Commit Graph

5039 Commits

Author SHA1 Message Date
Alberto Schiabel 3afaee05c5 Release: update version (#4177)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to next, this PR will
be updated.


# Releases
## @composio/core@0.18.0

### Minor Changes

- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.

### Patch Changes

- 449f4e1: Block automatic uploads when a sensitive directory or file
name is hidden by symlink resolution.
- 9545806: Bound the best-effort telemetry requests with a timeout so a
stalled telemetry endpoint cannot leave an SDK call pending
indefinitely.
- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- fe66cbe: Omit empty-string file-uploadable arguments from tool
execution requests instead of forwarding them to the backend, which
rejected them with "Input should be a valid dictionary or instance of
FileUploadable". This now also applies when
`dangerouslyAllowAutoUploadDownloadFiles` is off, and with it on an
empty value is no longer attempted as an upload.
- c0f1609: Fix three ComposioError subclasses
(ComposioToolVersionRequiredError, JsonSchemaToZodError,
JsonSchemaRefResolutionError) that omitted their `this.name` assignment
and therefore reported `name` as 'ComposioError' instead of their own
class name, mis-grouping distinct error types in error telemetry.
- d544006: Close a DNS-rebinding window in the SSRF guard: the address
validated by `assertSafeFetchTarget` is now the address `ssrfSafeFetch`
connects to, so a hostname is no longer resolved a second time between
the check and the connection. Each redirect hop is re-validated and
re-pinned. The request still carries the original hostname in `Host` and
TLS SNI, so certificate verification is unchanged. Hops whose effective
dispatcher is a configured route — a caller-supplied `dispatcher`, a
global `ProxyAgent`/`EnvHttpProxyAgent`, or `NODE_USE_ENV_PROXY`
env-proxy mode — keep the pre-flight check only, mirroring the Python
guard's documented proxy residual.
- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @composio/experimental@0.2.3

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/json-schema-to-zod@0.3.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/anthropic@0.11.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/claude-agent-sdk@0.11.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/cloudflare@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/google@0.10.3

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/langchain@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/llamaindex@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
## @composio/mastra@0.10.4

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 3c3b4da: `MastraProvider({ strict: true })` now keeps optional
parameters instead of dropping them: every property becomes required and
optional ones accept `null`, matching the OpenAI providers, and a `null`
argument the tool's own schema does not accept is dropped before
execution. Tools whose schema strict mode cannot express keep their
original schema with a warning.
## @composio/openai@0.12.1

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.
## @composio/openai-agents@0.10.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 9692db5: `OpenAIAgentsProvider({ strict: true })` now takes effect:
tools are registered with `strict: true` and a schema normalized for
OpenAI structured outputs (every property required, optional ones accept
`null`), a `null` argument the tool's own schema does not accept is
dropped before execution, and tools whose schema strict mode cannot
express are registered without strict mode with a warning. The option
was previously ignored.
## @composio/vercel@0.11.2

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- 04817cb: Fix strict-mode tool schemas for OpenAI structured outputs.
Strict normalization now applies OpenAI's contract at every depth
(nested objects, `anyOf` branches, array items, inlined `$ref`/`$defs`):
every object lists all of its properties in `required` and sets
`additionalProperties: false`, so tools with nested or optional
parameters no longer produce schemas the API rejects with a 400.
Optional parameters are no longer dropped: they stay available and are
widened to accept `null`, the emulation of optional fields OpenAI
documents, and the strict providers drop a `null` argument the tool's
own schema does not accept before executing the tool. Tools whose schema
strict mode cannot express (objects with arbitrary keys, `allOf`,
`prefixItems`, unresolved `$ref`s) are sent without strict mode with a
warning naming the tool and path, instead of being narrowed.
`@composio/core` exports the new `toStrictJsonSchema()` and
`omitNullToolArguments()` utilities; `removeNonRequiredProperties` is
unchanged for other callers. The Python `OpenAIResponsesProvider` gains
a matching opt-in `strict=True` constructor flag that also emits
`strict: true` on the wrapped tool.
## @composio/slim@0.18.0

### Patch Changes

- db7b576: Declare Node.js 22.22.3 as the minimum supported runtime for
every published TypeScript package so package managers surface
incompatible runtimes before users encounter ESM loading failures.
- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/cf-workers-basic@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/cf-workers-files@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/cf-workers-tool-router-ai@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## @e2e-tests/node-claude-agent-sdk@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/claude-agent-sdk@0.11.1
## @e2e-tests/node-custom-tools@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/node-json-schema-to-zod-v3@0.0.1

### Patch Changes

- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/node-json-schema-to-zod-v4@0.0.1

