Commit Graph

1261 Commits

Author SHA1 Message Date
sdkrelease[bot] dbe5a63965 Release: update version 2026-08-27 18:07:50 +00:00
Alberto Schiabel 08306f8bc1 Merge branch 'next' into fix/error-subclass-names 2026-08-27 18:51:36 +02:00
Alberto Schiabel 3c7b938bd1 Merge branch 'next' into fix/telemetry-request-timeout 2026-08-27 18:27:32 +02:00
jkomyno cf42328040 fix(telemetry): clear timeout on serialization errors 2026-08-27 18:23:38 +02:00
jkomyno f37c6fbec3 docs(strict-mode): correct provider support details 2026-08-27 15:51:18 +02:00
jkomyno a93e8df547 docs(providers): clarify strict schema behavior 2026-08-27 15:41:46 +02:00
jkomyno 9feca8f95d fix(json-schema): accept document-root references in strict mode 2026-08-27 15:39:38 +02:00
Alberto Schiabel 81631f83f4 Merge branch 'next' into fix/strict-mode-keep-optional-parameters 2026-08-27 15:14:24 +02:00
jkomyno c0880764cf fix(docs): escape pipes in generated text 2026-08-26 19:55:59 +02:00
jkomyno 8fe03eff47 test(json-schema): add strict-mode edge cases enumerated with a second model
Extends strict-cases.json to 68 cases with shapes enumerated independently
(single-element and three-member type arrays, null-only and null-carrying
enum/const properties, nested compositions, nullable objects in arrays,
tuple and boolean items, conditional and dependency keywords, oneOf beside
anyOf, boolean and malformed properties, $ref siblings and chains, legacy
definitions next to $defs, non-string required entries, ten-level
nesting) plus null-omission pairs for nullable, composed and $ref-typed
arguments. Checks in the generator that derives the pinned JSON.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:59:21 +02:00
jkomyno b47d5137c2 fix(core): report every construct strict mode cannot rewrite
Tuple-form items, boolean subschemas, malformed properties, oneOf left
beside anyOf, and the conditional and dependency keywords (not, if, then,
else, dependencies, dependentSchemas, propertyNames, contains,
additionalItems, unevaluatedItems, unevaluatedProperties) are now reported
as unsupported so the tool is sent without strict mode instead of with a
schema the API rejects. A root typed ["object"] is accepted, and an enum
or const that already includes null is not wrapped again.

omitNullToolArguments now follows the anyOf/oneOf branch that matches an
argument's shape, so nulls inside an object sent for a composed property
are reconciled against that branch.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:59:18 +02:00
jkomyno 678ac7260a fix(docs): complete generated string escaping 2026-08-26 17:41:41 +02:00
jkomyno 3ca07210d3 test(json-schema): drive strict-mode cases from a shared corpus
strict-cases.json (one byte-identical copy per language, next to
object-cases.json) pins the exact strict schema or the reported
incompatibilities for 44 shapes: optional widening at every depth,
nullable type arrays, compositions, enum/const wrapping, annotation
stripping, keyword-named and prototype-named properties, dynamic-key and
free-form objects, allOf/prefixItems, $defs recursion, dangling and
external refs, malformed required, non-object roots, plus null-omission
argument pairs. The TypeScript suite pins the implementation and the
Python suite checks parity against the same file.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:37:53 +02:00
jkomyno 991c57af80 fix(core): keep properties named like prototype keys under strict mode
toStrictJsonSchema assigned rewritten property schemas by name, so a
property called __proto__ set the prototype of the properties map instead
of being stored and disappeared from the strict schema. Own properties are
now defined explicitly, matching the other schema walkers in this module.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:37:25 +02:00
jkomyno 9692db5c0a fix(openai-agents): honor the strict option
OpenAIAgentsProvider accepted { strict } but always registered tools with
strict: false and additionalProperties: true. Strict mode now registers
tools with strict: true and a schema normalized by toStrictJsonSchema
(optional parameters required-nullable), drops null arguments the tool
schema rejects before execution, and registers tools strict mode cannot
express without strict mode with a warning.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:34:08 +02:00
jkomyno 3c3b4dae94 fix(mastra): keep optional parameters under strict mode
MastraProvider strict mode used the root-only, input-mutating
removeNonRequiredProperties, so "strict" meant something different from
the OpenAI providers. It now runs the same toStrictJsonSchema rewrite:
optional parameters become required-nullable, tools strict mode cannot
express keep their original schema with a warning, and null arguments the
tool schema rejects are dropped before execution.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:34:08 +02:00
jkomyno e6fb9f9d32 feat(core): keep $defs recursion under strict mode
OpenAI structured outputs support local $ref pointers, including recursive
definitions, so toStrictJsonSchema no longer inlines them: $defs and
definitions are normalized where they are declared, an optional $ref
property is widened with an anyOf null branch, and external or dangling
$refs are reported as unsupported. omitNullToolArguments follows local
$refs when deciding whether a null is accepted. The Vercel provider still
inlines definitions before converting to Zod, which does not follow $ref.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:28:48 +02:00
jkomyno fb30e8f299 fix(vercel): keep optional parameters available under strict mode
VercelProvider strict mode now widens optional parameters to nullable
instead of dropping them, keeps the original schema for tools strict mode
cannot express, and drops null arguments the tool schema rejects before
execution. The README and docs page described the old dropping behavior.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:32 +02:00
jkomyno 6a7ddbad06 fix(openai): send tools strict mode cannot express without strict
OpenAIResponsesProvider emits the strict schema and strict: true only when
the rewrite is lossless; otherwise the tool keeps its original schema with
strict: false and a warning names the tool and path. Tools without
parameters get a canonical empty closed object. Null arguments the tool
schema rejects are dropped before execution.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:31 +02:00
jkomyno 4f69975475 fix(core): keep optional parameters under strict mode instead of dropping them
toStrictJsonSchema now follows the contract OpenAI documents for structured
outputs: every property becomes required and optional ones are widened to
accept null, so the model keeps every parameter it could pass before. Type
arrays stay as they are (the API accepts them and rejects type next to
anyOf), so nullable objects stay nullable. Constructs strict mode cannot
express (objects with arbitrary keys, allOf, prefixItems, unresolved $refs,
non-object roots) are reported in `unsupported` instead of being narrowed.

omitNullToolArguments drops a null argument only where the tool's own
schema rejects it, so nullable fields keep an explicit null. The keyword
taxonomy shared by the three schema walkers now lives in one place.

Co-authored-by: AseemPrasad <aseemprasad0520@gmail.com>

Claude-Session: https://claude.ai/code/session_01TDrxCHn2hg51HmxVstSUgs
2026-08-26 17:19:30 +02:00
Alberto Schiabel 18944df9eb fix(cli): verify codex-acp tarballs against the lockfile before packaging them (#4217)
# Description

Found by the scheduled security audit while reviewing the CLI release
pipeline.

`ts/packages/cli/scripts/_acp-adapters.ts` downloads four
`@zed-industries/codex-acp-<platform>` tarballs directly from the
registry at release-build time — it has to, because `pnpm` only installs
the optional dependency matching the runner's own platform while the
archive must name all four. Those bytes were then extracted, `chmod
0755`'d, and packaged inside the published `composio` CLI archive
**without being checked against any known hash**.

That made the codex-acp binaries the one dependency in the release that
received none of the integrity verification `pnpm install
--frozen-lockfile` applies to everything else, despite `pnpm-lock.yaml`
already pinning a `sha512` for each of them:

```
'@zed-industries/codex-acp-linux-x64@0.16.0':
  resolution: {integrity: sha512-xs5zZBLpJuciEbZNx6ZSNL0qCa9h3i/zWpj40sp6QtF+L4Ow/7qzHdBzboGhHdcz1jrLedfZeRFDA2Elj8TLMA==}
```

Distribution is `curl -fsSL https://composio.dev/install | sh`, so
anything that reached those bytes between the registry and the archive
would ship executable to every CLI user inside an otherwise-signed
release.

## What changed

New `scripts/_tarball-integrity.ts`:

- `parseLockfileIntegrity` — maps every `name@version` in
`pnpm-lock.yaml` to its recorded hash. Line-based rather than a YAML
parse: the shape being read is two adjacent lines, and this keeps a
build script free of a YAML dependency.
- `expectedIntegrityFor` — returns the pinned hash, and **throws** for a
package the lockfile never resolved.
- `assertBytesMatchIntegrity` — Web Crypto digest compared against the
pinned value; the algorithm is read from the expected string so a
lockfile that moves off sha512 keeps working.
- `findLockfilePath` / `loadLockfileIntegrity` — walk up from the script
rather than resolving a fixed `../../..`.

`_acp-adapters.ts` now looks the hash up *before* the download and
verifies the archive bytes before extracting them.

Two deliberate choices:

- **Checked against the lockfile, not the registry's `dist.integrity`**
— whoever can serve the tarball can serve the metadata that vouches for
it.
- **Fail-closed throughout** — a missing lockfile, or a package absent
from it, aborts the build rather than packaging unverified bytes.

Scope is limited to the integrity gap. The `@zed-industries/codex-acp*`
family is deprecated upstream ("replaced by
`@agentclientprotocol/codex-acp`") and pinned at `0.16.0`; migrating it
is a separate call for whoever owns the ACP integration.

# How did I test this PR

**Unit — 16 new tests, all passing:**

```
$ vitest run test/src/scripts/tarball-integrity.test.ts
 Test Files  1 passed (1)
      Tests  16 passed (16)
```

Covers quoted scoped keys and unquoted bare keys, resolutions carrying
no integrity, `snapshots:` repeats, a package absent from the lockfile,
a version pinned under a different number, tampered bytes, a single
flipped byte, an uncomputable algorithm, sha256 as well as sha512, and
the upward lockfile walk (including the no-lockfile-anywhere case). One
test asserts this repository actually pins a hash for all four packaged
codex-acp binaries.

