This PR:
- unblocks https://github.com/ComposioHQ/composio/pull/4177 by
documenting TypeScript `@composio/core` `0.18.0`
- bumps Python `composio` and all 12 provider distributions from
`0.20.0` to `0.21.0`
- keeps `python/composio/__version__.py` and the pinned `uv.lock`
aligned with package metadata
- adds the combined customer-facing changelog for strict tool schemas,
safer file transfers, and runtime reliability updates
- records the Node.js 22.22.3 minimum for the TypeScript release
## Release sequence
1. Merge this PR into `next`.
2. Merge #4177 after its release-workflow check turns green; Changesets
publishes the TypeScript packages to npm.
3. Tag the resulting `next` commit as `py@0.21.0` to publish the Python
core and provider packages to PyPI.
## Verification
- `pnpm test:release-workflow`
- `mise exec -- uv lock --check`
- `make chk`
- `make build`
- `uv tool run twine check dist/*` (26 artifacts)
- `bun run test` in `docs/` (527 tests)
## What
`ComposioError` (`errors/ComposioError.ts`) assigns `name` as a class
field (`public name = 'ComposioError'`). Under the package tsconfig
(es2022 -> `useDefineForClassFields`), each subclass must reassign
`this.name` in its constructor or it inherits the base value. ~30
sibling subclasses do this; three omitted it:
- `ComposioToolVersionRequiredError` (`errors/ToolErrors.ts`)
- `JsonSchemaToZodError` (`errors/ValidationErrors.ts`)
- `JsonSchemaRefResolutionError` (`errors/ValidationErrors.ts`)
So `new JsonSchemaToZodError().name === 'ComposioError'`, and the same
for the other two. All three are thrown on real paths (`Tools.ts`,
`jsonSchema.ts`), and `error.name` is forwarded to error telemetry
(`telemetry/Telemetry.ts`), so these distinct error types silently
mis-group under the base name; any consumer branching on `err.name ===
'<ClassName>'` never matches.
## Fix
Add the missing `this.name = '<ClassName>'` at the end of each of the
three constructors, matching the established sibling pattern.
Runtime-only; no type or public-API change. (The two `PusherErrors`
subclasses set `name` via a class field, which already resolves
correctly, so they are intentionally left untouched.)
## Tests
Adds `test/errors/errorNames.test.ts` asserting each of the three
reports its own class name and is `instanceof ComposioError`. Verified
fails-before / passes-after; full `@composio/core` suite green (1095
tests), plus `tsc`, oxlint, and prettier clean.
## What
`TelemetryService.sendMetric` and `sendErrorLog` issue `await
fetch(...)` with no timeout. If the telemetry endpoint stalls, the await
never settles. Both are awaited on the SDK's telemetry path
(`Telemetry.ts` batch-processor callback, `sendMetric`, and
`sendErrorTelemetry`), so a stalled telemetry endpoint can leave an SDK
call pending indefinitely — which the existing `catch` comment says must
never happen ("telemetry failures should never affect SDK calls").
## Fix
Wrap both requests in a private `postWithTimeout` helper that bounds
each best-effort request with an `AbortController` + `setTimeout` (3s)
and clears the timer in `.finally()`. This mirrors the already-merged
bound on the background npm version check in `utils/version.ts` (#4027),
including the hand-rolled-timer-over-`AbortSignal.timeout` rationale: an
uncleared timer pins the workerd request context open for the full
timeout on every successful send. On timeout the abort rejects `fetch`,
which the existing `catch` swallows exactly as it already swallowed
network errors, so the best-effort / never-throws contract is unchanged.
## Tests
Adds a `TelemetryService network bounding` suite (mirrors
`version.test.ts`): asserts each method passes an `AbortSignal` and
clears its timer on success, and that a never-responding endpoint
resolves to `undefined` without throwing. Verified fails-before /
passes-after; full `@composio/core` suite green (1092 tests), plus
`tsc`, oxlint, and prettier all clean.
