Commit Graph

224 Commits

Author SHA1 Message Date
github-actions[bot] 43ef0e695a chore: version packages (#765)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents@1.13.0

### Minor Changes

- [#675](https://github.com/langchain-ai/deepagentsjs/pull/675)
[`ba8d4aa`](https://github.com/langchain-ai/deepagentsjs/commit/ba8d4aa71664c23027e57eee0fcaa2701d60408f)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): add
recursive delete tool

- [#752](https://github.com/langchain-ai/deepagentsjs/pull/752)
[`b20d6ad`](https://github.com/langchain-ai/deepagentsjs/commit/b20d6adc3dc7caf01281832548a17f381561318c)
Thanks
[@thushanth-bengre-langchain](https://github.com/thushanth-bengre-langchain)!
- feat(deepagents): add `ForkedSubAgent` for subagent conversation
forking

Lets a subagent inherit the parent's conversation history instead of
only seeing the task description.

### Patch Changes

- [#759](https://github.com/langchain-ai/deepagentsjs/pull/759)
[`85a55e1`](https://github.com/langchain-ai/deepagentsjs/commit/85a55e14da6cb19877ddd81d898d78d6ededfe74)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(deepagents): cap sandbox glob find so root searches cannot OOM the
host

Recursive glob listed every path under the search root (and with `-L`
could loop through `/proc/*/root`). Prune virtual filesystems and
soft-cap find output so a `glob("**/x", "/")` cannot exhaust the runtime
heap.

- [#768](https://github.com/langchain-ai/deepagentsjs/pull/768)
[`f124127`](https://github.com/langchain-ai/deepagentsjs/commit/f124127255fbd4e4b03eb84a4b39c70421a07e35)
Thanks [@casparb](https://github.com/casparb)! - fix(deepagents): accept
permission paths that exactly equal a composite route

A permission path equal to a single-file mount (e.g. `/instructions.md`)
was rejected when the backend supported execution, forcing users to
write `/instructions.md/**`. The route-scoping check now also accepts
the route root itself. Sibling prefixes such as `/workspace2/**` for
route `/workspace` remain rejected.

- [#769](https://github.com/langchain-ai/deepagentsjs/pull/769)
[`d4045de`](https://github.com/langchain-ai/deepagentsjs/commit/d4045de67715bf3cd6198b0d516d176c0e4b75d0)
Thanks [@hntrl](https://github.com/hntrl)! - chore(deps): update
langgraph deps to track serialization fix
## deepagents-acp@0.1.26

### Patch Changes

- [#769](https://github.com/langchain-ai/deepagentsjs/pull/769)
[`d4045de`](https://github.com/langchain-ai/deepagentsjs/commit/d4045de67715bf3cd6198b0d516d176c0e4b75d0)
Thanks [@hntrl](https://github.com/hntrl)! - chore(deps): update
langgraph deps to track serialization fix

- Updated dependencies
[[`85a55e1`](https://github.com/langchain-ai/deepagentsjs/commit/85a55e14da6cb19877ddd81d898d78d6ededfe74),
[`f124127`](https://github.com/langchain-ai/deepagentsjs/commit/f124127255fbd4e4b03eb84a4b39c70421a07e35),
[`d4045de`](https://github.com/langchain-ai/deepagentsjs/commit/d4045de67715bf3cd6198b0d516d176c0e4b75d0),
[`ba8d4aa`](https://github.com/langchain-ai/deepagentsjs/commit/ba8d4aa71664c23027e57eee0fcaa2701d60408f),
[`b20d6ad`](https://github.com/langchain-ai/deepagentsjs/commit/b20d6adc3dc7caf01281832548a17f381561318c)]:
  - deepagents@1.13.0
## @langchain/quickjs@0.6.2

### Patch Changes

- [#769](https://github.com/langchain-ai/deepagentsjs/pull/769)
[`d4045de`](https://github.com/langchain-ai/deepagentsjs/commit/d4045de67715bf3cd6198b0d516d176c0e4b75d0)
Thanks [@hntrl](https://github.com/hntrl)! - chore(deps): update
langgraph deps to track serialization fix
## @deepagents/evals@0.0.25

### Patch Changes

- Updated dependencies
[[`85a55e1`](https://github.com/langchain-ai/deepagentsjs/commit/85a55e14da6cb19877ddd81d898d78d6ededfe74),
[`f124127`](https://github.com/langchain-ai/deepagentsjs/commit/f124127255fbd4e4b03eb84a4b39c70421a07e35),
[`d4045de`](https://github.com/langchain-ai/deepagentsjs/commit/d4045de67715bf3cd6198b0d516d176c0e4b75d0),
[`ba8d4aa`](https://github.com/langchain-ai/deepagentsjs/commit/ba8d4aa71664c23027e57eee0fcaa2701d60408f),
[`b20d6ad`](https://github.com/langchain-ai/deepagentsjs/commit/b20d6adc3dc7caf01281832548a17f381561318c)]:
  - deepagents@1.13.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-19 20:01:24 -07:00
Thushanth Bengre b20d6adc3d feat(deepagents): introduce ForkedSubAgent type for subagent conversation forking (#752)
## Summary

Replaces the `mode` field on `SubAgent` with a new `ForkedSubAgent` type
for opt-in conversation forking. A `ForkedSubAgent` has no
`systemPrompt` of its own — it always inherits the parent's message
history and exact system prompt, plus mirrored middleware when its model
matches the parent's. `CompiledSubAgent` keeps its existing `mode:
"handoff" | "fork"` field, unchanged.

## Changes

- New `ForkedSubAgent` type — same shape as `SubAgent` minus
`systemPrompt`; always forks.
- `SubAgent` no longer has a `mode` field — always isolated (same as
before this feature existed).
- `CompiledSubAgent.mode` unchanged.
- Mirrored middleware (memory/custom) only added when the model matches
the parent's; the system prompt itself is inherited unconditionally
either way.
- Updated fork test coverage in `subagent.test.ts` for the new type.