**Live end-to-end against the real registry** — the real 74,914,872-byte
`@zed-industries/codex-acp-linux-x64@0.16.0` tarball, downloaded and run
through the same code path the build uses:

```
downloaded 74914872 bytes from https://registry.npmjs.org/@zed-industries/codex-acp-linux-x64/-/codex-acp-linux-x64-0.16.0.tgz
PASS: real tarball matches the lockfile pin
PASS: tampered rejected — TarballIntegrityError: Integrity mismatch for @zed-industries/codex-acp-linux-x64@0.16.0.
PASS: unpinned version refused — TarballIntegrityError: @zed-industries/codex-acp-linux-x64@0.99.0 has no integrity hash in pnpm-lock.yaml; refusing to package unverified bytes.
```

So the check passes on genuine bytes, rejects a single flipped byte in a
75 MB archive, and refuses a version the lockfile does not pin.

**Lint / types / boundaries:**

- `oxlint` on all three files — clean. (First draft used `node:crypto`;
`no-restricted-imports` bans it, so the digest went to Web Crypto.)
- `prettier --check` — clean.
- `tsc --noEmit` — no errors in any of the three changed files. This
sandbox has 820 pre-existing errors from an unbuilt workspace (only 7 of
70 projects installed); `test/src/scripts/release-artifacts.test.ts`
fails to import here for the same reason, on `next` as well as on this
branch.
- `pnpm run validate:boundaries` — `lint boundaries OK: 4 registered
disables across 4 files` (unchanged; `scripts/` and `test/` sit outside
the `src/` Effect boundary policy).

# Security

- **Grype** — `grype dir:ts/packages/cli/scripts --only-fixed --fail-on
medium` → `No vulnerabilities found`.
- **Socket** — could not run. `doppler secrets get SOCKET_API_TOKEN
--plain --project hermes --config dev_zen` returns empty in this cron
sandbox, so `socket ci` exits with `Auth Error`. Reporting rather than
skipping silently; this change adds no dependency, so the
dependency-alert surface is unchanged.
- No new dependencies, no new network destinations. The one behavioural
change is a fail-closed integrity check on bytes that were previously
trusted unverified.

Origin: cron-48e51eab745f /
[zen-cron-44e260352d1a](https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a)

Triggered by: saransh@composio.dev | Source: unknown
Session:
https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a
2026-08-25 23:57:49 +02:00
Alberto Schiabel 9e958948c5 fix(core): block sensitive upload paths hidden behind a symlinked directory (#4218)
# Description

Found by the scheduled security audit, while checking whether a test
failure on my other PR was pre-existing. It was — and the reason it
fails is a real gap in a shipped security control.

`isBlockedSensitiveFileUploadPath` (the GHSA-hp3h-89pf-5q58 denylist)
matched deny segments **only against the symlink-resolved path**. That
catches a benign name pointing at a secret — `~/innocent-name ->
~/nested/.aws/creds`, which the existing test covers — but misses the
inverse:

| Layout | Written path | Resolved path | Blocked before? |
|---|---|---|---|
| `~/innocent -> ~/.aws/creds` | no `.aws` | **`.aws`** | yes |
| `~/.claude -> /state/claude` | **`.claude`** | no `.claude` | **no** |

`~/.claude/settings.json` resolves to `/state/claude/settings.json`,
which has no `.claude` segment, so it sailed through — and `.claude` is
on the denylist precisely because it *"may contain API keys and project
context read by assistants"*.

This layout is not exotic. Dotfile managers (chezmoi, stow, yadm) and
containerised home directories produce it routinely — Composio's own
agent sandbox image has `/home/zen/.claude -> /state/claude`. For every
user in that shape the control was silently inactive, which is the worst
failure mode for a denylist: no error, no warning, upload proceeds.

The same hiding trick applies to the basename check (`~/.env ->
/state/plain-config`), so that path is fixed too.

## Why CI never caught this

`ts/packages/core/test/utils/sensitiveFileUploadPaths.test.ts` **already
asserts** the blocked behaviour:

```ts
expect(isBlockedSensitiveFileUploadPath(path.join(os.homedir(), '.claude', 'settings.json'))).toBe(true);
```

That assertion has been failing on `next` on any machine where
`~/.claude` is a symlink. It passes in CI only because `~/.claude` does
not exist on the runners: `existsSync` is false, no `realpath` runs, and
the written path keeps its `.claude` segment. The test is
environment-dependent, so green CI was never evidence the control
worked.

## The fix

The TypeScript `normalizePath` helper now returns both the written and
resolved segments, and the segment scan and basename check each consider
both. The Python guard now applies the same rule. Either path can carry
the denied name, so both SDKs inspect both forms.

# How did I test this PR

**The TypeScript fix is gated by tests — 3 fail without it, 13/13 pass
with it.**

Without the `src` change (test file only):

```
× blocks common credential directory segments
× blocks a sensitive directory that is itself a symlink to a plain path
× blocks a denied basename whose symlink target is named innocuously
  Tests  3 failed | 10 passed (13)
```

With the fix:

```
  Test Files  1 passed (1)
        Tests  13 passed (13)
```

Note the first of those three is the **pre-existing** assertion quoted
above — this PR turns it green rather than adding it.

Three tests added, each building a real symlink in a temp dir:
- sensitive directory that is itself a symlink to a plain path (the
`~/.claude -> /state/claude` case), asserting both
`isBlockedSensitiveFileUploadPath` and that `assertSafeFileUploadPath`
throws
- denied basename whose symlink target is named innocuously (`.env ->
plain-config`)
- **negative case**: an ordinary file reached through a symlinked
directory (`docs/document.pdf`) is still allowed, so the fix does not
over-block

The Python parity change adds the same three cases. Before the Python
source change, the sensitive written directory and basename both
returned `False`; with the fix, all 11 focused Python tests pass.

**Full verification:**

| Command | Result |
|---|---|
| `vitest run` in `ts/packages/core` | **48 files, 1114 tests passed** |
| `pnpm typecheck` (workspace) | **14/14 tasks successful**, exit 0 |
| `oxlint` on both changed files | exit 0, clean |
| `prettier --check` on both changed files | "All matched files use
Prettier code style!" |
| `nox -s chk` in `python/` | Ruff and mypy passed |
| `nox -s tst` in `python/` | **1339 passed, 33 skipped**, exit 0 |

# Security

- No dependency changes, no new network calls, no new imports. The diff
is limited to the equivalent TypeScript and Python guards, their tests,
and the required `@composio/core` patch changeset.
- This **strengthens** an existing control and cannot weaken it: the
previous match set is a strict subset of the new one, so nothing that
was blocked before is allowed now. The added negative test pins that the
widening does not over-block ordinary files.
- **Grype** — `grype dir:ts/packages/core --only-fixed --fail-on medium`
→ reported below.
- **Socket** — could not run; `doppler secrets get SOCKET_API_TOKEN
--plain --project hermes --config dev_zen` returns empty in this cron
sandbox, so `socket ci` exits `Auth Error`. Reporting rather than
skipping silently.
- Unrelated pre-existing note: the repo's `pnpm audit --prod` comment
flags `extract-zip <=2.0.1` with `Patched versions >=2.0.2`, a version
that does not exist on npm. Details in #4217.

Origin: cron-48e51eab745f /
[zen-cron-44e260352d1a](https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a)

Triggered by: saransh@composio.dev | Source: unknown
Session:
https://zen.corp.composio.io/dashboard/#/chat/zen-cron-44e260352d1a
2026-08-25 21:48:55 +02:00
Alberto Schiabel 52f8861c95 docs(gemini): update to use gemini 3.7 and new models (#4244)
## Summary

Updates docs and sample scripts to use latest Gemini models.

## Changes
- Vertex & Gemini sample scripts updated
- Plus accompanying markdown

## Type of change
- [ ] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [x] Documentation
- [ ] Breaking change

## How Has This Been Tested?

Visual inspection

## Checklist
- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [ ] I added tests or explain why not applicable
- [ ] I added a changeset if this change affects published packages

## Additional context
2026-08-25 16:08:11 +02:00
Alberto Schiabel f174b28c3a fix(sdk): omit empty file-uploadable arguments from tool execution (#4238)
This PR:

- closes https://github.com/ComposioHQ/composio/issues/4233
- stops forwarding `""` for a `file_uploadable` parameter (e.g. Gmail
`attachment`) to the backend, which rejected it with `Input should be a
valid dictionary or instance of FileUploadable`
- Python: parameterizes the upload walker on a `leaf` handler and adds
`FileHelper.drop_empty_file_uploads()`, run on both `Tools.execute`
paths when `dangerously_allow_auto_upload_download_files` is off (the
default)
- TypeScript: moves the walker into the runtime-neutral
`walkFileUploadableLeaves()` with a `DELETE_VALUE` sentinel and
`dropEmptyFileUploads()`, so the flag-off path also works on edge
runtimes; with the flag on, `''` is no longer attempted as an upload
(previously threw `Either path or blob must be provided`)
- TypeScript: `schemaHasFileProperty()` now looks through
`$defs`/`definitions`, so the flag-off pass (and the existing one-shot
warning) fire for `$ref`-based file schemas
- keeps each SDK's existing `null` semantics: Python omits `None` as
before, TypeScript still passes `null` through for schemas with a `null`
variant
- adds regression tests for both SDKs and a `@composio/core` changeset

## Context

Reproduced against staging with `composio==0.16.0` and the current SDK:
the live `GMAIL_CREATE_EMAIL_DRAFT` schema is `anyOf[FileUploadable,
array[FileUploadable]]` with no `null` variant, and `""` yields the
exact error from the issue on `no_auth` file tools
(`TEXT_TO_PDF_UPLOAD_FILE`). With this change the backend sees the
parameter as not provided, matching what the playground UI sends.
2026-08-25 16:01:54 +02:00
Mark McDonald 96c6260b8c Merge branch 'next' into 37f-docs 2026-08-25 15:07:51 +08:00
Mark McDonald e3d2c093e3 docs(gemini): update to use gemini 3.7 and new models 2026-08-25 15:05:11 +08:00
jkomyno 765d67ad65 fix(ts): preserve proxy compatibility suppression 2026-08-25 04:14:40 +02:00
jkomyno a61ad27940 fix(ts): preprocess session file uploads 2026-08-25 04:09:48 +02:00
jkomyno 505d8914ad fix(core): keep @ts-ignore on deprecated proxy param 2026-08-25 02:09:19 +02:00
jkomyno fe66cbeb77 fix(sdk): omit empty file-uploadable arguments from tool execution
Both SDKs forwarded "" for a file_uploadable parameter (e.g. Gmail
attachment) verbatim to the backend, which rejected it with a Pydantic
validation error. Python only dropped it inside the opt-in auto-upload
walker; TypeScript never did, and with auto-upload on it tried to upload
the empty string.