### Patch Changes

- Updated dependencies [db7b576]
  - @composio/json-schema-to-zod@0.3.1
## @e2e-tests/node-mastra-tool-router-zod-v3@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## @e2e-tests/node-mastra-tool-router-zod-v4@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## @e2e-tests/node-tool-router-files@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## @e2e-tests/node-tool-router-pagination@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## anthropic-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/anthropic@0.11.1
  - @composio/claude-agent-sdk@0.11.1
## cloudflare-wrangler-example@0.0.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## connected-accounts-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## error-handling-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## file-handling-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## google-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/google@0.10.3
## json-schema-to-zod-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## langchain-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/langchain@0.10.2
## llamaindex-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/llamaindex@0.10.2
## mastra-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [3c3b4da]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/mastra@0.10.4
## mcp-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## modifiers-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## openai-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [9692db5]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/openai-agents@0.10.2
  - @composio/openai@0.12.1
## session-management-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## tool-router-example@1.0.11

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [9692db5]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/claude-agent-sdk@0.11.1
  - @composio/openai-agents@0.10.2
  - @composio/vercel@0.11.2
## toolkits-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## tools-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## triggers-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
## vercel-example@0.1.10

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
  - @composio/vercel@0.11.2
## versioning-example@0.1.1

### Patch Changes

- Updated dependencies [449f4e1]
- Updated dependencies [9545806]
- Updated dependencies [db7b576]
- Updated dependencies [fe66cbe]
- Updated dependencies [c0f1609]
- Updated dependencies [d544006]
- Updated dependencies [04817cb]
  - @composio/core@0.18.0
py@0.21.0 @e2e-tests/node-custom-tools@0.0.1 @e2e-tests/cli-agent-signin@0.0.0 @composio/cloudflare@0.10.2 @composio/core@0.18.0 openai-example@0.1.10 @composio/claude-agent-sdk@0.11.1 @e2e-tests/node-tool-router-files@0.0.1 @composio/anthropic@0.11.1 versioning-example@0.1.1 modifiers-example@0.1.10 @composio/experimental@0.2.3 @e2e-tests/node-tool-router-pagination@0.0.1 @composio/google@0.10.3 @e2e-tests/node-openai-zod4-compat@0.0.0 mcp-example@0.1.1 @composio/json-schema-to-zod@0.3.1 @composio/langchain@0.10.2 @e2e-tests/node-vercel-ai-sdk-v6@0.0.0 @composio/llamaindex@0.10.2 mastra-example@0.1.1 vercel-example@0.1.10 @composio/mastra@0.10.4 @composio/openai-agents@0.10.2 @composio/openai@0.12.1 llamaindex-example@0.1.1 @e2e-tests/node-mastra-tool-router-zod-v4@0.0.1 @composio/slim@0.18.0 @e2e-tests/node-mastra-tool-router-zod-v3@0.0.1 @composio/vercel@0.11.2 langchain-example@0.1.10 triggers-example@0.1.1 @e2e-tests/cf-workers-basic@0.0.1 @e2e-tests/node-json-schema-to-zod-v4@0.0.1 @e2e-tests/cf-workers-files@0.0.1 json-schema-to-zod-example@0.1.1 @e2e-tests/node-typescript-mjs-import-nodenext@0.0.0 @e2e-tests/cf-workers-tool-router-ai@0.0.1 @e2e-tests/utils@0.0.0 tool-router-example@1.0.11 google-example@0.1.1 @e2e-tests/cli-install@0.0.0 @e2e-tests/cli-run@0.0.0 @e2e-tests/cli-setup-plugins@0.0.0 @e2e-tests/cli-toolkits-info@0.0.0 file-handling-example@0.1.1 @e2e-tests/cli-toolkits-list@0.0.0 @e2e-tests/cli-toolkits-search@0.0.0 @e2e-tests/cli-upgrade@0.0.0 @e2e-tests/cli-version@0.0.0 error-handling-example@0.1.10 @e2e-tests/cli-whoami@0.0.0 @e2e-tests/deno-esm-basic@0.0.0 @e2e-tests/node-cjs-basic@0.0.0 session-management-example@0.1.1 connected-accounts-example@0.1.10 @e2e-tests/node-claude-agent-sdk@0.0.1 tools-example@0.1.1 cloudflare-wrangler-example@0.0.1 @e2e-tests/node-vercel-ai-sdk-v7@0.0.0 @e2e-tests/node-esm-basic@0.0.0 @e2e-tests/node-file-roundtrip@0.0.0 toolkits-example@0.1.10 anthropic-example@0.1.1 @e2e-tests/node-json-schema-to-zod-v3@0.0.1
2026-08-27 20:19:15 +02:00
sdkrelease[bot] dbe5a63965 Release: update version 2026-08-27 18:07:50 +00:00
Alberto Schiabel e2270d12d0 chore(sdk): prepare Python 0.21.0 and TypeScript 0.18.0 (#4272)
This PR:

- unblocks https://github.com/ComposioHQ/composio/pull/4177 by
documenting TypeScript `@composio/core` `0.18.0`
- bumps Python `composio` and all 12 provider distributions from
`0.20.0` to `0.21.0`
- keeps `python/composio/__version__.py` and the pinned `uv.lock`
aligned with package metadata
- adds the combined customer-facing changelog for strict tool schemas,
safer file transfers, and runtime reliability updates
- records the Node.js 22.22.3 minimum for the TypeScript release

## Release sequence

1. Merge this PR into `next`.
2. Merge #4177 after its release-workflow check turns green; Changesets
publishes the TypeScript packages to npm.
3. Tag the resulting `next` commit as `py@0.21.0` to publish the Python
core and provider packages to PyPI.

## Verification

- `pnpm test:release-workflow`
- `mise exec -- uv lock --check`
- `make chk`
- `make build`
- `uv tool run twine check dist/*` (26 artifacts)
- `bun run test` in `docs/` (527 tests)
2026-08-27 20:05:43 +02:00
jkomyno 3cbc7556f5 chore(sdk): prepare Python 0.21.0 and TypeScript 0.18.0 2026-08-27 19:27:19 +02:00
Alberto Schiabel 82ca7384d5 fix(errors): set this.name on three ComposioError subclasses (#4128)
## What

`ComposioError` (`errors/ComposioError.ts`) assigns `name` as a class
field (`public name = 'ComposioError'`). Under the package tsconfig
(es2022 -> `useDefineForClassFields`), each subclass must reassign
`this.name` in its constructor or it inherits the base value. ~30
sibling subclasses do this; three omitted it:

- `ComposioToolVersionRequiredError` (`errors/ToolErrors.ts`)
- `JsonSchemaToZodError` (`errors/ValidationErrors.ts`)
- `JsonSchemaRefResolutionError` (`errors/ValidationErrors.ts`)

So `new JsonSchemaToZodError().name === 'ComposioError'`, and the same
for the other two. All three are thrown on real paths (`Tools.ts`,
`jsonSchema.ts`), and `error.name` is forwarded to error telemetry
(`telemetry/Telemetry.ts`), so these distinct error types silently
mis-group under the base name; any consumer branching on `err.name ===
'<ClassName>'` never matches.

## Fix

Add the missing `this.name = '<ClassName>'` at the end of each of the
three constructors, matching the established sibling pattern.
Runtime-only; no type or public-API change. (The two `PusherErrors`
subclasses set `name` via a class field, which already resolves
correctly, so they are intentionally left untouched.)

## Tests

Adds `test/errors/errorNames.test.ts` asserting each of the three
reports its own class name and is `instanceof ComposioError`. Verified
fails-before / passes-after; full `@composio/core` suite green (1095
tests), plus `tsc`, oxlint, and prettier clean.
2026-08-27 19:17:18 +02:00
Alberto Schiabel 08306f8bc1 Merge branch 'next' into fix/error-subclass-names 2026-08-27 18:51:36 +02:00
Alberto Schiabel b71471c6ef fix(telemetry): bound telemetry requests with an AbortSignal timeout (#4127)
## What

`TelemetryService.sendMetric` and `sendErrorLog` issue `await
fetch(...)` with no timeout. If the telemetry endpoint stalls, the await
never settles. Both are awaited on the SDK's telemetry path
(`Telemetry.ts` batch-processor callback, `sendMetric`, and
`sendErrorTelemetry`), so a stalled telemetry endpoint can leave an SDK
call pending indefinitely — which the existing `catch` comment says must
never happen ("telemetry failures should never affect SDK calls").

## Fix

Wrap both requests in a private `postWithTimeout` helper that bounds
each best-effort request with an `AbortController` + `setTimeout` (3s)
and clears the timer in `.finally()`. This mirrors the already-merged
bound on the background npm version check in `utils/version.ts` (#4027),
including the hand-rolled-timer-over-`AbortSignal.timeout` rationale: an
uncleared timer pins the workerd request context open for the full
timeout on every successful send. On timeout the abort rejects `fetch`,
which the existing `catch` swallows exactly as it already swallowed
network errors, so the best-effort / never-throws contract is unchanged.