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-08-19 19:56:11 -07:00
Hunter Lovell d4045de677 chore(deepagents): update langgraph deps (#769)
patches a ser/de bug for deepagents
2026-08-19 18:48:55 -07:00
Caspar Broekhuizen f124127255 fix(deepagents): accept permission paths equal to a composite route root (#768)
## Description

When filesystem `permissions` are combined with an execution-capable
backend, `createFilesystemMiddleware` requires every permission path to
be scoped to a `CompositeBackend` route. That check required a trailing
separator, so a permission path that exactly equals a single-file mount
(route `/instructions.md`, permission `/instructions.md`) was rejected
and users had to write `/instructions.md/**`. Python deepagents accepts
the exact form; this syncs JS with it by also accepting the route root
itself, mirroring `CompositeBackend.isPathWithinRoute`. It deliberately
does not adopt Python's looser bare `startsWith`, so sibling prefixes
like `/workspace2/**` for route `/workspace` are still rejected.

## Test Plan
- [ ] `npx vitest run src/middleware/fs.permissions.test.ts` in
`libs/deepagents` (new cases: exact file-mount route and exact directory
route root are accepted; sibling-prefix and `/**` rejections unchanged).

Made by [Open
SWE](https://openswe.vercel.app/agents/2758c734-16e9-54c3-b89f-ce698a566e71)

---------

Co-authored-by: Caspar Broekhuizen <25157475+casparb@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-08-19 10:03:48 -07:00
Christian Bromann 85a55e14da fix(deepagents): cap sandbox glob find so root searches cannot OOM the host (#759)
## Summary

Recursive glob listed every path under the search root, and with -L
could loop through proc pid root symlinks into the host heap.

- Sandbox `glob` listed the whole search tree via `find -L` and buffered
it in the host process, so `glob("**/…", "/")` could OOM the runtime.
Prune virtual filesystems and soft-cap find output; mark `truncated`
when the cap is hit.
2026-08-18 22:03:40 -07:00
Hunter Lovell ba8d4aa716 feat(deepagents): add recursive delete tool (#675)
## Summary

This adds a destructive `delete` filesystem tool backed by the core backend protocol, with recursive deletion for files/directories and write-permission enforcement over the whole target subtree.

## Changes

### Core filesystem backends

- Added `DeleteResult` and optional `delete(filePath)` support to the
backend protocol and adapters.
- Implemented recursive delete behavior for state, store, filesystem,
sandbox, context-hub, and composite backends.
- Preserved filesystem path containment and symlink safety: filesystem
deletes remove symlinks as links and do not follow them.
- Converts unsupported routed deletes in `CompositeBackend` into normal
backend errors.

### Filesystem middleware

- Added the final `delete` tool name with recursive file/directory
semantics.
- Treats `delete` as a write operation for filesystem permissions.
- Refuses recursive deletes if any deny-write permission pattern
overlaps the target subtree, without enumerating filesystem contents
first.
- Filters the `delete` tool out when the resolved backend does not
support deletion.

### Tests, evals, and prompts

- Added backend and middleware coverage for recursive deletes, missing
paths, symlink safety, unsupported backends, and permission denial.
- Added file-operation eval coverage for deleting a file and deleting a
directory recursively.
- Updated core filesystem prompts and sandbox examples to document the
new `delete` tool.
2026-08-18 20:04:11 -07:00
github-actions[bot] 2a01d04faf chore: version packages (#750)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.25

### Patch Changes

- Updated dependencies
[[`b2afb8d`](https://github.com/langchain-ai/deepagentsjs/commit/b2afb8d600570b633fd97d4d2f8fd8bdb229ce35),
[`68337fc`](https://github.com/langchain-ai/deepagentsjs/commit/68337fcca19a6d7cc18e8917d575ea9ca3aebcbe),
[`7550c65`](https://github.com/langchain-ai/deepagentsjs/commit/7550c65204bdd9141a88b9b42d46899e05c7bc43)]:
  - deepagents@1.12.4
## deepagents@1.12.4

### Patch Changes

- [#747](https://github.com/langchain-ai/deepagentsjs/pull/747)
[`b2afb8d`](https://github.com/langchain-ai/deepagentsjs/commit/b2afb8d600570b633fd97d4d2f8fd8bdb229ce35)
Thanks [@casparb](https://github.com/casparb)! - fix(deepagents): batch
concurrent Context Hub mutations

- [#751](https://github.com/langchain-ai/deepagentsjs/pull/751)
[`68337fc`](https://github.com/langchain-ai/deepagentsjs/commit/68337fcca19a6d7cc18e8917d575ea9ca3aebcbe)
Thanks
[@thushanth-bengre-langchain](https://github.com/thushanth-bengre-langchain)!
- fix(deepagents): coerce grep tool's max_count to a number

- [#749](https://github.com/langchain-ai/deepagentsjs/pull/749)
[`7550c65`](https://github.com/langchain-ai/deepagentsjs/commit/7550c65204bdd9141a88b9b42d46899e05c7bc43)
Thanks
[@thushanth-bengre-langchain](https://github.com/thushanth-bengre-langchain)!
- fix(deepagents): exclude summarization state from subagent
input/output
## @deepagents/evals@0.0.24

### Patch Changes

- Updated dependencies
[[`b2afb8d`](https://github.com/langchain-ai/deepagentsjs/commit/b2afb8d600570b633fd97d4d2f8fd8bdb229ce35),
[`68337fc`](https://github.com/langchain-ai/deepagentsjs/commit/68337fcca19a6d7cc18e8917d575ea9ca3aebcbe),
[`7550c65`](https://github.com/langchain-ai/deepagentsjs/commit/7550c65204bdd9141a88b9b42d46899e05c7bc43)]:
  - deepagents@1.12.4

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-14 09:43:10 -07:00
Thushanth Bengre 68337fcca1 fix(deepagents): coerce grep tool's max_count to a number (#751)
Fixes #745 

`max_count` was the only numeric grep param without type coercion,
causing ToolInputParsingException on stringified input. Switched to
z.coerce.number().
2026-08-14 12:18:42 -04:00
Thushanth Bengre 7550c65204 fix(deepagents): exclude summarization state from subagent input/output (#749)
Fixes #748 

Excludes `_summarizationEvent`/`_summarizationSessionId` from subagent
state input/output. These weren't in `EXCLUDED_STATE_KEYS`, so a stale
parent cutoffIndex could silently drop a subagent's task description,
and a subagent's own summarization event could overwrite the parent's on
return.
2026-08-14 08:54:08 -04:00
Caspar Broekhuizen b2afb8d600 fix(deepagents): batch concurrent Context Hub mutations (#747)
ContextHubBackend now preserves concurrent file mutations in one durable
commit and retains compatible remote changes during conflict recovery.