Run a schema-aware, upload-free pass on the default execute path that
omits empty file values, and reuse the same walker for staging when
auto-upload is enabled.

Closes #4233
2026-08-25 01:58:52 +02:00
jkomyno 994b2f2fff Merge branch next into chore/changesets-v3-migration 2026-08-25 01:44:03 +02:00
dependabot[bot] 96d6c87705 fix(deps): bump the npm-production group across 1 directory with 26 updates (#4231)
Bumps the npm-production group with 26 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
|
[@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript)
| `0.3.233` | `0.3.239` |
|
[@mastra/mcp](https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp)
| `1.16.0` | `1.17.1` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.256` |
`6.0.263` |
|
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript)
| `0.117.1` | `0.120.0` |
| [@google/genai](https://github.com/googleapis/js-genai) | `2.17.1` |
`2.18.0` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) |
`1.2.8` | `1.2.9` |
|
[@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core)
| `1.4.10` | `1.4.12` |
| [@langchain/openai](https://github.com/langchain-ai/langchainjs) |
`1.5.8` | `1.5.10` |
| [langchain](https://github.com/langchain-ai/langchainjs) | `1.5.9` |
`1.5.10` |
| [@openai/agents](https://github.com/openai/openai-agents-js) |
`0.16.0` | `0.17.0` |
| [@langchain/anthropic](https://github.com/langchain-ai/langchainjs) |
`1.5.6` | `1.5.8` |
| [@langchain/mcp-adapters](https://github.com/langchain-ai/langchainjs)
| `1.1.3` | `1.1.4` |
|
[@agentclientprotocol/sdk](https://github.com/agentclientprotocol/typescript-sdk)
| `1.3.0` | `1.4.0` |
| [typebox](https://github.com/sinclairzx81/typebox) | `1.3.14` |
`1.3.16` |
| [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) |
`2.0.32` | `2.0.34` |
|
[@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai)
| `4.0.42` | `4.0.45` |
|
[@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers)
| `0.21.3` | `0.22.0` |
| [@cloudflare/workers-types](https://github.com/cloudflare/workerd) |
`5.20260815.1` | `5.20260821.1` |
|
[@mastra/core](https://github.com/mastra-ai/mastra/tree/HEAD/packages/core)
| `1.52.1` | `1.61.0` |
|
[@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk)
| `1.26.0` | `1.30.0` |
|
[@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun)
| `1.3.14` | `1.4.0` |
|
[@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui)
| `4.1.10` | `4.1.11` |
| [pnpm](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm) | `11.21.0`
| `11.22.0` |
|
[publint](https://github.com/publint/publint/tree/HEAD/packages/publint)
| `0.3.23` | `0.3.24` |
|
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)
| `4.1.10` | `4.1.11` |
|
[wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler)
| `4.123.0` | `4.125.0` |


Updates `@anthropic-ai/claude-agent-sdk` from 0.3.233 to 0.3.239
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/releases">@​anthropic-ai/claude-agent-sdk's
releases</a>.</em></p>
<blockquote>
<h2>v0.3.239</h2>
<h2>What's changed</h2>
<ul>
<li><code>total_cost_usd</code> / <code>modelUsage.costUSD</code> now
include the 1.1× US-only-inference (data residency) multiplier when the
response reports <code>inference_geo: &quot;us&quot;</code></li>
<li>A result held back for background subagents in one-shot mode now
reports <code>total_cost_usd</code>, <code>duration_api_ms</code> and
<code>modelUsage</code> as of its release, not the turn-end
snapshot</li>
<li>Fixed <code>SYSTEM_PROMPT_DYNAMIC_BOUNDARY</code> in an array
<code>systemPrompt</code> being sent to the model as literal text on
Bedrock, Vertex, Foundry, and gateway providers</li>
<li>A repeated <code>initialize</code> on a running process is now
followed by a <code>background_tasks_changed</code> snapshot of the live
background tasks, so reconnecting hosts see work that is still
running</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.239
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.239
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.239
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.239
</code></pre>
<h2>v0.3.238</h2>
<h2>What's changed</h2>
<ul>
<li>Added <code>is_backgrounded</code> and <code>spawn_depth</code> to
<code>task_started</code> events for subagent tasks
(<code>is_backgrounded</code> also on background Bash tasks)</li>
<li>Added <code>suppressOriginalPrompt</code> to
<code>UserPromptExpansion</code> hook output, matching
<code>UserPromptSubmit</code></li>
<li>Added <code>command_lifecycle</code> state <code>refused</code>: a
cross-session peer message the session's receive-side policy declines
now reports this terminal state instead of producing no lifecycle
frames</li>
<li>Fixed SDK hook callbacks silently not applying after a host re-sends
<code>initialize</code> to an already-running CLI; the response now
reports <code>hooks_applied</code></li>
<li>Fixed <code>CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true</code> not
keeping <code>prompt_suggestion</code> messages on when the account is
near, but not over, its usage limit</li>
<li>Changed <code>vcs_state_changed</code> push events to emit one event
per pushed branch</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.238
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.238
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.238
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.238
</code></pre>
<h2>v0.3.237</h2>
<h2>What's changed</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.237</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/claude-agent-sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.3.239</h2>
<ul>
<li><code>total_cost_usd</code> / <code>modelUsage.costUSD</code> now
include the 1.1× US-only-inference (data residency) multiplier when the
response reports <code>inference_geo: &quot;us&quot;</code></li>
<li>A result held back for background subagents in one-shot mode now
reports <code>total_cost_usd</code>, <code>duration_api_ms</code> and
<code>modelUsage</code> as of its release, not the turn-end
snapshot</li>
<li>Fixed <code>SYSTEM_PROMPT_DYNAMIC_BOUNDARY</code> in an array
<code>systemPrompt</code> being sent to the model as literal text on
Bedrock, Vertex, Foundry, and gateway providers</li>
<li>A repeated <code>initialize</code> on a running process is now
followed by a <code>background_tasks_changed</code> snapshot of the live
background tasks, so reconnecting hosts see work that is still
running</li>
</ul>
<h2>0.3.238</h2>
<ul>
<li>Added <code>is_backgrounded</code> and <code>spawn_depth</code> to
<code>task_started</code> events for subagent tasks
(<code>is_backgrounded</code> also on background Bash tasks)</li>
<li>Added <code>suppressOriginalPrompt</code> to
<code>UserPromptExpansion</code> hook output, matching
<code>UserPromptSubmit</code></li>
<li>Added <code>command_lifecycle</code> state <code>refused</code>: a
cross-session peer message the session's receive-side policy declines
now reports this terminal state instead of producing no lifecycle
frames</li>
<li>Fixed SDK hook callbacks silently not applying after a host re-sends
<code>initialize</code> to an already-running CLI; the response now
reports <code>hooks_applied</code></li>
<li>Fixed <code>CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true</code> not
keeping <code>prompt_suggestion</code> messages on when the account is
near, but not over, its usage limit</li>
<li>Changed <code>vcs_state_changed</code> push events to emit one event
per pushed branch</li>
</ul>
<h2>0.3.237</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.237</li>
</ul>
<h2>0.3.236</h2>
<ul>
<li><code>PostToolUse</code> hooks can return
<code>hookSpecificOutput.classifierContext</code>, a short host-asserted
note about a tool call's result that the auto mode permission classifier
reads alongside that result</li>
</ul>
<h2>0.3.235</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.235</li>
</ul>
<h2>0.3.234</h2>
<ul>
<li>Removed unused <code>bypass_permissions_disabled</code> from
<code>ExitReason</code> type; the value was never emitted — TypeScript
consumers with an explicit <code>case</code> branch get a compile error
on upgrade (runtime unaffected)</li>
<li>Updated the <code>ApiKeySource</code> type to include the values
<code>system/init</code> actually reports
(<code>ANTHROPIC_API_KEY</code>, <code>apiKeyHelper</code>, <code>/login
managed key</code>, <code>none</code>)</li>
<li><code>vcs_state_changed</code> events report the directory the shell
finished in (an inner <code>cd</code> is reflected)</li>
<li>A peer <code>origin</code> injected by the host may declare the
sending session's permission class (<code>fromMode</code>) so a
same-class message is delivered to a recipient that runs without
asking</li>
<li><code>SDKSystemMessage</code>
(<code>system</code>/<code>init</code>) gains an optional
<code>effort</code> field: the session's applied effort level, or
<code>null</code> when none is sent. Set on Remote Control bridge init
frames</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/ae7e3dd656244b67e8634c33b3137775ae5a3fcd"><code>ae7e3dd</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/c4fdbe3a4309f7165a4c3bee179c155d0422ff4c"><code>c4fdbe3</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/591a180a197a73ce90042a6f97a7c59c100d2c3a"><code>591a180</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/d933c997f2282179582d97c562b4d3451e74c0ee"><code>d933c99</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/076593f6db4357c3a050a5ed19c39ba1217eab3a"><code>076593f</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/a616205d6cb7c2f5907120f660f6391310918369"><code>a616205</code></a>
chore: Update CHANGELOG.md</li>
<li>See full diff in <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/compare/v0.3.233...v0.3.239">compare
view</a></li>
</ul>
</details>
<br />

