schema these providers emit for $ref-using tools.
Downstream snapshot tests on tool definitions will see diffs. Schemas
the Composio API ships with a $ref but no $defs block (e.g.
GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than
throwing. The strict-structured-outputs path of @composio/openai-agents
is unchanged — OpenAI supports $defs/$ref natively, including recursion.
## @composio/google@0.11.0

### Minor Changes

- 9447932: Dereference internal $ref/$defs in tool input schemas before
provider translation, so properties reachable only through a reference
keep their types and validation instead of degrading to untyped (z.any)
or being emitted as a dangling reference.

This changes the JSON Schema these providers emit for $ref-using tools.
Downstream snapshot tests on tool definitions will see diffs. Schemas
the Composio API ships with a $ref but no $defs block (e.g.
GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than
throwing. The strict-structured-outputs path of @composio/openai-agents
is unchanged — OpenAI supports $defs/$ref natively, including recursion.
## @composio/langchain@0.11.0

### Minor Changes

- 9447932: Dereference internal $ref/$defs in tool input schemas before
provider translation, so properties reachable only through a reference
keep their types and validation instead of degrading to untyped (z.any)
or being emitted as a dangling reference.

This changes the JSON Schema these providers emit for $ref-using tools.
Downstream snapshot tests on tool definitions will see diffs. Schemas
the Composio API ships with a $ref but no $defs block (e.g.
GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than
throwing. The strict-structured-outputs path of @composio/openai-agents
is unchanged — OpenAI supports $defs/$ref natively, including recursion.
## @composio/llamaindex@0.11.0

### Minor Changes

- 9447932: Dereference internal $ref/$defs in tool input schemas before
provider translation, so properties reachable only through a reference
keep their types and validation instead of degrading to untyped (z.any)
or being emitted as a dangling reference.

This changes the JSON Schema these providers emit for $ref-using tools.
Downstream snapshot tests on tool definitions will see diffs. Schemas
the Composio API ships with a $ref but no $defs block (e.g.
GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than
throwing. The strict-structured-outputs path of @composio/openai-agents
is unchanged — OpenAI supports $defs/$ref natively, including recursion.
## @composio/openai-agents@0.11.0

### Minor Changes

- 9447932: Dereference internal $ref/$defs in tool input schemas before
provider translation, so properties reachable only through a reference
keep their types and validation instead of degrading to untyped (z.any)
or being emitted as a dangling reference.

This changes the JSON Schema these providers emit for $ref-using tools.
Downstream snapshot tests on tool definitions will see diffs. Schemas
the Composio API ships with a $ref but no $defs block (e.g.
GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than
throwing. The strict-structured-outputs path of @composio/openai-agents
is unchanged — OpenAI supports $defs/$ref natively, including recursion.
## @composio/vercel@0.12.0

### Minor Changes

- 9447932: Dereference internal $ref/$defs in tool input schemas before
provider translation, so properties reachable only through a reference
keep their types and validation instead of degrading to untyped (z.any)
or being emitted as a dangling reference.

This changes the JSON Schema these providers emit for $ref-using tools.
Downstream snapshot tests on tool definitions will see diffs. Schemas
the Composio API ships with a $ref but no $defs block (e.g.
GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than
throwing. The strict-structured-outputs path of @composio/openai-agents
is unchanged — OpenAI supports $defs/$ref natively, including recursion.
## @composio/core@0.18.1

### Patch Changes

- 8a56383: Fix: automatic S3 file downloads are now capped at 100 MiB
(configurable per call) to prevent memory exhaustion from oversized or
streaming responses.
- 7420927: Fix custom toolkit child slug mapping: reject response tools
that have local handles but no exact toolkit match instead of silently
dropping them or binding another toolkit's handler, derive bare-slug
ambiguity from local definitions, and only reuse a same-toolkit bare
alias in customToolkits().
- 1d31c80: Redact credential-shaped values at the SDK log boundary.
- 95f9d32: Expose the runtime-conditional SSRF-safe fetch helper for
protected URL upload consumers.
- 0d28bef: Map file-download transport failures to the SDK error
contract and bound streamed response bodies.
- 52efb5b: Fix trigger subscriptions ignoring the `authConfigId` filter.
- Updated dependencies [ab289d6]
  - @composio/json-schema-to-zod@0.3.2
## @composio/experimental@0.2.4

### Patch Changes

- 4e633d1: Update TypeBox to 1.3.18.
## @composio/json-schema-to-zod@0.3.2

### Patch Changes

- ab289d6: Preserve Draft 7 acceptance across primitive, composed,
referenced, conditional, and typeless schemas. Enforce sibling and
object/array assertions, retain positional tuple and `additionalItems`
behavior, and prevent native Zod materialization from rejecting values
already accepted by the source schema.
## @composio/openai@0.12.2