---

Concurrent callers previously reused the same parent commit, causing
409s. Retries could also replay stale edit payloads.

Mutations now coalesce for 50 ms into serialized multi-file commits.
Conflict recovery replays ordered edit intent against refreshed state;
explicit writes, uploads, and deletes remain last-writer-wins.

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-08-13 15:54:55 -07:00
github-actions[bot] 44d6d3dfea chore: version packages (#733)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.24

### Patch Changes

- Updated dependencies
[[`77e104f`](https://github.com/langchain-ai/deepagentsjs/commit/77e104f26a62ae34afbb1393edf191009d37280c),
[`239be7e`](https://github.com/langchain-ai/deepagentsjs/commit/239be7e883227e463504652bc00272ec947a21a6),
[`1439bbf`](https://github.com/langchain-ai/deepagentsjs/commit/1439bbfb267e92b7a19ce0924399591495976c21)]:
  - deepagents@1.12.3
## deepagents@1.12.3

### Patch Changes

- [#724](https://github.com/langchain-ai/deepagentsjs/pull/724)
[`77e104f`](https://github.com/langchain-ai/deepagentsjs/commit/77e104f26a62ae34afbb1393edf191009d37280c)
Thanks [@gethin-langchain](https://github.com/gethin-langchain)! -
feat(deepagents): add `output_mode` parameter to the `grep` tool
(`files_with_matches` / `content` / `count`)

- [#732](https://github.com/langchain-ai/deepagentsjs/pull/732)
[`239be7e`](https://github.com/langchain-ai/deepagentsjs/commit/239be7e883227e463504652bc00272ec947a21a6)
Thanks [@hntrl](https://github.com/hntrl)! - fix(deepagents): disable
summary-input trimming by default

Match Python DeepAgents by providing the full selected conversation to
the summarizer unless `trimTokensToSummarize` is explicitly configured.
This prevents oversized tool results from producing context-empty
summaries under the default configuration.

- [#739](https://github.com/langchain-ai/deepagentsjs/pull/739)
[`1439bbf`](https://github.com/langchain-ai/deepagentsjs/commit/1439bbfb267e92b7a19ce0924399591495976c21)
Thanks [@taoche](https://github.com/taoche)! - fix(deepagents): extract
text from content blocks when building the summary
## @deepagents/evals@0.0.23

### Patch Changes

- Updated dependencies
[[`77e104f`](https://github.com/langchain-ai/deepagentsjs/commit/77e104f26a62ae34afbb1393edf191009d37280c),
[`239be7e`](https://github.com/langchain-ai/deepagentsjs/commit/239be7e883227e463504652bc00272ec947a21a6),
[`1439bbf`](https://github.com/langchain-ai/deepagentsjs/commit/1439bbfb267e92b7a19ce0924399591495976c21)]:
  - deepagents@1.12.3

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-12 16:02:01 -07:00
Wei Tao 1439bbfb26 fix(deepagents): extract text from content blocks when building the summary (#739)
## Description

`SummarizationMiddleware`'s `createSummary` falls back to
`JSON.stringify(response.content)` when the summarization model's
response content is not a string:

```ts
return typeof response.content === "string"
  ? response.content
  : JSON.stringify(response.content);
```

When the summarization model responds with a content block array, the
raw blocks are stringified verbatim into the summary `HumanMessage`.
This happens in practice when:

- **Thinking/reasoning is enabled** on the summarization model (e.g.
Claude on Bedrock with `thinking`): the content is `[{type: "reasoning",
reasoning: ..., signature: <opaque multi-KB signature>}, {type: "text",
...}]`, and the reasoning signature lands in the summary.
- **`invoke()` takes the internal streaming path** (a `prefersStreaming`
callback handler is attached, e.g. inside `streamEvents`, and
`disableStreaming` is not set): the aggregated `AIMessageChunk` content
is an array of many small text fragments.

Observed in production: a summary message of ~56KB consisting of an ~8KB
opaque reasoning signature plus hundreds of
`{"type":"text","text":"..."}` fragments — the "summary" ended up
bloating the context it was supposed to compact, and subsequent model
calls overflowed.

## Fix

Use the message's `text` accessor for non-string content, which extracts
and joins only the text blocks. String content is returned as-is
(unchanged behavior).

## Testing

Added a unit test where the summarization model returns reasoning +
split text blocks, asserting the summary message contains the joined
text and no reasoning payload. All 33 existing tests pass.

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-08-11 00:15:46 -07:00
gethin-langchain 77e104f26a feat(deepagents): add output_mode parameter to the grep tool (#724)
## Summary
- The grep tool's description mentioned output_mode, but it was never an
actual parameter the tool always returned one hardcoded format.
- Added output_mode (files_with_matches/content/count) as a real schema
parameter, using the existing formatGrepMatches helper.

## Test plan
- Added tests in fs.test.ts for files_with_matches and count modes.
- All tests pass.

Note: default output is now sorted by path with no blank lines between
file groups (minor formatting change, same info).

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-08-06 07:13:21 +00:00
Hunter Lovell 239be7e883 fix(deepagents): disable summary input trimming by default (#732)
## Summary

Prevent default DeepAgents JS summarization from discarding an oversized
message before it reaches the summary model

## Changes

### `deepagents`

- Make `trimTokensToSummarize` opt-in rather than defaulting to 4,000
tokens.
- Preserve existing capped behavior when callers explicitly configure
the option.
- Add coverage confirming oversized summary input reaches the summary
model under default configuration.
- Add a patch changeset for the bug fix.
2026-08-05 14:42:51 -07:00
github-actions[bot] 5af75fffbe chore: version packages (#726)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.23

### Patch Changes

- Updated dependencies
[[`590c2a5`](https://github.com/langchain-ai/deepagentsjs/commit/590c2a5042473f096d5fac5ddbb4be96e2ace0f2)]:
  - deepagents@1.12.2
## deepagents@1.12.2

### Patch Changes

- [#723](https://github.com/langchain-ai/deepagentsjs/pull/723)
[`590c2a5`](https://github.com/langchain-ai/deepagentsjs/commit/590c2a5042473f096d5fac5ddbb4be96e2ace0f2)
Thanks
[@thushanth-bengre-langchain](https://github.com/thushanth-bengre-langchain)!
- fix(deepagents): prevent stack overflow in CompositeBackend grep/glob
on huge result sets, and add a grep match-count cap

`CompositeBackend` accumulated merged `ls`/`grep`/`glob` results with
`push(...entries)`, which passes every entry as a separate function
argument and overflows the call stack (RangeError: Maximum call stack
size exceeded) when a broad search over a large tree returns hundreds of
thousands of entries. Results are now accumulated with a plain loop, so
no result-set size can overflow the stack.