This PR:
- builds on top of https://github.com/ComposioHQ/composio/pull/4209 by
@AseemPrasad, keeping its recursive `toStrictJsonSchema()` and Python
parity while changing the mechanism so strict mode stops deleting
parameters
- keeps every optional parameter under `strict: true`: properties become
required and optional ones accept `null` (the emulation OpenAI
documents), instead of dropping 42% of parameters across the 930-tool
corpus; `type` arrays stay as they are, so nullable objects stay
nullable
- sends tools whose schema strict mode cannot express (objects with
arbitrary keys, `allOf`, `prefixItems`, dangling `$ref`s, non-object
roots) with `strict: false` and a warning naming the tool and path,
instead of narrowing them to empty closed objects
- adds `omitNullToolArguments()`: the strict providers drop a `null`
argument only where the tool's own schema rejects it, so nullable fields
keep an explicit `null`
- keeps local `$ref`/`$defs` (recursion included) under strict mode
instead of inlining them
- brings the Python `OpenAIResponsesProvider(strict=True)` to parity:
emits `strict`, calls the base initializer, mirrors the rewrite and null
omission
- makes Mastra and openai-agents use the same strict semantics
(`OpenAIAgentsProvider({ strict: true })` previously had no effect)
- pins the behavior with a shared `strict-cases.json` corpus
(byte-identical TypeScript/Python copies) plus edge-case regression
tests enumerated independently with a second model
## Context
OpenAI's structured-outputs contract accepts `"type": ["string",
"null"]` and rejects `type` next to `anyOf`. Validated against OpenAI's
own `toStrictJsonSchema` converter over the 930 real tool schemas in
`ts/packages/cli/test/__mocks__/tools.json`: the previous approach was
accepted for 930/930 tools but only after removing 1,682 properties;
this one emits strict schemas for 816 tools (all accepted, no property
lost, idempotent) and downgrades the 114 tools that use free-form or
map-style parameters.
https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
## Summary
Auto-generated TypeScript SDK reference docs from
`ts/packages/core/src/`.
Regenerates pages at `docs/content/reference/sdk-reference/typescript/`
to reflect changes in the core package's public API (new methods,
updated signatures, changed types).
## Summary
Automated sync of backend data into the docs site. Triggered by:
`schedule`.
## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs
## Summary
- stop installing the independently distributed Autogen adapter into the
shared CrewAI/LangChain/LangGraph unit-test environment
- run the Autogen import guard and signature regressions in their own
matrix environment
- align the local `tst` nox session with the compatible shared provider
set and add `tst_autogen` for isolated Autogen coverage
## Root cause
`autogen-core==0.7.5` requires `protobuf~=5.29.3`, while CrewAI's
current telemetry dependency chain requires
`googleapis-common-protos>=1.75.1`, whose generated modules require
`protobuf>=6.33.5`.
The packages are independently distributed adapters and are not tested
together, but the workflow installed both into one virtual environment.
Because the installs were sequential, installing Autogen last downgraded
`protobuf` to `5.29.6` and left the already-installed Google modules
unusable:
```text
google.protobuf.runtime_version.VersionError: Detected incompatible Protobuf Gencode/Runtime versions when loading google/rpc/error_details.proto: gencode 6.33.5 runtime 5.29.6.
```
## Regression coverage
The shared suite intentionally skips Autogen because loading it
alongside CrewAI creates the incompatible protobuf environment. CI now
runs these existing regressions in the isolated Autogen environment
instead:
- `test_autogen_signature_honors_skip_defaults`
- `test_autogen_signature_preserves_default`
Developers can reproduce that boundary with `nox -s tst_autogen`.
## Verification
- reproduced the downgrade after the Autogen provider installation
- shared provider environment imports `google.rpc.error_details_pb2`
with `protobuf==6.33.6`
- isolated Autogen environment imports `composio_autogen` with
`protobuf==5.29.6`
- isolated Autogen regressions: 2 passed
- Python unit suite: 1,355 passed, 35 skipped
- Ruff and mypy: passed
- agent-skill and skill-routing validators: passed
- Prettier and `git diff --check`: passed
No Changeset is required: this only changes CI and test-environment
setup.
## Summary
Auto-generated Python SDK reference docs from `python/composio/`.
Regenerates pages at `docs/content/reference/sdk-reference/python/` to
reflect changes in the Python package's public API (new methods, updated
signatures, changed types).
Extends strict-cases.json to 68 cases with shapes enumerated independently
(single-element and three-member type arrays, null-only and null-carrying
enum/const properties, nested compositions, nullable objects in arrays,
tuple and boolean items, conditional and dependency keywords, oneOf beside
anyOf, boolean and malformed properties, $ref siblings and chains, legacy
definitions next to $defs, non-string required entries, ten-level
nesting) plus null-omission pairs for nullable, composed and $ref-typed
arguments. Checks in the generator that derives the pinned JSON.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
to_strict_json_schema reports the same constructs as the TypeScript
implementation (tuple items, boolean subschemas, malformed properties,
oneOf beside anyOf, conditional and dependency keywords), accepts a root
typed ["object"], leaves enum/const that already include null alone, and
omit_null_tool_arguments follows the composition branch matching the
argument's shape.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
Tuple-form items, boolean subschemas, malformed properties, oneOf left
beside anyOf, and the conditional and dependency keywords (not, if, then,
else, dependencies, dependentSchemas, propertyNames, contains,
additionalItems, unevaluatedItems, unevaluatedProperties) are now reported
as unsupported so the tool is sent without strict mode instead of with a
schema the API rejects. A root typed ["object"] is accepted, and an enum
or const that already includes null is not wrapped again.