Updates `@mastra/mcp` from 1.16.0 to 1.17.1
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/mastra-ai/mastra/blob/main/packages/mcp/CHANGELOG.md">@​mastra/mcp's
changelog</a>.</em></p>
<blockquote>
<h2>1.17.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>Fixed MCP tool listing when a tool has no input schema. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21861">#21861</a>)</p>
</li>
<li>
<p>Fixed <code>Cannot find package '@modelcontextprotocol/sdk'</code>
when importing <code>@mastra/mcp</code> in projects that skip automatic
peer installation (e.g. npm with <code>--legacy-peer-deps</code>), by
declaring the MCP SDK v1 peer required by
<code>@modelcontextprotocol/ext-apps</code> as a direct dependency. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21999">#21999</a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/mastra-ai/mastra/commit/88d14cac008582a618fecc3d5c7fd3bdf4f6ddc3"><code>88d14ca</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/480e491588bd6a7a1c9ee4407590ad625dd33952"><code>480e491</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/acc3471de5f3fde8027ee4e355af292b2bc1bc30"><code>acc3471</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/b6a771ef23d203ddb348efca8065eff65def8191"><code>b6a771e</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/3bb88ddf07fb98f3cd16d3bff94e51cd3b45d011"><code>3bb88dd</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/d23e75d57cc7cf5b9bfdbee896bf5a6a2484fed7"><code>d23e75d</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/c8faa4e1cfebaec56b65e754e90b9fe46d153359"><code>c8faa4e</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/d378d7511f71309ed61a8f6b93cd0361dc6cb70f"><code>d378d75</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/26d40160ff7f7d8bf95fee2039a52cbc83863533"><code>26d4016</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/7c60df5c7872343fbac5c3e5b1175c8076a5abfd"><code>7c60df5</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/f2031a47445e8f67a89ba1309036816f97ab7a65"><code>f2031a4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/cad42082e6aa1776168a94914f523334be45d929"><code>cad4208</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/8e529d4ac754efef04b225841349e0da9edf89a6"><code>8e529d4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/57c51035a2a36e3df3c4f32f46bb789a66ed5946"><code>57c5103</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/038b7b405cb4ac25ab3f3031334111b1f87ac112"><code>038b7b4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/4132d61f8367077120ee9e6420d3224dffd93c93"><code>4132d61</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/d378d7511f71309ed61a8f6b93cd0361dc6cb70f"><code>d378d75</code></a>]:</p>
<ul>
<li><code>@​mastra/core</code><a
href="https://github.com/1"><code>@​1</code></a>.61.0</li>
</ul>
</li>
</ul>
<h2>1.17.1-alpha.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>Fixed <code>Cannot find package '@modelcontextprotocol/sdk'</code>
when importing <code>@mastra/mcp</code> in projects that skip automatic
peer installation (e.g. npm with <code>--legacy-peer-deps</code>), by
declaring the MCP SDK v1 peer required by
<code>@modelcontextprotocol/ext-apps</code> as a direct dependency. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21999">#21999</a>)</p>
</li>
<li>
<p>Updated dependencies:</p>
<ul>
<li><code>@​mastra/core</code><a
href="https://github.com/1"><code>@​1</code></a>.61.0-alpha.4</li>
</ul>
</li>
</ul>
<h2>1.17.1-alpha.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>Fixed MCP tool listing when a tool has no input schema. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21861">#21861</a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/mastra-ai/mastra/commit/88d14cac008582a618fecc3d5c7fd3bdf4f6ddc3"><code>88d14ca</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/038b7b405cb4ac25ab3f3031334111b1f87ac112"><code>038b7b4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/4132d61f8367077120ee9e6420d3224dffd93c93"><code>4132d61</code></a>]:</p>
<ul>
<li><code>@​mastra/core</code><a
href="https://github.com/1"><code>@​1</code></a>.60.1-alpha.0</li>
</ul>
</li>
</ul>
<h2>1.17.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p>MCP tools served over HTTP now see the authenticated caller. When an
MCP server runs behind a Mastra server with <code>server.auth</code>
configured, the resolved user is bridged into
<code>extra.authInfo</code> automatically, on both the streamable HTTP
and SSE transports. Previously <code>extra.authInfo</code> was always
undefined because the request handed to the MCP transport was rebuilt
without the auth data. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21689">#21689</a>)</p>
<p><strong>Custom verification</strong></p>
<p>If your own middleware verifies the caller, build the auth info
yourself with the new <code>server.mcpOptions.setRequestAuth</code>
hook:</p>
<pre lang="ts"><code>export const mastra = new Mastra({
  mcpServers: { myServer },
  server: {
    middleware: [verifyBearerToken],
    mcpOptions: {
      setRequestAuth: (req, requestContext) =&gt; {
        const payload = requestContext.get('bearerPayload');
req.auth = { token: payload.token, clientId: payload.sub, scopes:
payload.scope.split(' ') };
      },
    },
</code></pre>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/mastra-ai/mastra/commit/ce66f918f0e27984772b524220e87be0e69cebe3"><code>ce66f91</code></a>
chore: version - exit prerelease mode</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/cc6549590e54065c70721a2b4af025c91550792b"><code>cc65495</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/22001">#22001</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/1d41dd06a001c6fee3aab1cdf1ec759f2070df3e"><code>1d41dd0</code></a>
fix(mcp): declare <code>@​modelcontextprotocol/sdk</code> v1 as a direct
dependency (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21999">#21999</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/8c6990aefc426c68a63560328bef4033f9ae8f77"><code>8c6990a</code></a>
chore: version packages</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/64cd7ac22c2c7a6e6b533a4b3a9ede432700f1fb"><code>64cd7ac</code></a>
fix(mcp): list tools without input schemas (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21861">#21861</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/c23d44525cb59f271fca8978bbaae05b7b6b3b9e"><code>c23d445</code></a>
chore: version - exit prerelease mode</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/86bde188a70540ebe849bd8a77594d88ffb77e2f"><code>86bde18</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21734">#21734</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/39ba1b9ce256a9a910a16f125cc6a59588185bfe"><code>39ba1b9</code></a>
feat(mcp): elicitation on the 2026-07-28 protocol leg via multi
round-trip re...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/0f53aeb119158bd9f83bd8ef667f1f675740e8f0"><code>0f53aeb</code></a>
feat(mcp): opt-in MCP protocol revision 2026-07-28 behind a
protocolVersion f...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/9f626699ac4422352721b2a3ca95ed5543763294"><code>9f62669</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21597">#21597</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/mastra-ai/mastra/commits/@mastra/mcp@1.17.1/packages/mcp">compare
view</a></li>
</ul>
</details>
<br />

Updates `ai` from 6.0.256 to 6.0.263
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/ai/blob/ai@6.0.263/packages/ai/CHANGELOG.md">ai's
changelog</a>.</em></p>
<blockquote>
<h2>6.0.263</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [1e70580]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.179</li>
</ul>
</li>
</ul>
<h2>6.0.262</h2>
<h3>Patch Changes</h3>
<ul>
<li>30526e9: Prevent exceptions in streaming <code>onChunk</code> and
<code>onError</code> callbacks from terminating the stream or masking
provider errors.</li>
<li>Updated dependencies [7de3226]</li>
<li>Updated dependencies [504da15]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.178</li>
</ul>
</li>
</ul>
<h2>6.0.261</h2>
<h3>Patch Changes</h3>
<ul>
<li>f1afbf9: Fix array-backed language model mocks to return configured
results in order from the first call.</li>
</ul>
<h2>6.0.260</h2>
<h3>Patch Changes</h3>
<ul>
<li>98c656f: fix: reject <code>streamObject</code> result promises and
report failed completion when the provider stream errors</li>
<li>b253d52: Filter preliminary tool outputs when
<code>ignoreIncompleteToolCalls</code> is enabled.</li>
<li>9e15cb4: Prevent automatic tool execution when a model call ends
with an unsafe finish reason.</li>
</ul>
<h2>6.0.259</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [def7999]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.177</li>
</ul>
</li>
</ul>
<h2>6.0.258</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [96304fc]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.176</li>
</ul>
</li>
</ul>
<h2>6.0.257</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [000b243]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.175</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/ai/commit/23e4c50cf56b0a9fca260098b731b1f730fd6254"><code>23e4c50</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19261">#19261</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/b55c2a9941725e0723a0abb0dc26a00baddab59b"><code>b55c2a9</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19212">#19212</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/30526e9ec8265181756c24ac6e8ff41b17d4366f"><code>30526e9</code></a>
[v6.0] fix: contain streaming callback exceptions without interrupting
consum...</li>
<li><a
href="https://github.com/vercel/ai/commit/d3f6cc9591a5482656decf88ee5cd08cdfaddc58"><code>d3f6cc9</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19191">#19191</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/f1afbf981dc66ea4ca290d778232b96640b6c14a"><code>f1afbf9</code></a>
[v6.0] fix: return array-backed mock language model results in
configured ord...</li>
<li><a
href="https://github.com/vercel/ai/commit/bb5526fc0b981bcb2c95accde20bf93b1b317de2"><code>bb5526f</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19131">#19131</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/9e15cb48a5f82f8e241ed71ad28918341ae5b16a"><code>9e15cb4</code></a>
[v6.0] fix: automatic tools executing after unsafe model finish reasons
(<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19120">#19120</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/b253d5245e9cd29a59811d1a18677c63c9a77f93"><code>b253d52</code></a>
[v6.0] fix: omit preliminary tool outputs when ignoring incomplete tool
calls...</li>
<li><a
href="https://github.com/vercel/ai/commit/98c656f768f0ae3a887b4251340f397d878ce5de"><code>98c656f</code></a>
[v6.0] fix: settle streamObject results and report provider stream
failures w...</li>
<li><a
href="https://github.com/vercel/ai/commit/815515120857394d2a3d3979a399f2cf4380a80f"><code>8155151</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19079">#19079</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/ai/commits/ai@6.0.263/packages/ai">compare
view</a></li>
</ul>
</details>
<br />