`grep` also gains an optional `maxCount` (backend) / `max_count` (tool)
cap, mirroring the Python SDK. When the cap is hit, results are flagged
`truncated: true` on `GrepResult`/`GlobResult` and the grep tool appends
a note telling the model to narrow the search. The cap defaults to 1000
via the `grepMaxCount` middleware option (set to `null` to disable).
`CompositeBackend` splits the budget across routed backends and
OR-propagates the `truncated` flag on merged results.
## @deepagents/evals@0.0.22

### Patch Changes

- Updated dependencies
[[`590c2a5`](https://github.com/langchain-ai/deepagentsjs/commit/590c2a5042473f096d5fac5ddbb4be96e2ace0f2)]:
  - deepagents@1.12.2

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-04 15:20:01 -04:00
thushanth-bengre-langchain 590c2a5042 fix(deepagents): prevent stack overflow in CompositeBackend grep/glob (#723)
## Summary

- Fixes `RangeError: Maximum call stack size exceeded` from
`CompositeBackend.glob`/`grep` when a broad search (e.g.
`**/*.{ts,tsx,...}` at `/`) returns hundreds of thousands of entries.
Root cause: results were merged with `push(...entries)`, which passes
each entry as a separate function argument and overflows V8's
argument-stack limit. Now accumulated with a plain loop.
- Ports the Python SDK's grep match-count cap (`ef591e7`): optional
`maxCount` backend param / `max_count` tool arg, `grepMaxCount`
middleware option (default 1000, `null` disables), `truncated` flag on
`GrepResult`/`GlobResult`, and a truncation note in the grep tool
output. `CompositeBackend` splits the budget across routes and
OR-propagates `truncated`.

## Backward compatibility

- `truncated` is optional; `maxCount` defaults to unset everywhere. No
required changes for existing or new users.

## Test plan

- [x] Regression test: mocked backend returning 200k entries —
`glob`/`grep` complete without `RangeError` (verified it fails with the
old spread).
- [x] Cap enforcement, `truncated` propagation across composite routes,
middleware note rendering.
- [x] `pnpm test` (format + lint + all lib tests) passes.
2026-08-04 11:27:03 -07:00
github-actions[bot] 064b1724de chore: version packages (#715)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.22

### Patch Changes

- Updated dependencies
[[`ffec5de`](https://github.com/langchain-ai/deepagentsjs/commit/ffec5de0e66ed5ab64bc4c6bee2ff90effb4bfa1)]:
  - deepagents@1.12.1
## deepagents@1.12.1

### Patch Changes

- [#713](https://github.com/langchain-ai/deepagentsjs/pull/713)
[`ffec5de`](https://github.com/langchain-ai/deepagentsjs/commit/ffec5de0e66ed5ab64bc4c6bee2ff90effb4bfa1)
Thanks [@gethin-langchain](https://github.com/gethin-langchain)! -
fix(deepagents): grep/glob match when `path` points directly at a file
## @deepagents/evals@0.0.21

### Patch Changes

- Updated dependencies
[[`ffec5de`](https://github.com/langchain-ai/deepagentsjs/commit/ffec5de0e66ed5ab64bc4c6bee2ff90effb4bfa1)]:
  - deepagents@1.12.1

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-31 08:10:45 +00:00
gethin-langchain ffec5de0e6 fix(deepagents): grep/glob match when path points directly at a file (#713)
## Summary
- `grep`/`glob` on `StateBackend`/`StoreBackend` returned zero matches
whenever `path` pointed at an exact file (no glob) — the shared
`validatePath` helper forced a trailing `/` before prefix-matching, so a
file's own key could never match itself+`/`.
- Added a `filterFilesByPath` helper that checks for an exact key match
in the files map first, falling back to the existing directory-prefix
behavior otherwise.

## Test plan
- [x] Added regression tests in `utils.test.ts`: exact-file path (no
glob) for grep and glob, plus directory + glob/filename non-regression
cases for both.
- [x] `pnpm --filter deepagents test` — all tests pass.
2026-07-31 00:54:11 -07:00
github-actions[bot] bed2d344bc chore: version packages (#712)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents@1.12.0

### Minor Changes

- [#703](https://github.com/langchain-ai/deepagentsjs/pull/703)
[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): adopt
more minimal prompting

We've observed that current models don't need as verbose of prompting
guidance, so we're reducing the amount of perscriptive guidance that
deepagents has. This is reflected in the generic system prompt (which is
now blank), and in the tool descriptions (which have been simplified).

- [#708](https://github.com/langchain-ai/deepagentsjs/pull/708)
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): make todo
middleware opt-in

- [#674](https://github.com/langchain-ai/deepagentsjs/pull/674)
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): allow
`write_file` to create missing files or completely replace existing
files
## deepagents-acp@0.1.21

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0
## @langchain/node-vfs@1.0.0

### Patch Changes

- [#674](https://github.com/langchain-ai/deepagentsjs/pull/674)
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)
Thanks [@hntrl](https://github.com/hntrl)! - fix: allow
`VfsBackend.write` to overwrite existing files while continuing to
reject symlinks
## @langchain/daytona@1.0.0


## @langchain/deno@1.0.0


## @langchain/modal@1.0.0


## @langchain/quickjs@1.0.0


## @langchain/sandbox-standard-tests@2.0.0


## @deepagents/evals@0.0.20

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-29 09:47:28 -07:00
Hunter Lovell b177148922 chore: exit pre-release (#711) 2026-07-29 09:26:40 -07:00
github-actions[bot] 149f4585f1 chore: version packages (rc) (#709)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`main` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `main`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## deepagents@1.12.0-rc.1

### Minor Changes

- [#708](https://github.com/langchain-ai/deepagentsjs/pull/708)
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): make todo
middleware opt-in
## deepagents-acp@0.1.21-rc.1

### Patch Changes

- Updated dependencies
[[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0)]:
  - deepagents@1.12.0-rc.1
## @deepagents/evals@0.0.20-rc.1

### Patch Changes

- Updated dependencies
[[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0)]:
  - deepagents@1.12.0-rc.1

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-27 08:48:51 -07:00
Hunter Lovell 1225a7ff86 feat(deepagents): make todo middleware opt-in (#708)
## Summary

Makes `todoListMiddleware` opt-in. Default agents and default subagents
no longer expose `write_todos` or the `todos` state channel, reducing
the default tool surface while preserving explicit opt-in.