### Patch Changes

- 620075a: Fix: stop printing MCP server URLs (credential-bearing) to
stdout via console.log in the OpenAI Responses provider; log server
names via logger.debug instead.
## @composio/slim@0.18.1

### Patch Changes

- Updated dependencies [ab289d6]
  - @composio/json-schema-to-zod@0.3.2
## @e2e-tests/cf-workers-basic@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## @e2e-tests/cf-workers-files@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## @e2e-tests/cf-workers-tool-router-ai@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## @e2e-tests/node-claude-agent-sdk@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/claude-agent-sdk@0.12.0
## @e2e-tests/node-custom-tools@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## @e2e-tests/node-json-schema-to-zod-v3@0.0.2

### Patch Changes

- Updated dependencies [ab289d6]
  - @composio/json-schema-to-zod@0.3.2
## @e2e-tests/node-json-schema-to-zod-v4@0.0.2

### Patch Changes

- Updated dependencies [ab289d6]
  - @composio/json-schema-to-zod@0.3.2
## @e2e-tests/node-mastra-tool-router-zod-v3@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/mastra@0.10.4
## @e2e-tests/node-mastra-tool-router-zod-v4@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/mastra@0.10.4
## @e2e-tests/node-tool-router-files@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## @e2e-tests/node-tool-router-pagination@0.0.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## anthropic-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/claude-agent-sdk@0.12.0
  - @composio/anthropic@0.11.1
## connected-accounts-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## error-handling-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## file-handling-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## google-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/google@0.11.0
## json-schema-to-zod-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## langchain-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/langchain@0.11.0
## llamaindex-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/llamaindex@0.11.0
## mastra-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/mastra@0.10.4
## mcp-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## modifiers-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## openai-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [620075a]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/openai-agents@0.11.0
  - @composio/openai@0.12.2
## session-management-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## tool-router-example@1.0.12

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/claude-agent-sdk@0.12.0
  - @composio/vercel@0.12.0
  - @composio/openai-agents@0.11.0
## toolkits-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## tools-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## triggers-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## vercel-example@0.1.11

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [9447932]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
  - @composio/vercel@0.12.0
## versioning-example@0.1.2

### Patch Changes

- Updated dependencies [8a56383]
- Updated dependencies [7420927]
- Updated dependencies [1d31c80]
- Updated dependencies [95f9d32]
- Updated dependencies [0d28bef]
- Updated dependencies [52efb5b]
  - @composio/core@0.18.1
## @composio/json-schema-to-effect-schema@0.1.1

### Patch Changes

- ab289d6: Translate draft-4 boolean
`exclusiveMinimum`/`exclusiveMaximum` flags (as emitted by OpenAPI 3.0
exporters) into their Draft 7 numeric spelling so exclusive bounds are
enforced instead of silently ignored.

Co-authored-by: sdkrelease[bot] <294075132+sdkrelease[bot]@users.noreply.github.com>
@e2e-tests/node-tool-router-pagination@0.0.2 @composio/claude-agent-sdk@0.12.0 @composio/langchain@0.11.0 langchain-example@0.1.11 @composio/json-schema-to-zod@0.3.2 google-example@0.1.2 llamaindex-example@0.1.2 @composio/json-schema-to-effect-schema@0.1.1 @composio/llamaindex@0.11.0 mastra-example@0.1.2 @composio/google@0.11.0 file-handling-example@0.1.2 mcp-example@0.1.2 @composio/experimental@0.2.4 @composio/openai-agents@0.11.0 modifiers-example@0.1.11 error-handling-example@0.1.11 @composio/openai@0.12.2 openai-example@0.1.11 connected-accounts-example@0.1.11 @e2e-tests/node-custom-tools@0.0.2 @composio/slim@0.18.1 session-management-example@0.1.2 json-schema-to-zod-example@0.1.2 anthropic-example@0.1.2 tool-router-example@1.0.12 @composio/vercel@0.12.0 @composio/core@0.18.1 @e2e-tests/node-claude-agent-sdk@0.0.2 @e2e-tests/node-tool-router-files@0.0.2 vercel-example@0.1.11 @e2e-tests/cf-workers-tool-router-ai@0.0.2 @e2e-tests/cf-workers-basic@0.0.2 toolkits-example@0.1.11 @e2e-tests/node-mastra-tool-router-zod-v4@0.0.2 @e2e-tests/node-mastra-tool-router-zod-v3@0.0.2 tools-example@0.1.2 versioning-example@0.1.2 @e2e-tests/node-json-schema-to-zod-v3@0.0.2 @e2e-tests/cf-workers-files@0.0.2 triggers-example@0.1.2 @e2e-tests/node-json-schema-to-zod-v4@0.0.2
2026-09-04 21:01:00 +02:00
Alberto Schiabel 684a392816 chore(python): prepare 0.21.1 release (#4361)
## Summary