## Tests

Adds a `TelemetryService network bounding` suite (mirrors
`version.test.ts`): asserts each method passes an `AbortSignal` and
clears its timer on success, and that a never-responding endpoint
resolves to `undefined` without throwing. Verified fails-before /
passes-after; full `@composio/core` suite green (1092 tests), plus
`tsc`, oxlint, and prettier all clean.
2026-08-27 18:29:23 +02:00
Alberto Schiabel 3c7b938bd1 Merge branch 'next' into fix/telemetry-request-timeout 2026-08-27 18:27:32 +02:00
jkomyno cf42328040 fix(telemetry): clear timeout on serialization errors 2026-08-27 18:23:38 +02:00
Alberto Schiabel b20ca59d91 fix(openai): keep optional parameters under strict mode instead of dropping them (#4257)
This PR:

- builds on top of https://github.com/ComposioHQ/composio/pull/4209 by
@AseemPrasad, keeping its recursive `toStrictJsonSchema()` and Python
parity while changing the mechanism so strict mode stops deleting
parameters
- keeps every optional parameter under `strict: true`: properties become
required and optional ones accept `null` (the emulation OpenAI
documents), instead of dropping 42% of parameters across the 930-tool
corpus; `type` arrays stay as they are, so nullable objects stay
nullable
- sends tools whose schema strict mode cannot express (objects with
arbitrary keys, `allOf`, `prefixItems`, dangling `$ref`s, non-object
roots) with `strict: false` and a warning naming the tool and path,
instead of narrowing them to empty closed objects
- adds `omitNullToolArguments()`: the strict providers drop a `null`
argument only where the tool's own schema rejects it, so nullable fields
keep an explicit `null`
- keeps local `$ref`/`$defs` (recursion included) under strict mode
instead of inlining them
- brings the Python `OpenAIResponsesProvider(strict=True)` to parity:
emits `strict`, calls the base initializer, mirrors the rewrite and null
omission
- makes Mastra and openai-agents use the same strict semantics
(`OpenAIAgentsProvider({ strict: true })` previously had no effect)
- pins the behavior with a shared `strict-cases.json` corpus
(byte-identical TypeScript/Python copies) plus edge-case regression
tests enumerated independently with a second model

## Context

OpenAI's structured-outputs contract accepts `"type": ["string",
"null"]` and rejects `type` next to `anyOf`. Validated against OpenAI's
own `toStrictJsonSchema` converter over the 930 real tool schemas in
`ts/packages/cli/test/__mocks__/tools.json`: the previous approach was
accepted for 930/930 tools but only after removing 1,682 properties;
this one emits strict schemas for 816 tools (all accepted, no property
lost, idempotent) and downgrades the 114 tools that use free-form or
map-style parameters.

https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-27 16:05:56 +02:00
jkomyno 013f753195 chore(docs): rebuild KB semantic artifact 2026-08-27 15:53:22 +02:00
jkomyno f37c6fbec3 docs(strict-mode): correct provider support details 2026-08-27 15:51:18 +02:00
jkomyno 92b0e423e8 chore(docs): rebuild KB semantic artifact 2026-08-27 15:44:29 +02:00
jkomyno a93e8df547 docs(providers): clarify strict schema behavior 2026-08-27 15:41:46 +02:00
jkomyno 9feca8f95d fix(json-schema): accept document-root references in strict mode 2026-08-27 15:39:38 +02:00
jkomyno 507c4fe3a8 fix(python): preserve explicit empty tool schemas 2026-08-27 15:38:27 +02:00
jkomyno d9ea7bbb90 chore(docs): rebuild KB semantic artifact 2026-08-27 15:29:29 +02:00
Alberto Schiabel 81631f83f4 Merge branch 'next' into fix/strict-mode-keep-optional-parameters 2026-08-27 15:14:24 +02:00
Alberto Schiabel 64db269a33 fix(deps-dev): bump langchain-openai from 1.4.3 to 1.6.0 in /python in the pip-version group across 1 directory (#4196)
Bumps the pip-version group with 1 update in the /python directory:
[langchain-openai](https://github.com/langchain-ai/langchain).