## Changes

- Remove default todo middleware from the main, general-purpose, and
declarative subagent stacks.
- Preserve opt-in support through `middleware: [todoListMiddleware()]`;
declarative subagents opt in through their own middleware.
- Remove `write_todos` from always-present tool typing and built-in
name-collision handling.
- Update state and subagent documentation plus shared runtime assertions
for the optional todo state/tool.

### Harness profiles and coverage

- Re-add todo middleware in the Codex harness profile because its
model-specific prompt requires `write_todos`
- Apply profile `extraMiddleware` to subagent stacks, with profile
factories creating fresh instances per stack.
- Add coverage for default exclusion, explicit opt-in,
main/GP/declarative isolation, profile middleware propagation, and type
inference.
2026-07-24 15:40:43 -07:00
github-actions[bot] a55022dc2f chore: version packages (rc) (#699)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`main` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `main`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## deepagents@1.12.0-rc.0

### Minor Changes

- [#703](https://github.com/langchain-ai/deepagentsjs/pull/703)
[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): adopt
more minimal prompting

We've observed that current models don't need as verbose of prompting
guidance, so we're reducing the amount of perscriptive guidance that
deepagents has. This is reflected in the generic system prompt (which is
now blank), and in the tool descriptions (which have been simplified).

- [#674](https://github.com/langchain-ai/deepagentsjs/pull/674)
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): allow
`write_file` to create missing files or completely replace existing
files
## deepagents-acp@0.1.21-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @langchain/daytona@1.0.0-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @langchain/deno@1.0.0-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @langchain/modal@1.0.0-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @langchain/node-vfs@1.0.0-rc.0

### Patch Changes

- [#674](https://github.com/langchain-ai/deepagentsjs/pull/674)
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)
Thanks [@hntrl](https://github.com/hntrl)! - fix: allow
`VfsBackend.write` to overwrite existing files while continuing to
reject symlinks

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @langchain/quickjs@1.0.0-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @langchain/sandbox-standard-tests@2.0.0-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0
## @deepagents/evals@0.0.20-rc.0

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0-rc.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-23 21:18:40 -07:00
Hunter Lovell d25097f78d feat(deepagents): simplify prompting (#703)
## Summary

The SDK currently ships authored base prose plus middleware guidance
that largely duplicates the tool schemas. This change adopts a more lean
default: no authored base prompt, no duplicate built-in usage prose, and
concise tool descriptions.

Skills, memory, custom system prompts, custom tool descriptions, and
required filesystem routing context remain intact. The legacy
base-prompt surface is removed rather than preserved as a default path.

## Changes

### Default prompt

- Remove the authored default base prompt and its obsolete public
surface.
- Suppress LangChain's default todo middleware prompt while leaving
deepagents-owned middleware prompt-free by default.
- Remove unused filesystem, subagent, async-subagent, and execution
prompt constants and exports.

### Durable tool guidance

- Keep large-result recovery guidance in `read_file` and `grep`
descriptions.
- Keep async task status freshness guidance in `check_async_task` and
`list_async_tasks` descriptions.
- Trim filesystem and task descriptions to their purpose and
load-bearing constraints.
- Build grep and execute descriptions from the configured filesystem
tool set so they do not recommend unavailable tools.

### Token impact

Offline (`o200k_base`, default-agent tool schemas):

| Tool | Before | After | Delta |
| --- | ---: | ---: | ---: |
| `task` | 1,664 | 389 | -77% |
| `read_file` | 728 | 494 | -32% |
| `grep` | 688 | 555 | -19% |
| `edit_file` | 273 | 257 | -6% |
| `glob` | 217 | 172 | -21% |
| `write_file` | 177 | 177 | — |
| `delete` | 146 | 146 | — |
| `ls` | 111 | 111 | — |
| **Total** | **4,005** | **2,302** | **-43%** |

For a default-agent `hello` turn, input tokens drop from 5,395 to 1,895
(-65%).

### Evaluation results

The lean prompt matched the baseline on correctness (0.81) and solve
rate (0.635 vs. 0.634). Unified evaluation macro and micro scores
improved from 0.413 to 0.437 and from 0.371 to 0.394, respectively. (see
more detailed results in
https://github.com/langchain-ai/deepagents/pull/5009 and
https://github.com/langchain-ai/deepagents/pull/4859)
2026-07-23 21:06:12 -07:00
Hunter Lovell ef794da80b chore: rc pre-release (#701) 2026-07-23 18:56:03 -07:00
Hunter Lovell dd142fe4fc feat(deepagents): allow write_file to overwrite files (#674)
## Summary

`write_file` now creates missing files and replaces existing files
entirely, removing the previous create-only error path while preserving
write permissions and symlink protections.

## Changes

### deepagents filesystem backends

- Updated `FilesystemBackend`, `StateBackend`, `StoreBackend`,
`BaseSandbox`, and `node-vfs` write behavior to allow full-file
replacement on existing paths.
- Preserved path safety and symlink protections in filesystem-backed
writes.
- Removed the sandbox existence precheck so writes rely on the
upload/write transport.

### Tool prompts and examples

- Aligned the `write_file` tool description and schema text with the
Python SDK wording.
- Updated sandbox example prompts so `write_file` is described as
creating or fully replacing files.

### Tests and evals

- Updated backend, middleware, and shared sandbox standard tests that
previously expected an existing-file error.
- Added overwrite coverage for filesystem, sandbox, state, store,
middleware, node-vfs, and file-operation evals.