Updates `@anthropic-ai/sdk` from 0.117.1 to 0.120.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@​anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.120.0</h2>
<h2>0.120.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.119.0...sdk-v0.120.0">sdk-v0.119.0...sdk-v0.120.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> managed agents web search config and self
hosted sandbox memory (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ba8ec50ffe31e10781971a942d54289439307424">ba8ec50</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> use a single pnpm workspace lockfile (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3c32145d2bc4d53888c6c6857c9af216eec95fb9">3c32145</a>)</li>
</ul>
<h2>sdk: v0.119.0</h2>
<h2>0.119.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.118.0...sdk-v0.119.0">sdk-v0.118.0...sdk-v0.119.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> Files and Skills APIs are now GA; add computer
use and browser use toolsets (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab41aa32b92a7964b35beb42a6be5b0bec1dd735">ab41aa3</a>)</li>
</ul>
<h2>sdk: v0.118.0</h2>
<h2>0.118.0 (2026-08-18)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.118.0">sdk-v0.117.1...sdk-v0.118.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> additions to files and memory stores (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/fdc03790dc3e7fb0352298382f8a9603e92e19c2">fdc0379</a>)</li>
<li><strong>api:</strong> updates to skill, files, and user profiles (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/671e6b187f475b5a7a797adbbe5b908bd74d3935">671e6b1</a>)</li>
<li><strong>client:</strong> add helpers for accessing the workspace ID
in response headers (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/28aa5afe3284bcdc2cc35264f6f4d8dd762e186f">28aa5af</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>api:</strong> remove unsupported mid_conv_system content
block (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ae6ca9403125b5a0effb22c9d9c65804a99a80bd">ae6ca94</a>)</li>
<li><strong>session-runner:</strong> retry tool-result sends for at
least the lease TTL (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7dc632557bfea8475aab8345e27469f02faa6a5a">7dc6325</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> bump zod to 4.4.3 (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/334">#334</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/faa5b7b841a31967ee4679423c22802d4e70c79f">faa5b7b</a>)</li>
<li><strong>internal:</strong> remove leftover prism references (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a163b960ce982ffb2827a0e95a5ae05a1120aa51">a163b96</a>)</li>
<li>stop shipping the v0.50 migration guide and migrate CLI (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/53992d708ba024c25adabc864fe0268cc065865d">53992d7</a>)</li>
</ul>
<h3>Documentation</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.120.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.119.0...sdk-v0.120.0">sdk-v0.119.0...sdk-v0.120.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> managed agents web search config and self
hosted sandbox memory (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ba8ec50ffe31e10781971a942d54289439307424">ba8ec50</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> use a single pnpm workspace lockfile (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3c32145d2bc4d53888c6c6857c9af216eec95fb9">3c32145</a>)</li>
</ul>
<h2>0.119.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.118.0...sdk-v0.119.0">sdk-v0.118.0...sdk-v0.119.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> Files and Skills APIs are now GA; add computer
use and browser use toolsets (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab41aa32b92a7964b35beb42a6be5b0bec1dd735">ab41aa3</a>)</li>
</ul>
<h2>0.118.0 (2026-08-18)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.118.0">sdk-v0.117.1...sdk-v0.118.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> additions to files and memory stores (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/fdc03790dc3e7fb0352298382f8a9603e92e19c2">fdc0379</a>)</li>
<li><strong>api:</strong> updates to skill, files, and user profiles (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/671e6b187f475b5a7a797adbbe5b908bd74d3935">671e6b1</a>)</li>
<li><strong>client:</strong> add helpers for accessing the workspace ID
in response headers (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/28aa5afe3284bcdc2cc35264f6f4d8dd762e186f">28aa5af</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>api:</strong> remove unsupported mid_conv_system content
block (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ae6ca9403125b5a0effb22c9d9c65804a99a80bd">ae6ca94</a>)</li>
<li><strong>session-runner:</strong> retry tool-result sends for at
least the lease TTL (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7dc632557bfea8475aab8345e27469f02faa6a5a">7dc6325</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> bump zod to 4.4.3 (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/334">#334</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/faa5b7b841a31967ee4679423c22802d4e70c79f">faa5b7b</a>)</li>
<li><strong>internal:</strong> remove leftover prism references (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a163b960ce982ffb2827a0e95a5ae05a1120aa51">a163b96</a>)</li>
<li>stop shipping the v0.50 migration guide and migrate CLI (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/53992d708ba024c25adabc864fe0268cc065865d">53992d7</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>tools:</strong> warn that blocking tool bodies stall the
worker heartbeat (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/299">#299</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/908fdb5d9de8809190bdcf9d14a8319e80d8f31c">908fdb5</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bfa9197f0182084941052be9752c948638421601"><code>bfa9197</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bc167f3c8fe36137c5594a3776e9677d493e6618"><code>bc167f3</code></a>
feat(api): managed agents web search config and self hosted sandbox
memory</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/83fd8981a7b11321257027c817755305cc0a4b59"><code>83fd898</code></a>
chore(internal): use a single pnpm workspace lockfile (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7fe6dd50d509bb68eb0981ad1f7ad046984b426e"><code>7fe6dd5</code></a>
remove internal ticket references from changelog- <a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/360">#360</a></li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/c67e4e2d2329d25ba057f5e60c6dec3b2f33ba97"><code>c67e4e2</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/50fc0dba920417d641734f4abef51627c4785380"><code>50fc0db</code></a>
feat(api): Files and Skills APIs are now GA; add computer use and
browser use...</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/18ea26d324911c3236f2ce762dd0c87f04d038d3"><code>18ea26d</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/6ed9ddd8924924d20ff4610b83668754629f9478"><code>6ed9ddd</code></a>
feat(api): updates to skill, files, and user profiles</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/91921f5f0410a8caa638a85b0d38a8102d7e3c91"><code>91921f5</code></a>
fix(session-runner): retry tool-result sends for at least the lease TTL
(<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/142adcc2b864940a72464e41b63cc5733f38187b"><code>142adcc</code></a>
docs(tools): warn that blocking tool bodies stall the worker heartbeat
(<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/299">#299</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.120.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@google/genai` from 2.17.1 to 2.18.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/releases">@​google/genai's
releases</a>.</em></p>
<blockquote>
<h2>v2.18.0</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">2.18.0</a>
(2026-08-19)</h2>
<h3>Features</h3>
<ul>
<li>Add <code>mode</code> enum (<code>VERBATIM</code>,
<code>SMART</code>) to <code>AudioTranscriptionConfig</code> and
<code>TranscriptionConfig</code>. (<a
href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709">4c5208b</a>)</li>
<li>Add enable_data_retention to ToolParallelAiSearch, Add step_count to
ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (<a
href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab">f52c208</a>)</li>
<li>Add IDLE state to live connection status enum and mark
REQUIRES_ACTION as deprecated. (<a
href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857">2f110f2</a>)</li>
<li>add video resolution and extension task parameters (<a
href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d">39b2a2d</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>fix examples (<a
href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8">3f631be</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md">@​google/genai's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">2.18.0</a>
(2026-08-19)</h2>
<h3>Features</h3>
<ul>
<li>Add <code>mode</code> enum (<code>VERBATIM</code>,
<code>SMART</code>) to <code>AudioTranscriptionConfig</code> and
<code>TranscriptionConfig</code>. (<a
href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709">4c5208b</a>)</li>
<li>Add enable_data_retention to ToolParallelAiSearch, Add step_count to
ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (<a
href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab">f52c208</a>)</li>
<li>Add IDLE state to live connection status enum and mark
REQUIRES_ACTION as deprecated. (<a
href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857">2f110f2</a>)</li>
<li>add video resolution and extension task parameters (<a
href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d">39b2a2d</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>fix examples (<a
href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8">3f631be</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/googleapis/js-genai/commit/128781fdfec5d33f24d8305d90964f3b75b0774f"><code>128781f</code></a>
chore(main): release 2.18.0 (<a
href="https://redirect.github.com/googleapis/js-genai/issues/1856">#1856</a>)</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/67f4cf7c48059de776d2841a5cf5129361a97c49"><code>67f4cf7</code></a>
chore: Internal Changes</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857"><code>2f110f2</code></a>
feat: Add IDLE state to live connection status enum and mark
REQUIRES_ACTION ...</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8"><code>3f631be</code></a>
fix: fix examples</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709"><code>4c5208b</code></a>
feat: Add <code>mode</code> enum (<code>VERBATIM</code>,
<code>SMART</code>) to <code>AudioTranscriptionConfig</code> and...</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab"><code>f52c208</code></a>
feat: Add enable_data_retention to ToolParallelAiSearch, Add step_count
to Re...</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d"><code>39b2a2d</code></a>
feat: add video resolution and extension task parameters</li>
<li>See full diff in <a
href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/core` from 1.2.8 to 1.2.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/core's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.9</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11402">#11402</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- Fix ChatVertexAI/ChatGoogle content blocks: include
<code>tool_call</code> blocks from <code>message.tool_calls</code> and
skip spurious empty <code>text</code> blocks in
<code>contentBlocks</code>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a>
fix(google-common): release endpoint routing fix as patch (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a>
feat(google): add gateway support for genai (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
chore(langchain): update langgraph deps (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a>
fix(anthropic): round-trip tool search server-tool result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
fix(openai): drop Gemini functionCall content blocks in Chat Completions
mess...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a>
fix(google-genai): throw ContentBlockedError when Gemini candidate has
no con...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
fix(openai): retain cache_write_tokens, update to v7 sdk (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11399">#11399</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5ff9179e25f594d7cd21e176fdadd953190375c5"><code>5ff9179</code></a>
fix(google-genai): guard streaming chunks when candidate has no content
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10742">#10742</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a>
fix(core): include tool_call blocks and skip empty text blocks in
ChatVertexA...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.8...@langchain/core@1.2.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/langgraph` from 1.4.10 to 1.4.12
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/releases">@​langchain/langgraph's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/langgraph</code><a
href="https://github.com/1"><code>@​1</code></a>.4.12</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2714">#2714</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
Update checkpoint integrations to require the patched checkpoint
serializer release.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-checkpoint</code><a
href="https://github.com/1"><code>@​1</code></a>.1.5</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/langgraph</code><a
href="https://github.com/1"><code>@​1</code></a>.4.11</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2706">#2706</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a>
Thanks <a
href="https://github.com/zduric-langchain"><code>@​zduric-langchain</code></a>!
- fix(langgraph): dedupe merged callback handlers by identity</p>
<p><code>mergeCallbacks</code> concatenated <code>handlers</code> and
<code>inheritableHandlers</code> while
deduping <code>tags</code>, so a handler inherited by both the ambient
and the explicit
config picked up an extra registration at every graph boundary. With
tracing
on, a nested <code>streamMode: &quot;messages&quot;</code> run delivered
every token twice.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/3ce9f8d11dd64b1d091a25162603c49e6f4a426f"><code>3ce9f8d</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/51b42020f7c730a15193aa907056881e3d961924"><code>51b4202</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a86f813954e010fbf30711c37baa5c53444613d5"><code>a86f813</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-sdk</code><a
href="https://github.com/1"><code>@​1</code></a>.9.30</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md">@​langchain/langgraph's
changelog</a>.</em></p>
<blockquote>
<h2>1.4.12</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2714">#2714</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
Update checkpoint integrations to require the patched checkpoint
serializer release.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-checkpoint</code><a
href="https://github.com/1"><code>@​1</code></a>.1.5</li>
</ul>
</li>
</ul>
<h2>1.4.11</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2706">#2706</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a>
Thanks <a
href="https://github.com/zduric-langchain"><code>@​zduric-langchain</code></a>!
- fix(langgraph): dedupe merged callback handlers by identity</p>
<p><code>mergeCallbacks</code> concatenated <code>handlers</code> and
<code>inheritableHandlers</code> while
deduping <code>tags</code>, so a handler inherited by both the ambient
and the explicit
config picked up an extra registration at every graph boundary. With
tracing
on, a nested <code>streamMode: &quot;messages&quot;</code> run delivered
every token twice.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/3ce9f8d11dd64b1d091a25162603c49e6f4a426f"><code>3ce9f8d</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/51b42020f7c730a15193aa907056881e3d961924"><code>51b4202</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a86f813954e010fbf30711c37baa5c53444613d5"><code>a86f813</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-sdk</code><a
href="https://github.com/1"><code>@​1</code></a>.9.30</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/6530ba9b4c577c560422d9c9de18914e67411d9d"><code>6530ba9</code></a>
chore: version packages (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2715">#2715</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/c3b27a997c682a64f65904b2a97a5ee4d6e741b0"><code>c3b27a9</code></a>
fix(checkpoint): narrow re-constructable types in JsonPlusSerializer (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2709">#2709</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/659d628d196f6b1ba7aa46b30293c31ff5715cf4"><code>659d628</code></a>
chore: version packages (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2704">#2704</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a>
fix(langgraph): dedupe merged callback handlers by identity (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2706">#2706</a>)</li>
<li>See full diff in <a
href="https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.12/libs/langgraph-core">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/openai` from 1.5.8 to 1.5.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/openai's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11419">#11419</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/c26c87e41bccd01111e170c32ba1e5eec94ba3a6"><code>c26c87e</code></a>
Thanks <a href="https://github.com/chiliec"><code>@​chiliec</code></a>!
- fix(openai): send content null (not []) for tool-call-only v1
assistant messages</li>
</ul>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11399">#11399</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
Thanks <a
href="https://github.com/gethin-langchain"><code>@​gethin-langchain</code></a>!
- update to v7 openai sdk</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11403">#11403</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- Drop Gemini-native <code>functionCall</code> content blocks (already
carried in <code>tool_calls</code>) when converting messages to Chat
Completions API params, fixing requests that fail when a
<code>ChatGoogleGenerativeAI</code> message is passed to
<code>ChatOpenAI</code> (e.g. a cross-provider handoff in
LangGraph).</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11399">#11399</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
Thanks <a
href="https://github.com/gethin-langchain"><code>@​gethin-langchain</code></a>!
- Map OpenAI's <code>cache_write_tokens</code> to
<code>cache_creation</code> in
<code>usage_metadata.input_token_details</code>, mirroring the existing
<code>cached_tokens</code> -&gt; <code>cache_read</code> mapping across
the Chat Completions and Responses APIs. Previously, prompt cache-write
token counts were silently dropped.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d5264a180b2dd121d5fba54e9272d34352875d7b"><code>d5264a1</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11427">#11427</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c26c87e41bccd01111e170c32ba1e5eec94ba3a6"><code>c26c87e</code></a>
fix(openai): send content null (not []) for tool-call-only v1 assistant
messa...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/041a75581666a7fd551e6df62226dcf873be50cc"><code>041a755</code></a>
fix(anthropic): preserve generic tool_search_tool_result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11421">#11421</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a>
fix(google-common): release endpoint routing fix as patch (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a>
feat(google): add gateway support for genai (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
chore(langchain): update langgraph deps (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a>
fix(anthropic): round-trip tool search server-tool result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
fix(openai): drop Gemini functionCall content blocks in Chat Completions
mess...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a>
fix(google-genai): throw ContentBlockedError when Gemini candidate has
no con...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/openai@1.5.8...@langchain/openai@1.5.10">compare
view</a></li>
</ul>
</details>
<br />