Updates `langchain-openai` from 1.4.3 to 1.6.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchain/releases">langchain-openai's
releases</a>.</em></p>
<blockquote>
<h2>langchain-openai==1.6.0</h2>
<p>Changes since langchain-openai==1.5.2</p>
<p>release(openai): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39762">#39762</a>)
feat(core): add standard model exception types (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39538">#39538</a>)
fix(openai): raise clear error on unexpected response type in
<code>_create_chat_result</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39731">#39731</a>)</p>
<h2>langchain-openai==1.5.2</h2>
<p>Changes since langchain-openai==1.5.1</p>
<p>release(openai): 1.5.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39719">#39719</a>)
fix(openai): preserve reasoning item boundaries (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39278">#39278</a>)
release(openai): 1.5.2a1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39709">#39709</a>)
feat(openai): extract gateway metadata from response headers when
available (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39706">#39706</a>)
chore(openai): update snapshots (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39657">#39657</a>)
fix(openai): support o-series models in
<code>get_num_tokens_from_messages</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38710">#38710</a>)</p>
<h2>langchain-openai==1.5.2a1</h2>
<p>Initial release</p>
<p>release(openai): 1.5.2a1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39709">#39709</a>)
feat(openai): extract gateway metadata from response headers when
available (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39706">#39706</a>)
chore(openai): update snapshots (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39657">#39657</a>)
fix(openai): support o-series models in
<code>get_num_tokens_from_messages</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38710">#38710</a>)
release(openai): 1.5.1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39653">#39653</a>)
fix(openai): preserve streamed encrypted reasoning (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39635">#39635</a>)
chore(infra): support langsmith gateway in CI (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39651">#39651</a>)
release(openai): 1.5.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39629">#39629</a>)
feat(openai): support openai 3.0 SDK (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39613">#39613</a>)
chore(partners): bump langgraph floor in openai and huggingface
lockfiles (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39617">#39617</a>)
release(openai): 1.4.3 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39485">#39485</a>)
fix(openai): filter invalid tool calls from content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39366">#39366</a>)
chore(openai): update guidance for responses API for OpenAI-compatible
providers (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39327">#39327</a>)
chore(openai): update docstring for
<code>include_response_headers</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39326">#39326</a>)
release(openai): 1.4.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39322">#39322</a>)
fix(openai): handle <code>ContextWindowExceededError</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39300">#39300</a>)
chore: bump the minor-and-patch group across 3 directories with 7
updates (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39187">#39187</a>)
fix(openai): filter langchain-generated content block IDs (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39209">#39209</a>)
fix(openai): preserve Responses <code>text</code> options (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39204">#39204</a>)
fix(openai): redact MCP <code>authorization</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39155">#39155</a>)
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39050">#39050</a>)
release(openai): 1.4.1 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39045">#39045</a>)
feat(anthropic,fireworks,openai): support langsmith gateway through env
var (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38742">#38742</a>)
fix(openai): correct <code>gpt-5.3-chat-latest</code> profile (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39009">#39009</a>)
release(openai): 1.4.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38983">#38983</a>)
chore: bump pillow from 12.2.0 to 12.3.0 in /libs/partners/openai (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38999">#38999</a>)
feat(core): add <code>reasoning_effort</code> as a standard chat model
parameter (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38887">#38887</a>)
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38797">#38797</a>)
release(openai): 1.3.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38785">#38785</a>)
feat(openai): support explicit prompt caching (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/38762">#38762</a>)</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchain/commit/3478c28ef21435162cb67abbd2aaef67c7cd8981"><code>3478c28</code></a>
release(anthropic): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39763">#39763</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/420dfc94516f57a4d8662132a55bc532afbc6045"><code>420dfc9</code></a>
release(openai): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39762">#39762</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/85602c3676fbd51e098a01d7c66638719f529f84"><code>85602c3</code></a>
release(core): 1.6.0 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39760">#39760</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/5c3538e83a24eaf819ecec066773a232dcd4a8e6"><code>5c3538e</code></a>
fix(core): resolve postponed annotations in
`StructuredTool._injected_args_ke...</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/9984a87fa5a6971c76cb12fc75b37ed74286b740"><code>9984a87</code></a>
feat(core): add standard model exception types (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39538">#39538</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/b3e9eef13c23c3a048f9846e1592b658f85f5f94"><code>b3e9eef</code></a>
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39751">#39751</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/ded2a1fb3c06a9562d9079e42099020ecaca4060"><code>ded2a1f</code></a>
fix(core): allow deserializing <code>RunnablePick</code> (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/39753">#39753</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/04ae7447d72e61841905a41b309856c5191452fb"><code>04ae744</code></a>
fix(core): make <code>convert_to_openai_function</code> handle callables
and non-dict ma...</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/37f266278d780cd7ebdfbf1891ba92066192d687"><code>37f2662</code></a>
feat(langchain): support custom token_counter in
ContextEditingMiddleware (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/3">#3</a>...</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/2019bf5ebe50324c548f67c2666a804343f9b772"><code>2019bf5</code></a>
fix(openai): raise clear error on unexpected response type in
`_create_chat_r...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchain/compare/langchain-openai==1.4.3...langchain-openai==1.6.0">compare
view</a></li>
</ul>
</details>
<br />
2026-08-27 15:13:51 +02:00
Alberto Schiabel 5de192a5b8 docs: update TypeScript SDK reference from source (#4260)
## Summary
Auto-generated TypeScript SDK reference docs from
`ts/packages/core/src/`.

Regenerates pages at `docs/content/reference/sdk-reference/typescript/`
to reflect changes in the core package's public API (new methods,
updated signatures, changed types).
2026-08-27 15:09:03 +02:00
Alberto Schiabel e02bb58aa0 docs: update toolkits, API spec, and meta tools data (#4189)
## Summary
Automated sync of backend data into the docs site. Triggered by:
`schedule`.