### Release

- Added a changeset for `deepagents` documenting the new overwrite
behavior.
2026-07-22 16:10:05 -07:00
github-actions[bot] 60e32118b0 chore: version packages (#694)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.20

### Patch Changes

- Updated dependencies
[[`2ebb178`](https://github.com/langchain-ai/deepagentsjs/commit/2ebb1785e4625ecf82635582e17fe41fbfbac603)]:
  - deepagents@1.11.1
## deepagents@1.11.1

### Patch Changes

- [#693](https://github.com/langchain-ai/deepagentsjs/pull/693)
[`2ebb178`](https://github.com/langchain-ai/deepagentsjs/commit/2ebb1785e4625ecf82635582e17fe41fbfbac603)
Thanks [@colifran](https://github.com/colifran)! - fix(deepagents):
return recoverable errors for invalid/denied filesystem tool paths
instead of throwing
## @deepagents/evals@0.0.19

### Patch Changes

- Updated dependencies
[[`2ebb178`](https://github.com/langchain-ai/deepagentsjs/commit/2ebb1785e4625ecf82635582e17fe41fbfbac603)]:
  - deepagents@1.11.1

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-17 15:10:22 -07:00
Colin Francis 2ebb1785e4 fix(deepagents): return recoverable errors for invalid/denied filesystem tool paths instead of throwing (#693)
### Summary

Invalid (non-absolute, `..`, or `~`) or denied filesystem paths passed
by an agent cause the tool to throw which raises a `MiddlewareError` and
causes the whole agent run to crash.

This PR replaces `enforcePermission` which was re-validating the path
without a try/catch with `checkPermission` which returns the error to
the model as a normal tool result so the model can correct the path and
try again instead of crashing.

### Tests

Updated the three permission suites to assert an error result instead of
a throw and added a regression block for `~`/relative/`..` paths that
returns a recoverable error and never calls the backend.
2026-07-17 14:58:14 -07:00
github-actions[bot] f127e3d442 chore: version packages (#676)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents@1.11.0

### Minor Changes

- [#671](https://github.com/langchain-ai/deepagentsjs/pull/671)
[`6ae9d1e`](https://github.com/langchain-ai/deepagentsjs/commit/6ae9d1eab92131ea9cfd7bef024cf1ab343641ea)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): add
allowlist for filesystem middleware tools

- [#669](https://github.com/langchain-ai/deepagentsjs/pull/669)
[`4643148`](https://github.com/langchain-ai/deepagentsjs/commit/4643148e8b64c796d3144210bac3ad1c6f5b2091)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): add
structured system prompt configuration

- [#673](https://github.com/langchain-ai/deepagentsjs/pull/673)
[`eb18c70`](https://github.com/langchain-ai/deepagentsjs/commit/eb18c70d8d0871bc72aeb8be6581a98506829c6f)
Thanks [@hntrl](https://github.com/hntrl)! - feat(backends): add delete
protocol support

Adds a `DeleteResult` type and optional backend `delete` method,
preserves delete through backend protocol adaptation, and implements
file deletion across the built-in state, store, filesystem, composite,
context hub, sandbox, and node-vfs backends.

### Patch Changes

- [#691](https://github.com/langchain-ai/deepagentsjs/pull/691)
[`39a7049`](https://github.com/langchain-ai/deepagentsjs/commit/39a7049e4dbf99a31223c4e31cf79a2ed5115634)
Thanks [@colifran](https://github.com/colifran)! - fix(deepagents):
backend adapter drops route prefixes

- [#672](https://github.com/langchain-ai/deepagentsjs/pull/672)
[`cc26c41`](https://github.com/langchain-ai/deepagentsjs/commit/cc26c41df2851acacc86a743878b5c847a8f5d59)
Thanks [@hntrl](https://github.com/hntrl)! - fix(deepagents): allow
custom middleware to replace defaults by name
## deepagents-acp@0.1.19

### Patch Changes

- Updated dependencies
[[`39a7049`](https://github.com/langchain-ai/deepagentsjs/commit/39a7049e4dbf99a31223c4e31cf79a2ed5115634),
[`6ae9d1e`](https://github.com/langchain-ai/deepagentsjs/commit/6ae9d1eab92131ea9cfd7bef024cf1ab343641ea),
[`cc26c41`](https://github.com/langchain-ai/deepagentsjs/commit/cc26c41df2851acacc86a743878b5c847a8f5d59),
[`4643148`](https://github.com/langchain-ai/deepagentsjs/commit/4643148e8b64c796d3144210bac3ad1c6f5b2091),
[`eb18c70`](https://github.com/langchain-ai/deepagentsjs/commit/eb18c70d8d0871bc72aeb8be6581a98506829c6f)]:
  - deepagents@1.11.0
## @langchain/node-vfs@0.2.1

### Patch Changes

- [#673](https://github.com/langchain-ai/deepagentsjs/pull/673)
[`eb18c70`](https://github.com/langchain-ai/deepagentsjs/commit/eb18c70d8d0871bc72aeb8be6581a98506829c6f)
Thanks [@hntrl](https://github.com/hntrl)! - feat(backends): add delete
protocol support

Adds a `DeleteResult` type and optional backend `delete` method,
preserves delete through backend protocol adaptation, and implements
file deletion across the built-in state, store, filesystem, composite,
context hub, sandbox, and node-vfs backends.
## @deepagents/evals@0.0.18

### Patch Changes

- Updated dependencies
[[`39a7049`](https://github.com/langchain-ai/deepagentsjs/commit/39a7049e4dbf99a31223c4e31cf79a2ed5115634),
[`6ae9d1e`](https://github.com/langchain-ai/deepagentsjs/commit/6ae9d1eab92131ea9cfd7bef024cf1ab343641ea),
[`cc26c41`](https://github.com/langchain-ai/deepagentsjs/commit/cc26c41df2851acacc86a743878b5c847a8f5d59),
[`4643148`](https://github.com/langchain-ai/deepagentsjs/commit/4643148e8b64c796d3144210bac3ad1c6f5b2091),
[`eb18c70`](https://github.com/langchain-ai/deepagentsjs/commit/eb18c70d8d0871bc72aeb8be6581a98506829c6f)]:
  - deepagents@1.11.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-15 21:08:41 -07:00
Colin Francis 39a7049e4d fix(deepagents): backend adapter drops route prefixes (#691)
### Summary

`adaptBackendProtocol` rebuilds the backend into a v2 backend protocol
but drops its `routePrefixes`. Since `resolveBackend` runs every backend
through the adapter, a resolved `CompositeBackend` was no longer
detected as composite. That made the execute tool's guard fail at
invocation and disable the execute tool even when filesystem permissions
were correctly scoped to composite routes.