- bump the Python SDK and all provider package versions to `0.21.1`
- regenerate the root `uv.lock` from the updated workspace metadata
- keep the existing coordinated changelog as the release authority

## Verification

- `pnpm test:release-workflow`
- `make build` (26 artifacts)
- `python -m twine check python/dist/*`
py@0.21.1
2026-09-04 20:50:30 +02:00
Alberto Schiabel 1ab8b3c683 fix(toolchain): pin stable Bun 1.4.1 binaries (#4357)
This PR:

- replaces the temporary Bun canary pin with the signed stable `1.4.1`
platform packages
- restores Linux ARM64 cross-compilation, which blocked the CLI beta
workflow after https://github.com/ComposioHQ/composio/pull/4315
- preserves immutable per-platform tarballs and checksums through mise's
HTTP backend
- keeps the declared revision aligned with `bun --revision`

## Verification

- both macOS platform binaries pass `codesign --verify --strict`
- `pnpm test:toolchain`
- `pnpm test:release-workflow`
- `pnpm build:packages`
- `pnpm --filter @composio/cli build:binary:cross --target
bun-linux-arm64`
- `taplo fmt --check mise.toml`
- `git diff --check`
@composio/cli@0.4.1 @composio/cli@0.4.1-beta.377
2026-09-04 19:39:26 +02:00
Alberto Schiabel cfeada600d docs(changelog): document September CLI and SDK releases (#4350)
This PR:

- prepares the coordinated September 4 changelog for CLI `0.4.1`, Python
SDK `0.21.1`, and the TypeScript SDK release
- gives DevRel one customer-facing source for credential security, file
transfers, JSON Schema behavior, and custom-tool routing
- records the TypeScript provider and schema-converter package matrix,
including the releases added after #4316 merged
- adds the `@composio/core` `0.18.1` row that the refreshed release PR
#4285 now requires
- corrects the download-limit guidance and documents the fallback for a
`$ref` without matching `$defs`

The listed versions are coordinated release targets. They are not all
published yet, so this changelog and the release PRs still need to be
sequenced together.

## Verification

- `pnpm exec prettier --check
docs/content/changelog/09-04-26-cli-and-sdk-releases.mdx`
- `cd docs && bun run types:check`
- `cd docs && bun run lint:links`
- `cd docs && bun run test` (541 passed)
- `pnpm test:release-workflow`
2026-09-04 19:13:09 +02:00
Alberto Schiabel 0d4383c4f7 fix(docs): isolate product theme from next-themes storage, switcher link fixes (#4349)
## Summary

Applies the top findings from a multi-reviewer code review of #4335
(which merged before these could land on the PR branch). Four validated
findings, all small and behavior-preserving outside the fixes
themselves:

- **Cross-tab theme fight (P1):** #4335 routed the product-derived theme
through next-themes' shared `theme` localStorage key -- written by the
root layout's inline head script on every hard load and by `setTheme` on
every client switch. next-themes listens for cross-tab storage events on
that key, so two docs tabs on different products (Platform dark / For
You light) silently repaint each other with no self-heal (the provider
effect's deps are `[product, setTheme]`, so the flipped tab never
corrects). The product theme is derived state, not a preference: this PR
applies it directly to the document element (`applyProductTheme`) and
passes `forcedTheme: initialTheme` from the server-resolved product so
hydration cannot flip a stale stored value. No `theme` localStorage
writes remain anywhere.
- **theme-color meta (P2):** the two `prefers-color-scheme`-keyed metas
meant mobile browser chrome mismatched the forced page theme (white
chrome over dark Platform pages for light-OS users). Now a single meta
keyed to the product theme.
- **Switcher current-option href (P2):** the popover option marked
`aria-current="page"` resolved to the product landing route, so
middle-click, hover status bar, and copy-link all pointed at the wrong
URL. It now hrefs the current pathname.
- **Explore-card aria-label (P3):** `aria-label` replaced the link's
accessible name, so the product description inside the card was not
announced. Dropped; heading + description now form the name.