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs
2026-08-27 14:10:39 +02:00
Sushmithamallesh ca8661e961 docs: update toolkits and API data 2026-08-26 20:46:13 +00:00
jkomyno 0a0095ea82 docs: auto-generate TypeScript SDK reference 2026-08-26 18:10:48 +00:00
Alberto Schiabel 14797bbee6 fix(docs): complete generated string escaping (#4256)
This PR:

- fixes CodeQL alerts
[#48](https://github.com/ComposioHQ/composio/security/code-scanning/48),
[#49](https://github.com/ComposioHQ/composio/security/code-scanning/49),
[#50](https://github.com/ComposioHQ/composio/security/code-scanning/50),
[#51](https://github.com/ComposioHQ/composio/security/code-scanning/51),
[#88](https://github.com/ComposioHQ/composio/security/code-scanning/88),
and
[#89](https://github.com/ComposioHQ/composio/security/code-scanning/89)
- encodes Markdown table delimiters as HTML entities without consuming
existing backslashes
- serializes generated YAML frontmatter strings with `JSON.stringify()`
- escapes existing backslashes before adding MDX metacharacter escapes
in the core docs generator
- adds regression coverage for Markdown tables, YAML frontmatter, and
MDX text
- verifies 38 focused docs tests, docs type-checking and lint, core
type-checking, all 1,123 core tests, and changeset validation
2026-08-26 20:09:14 +02:00
jkomyno c0880764cf fix(docs): escape pipes in generated text 2026-08-26 19:55:59 +02:00
Alberto Schiabel 1862d91faf fix(py): isolate incompatible provider dependencies (#4254)
## Summary

- stop installing the independently distributed Autogen adapter into the
shared CrewAI/LangChain/LangGraph unit-test environment
- run the Autogen import guard and signature regressions in their own
matrix environment
- align the local `tst` nox session with the compatible shared provider
set and add `tst_autogen` for isolated Autogen coverage

## Root cause

`autogen-core==0.7.5` requires `protobuf~=5.29.3`, while CrewAI's
current telemetry dependency chain requires
`googleapis-common-protos>=1.75.1`, whose generated modules require
`protobuf>=6.33.5`.

The packages are independently distributed adapters and are not tested
together, but the workflow installed both into one virtual environment.
Because the installs were sequential, installing Autogen last downgraded
`protobuf` to `5.29.6` and left the already-installed Google modules
unusable:

```text
google.protobuf.runtime_version.VersionError: Detected incompatible Protobuf Gencode/Runtime versions when loading google/rpc/error_details.proto: gencode 6.33.5 runtime 5.29.6.
```

## Regression coverage

The shared suite intentionally skips Autogen because loading it
alongside CrewAI creates the incompatible protobuf environment. CI now
runs these existing regressions in the isolated Autogen environment
instead:

- `test_autogen_signature_honors_skip_defaults`
- `test_autogen_signature_preserves_default`

Developers can reproduce that boundary with `nox -s tst_autogen`.

## Verification

- reproduced the downgrade after the Autogen provider installation
- shared provider environment imports `google.rpc.error_details_pb2`
with `protobuf==6.33.6`
- isolated Autogen environment imports `composio_autogen` with
`protobuf==5.29.6`
- isolated Autogen regressions: 2 passed
- Python unit suite: 1,355 passed, 35 skipped
- Ruff and mypy: passed
- agent-skill and skill-routing validators: passed
- Prettier and `git diff --check`: passed

No Changeset is required: this only changes CI and test-environment
setup.
2026-08-26 19:48:32 +02:00
jkomyno 78fb09efdf test(py): preserve isolated Autogen regression coverage 2026-08-26 19:40:26 +02:00
jkomyno c5690031d3 fix(py): isolate incompatible provider dependencies 2026-08-26 19:40:26 +02:00
Alberto Schiabel fa775cc38d docs: update Python SDK reference from source (#4179)
## Summary
Auto-generated Python SDK reference docs from `python/composio/`.

Regenerates pages at `docs/content/reference/sdk-reference/python/` to
reflect changes in the Python package's public API (new methods, updated
signatures, changed types).
2026-08-26 19:21:20 +02:00
jkomyno 8fe03eff47 test(json-schema): add strict-mode edge cases enumerated with a second model
Extends strict-cases.json to 68 cases with shapes enumerated independently
(single-element and three-member type arrays, null-only and null-carrying
enum/const properties, nested compositions, nullable objects in arrays,
tuple and boolean items, conditional and dependency keywords, oneOf beside
anyOf, boolean and malformed properties, $ref siblings and chains, legacy
definitions next to $defs, non-string required entries, ten-level
nesting) plus null-omission pairs for nullable, composed and $ref-typed
arguments. Checks in the generator that derives the pinned JSON.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:59:21 +02:00
jkomyno 84684c6c8d fix(python): mirror the strict-mode incompatibility and branch rules
to_strict_json_schema reports the same constructs as the TypeScript
implementation (tuple items, boolean subschemas, malformed properties,
oneOf beside anyOf, conditional and dependency keywords), accepts a root
typed ["object"], leaves enum/const that already include null alone, and
omit_null_tool_arguments follows the composition branch matching the
argument's shape.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:59:20 +02:00
jkomyno b47d5137c2 fix(core): report every construct strict mode cannot rewrite
Tuple-form items, boolean subschemas, malformed properties, oneOf left
beside anyOf, and the conditional and dependency keywords (not, if, then,
else, dependencies, dependentSchemas, propertyNames, contains,
additionalItems, unevaluatedItems, unevaluatedProperties) are now reported
as unsupported so the tool is sent without strict mode instead of with a
schema the API rejects. A root typed ["object"] is accepted, and an enum
or const that already includes null is not wrapped again.