This PR fixes this by forwarding `routePrefixes` through
`adaptBackendProtocol` instead of dropping them.

### Tests

Added unit tests in backends/utils.test.ts to verify that
`routePrefixes` is forwarded through `adaptBackendProtocol` and
`adaptSandboxProtocol` and not added for non-composite backends.
2026-07-15 20:25:35 -07:00
Hunter Lovell cc26c41df2 fix(deepagents): merge custom middleware by name (#672)
## Summary

Adds middleware override behavior to replace default middleware by
`.name` instead of always being appended.

## Changes

- Add name-keyed middleware merging so custom middleware replaces
matching default middleware in-place and appends novel middleware after
the core stack.
- Apply default-slot middleware overrides consistently when constructing
main-agent and subagent middleware stacks, while preventing parent-only
middleware from propagating unless it matches a subagent default slot.
- Move harness tool exclusion into a private `_ToolExclusionMiddleware`
helper so excluded tools are stripped after tool-injecting middleware
has run.
- Add coverage for main-agent replacement, subagent/default override
propagation, parent-only middleware isolation, profile exclusions,
tool-exclusion ordering, and merge precedence.
2026-07-14 19:08:52 -07:00
Hunter Lovell f09bc61d7a feat(deepagents): implement delete across backends (#680)
## Summary

Implements the optional backend `delete` protocol across the built-in
backend implementations now that the delete protocol surface is
available. This keeps delete behavior backend-local and does not expose
a new filesystem tool to agents.

## Changes

### deepagents

- Implements `delete(filePath)` for filesystem, store, composite,
context hub, and sandbox backends.
- Uses backend-specific safety semantics: filesystem deletion goes
through existing path resolution and only unlinks files, store deletion
treats paths as exact keys, context hub deletion commits null entries,
and sandbox deletion uses shell-quoted `rm -f`.
- Adds tests covering successful deletion, missing paths, directory
rejection where applicable, composite route path restoration, store
wildcard literal behavior, and context hub cache updates/failure
handling.

### @langchain/node-vfs

- Implements `delete(filePath)` for the VFS backend.
- Adds tests for file deletion, missing paths, directory rejection, and
preserving non-target files.
2026-07-14 17:31:16 -07:00
Hunter Lovell 6ae9d1eab9 feat(deepagents): add filesystem tool allowlist (#671)
## Summary

Adds a `tools` allowlist option to `createFilesystemMiddleware` so
callers can restrict which built-in filesystem tools are exposed to the
model. The middleware now builds the filesystem system prompt from the
tools that are actually visible on the request, avoiding instructions
for tools that were filtered by the allowlist or backend capability
checks.

## Changes

- Adds a public `FsToolName` type and `tools` option to
`FilesystemMiddlewareOptions`.
- Filters filesystem middleware tools at construction time when an
explicit allowlist is provided, while preserving existing `execute`
backend capability filtering.
- Requires `read_file` in explicit allowlists because it is needed for
filesystem workflows and large-result recovery.
- Generates the filesystem tool prompt dynamically from visible
filesystem tools, and only appends execute-specific instructions when
`execute` is actually available.
- Adds unit and integration coverage for allowlist behavior, prompt
filtering, unsupported `execute`, and user-provided non-filesystem
tools.
2026-07-14 13:42:55 -07:00
Hunter Lovell eb18c70d8d feat(deepagents): add delete protocol support (#673)
## Summary

Adds protocol-level delete support for deepagents backends.

## Changes

### deepagents

- Adds `DeleteResult` to the backend protocol exports.
- Adds optional `delete(filePath)` support to v1 and v2 backend
protocols.
- Preserves optional delete implementations when adapting backends to
the v2 protocol.
- Implements `StateBackend.delete()` for zero-argument StateBackend
instances by sending `{ [filePath]: null }` through `__pregel_send`.
- Adds a changeset for the new backend protocol capability.
2026-07-14 10:20:08 -07:00
Hunter Lovell 4643148e8b feat(deepagents): add structured system prompt configuration (#669)
## Summary

Ports the system prompt configuration in langchain-ai/deepagents#4437
2026-07-13 16:24:56 -07:00
github-actions[bot] 4507acd92e chore: version packages (#670)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.18

### Patch Changes

- Updated dependencies
[[`7c8a770`](https://github.com/langchain-ai/deepagentsjs/commit/7c8a770fac90fd50dfe08af67a0ce073a33e4ef7)]:
  - deepagents@1.10.8
## deepagents@1.10.8

### Patch Changes

- [#668](https://github.com/langchain-ai/deepagentsjs/pull/668)
[`7c8a770`](https://github.com/langchain-ai/deepagentsjs/commit/7c8a770fac90fd50dfe08af67a0ce073a33e4ef7)
Thanks [@colifran](https://github.com/colifran)! - fix(deepagents):
fast-glob follows directory symlink cycles leading to ELOOP crashes
## @deepagents/evals@0.0.17

### Patch Changes

- Updated dependencies
[[`7c8a770`](https://github.com/langchain-ai/deepagentsjs/commit/7c8a770fac90fd50dfe08af67a0ce073a33e4ef7)]:
  - deepagents@1.10.8

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-13 12:50:19 -07:00
Colin Francis 7c8a770fac fix(deepagents): fast-glob follows directory symlink cycles leading to ELOOP crashes (#668)
### Summary

`fast-glob` follows symbolic links by default so the `glob`/`grep` tools
in `FilesystemBackend` and `LocalShellBackend` walked directory symlink
cycles recursively causing `ELOOP` crashes. and aborted the run over a
target repo.

This PR fixes by adding`followSymbolicLinks: false` to all four
`fast-glob` calls. Bonus: this keeps traversal inside the search root.