## Changes

- `docs/app/layout.tsx` -- inline script no longer writes localStorage
(pre-paint class priming unchanged); single product-keyed `theme-color`
meta; `forcedTheme: initialTheme` on `RootProvider`.
- `docs/components/docs-product-context.tsx` -- `setTheme`/`useTheme`
removed; new `applyProductTheme` used in the product effect and the
flushSync commit.
- `docs/components/product-switcher.tsx` -- `destination = isCurrent ?
pathname : docsProductDestination(...)`.
- `docs/components/home-surfaces.tsx` -- Explore-card `aria-label`
removed.
- `docs/tests/static/product-navigation.test.ts` -- pins the new
invariants (`applyProductTheme`, `forcedTheme: initialTheme`, and a
negative assertion that `localStorage.setItem('theme'` stays out).

## Testing

- `bun test tests/static/` -- 541 pass / 0 fail
- `bun run types:check` -- clean
- `bun run lint` -- only pre-existing warnings (`home-surfaces.tsx:102`
`no-img-element` is in `ForYouVisual`, untouched)
- Worth a manual check: two tabs on different products no longer repaint
each other (static tests cannot prove cross-tab storage isolation)

## Notes

- Docs-only change; no changeset required.
- Review context: follow-up to #4335. Remaining review findings
(navigation state-machine races, theme-scope design call, decision
record) are tracked separately.
2026-09-04 17:32:27 +02:00
Alberto Schiabel ab289d6224 fix(sdk): preserve primitive JSON Schema semantics (#4316)
## Summary

- preserve boolean, empty, null, type-array, enum, const, and
scalar-constraint semantics across every Python conversion entry point
- intersect Zod enum and const values with declared types and
constraints, including compound JSON values
- default unversioned exact validation to Draft 7 and apply inclusive
and numeric exclusive bounds independently
- run one byte-identical corpus through Python, Zod, and Effect so
accepted and rejected inputs stay aligned
- keep exact JSON Schema acceptance separate from Pydantic default
materialization

## Review follow-up (second push)

- Python: exact Draft 7 acceptance now wraps all three entry points
(`json_schema_to_pydantic_type`, `json_schema_to_model`,
`pydantic_model_from_param_schema`), so they can no longer disagree
- Python: draft-4 boolean `exclusiveMinimum`/`exclusiveMaximum` (OpenAPI
3.0 style) no longer crash conversion — exact validation falls back to
Draft 4, and the library input is translated to the numeric spelling
- Python: ECMA-only regex patterns (look-around) no longer crash
pydantic model builds — Rust-incompatible patterns fall back to Python
`re`
- Python: type arrays with sibling constraints no longer raise
`TypeError` on valid input — constraints are scoped per member before
the library sees them
- Python: integral floats satisfy `integer`, `const` intersects `enum`,
annotation-only schemas accept anything, and an optional property with
an empty `enum` tolerates absence
- Zod: typeless scalar constraints apply per instance type, and string
lengths count Unicode code points instead of UTF-16 code units
- Effect: draft-4 boolean exclusive bounds are enforced instead of
silently ignored
- `multipleOf` uses decimal scaling in all three converters (declared
`divergesFromJsonSchema` on the corpus case)
- shared corpus grows by 13 primitive cases; new property-based tests
check acceptance against real Draft 7 oracles (hypothesis + `jsonschema`
in Python, fast-check + Ajv in TypeScript)

## Verification

- Python `make chk` (ruff + mypy)
- Python pytest: 1,572 passed (5 langchain-extra tests need an env this
sandbox lacks; unchanged from base)
- `@composio/json-schema-to-zod`: 187 passed incl. 300-run fast-check
property test; typecheck + build
- `@composio/json-schema-to-effect-schema`: 133 passed; typecheck
- `@composio/core` corpus ingress tests: 61 passed
- shared Python/TypeScript corpus files are byte-identical
(shasum-verified)
- `git diff --check`

## Contributor context

This replaces four narrow proposals after independent local
reproduction:

- [#4301](https://github.com/ComposioHQ/composio/pull/4301) ·
[Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4301)
- [#4302](https://github.com/ComposioHQ/composio/pull/4302) ·
[Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4302)
- [#4303](https://github.com/ComposioHQ/composio/pull/4303) ·
[Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4303)
- [#4307](https://github.com/ComposioHQ/composio/pull/4307) ·
[Glen](https://app.tryglen.com/ComposioHQ/composio/pull/4307)

---------

Co-authored-by: simpleqt <89645338+simpleqt@users.noreply.github.com>
2026-09-04 14:19:02 +02:00
Brendan O'Leary abefd6962f feat(docs): add product context switcher (#4335)
## Summary