omitNullToolArguments now follows the anyOf/oneOf branch that matches an
argument's shape, so nulls inside an object sent for a composed property
are reconciled against that branch.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
strict-cases.json (one byte-identical copy per language, next to
object-cases.json) pins the exact strict schema or the reported
incompatibilities for 44 shapes: optional widening at every depth,
nullable type arrays, compositions, enum/const wrapping, annotation
stripping, keyword-named and prototype-named properties, dynamic-key and
free-form objects, allOf/prefixItems, $defs recursion, dangling and
external refs, malformed required, non-object roots, plus null-omission
argument pairs. The TypeScript suite pins the implementation and the
Python suite checks parity against the same file.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
to_strict_json_schema iterated a string-valued required character by
character, so a malformed required kept same-named properties non-nullable
while the TypeScript implementation treats it as absent and widens every
property. Both SDKs now agree.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
toStrictJsonSchema assigned rewritten property schemas by name, so a
property called __proto__ set the prototype of the properties map instead
of being stored and disappeared from the strict schema. Own properties are
now defined explicitly, matching the other schema walkers in this module.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
OpenAIAgentsProvider accepted { strict } but always registered tools with
strict: false and additionalProperties: true. Strict mode now registers
tools with strict: true and a schema normalized by toStrictJsonSchema
(optional parameters required-nullable), drops null arguments the tool
schema rejects before execution, and registers tools strict mode cannot
express without strict mode with a warning.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
MastraProvider strict mode used the root-only, input-mutating
removeNonRequiredProperties, so "strict" meant something different from
the OpenAI providers. It now runs the same toStrictJsonSchema rewrite:
optional parameters become required-nullable, tools strict mode cannot
express keep their original schema with a warning, and null arguments the
tool schema rejects are dropped before execution.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
This PR:
- fixes all 11 open CodeQL alerts
([#118](https://github.com/ComposioHQ/composio/security/code-scanning/118)
through
[#128](https://github.com/ComposioHQ/composio/security/code-scanning/128))
for cache poisoning through untrusted code execution
- makes the workflow-selected `github.sha` authoritative for CLI build
and release checkouts
- requires stable promotion to run at the immutable beta tag and rejects
tag/release commit mismatches
- removes the manually supplied `beta_tag` data path into executable
jobs
- updates the CLI release playbook for tag-scoped promotion
- verifies the release contract with `pnpm test:release-workflow`,
agent-skill validators, shell syntax, formatting, and changeset
validation
OpenAI structured outputs support local $ref pointers, including recursive
definitions, so toStrictJsonSchema no longer inlines them: $defs and
definitions are normalized where they are declared, an optional $ref
property is widened with an anyOf null branch, and external or dangling
$refs are reported as unsupported. omitNullToolArguments follows local
$refs when deciding whether a null is accepted. The Vercel provider still
inlines definitions before converting to Zod, which does not follow $ref.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
The strict flag now calls the base initializer (schema_config kwargs keep
working), emits strict on the wrapped tool, and mirrors the TypeScript
pipeline: optional parameters become required-nullable, unsupported
schemas downgrade the tool to non-strict, and null arguments the tool
schema rejects are dropped before execution.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
VercelProvider strict mode now widens optional parameters to nullable
instead of dropping them, keeps the original schema for tools strict mode
cannot express, and drops null arguments the tool schema rejects before
execution. The README and docs page described the old dropping behavior.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
OpenAIResponsesProvider emits the strict schema and strict: true only when
the rewrite is lossless; otherwise the tool keeps its original schema with
strict: false and a warning names the tool and path. Tools without
parameters get a canonical empty closed object. Null arguments the tool
schema rejects are dropped before execution.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
toStrictJsonSchema now follows the contract OpenAI documents for structured
outputs: every property becomes required and optional ones are widened to
accept null, so the model keeps every parameter it could pass before. Type
arrays stay as they are (the API accepts them and rejects type next to
anyOf), so nullable objects stay nullable. Constructs strict mode cannot
express (objects with arbitrary keys, allOf, prefixItems, unresolved $refs,
non-object roots) are reported in `unsupported` instead of being narrowed.
omitNullToolArguments drops a null argument only where the tool's own
schema rejects it, so nullable fields keep an explicit null. The keyword
taxonomy shared by the three schema walkers now lives in one place.
Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>
Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
Automated knowledge-base refresh for `ComposioHQ/support-knowledge`.
- Source commit: `5eac683455ff252a7a3b62f33ab6566445009b52` (unchanged;
rebuilt a stale semantic artifact)
- Regenerated public KB pages and search records
- Reused unchanged vectors and rebuilt the checked semantic artifact
- Ran KB freshness and semantic-artifact verification
Automated knowledge-base refresh for `ComposioHQ/support-knowledge`.
- Source commit: `d57f3d69079ee3819f4136df54512cdf0416cec0` (unchanged;
rebuilt a stale semantic artifact)
- Regenerated public KB pages and search records
- Reused unchanged vectors and rebuilt the checked semantic artifact
- Ran KB freshness and semantic-artifact verification