Updates `langchain` from 1.5.9 to 1.5.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">langchain's
releases</a>.</em></p>
<blockquote>
<h2>langchain@1.5.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11412">#11412</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
chore(langgraph): update langgraph deps to track serialization fix</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a>
fix(google-common): release endpoint routing fix as patch (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a>
feat(google): add gateway support for genai (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
chore(langchain): update langgraph deps (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a>
fix(anthropic): round-trip tool search server-tool result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
fix(openai): drop Gemini functionCall content blocks in Chat Completions
mess...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a>
fix(google-genai): throw ContentBlockedError when Gemini candidate has
no con...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
fix(openai): retain cache_write_tokens, update to v7 sdk (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11399">#11399</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5ff9179e25f594d7cd21e176fdadd953190375c5"><code>5ff9179</code></a>
fix(google-genai): guard streaming chunks when candidate has no content
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10742">#10742</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a>
fix(core): include tool_call blocks and skip empty text blocks in
ChatVertexA...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/langchain@1.5.9...langchain@1.5.10">compare
view</a></li>
</ul>
</details>
<br />

Updates `@openai/agents` from 0.16.0 to 0.17.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/openai/openai-agents-js/releases">@​openai/agents's
releases</a>.</em></p>
<blockquote>
<h2>v0.17.0</h2>
<h2>Key Changes</h2>
<h3>Output-guardrail replay safety</h3>
<p>Serialized output-bearing approval checkpoints now fail closed with
<code>UserError</code> when the SDK cannot prove which response owns a
pending terminal tool output. Continue with the live
<code>RunState</code> when possible, or start a new run from safe input
instead of replaying ambiguous serialized items. When an output
guardrail rejects a completed function-tool result used as final output,
the SDK replaces rejected content in SDK-owned replay surfaces with
<code>Output withheld by an output guardrail.</code>, sanitizes current
guardrail metadata, and preserves earlier accepted history. This does
not undo external tool side effects or erase application-owned
copies.</p>
<h3>Complete guardrail batch results</h3>
<p>Guardrails started in the same batch now settle before the runner
surfaces a tripwire or execution failure. Completed sibling results
remain available in run state while further run processing is
halted.</p>
<h3>Explicit OpenAI client configuration</h3>
<p><code>OpenAIProvider</code> now rejects <code>organization</code> or
<code>project</code> when <code>openAIClient</code> is also supplied
because provider-level values cannot modify an already-created client.
Configure these values when constructing the <code>OpenAI</code> client,
then pass that client through <code>openAIClient</code>.</p>
<h2>What's Changed</h2>
<ul>
<li>fix(core): redact blocked tool outputs and aliases from replay state
by <a href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1712">openai/openai-agents-js#1712</a></li>
<li>fix(openai): reject ignored explicit-client options by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1718">openai/openai-agents-js#1718</a></li>
</ul>
<h3>Documentation &amp; Other Changes</h3>
<ul>
<li>docs: v01.6.1 release by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1696">openai/openai-agents-js#1696</a></li>
<li>docs: fix access token typo in connectors example by <a
href="https://github.com/Chair403"><code>@​Chair403</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1716">openai/openai-agents-js#1716</a></li>
<li>fix: keep Codex verification for development sandboxed by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1707">openai/openai-agents-js#1707</a></li>
<li>chore: update versions by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1717">openai/openai-agents-js#1717</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Chair403"><code>@​Chair403</code></a>
made their first contribution in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1716">openai/openai-agents-js#1716</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/openai/openai-agents-js/compare/v0.16.1...v0.17.0">https://github.com/openai/openai-agents-js/compare/v0.16.1...v0.17.0</a></p>
<h2>v0.16.1</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(core): add model call timeouts by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1679">openai/openai-agents-js#1679</a></li>
<li>feat(sandbox): add run-scoped sandbox working directories by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1683">openai/openai-agents-js#1683</a></li>
<li>feat(sandbox): allow Docker sandboxes to disable networking by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1695">openai/openai-agents-js#1695</a></li>
<li>feat(extensions): add Modal sandbox resource options by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1693">openai/openai-agents-js#1693</a></li>
<li>fix(core): honor exact call approval decisions by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1694">openai/openai-agents-js#1694</a></li>
<li>fix(sandbox): validate view_image raster content by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1704">openai/openai-agents-js#1704</a></li>
<li>fix(sandbox): validate dynamic compaction ratios by <a
href="https://github.com/sylvesterkaczmarek"><code>@​sylvesterkaczmarek</code></a>
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1691">openai/openai-agents-js#1691</a></li>
<li>fix(sandbox): trace effective run-scoped sandbox paths by <a
href="https://github.com/sylvesterkaczmarek"><code>@​sylvesterkaczmarek</code></a>
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1697">openai/openai-agents-js#1697</a></li>
</ul>
<h3>Documentation &amp; Other Changes</h3>
<ul>
<li>docs: prepare v0.16.0 release documentation by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1646">openai/openai-agents-js#1646</a></li>
<li>docs: document Agent.clone list property sharing by <a
href="https://github.com/thegoodengineer"><code>@​thegoodengineer</code></a>
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1705">openai/openai-agents-js#1705</a></li>
<li>chore: update versions by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1688">openai/openai-agents-js#1688</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/openai/openai-agents-js/commit/0319b657e64e0c132629fe9ed4d524f7cde93445"><code>0319b65</code></a>
chore: update versions (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1717">#1717</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/d80736ace3c8ac32c41ba2b353a3e64ed31354b3"><code>d80736a</code></a>
fix(openai): reject ignored explicit-client options (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1718">#1718</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/b9ecb03ede8845fd8e2da74667242b7d2cf3d7c3"><code>b9ecb03</code></a>
docs: fix access token typo in connectors example (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1716">#1716</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/33fe55c62e5a0535766f8adbac63430593b7acd9"><code>33fe55c</code></a>
fix(core): redact blocked tool outputs and aliases from replay state (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1712">#1712</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/2d68a10f8c1593f37a8e291e7bce00634ba3e5dd"><code>2d68a10</code></a>
test: remove flaky example process-group test</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/dcbb1e7ba9bcf5ce50052a2a8d287c94d1d84daf"><code>dcbb1e7</code></a>
chore: move example and integration runners out of skills</li>
<li><a href="https://github.com/openai/openai-agents-js/commit/272...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-08-25 01:38:21 +02:00
Alberto Schiabel 700327c2a6 Merge branch 'next' into chore/changesets-v3-migration 2026-08-25 01:18:03 +02:00
jkomyno 3e8ce1eae2 fix(release): use Changesets v3 action protocol 2026-08-25 01:11:35 +02:00
tgolob db7b576437 fix(ts): declare the supported Node.js engine floor (#4219)
## Summary

The ESM-only transition in #3494 established Node.js 22.22.3 as the
minimum supported runtime for the public TypeScript SDK packages, but
their published manifests still omit `engines.node`.