omitNullToolArguments now follows the anyOf/oneOf branch that matches an
argument's shape, so nulls inside an object sent for a composed property
are reconciled against that branch.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:59:18 +02:00
jkomyno 678ac7260a fix(docs): complete generated string escaping 2026-08-26 17:41:41 +02:00
jkomyno 3ca07210d3 test(json-schema): drive strict-mode cases from a shared corpus
strict-cases.json (one byte-identical copy per language, next to
object-cases.json) pins the exact strict schema or the reported
incompatibilities for 44 shapes: optional widening at every depth,
nullable type arrays, compositions, enum/const wrapping, annotation
stripping, keyword-named and prototype-named properties, dynamic-key and
free-form objects, allOf/prefixItems, $defs recursion, dangling and
external refs, malformed required, non-object roots, plus null-omission
argument pairs. The TypeScript suite pins the implementation and the
Python suite checks parity against the same file.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:37:53 +02:00
jkomyno e4d24bc04b fix(python): treat a non-array required as absent under strict mode
to_strict_json_schema iterated a string-valued required character by
character, so a malformed required kept same-named properties non-nullable
while the TypeScript implementation treats it as absent and widens every
property. Both SDKs now agree.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:37:27 +02:00
jkomyno 991c57af80 fix(core): keep properties named like prototype keys under strict mode
toStrictJsonSchema assigned rewritten property schemas by name, so a
property called __proto__ set the prototype of the properties map instead
of being stored and disappeared from the strict schema. Own properties are
now defined explicitly, matching the other schema walkers in this module.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:37:25 +02:00
jkomyno 9692db5c0a fix(openai-agents): honor the strict option
OpenAIAgentsProvider accepted { strict } but always registered tools with
strict: false and additionalProperties: true. Strict mode now registers
tools with strict: true and a schema normalized by toStrictJsonSchema
(optional parameters required-nullable), drops null arguments the tool
schema rejects before execution, and registers tools strict mode cannot
express without strict mode with a warning.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:34:08 +02:00
jkomyno 3c3b4dae94 fix(mastra): keep optional parameters under strict mode
MastraProvider strict mode used the root-only, input-mutating
removeNonRequiredProperties, so "strict" meant something different from
the OpenAI providers. It now runs the same toStrictJsonSchema rewrite:
optional parameters become required-nullable, tools strict mode cannot
express keep their original schema with a warning, and null arguments the
tool schema rejects are dropped before execution.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:34:08 +02:00
Alberto Schiabel b6e079ba3d fix(ci): prevent cache poisoning in CLI releases (#4255)
This PR:

- fixes all 11 open CodeQL alerts
([#118](https://github.com/ComposioHQ/composio/security/code-scanning/118)
through
[#128](https://github.com/ComposioHQ/composio/security/code-scanning/128))
for cache poisoning through untrusted code execution
- makes the workflow-selected `github.sha` authoritative for CLI build
and release checkouts
- requires stable promotion to run at the immutable beta tag and rejects
tag/release commit mismatches
- removes the manually supplied `beta_tag` data path into executable
jobs
- updates the CLI release playbook for tag-scoped promotion
- verifies the release contract with `pnpm test:release-workflow`,
agent-skill validators, shell syntax, formatting, and changeset
validation
2026-08-26 17:30:59 +02:00
jkomyno e6fb9f9d32 feat(core): keep $defs recursion under strict mode
OpenAI structured outputs support local $ref pointers, including recursive
definitions, so toStrictJsonSchema no longer inlines them: $defs and
definitions are normalized where they are declared, an optional $ref
property is widened with an anyOf null branch, and external or dangling
$refs are reported as unsupported. omitNullToolArguments follows local
$refs when deciding whether a null is accepted. The Vercel provider still
inlines definitions before converting to Zod, which does not follow $ref.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:28:48 +02:00
jkomyno b015075910 fix(ci): prevent cache poisoning in CLI releases 2026-08-26 17:21:57 +02:00
jkomyno 15e2b72f3d fix(python): emit strict and keep base provider config in OpenAIResponsesProvider
The strict flag now calls the base initializer (schema_config kwargs keep
working), emits strict on the wrapped tool, and mirrors the TypeScript
pipeline: optional parameters become required-nullable, unsupported
schemas downgrade the tool to non-strict, and null arguments the tool
schema rejects are dropped before execution.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:33 +02:00
jkomyno fb30e8f299 fix(vercel): keep optional parameters available under strict mode
VercelProvider strict mode now widens optional parameters to nullable
instead of dropping them, keeps the original schema for tools strict mode
cannot express, and drops null arguments the tool schema rejects before
execution. The README and docs page described the old dropping behavior.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:32 +02:00
jkomyno 6a7ddbad06 fix(openai): send tools strict mode cannot express without strict
OpenAIResponsesProvider emits the strict schema and strict: true only when
the rewrite is lossless; otherwise the tool keeps its original schema with
strict: false and a warning names the tool and path. Tools without
parameters get a canonical empty closed object. Null arguments the tool
schema rejects are dropped before execution.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:31 +02:00
jkomyno 4f69975475 fix(core): keep optional parameters under strict mode instead of dropping them
toStrictJsonSchema now follows the contract OpenAI documents for structured
outputs: every property becomes required and optional ones are widened to
accept null, so the model keeps every parameter it could pass before. Type
arrays stay as they are (the API accepts them and rejects type next to
anyOf), so nullable objects stay nullable. Constructs strict mode cannot
express (objects with arbitrary keys, allOf, prefixItems, unresolved $refs,
non-object roots) are reported in `unsupported` instead of being narrowed.

omitNullToolArguments drops a null argument only where the tool's own
schema rejects it, so nullable fields keep an explicit null. The keyword
taxonomy shared by the three schema walkers now lives in one place.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:30 +02:00
Alberto Schiabel c6c4b76810 docs(kb): refresh public support knowledge (#4252)
Automated knowledge-base refresh for `ComposioHQ/support-knowledge`.

- Source commit: `5eac683455ff252a7a3b62f33ab6566445009b52` (unchanged;
rebuilt a stale semantic artifact)
- Regenerated public KB pages and search records
- Reused unchanged vectors and rebuilt the checked semantic artifact
- Ran KB freshness and semantic-artifact verification
2026-08-26 14:41:34 +02:00
jkomyno 94f3d93ccc docs(kb): refresh public support knowledge 2026-08-26 12:37:46 +00:00
Alberto Schiabel d567b07321 fix(docs): stabilize toolkit knowledge and refresh KB (#4234)
## What changed

- refresh the public KB from merged [support-knowledge
#11](https://github.com/ComposioHQ/support-knowledge/pull/11), pinned to
`5eac683`
- add production-readiness and session-policy guides plus current
toolkit/OAuth corrections
- route single-resource KB toolkit pages directly to canonical toolkit
docs across HTML, `.md`, sitemap, and agent discovery
- preserve reviewed curation during refreshes, validate sources/links,
and report automation failures
- automatically rebuild stale semantic artifacts on current same-repo
MEMBER/OWNER docs PRs; public and fork PRs remain read-only
- rebuild semantic search with 888 public Docs/KB records

Most changed files are generated KB pages updating the source pin.

## Verification

- 521 static tests + 88 production-build integration tests
- typecheck, lint, Actions lint, link validation, production build, and
semantic freshness pass
- [Vercel
preview](https://docs-git-codex-docs-toolkit-kb-routing.preview.composio.dev)

## Follow-up

Release Bot still needs `support-knowledge` read access before automatic
upstream refresh can run. Failures are tracked in
[#4241](https://github.com/ComposioHQ/composio/issues/4241).

Context: [Sarah’s Slack
thread](https://composioworkspace.slack.com/archives/C0AK054L1T6/p1787367361647249?thread_ts=1787365155.082829)
·
[PRD](https://app.notion.com/p/composio/Support-Knowledge-Platform-PRD-3bcf261a6dfe816297f9feeb5398a9af)
2026-08-26 14:36:12 +02:00
jkomyno 3ce6196d2d merge: integrate next (KB identifier-URL fix + self-healing CI) into #4234 2026-08-26 14:19:15 +02:00
Alberto Schiabel 56b7b19e45 docs(kb): refresh public support knowledge (#4251)
Automated knowledge-base refresh for `ComposioHQ/support-knowledge`.

- Source commit: `d57f3d69079ee3819f4136df54512cdf0416cec0` (unchanged;
rebuilt a stale semantic artifact)
- Regenerated public KB pages and search records
- Reused unchanged vectors and rebuilt the checked semantic artifact
- Ran KB freshness and semantic-artifact verification
2026-08-26 13:24:22 +02:00