Add a product context switcher that separates the docs into two paths
just like the Dashboard:

- Composio For You, for connecting apps to existing AI clients
- Composio Platform, for building agents with the SDK

The selected product controls the docs sidebar and persists across
navigation. Product-specific URLs set the matching context, while shared
pages remain open when readers switch products.


https://github.com/user-attachments/assets/e3f6905d-7238-43a2-a51e-145a01688c04

## Changes

- Define product labels, landing pages, route ownership, sidebar groups,
and equivalent destinations in one configuration.
- Build separate Fumadocs page trees for For You and Platform.
- Add an accessible product switcher and a separate home link to the
site header.
- Force dark mode for Platform and light mode for For You, with no
separate theme toggle.
- Update the homepage cards to select the matching product.
- Add a reduced-motion-aware transition with a 1.5-second navigation
timeout.
- Test route classification, destination mapping, complete page-tree
coverage, and switcher semantics.

## Testing

- `bun test tests/static/ --reporter=dot` — 541 passed
- `bun run types:check`
- `bun run lint`
- `bun run build`
- Tested both product directions in the local docs site.
- Verified that the home link works, Platform stays dark, For You stays
light, and shared Security pages remain open when switching products.

## Notes

This is a docs-only change and does not require a changeset.
2026-09-03 12:31:52 -04:00
Brendan O'Leary 33434bbe93 Merge branch 'next' into bdo/add-context-switcher 2026-09-03 12:24:14 -04:00
Brendan O'Leary 4e08394e67 chore(code-owners): add brendan as a codeowner for docs (#4342)
## Summary
Explain the motivation and context for this change. Link to any related
issues.

Fixes #

## Changes
- 
- 

## Type of change
- [ ] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?
Describe the tests you ran and instructions so reviewers can reproduce.
Include any relevant config/versions.

## Screenshots (if applicable)

## Checklist
- [ ] I have read the Code of Conduct and this PR adheres to it
- [ ] I ran linters/tests locally and they passed
- [ ] I updated documentation as needed
- [ ] I added tests or explain why not applicable
- [ ] I added a changeset if this change affects published packages

## Additional context
2026-09-03 17:12:03 +02:00
Brendan O'Leary 0fbed5273b docs(auth): clarify managed OAuth app coverage (#4322)
## Summary
Clarifies that the managed auth page covers OAuth apps, not every
credential type.

Fixes #

## Changes
- Renames the page and tabs around managed OAuth.
- Explains the difference between OAuth app credentials and user
authorization.
- Clarifies how toolkits with multiple authentication methods appear.
- Keeps the browser and agent-readable versions consistent.
- Replaces the API-key-based PostHog example with Gmail.

## Type of change
- [ ] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [x] Documentation
- [ ] Breaking change

## How Has This Been Tested?
Describe the tests you ran and instructions so reviewers can reproduce.
Include any relevant config/versions.

## Screenshots (if applicable)

## Checklist
- [ ] I have read the Code of Conduct and this PR adheres to it
- [ ] I ran linters/tests locally and they passed
- [ ] I updated documentation as needed
- [ ] I added tests or explain why not applicable
- [ ] I added a changeset if this change affects published packages

## Additional context
2026-09-03 10:45:00 -04:00
Brendan O'Leary 7dd5832ded chore(docs): rebuild KB semantic artifact 2026-09-03 10:36:49 -04:00
Brendan O'Leary 985d0d0777 docs(auth): clarify managed OAuth app coverage 2026-09-03 10:36:49 -04:00
sdkrelease[bot] 027b773b36 docs: update Python SDK reference from source (#4339)
## Summary
Auto-generated Python SDK reference docs from `python/composio/`.

Regenerates pages at `docs/content/reference/sdk-reference/python/` to
reflect changes in the Python package's public API (new methods, updated
signatures, changed types).

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-09-03 15:47:50 +02:00
sdkrelease[bot] eb951dff34 docs: update guides for SDK changes (#4274)
## Summary
Automated docs update triggered by SDK source changes on `next`.

- Claude reviewed the SDK diff and updated guides, FAQs, or examples
  that reference changed APIs or features.
- The docs `@composio/*` dependencies were realigned to their latest
  published releases so Twoslash snippets and example apps validate
  against versions users can actually install.

## Review checklist
- [ ] Changes accurately reflect the new SDK behavior
- [ ] No unrelated docs were modified
- [ ] Code examples are correct and complete
- [ ] If a documented feature is not published yet, the Twoslash build
      will fail — wait for the release instead of working around it

Generated by Claude Code via GitHub Actions.

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-09-03 14:09:16 +02:00