That leaves package managers without a package-level compatibility
signal before an older runtime encounters an ESM loading failure. For
example, the current `@composio/core@0.17.0` package fails with
`ERR_REQUIRE_ESM` when required on Node.js 22.0.0, while the same load
succeeds on Node.js 22.22.3.

This aligns the published metadata with the support floor already
documented and tested by the repository.

Related: #3494

## Changes

- Add `"engines": { "node": ">=22.22.3" }` to all 14 public TypeScript
release workspaces.
- Add a release-workflow invariant that discovers public TypeScript
workspaces from the root workspace configuration and rejects missing or
drifted Node.js engine ranges.
- Add a patch changeset covering exactly those 14 published packages.

<details>
<summary>Package scope</summary>

- Core packages: `@composio/core`, `@composio/slim`,
`@composio/experimental`, and `@composio/json-schema-to-zod`
- Providers: Anthropic, Claude Agent SDK, Cloudflare, Google, LangChain,
LlamaIndex, Mastra, OpenAI Agents, OpenAI, and Vercel
- Excluded as private/unpublished: CLI, CLI keyring, CLI local tools,
JSON Schema to Effect Schema, and TypeScript builders

</details>

## Type of change

- [x] Bug fix
- [ ] New feature
- [ ] Refactor/Chore
- [ ] Documentation
- [ ] Breaking change

## How Has This Been Tested?

Validated with the repository-pinned Node.js 24.17.0, pnpm 11.8.0, and
Bun 1.4.0 toolchain:

- `pnpm install --frozen-lockfile`
- `pnpm run test:release-workflow`
- `pnpm validate:changesets`
- `pnpm exec changeset status --since=origin/next` (exactly 14 patch
releases)
- `pnpm build:packages` (19/19 packages)
- `pnpm typecheck` (14/14 tasks)
- `pnpm lint:packages` (successful; only pre-existing warnings in
untouched source files)
- Prettier over every touched file
- `git diff --check origin/next...HEAD`

The published-package probe also confirmed that `@composio/core@0.17.0`
has no `engines` metadata, CommonJS loading fails on Node.js 22.0.0, and
the same package loads successfully on Node.js 22.22.3.

No lockfiles, generated files, or runtime source files changed.

## Screenshots (if applicable)

Not applicable.

## Checklist

- [x] I have read the Code of Conduct and this PR adheres to it
- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable
- [x] I added a changeset if this change affects published packages

## Additional context

The runtime floor itself is not new: #3494 shipped and documented it as
a breaking change in the existing `0.x` line. This patch makes registry
metadata accurately reflect that existing support contract, so the
accompanying releases are patches.

---------

Co-authored-by: Tomas Golob <tgolob@users.noreply.github.com>
Co-authored-by: Alberto Schiabel <jkomyno@users.noreply.github.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-08-25 01:11:05 +02:00
sdkrelease[bot] 0726c95931 chore(cli): refresh baked toolkit slugs (#4225)
## Summary
Automated refresh of the toolkit slugs the CLI knows without asking
the API, generated by
`ts/packages/cli/scripts/generate-toolkit-slugs.ts`.

Toolkits added since the last refresh currently cost users one
toolkit-list fetch (~2 s) the first time they run one of that
toolkit's tools. Merging this makes them free.

The generator refuses to write a list that is short, malformed, or
missing staple toolkits, so a bad fetch opens no PR at all.

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-08-24 20:20:41 +02:00
Alberto Schiabel 38ed791982 test(core): stub file upload client boundary (#4227) 2026-08-24 13:42:45 +02:00
Alberto Schiabel d787107dfa fix(examples): declare provider deps and drop magic-flow-demo (#4221)
Follow-up to the live-sweep findings in #4135. Independent of it — this
targets `next` directly.

## Python entries could never resolve their provider imports

`harness/run.mjs` runs each Python entry as `uv run --project python
[--with <dep>]... python <file>`. The base environment is the `python`
project only, so the provider packages are present just when an entry
names them in `pyWith`. Six entries import a provider and declared none,
and have failed with `ModuleNotFoundError` every time the sweep has run
since it landed on 2026-08-14:

| entry | imports | had |
| --- | --- | --- |
| `py/tool_router/files` | `composio_openai` | no `pyWith` |
| `py/tool_router/preload` | `composio_openai_agents` |
`openai-agents>=0.19` only |
| `py/tool_router/direct_tools_preset` | `composio_openai_agents` |
`openai-agents>=0.19` only |
| `py/tool_router/tools` | `composio_openai_agents` |
`openai-agents>=0.19` only |
| `py/tool_router/tool_router_mcp` | `composio_openai_agents` |
`openai-agents>=0.19` only |
| `py/custom_tools_agent_test` | `composio_openai_agents` |
`openai-agents>=0.19` only |

Those entries declared the upstream `openai-agents` SDK but not the
Composio provider built on it.

### Why local paths, not package names

A bare `--with composio-openai-agents` resolves from **PyPI**, so the
sweep would exercise the published provider rather than this repo's —
and it drags the published `composio` in with it. Declaring
`./python/providers/<name>` plus `./python` keeps both local. Verified
in the resulting overlay:

```
composio        : file:///…/composio2/python
composio-openai : file:///…/composio2/python/providers/openai
```

`py/tool_router/claude_agent` already had `./python` but named its
provider, so it was testing the **published**
`composio-claude-agent-sdk` against the repo's `composio` (confirmed:
that dist has no `direct_url.json`). Pointed at the local path too, so
every entry now tests repo code under one convention.

## Deleting `ts/connected-accounts/magic-flow-demo`

- Not substantively touched since **2025-06-20** — ~14 months. The only
later commits are a model-version bump and its same-day revert, which
net to zero.
- It calls an endpoint the backend has retired. The sweep gets `400`:
*"Creating connections on this endpoint for Composio-managed OAuth auth
configs is no longer supported. Use POST /api/v3/connected_accounts/link
instead."*
- It could not pass unattended even if that were fixed:
`waitForConnection()` blocks until a human completes a browser OAuth
grant.

Removed the source, its manifest entry, and its README bullet. Rewriting
it onto `/connected_accounts/link` would be a genuinely new example
rather than a repair, so it seemed better to drop it than to carry a
broken one.

## Verified against the live staging backend

Not just locally — these entries were **executed** against
`staging-backend.composio.dev` (`llm=mock`, zero model spend):

```
provisioned state: complete
sweep 20260823224239-lk9413-baseline-mock: 5 entries
  ✓ py/tool_router/toolkits (5.8s)
  ✓ py/tool_router/preload (11.1s)
  ✓ py/tool_router/direct_tools_preset (11.2s)
  ✓ py/tool_router/files (12.3s)
  ✓ py/auth_configs (3.9s)
sweep: 5 green / 0 red / 0 skipped
```

All three previously-broken entries now pass end to end; `toolkits` and
`auth_configs` ran as unchanged controls. As far as I can tell from the
workflow history, this is the first time any of these examples has
completed green — the nightly has failed at `Verify provisioned project
state` on every run since it was introduced.

The run needed a branch carrying both these fixes and #4135's scoped
provisioning, since `next`'s provisioning tries to create a
`googledrive` auth config and dies before sweeping anything. That branch
was throwaway and is deleted.

Other checks: `node harness/run.mjs selftest` passes, `pnpm run
test:examples` validates 20 packages, the connected-accounts package
typechecks, and all 92 remaining manifest entries point at files that
exist.

### Still unproven

The other three entries fixed here — `tools`, `tool_router_mcp`,
`custom_tools_agent_test` — need github/gmail connected accounts, which
staging does not yet have. They get past their imports but cannot be run
end to end until those grants exist. `py/modifiers` is `tier=X`,
excluded by design.

## Related

`py/tool_router/tool_router_mcp` also exits **0** when
`COMPOSIO_API_KEY` is unset, so the harness would score it green while
it did nothing. Fixed separately in #4222.
2026-08-24 00:47:10 +02:00
composio-zen[bot] 7677f84968 fix(core): block sensitive upload paths hidden behind a symlinked directory
The sensitive-file-upload denylist matched deny segments only against the
symlink-resolved path. That catches a benign name pointing at a secret
(`~/innocent -> ~/.aws/creds`, which the existing test covers) but misses the
inverse: a sensitive directory that is itself a symlink to a target without the
denied segment. `~/.claude -> /state/claude` resolves to `/state/claude/...`,
which contains no `.claude` segment, so the denylist let it through — and
`.claude` is on the list precisely because it "may contain API keys".

That layout is not exotic. Dotfile managers (chezmoi, stow, yadm) and
containerised home directories produce it routinely; Composio's own agent
sandbox image does. For those users the control was silently inactive.

The repository's own test asserted the blocked behaviour and has been failing
wherever `~/.claude` is a symlink. CI never caught it because `~/.claude` does
not exist on the runners, so no realpath happens and the written path keeps its
`.claude` segment.

Match both the written and the resolved path, for directory segments and for
the basename check, since either one can be the one carrying the denied name.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 17:10:11 +00:00
composio-zen[bot] 2d409c7417 fix(cli): verify codex-acp tarballs against the lockfile before packaging them
The release build downloads four `@zed-industries/codex-acp-<platform>`
tarballs itself, because pnpm will only install the one matching the runner's
platform and the archive has to name all four. Those bytes were extracted and
copied, executable, into the published CLI archive without ever being checked
against a known hash — the one dependency in the release that got none of the
integrity verification `pnpm install --frozen-lockfile` applies to everything
else.

`pnpm-lock.yaml` already pins a sha512 for each of them, so the fix is to use
it. The hash is read from the lockfile rather than the registry's own
`dist.integrity`, since whoever can serve a tarball can serve the metadata
vouching for it, and it is looked up before the download so a package the
lockfile never resolved aborts the build instead of shipping unverified bytes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 16:42:42 +00:00
Alberto Schiabel 1bf17e13a2 fix(cli): refresh toolkit catalog with production key (#4216)
This PR:
- refreshes the baked CLI toolkit catalog from 1,070 to 1,381 slugs
- updates the snapshot timestamp so release builds no longer warn about
the old catalog
- routes the scheduled production refresh through
`COMPOSIO_DOCS_API_KEY`
- preserves the shared `COMPOSIO_API_KEY` contract for staging SDK and
example suites
- verifies the generated catalog contract with its focused Vitest suite
- verifies the workflow file with Prettier and `git diff --check`
2026-08-23 17:27:57 +02:00
Alberto Schiabel a0c3bcc2c8 fix(cli): make upgrade downloads visible and half the size (#4187)
## Problem

`composio upgrade` from `0.3.4-beta.351` to `0.4.0-beta.359` looked hung
for several minutes:

```
◐  New version available: @composio/cli@0.4.0-beta.359 (current: @composio/cli@0.3.4-beta.351). Downloading.
```

Two independent defects behind that.

**No feedback.** `upgrade-binary.ts` printed that message once and then
said nothing until the download finished. The only byte-level signal was
a `logDebug`, invisible in a normal run, because the body was read with
a single buffered `response.arrayBuffer`.

**Mostly wasted payload.** The archive is 338 MB, and ~651 MB of what it
unpacks is `codex-acp` binaries for the three platforms the host cannot
execute. Measured on a darwin-arm64 install:

```
~/.composio                      967 MB total
  codex/darwin-arm64  180 MB     ← the only one this Mac can run
  codex/darwin-x64    190 MB  ┐
  codex/linux-arm64   208 MB  ├─  620 MB of dead weight
  codex/linux-x64     222 MB  ┘
```

## Changes

**Progress reporting.** The response is streamed and reported on a 250
ms interval: `Downloading... 42% (142.0 MB / 338.0 MB)`. The total comes
from the release asset's `size` (newly decoded — the field was being
dropped), falling back to `content-length`, and falling back again to a
plain byte count so an unknown size degrades instead of failing.

**Half the payload.** Each archive now carries real bytes only for the
`codex-acp` binary its own platform can execute.

The other three paths cannot simply be dropped — that is exactly the
break #4186 just repaired. A CLI released before 2026-08-18 verifies a
downloaded package against all four codex-acp paths and refuses one
missing any of them. So they ship as **empty placeholders**: the
existence check passes at zero bytes, and since no host ever executes a
foreign codex-acp, the placeholder is never read. Once no supported
client performs that check, placeholders become plain omissions —
`archiveCompanionEntries` is where that switch lives.

As a guard, codex adapter resolution now requires a non-empty file, so a
zero-byte binary resolves as absent and falls through to the existing
bundled → PATH → npx chain rather than trying to exec it.

Expected effect: download 338 MB → ~165 MB, install footprint 967 MB →
~347 MB.

## Verification

- Full CLI suite: **122 files, 1262 passed, 1 skipped**
- `pnpm --filter @composio/cli typecheck` — clean
- The existing `upgrade-binary` download tests run against a real HTTP
server and pass unchanged, covering the buffered → streamed rewrite
- New tests: progress formatting (known total, unknown total, zero
total, overshoot) and `archiveCompanionEntries` (all four paths named,
exactly one copied, three placeholdered, portable assets copied)
- `pnpm validate:changesets` — passes; note lands in
`ts/packages/cli/CHANGELOG.md`

Not verifiable locally: actual archive sizes and a real upgrade against
a pre-2026-08-18 client. Both need a beta build — worth confirming on
the beta cut from this branch before it goes near a stable promotion.

Independent of the `0.4.0` release in flight; `0.4.0-beta.359` is
unaffected.

https://claude.ai/code/session_01JkwtxPHfobZxzvAqe53x62
2026-08-23 13:07:12 +02:00
Alberto Schiabel f926058147 fix(cli): refuse symlink entries when extracting archives (#4210)
Addresses the `pnpm audit --prod` warning that has been riding along on
recent CLI PRs: **`extract-zip` unvalidated symlink path traversal**,
[GHSA-jmr9-qjv8-65gv](https://github.com/advisories/GHSA-jmr9-qjv8-65gv)
/ CVE-2026-56876, high.

## There is no version to upgrade to

`pnpm audit` renders "Patched versions >=2.0.2", which reads like a bump
would fix it. It would not:

- `npm view extract-zip versions` ends at **2.0.1** — no 2.0.2 was ever
published
- the advisory itself records `"first_patched_version": null`

So `pnpm audit --fix --prod` cannot resolve this, and neither can a
version constraint.

## What the flaw actually is

I reproduced it rather than working from the summary. `extract-zip`
2.0.1 **does** block writes that traverse a symlink — an archive with
`link -> ../../ESCAPED` plus `link/pwned.txt` is refused with `Out of
bound path ... while processing file link/pwned.txt`, and nothing lands
outside the target.

What it does not do is validate the symlink itself. An archive whose
only entry is `escape-abs -> /tmp/ABSOLUTE-TARGET` extracts cleanly and
plants that dangling symlink in the output directory. Per the advisory:
*"Depending on how extract-zip is used, an attacker could read or write
to arbitrary files."* Every call site here extracts an archive and then
reads or copies files back out of the tree, which is exactly the shape
that turns a planted symlink into an arbitrary-path read.

## Why not swap the library

`#4183` moved tar extraction to `Bun.Archive`, so that was the obvious
candidate. It does not work: **`Bun.Archive` cannot read zip archives at
all.** A benign zip fails with `ReadError`, same as the malicious ones —
those "refusals" were read failures, not security. Verified before
ruling it out.

## Why not fix it upstream

Because it already is, three times over, and none of it has moved:

| PR | Date | Targets |
| --- | --- | --- |
|
[max-mapper/extract-zip#158](https://github.com/max-mapper/extract-zip/pull/158)
| 2026-08-14 | GHSA-jmr9-qjv8-65gv, this advisory |
| [#160](https://github.com/max-mapper/extract-zip/pull/160) |
2026-08-17 | CVE-2026-19693, symlink at the final path component |
| [#161](https://github.com/max-mapper/extract-zip/pull/161) |
2026-08-20 | CVE-2026-56876 again, and bumps the version to 2.0.2 |

All three are mergeable with zero review comments. The repository's last
commit to `master` was **August 2021**; 2.0.1 shipped June 2020. [Issue
#159](https://github.com/max-mapper/extract-zip/issues/159), a
downstream consumer asking whether a patched release is planned, has
three replies — every one from another stranded consumer, none from a
maintainer.

A fourth PR would not be a contribution. And our implementation is the
wrong shape to upstream regardless: refusing *every* symlink is right
for an application whose archives never carry one, but a breaking change
for a general-purpose library, where the correct fix is validating that
a link's resolved target stays inside the extraction root — which is
what #158 and #161 already do. Upstream even tracks "do not extract
symlinks" as a separate [feature
request](https://github.com/max-mapper/extract-zip/issues/140), open
since 2023.

So this is a deliberate local workaround on a timeline we control. The
helper's doc comment records the tracking PRs and the condition for
deleting it: a published release that actually carries the fix.

## The fix

No archive either package extracts — release binaries, companion assets,
skills, sidecar bundles — legitimately contains a symlink. So the entry
type is refused outright, via `extract-zip`'s own `onEntry` hook, which
runs **before** the entry is written. A rejected archive plants nothing.

All four call sites now go through it:

| package | call site |
| --- | --- |
| `cli` | `services/upgrade-binary.ts` |
| `cli` | `services/run-companion-modules.ts` |
| `cli` | `effects/install-skill.ts` |
| `cli-local-tools` | `src/bundled-binaries.ts` |

Each package carries its own copy of the helper rather than sharing one.
`run-companion-modules.ts` is bundled as a standalone companion module
and imports nothing from `@composio/cli-local-tools`; routing it through
that package to share ~15 lines would pull the local-tools tree into
those bundles.

## Verification

Committed three fixture archives (827 bytes total) and tested against
real zips, not mocks:

- benign archive extracts, contents intact
- `symlink-absolute.zip` (`-> /tmp/ABSOLUTE-TARGET`) refused, output
directory left empty
- `symlink-relative.zip` (`-> ../../outside`) refused, output directory
left empty
- `isSymlinkZipEntry` unit-tested across symlink, regular file,
directory, and Windows-authored entries with no Unix mode

**Mutation-checked:** neutering the predicate makes exactly the three
symlink tests fail and leaves the other four green, so the suite
genuinely detects the regression rather than passing by construction.

Suites: `@composio/cli` 123 files / 1263 passed,
`@composio/cli-local-tools` 7 files / 20 passed. Typecheck clean on
both. `pnpm validate:changesets` passes; note lands in
`ts/packages/cli/CHANGELOG.md`.

`extract-zip` stays as the dependency — it is still the only working zip
reader here, and with symlink entries refused the advisory's vector no
longer applies to this codebase.

https://claude.ai/code/session_01JkwtxPHfobZxzvAqe53x62
2026-08-23 12:28:24 +02:00
AseemPrasad e57661755b Merge branch 'next' of https://github.com/ComposioHQ/composio into asimcomposio
# Conflicts:
#	python/composio/core/provider/_openai_responses.py
#	ts/packages/providers/openai/src/OpenAIResponsesProvider.ts
2026-08-23 01:19:42 +05:30
AseemPrasad 04817cb20d fix(openai): recursive strict-mode schema normalization for structured outputs (+ Python parity) 2026-08-23 00:17:57 +05:30
shams haroon a09aa44d68 chore(cli): remove unused vitest alias 2026-08-20 18:12:20 -07:00
shams haroon 7ed76f97fc fix(cli): resolve custom schemas through tool router 2026-08-20 16:16:02 -07:00
shams haroon e71b6c9961 refactor(cli): keep existing search cache behavior 2026-08-20 15:48:02 -07:00
shams haroon e19b998a9f Revert "fix(cli): avoid refreshing consumer cache on every search"
This reverts commit 9596776465.
2026-08-20 15:46:28 -07:00
shams haroon 623aee4ce9 Revert "refactor(cli): simplify search retry flow"
This reverts commit c180103835.
2026-08-20 15:46:25 -07:00