### Tests
Unit tests in `filesystem.test.ts` and `local-shell.test.ts` verifying
that a `sub/sub -> .` cycle now traverses cleanly without traversing
symlinks.

This is an upstream fix for:
https://github.com/langchain-ai/openwiki/issues/72
2026-07-13 12:41:34 -07:00
github-actions[bot] 3eab2cad6f chore: version packages (#660)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.17

### Patch Changes

- Updated dependencies
[[`8efde93`](https://github.com/langchain-ai/deepagentsjs/commit/8efde93792dfc324e70b441eacbb810532f347c4)]:
  - deepagents@1.10.7
## deepagents@1.10.7

### Patch Changes

- [#659](https://github.com/langchain-ai/deepagentsjs/pull/659)
[`8efde93`](https://github.com/langchain-ai/deepagentsjs/commit/8efde93792dfc324e70b441eacbb810532f347c4)
Thanks [@Kowshik4593](https://github.com/Kowshik4593)! - Fix: Normalize
`path` to `file_path` in filesystem tools (`read_file`, `write_file`,
and `edit_file`) and align the prompt documentation examples to prevent
validation schema failures on weaker/custom models.
## @deepagents/evals@0.0.16

### Patch Changes

- Updated dependencies
[[`8efde93`](https://github.com/langchain-ai/deepagentsjs/commit/8efde93792dfc324e70b441eacbb810532f347c4)]:
  - deepagents@1.10.7

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Colin Francis <colin.francis@langchain.dev>
2026-07-08 14:04:15 -07:00
Kowshik Padala 8efde93792 feat(deepagents): implement filesystem state management middleware with atomic update support and testing (#659)
## Problem
Addresses #658.

When using weaker or custom LLMs (e.g., smaller open-source models) in
`deepagents` and consumers like `openwiki`, the agent immediately
crashes with a schema validation error on the first filesystem tool
call:


This occurs because:
1. `ls` defines its directory argument as `path`, but `read_file`,
`write_file`, and `edit_file` expect `file_path`. Models often default
to `path` across all filesystem tools.
2. The description prompt examples in `fs.ts` and `skills.ts` show
`read_file(path, ...)`, instructing models to use the wrong parameter
name.

## Proposed Changes
This PR solves both prompt inconsistencies and schema validation
failures with a fully backward-compatible input normalization helper:

1. **Prompt Alignment**: Fixed references in `fs.ts` and `skills.ts` to
instruct the model to use `file_path` (aligned with the prompt fixes in
#644).
2. **Schema Input Normalization**: Added a `normalizeFilePathInput`
preprocessor helper to the `read_file`, `write_file`, and `edit_file`
Zod schemas using `z.preprocess`. This dynamically maps the `path` key
to `file_path` if the model still passes `path`.

## Verification & Tests
- Added unit tests in `fs.test.ts` to assert that:
- `path` parameter normalization maps correctly to `file_path` for
`read_file`, `write_file`, and `edit_file`.
  - All instruction examples contain only valid schema fields.
- Verified that `zod-to-json-schema` unwraps the `z.preprocess` layer
perfectly, preserving the original schema descriptions and definitions
sent to the LLM.
- Ran all filesystem tests successfully (`npx vitest run
src/middleware/fs.test.ts` passes).
2026-07-08 13:20:36 -07:00
github-actions[bot] ff8cc5c4b4 chore: version packages (#607)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/quickjs@0.6.0

### Minor Changes

- [#606](https://github.com/langchain-ai/deepagentsjs/pull/606)
[`3c8f8b2`](https://github.com/langchain-ai/deepagentsjs/commit/3c8f8b2ea6f0204353c63bf49c3fdc6655bf1069)
Thanks [@colifran](https://github.com/colifran)! - chore(quickjs):
disallow task as a configurable ptc tool
## deepagents-acp@0.1.16

### Patch Changes

- Updated dependencies
[[`d7ecab2`](https://github.com/langchain-ai/deepagentsjs/commit/d7ecab2d9f9d41321a043eed6edc3366a1381a67),
[`1a2b2df`](https://github.com/langchain-ai/deepagentsjs/commit/1a2b2df5528f0f61870b054fff8291355f6a2a0b),
[`42f34b6`](https://github.com/langchain-ai/deepagentsjs/commit/42f34b65ededf4a1fbf3cd4bbff486ddfeb320e9),
[`0ae10d7`](https://github.com/langchain-ai/deepagentsjs/commit/0ae10d7e26c84203a5273939c9ad7a9c8c8661c6)]:
  - deepagents@1.10.6
## deepagents@1.10.6

### Patch Changes

- [#608](https://github.com/langchain-ai/deepagentsjs/pull/608)
[`d7ecab2`](https://github.com/langchain-ai/deepagentsjs/commit/d7ecab2d9f9d41321a043eed6edc3366a1381a67)
Thanks [@aolsenjazz](https://github.com/aolsenjazz)! - fix(deepagents):
forward subagent results as text

Fixed a 400 `invalid_request_error` that occurred when a subagent used
an Anthropic server-side tool (web search, web fetch, or code
execution): the subagent's `server_tool_use`/`*_tool_result` blocks were
forwarded to the parent agent as `tool_result` content, which the API
rejects. Subagent results are now passed back to the parent as their
text content (matching the Python implementation), which resolves the
error and also handles a trailing empty `end_turn` message.

- [#656](https://github.com/langchain-ai/deepagentsjs/pull/656)
[`1a2b2df`](https://github.com/langchain-ai/deepagentsjs/commit/1a2b2df5528f0f61870b054fff8291355f6a2a0b)
Thanks [@colifran](https://github.com/colifran)! - fix(deepagents):
default unknown file extensions to text/plain

- [#611](https://github.com/langchain-ai/deepagentsjs/pull/611)
[`42f34b6`](https://github.com/langchain-ai/deepagentsjs/commit/42f34b65ededf4a1fbf3cd4bbff486ddfeb320e9)
Thanks [@aolsenjazz](https://github.com/aolsenjazz)! - feat(deepagents):
add bedrockPromptCachingMiddleware to default stack

Add bedrockPromptCachingMiddleware to default middleware stack. This
automatically opts-in to Bedrock prompt caching for Nova and Anthropic
models

- [#613](https://github.com/langchain-ai/deepagentsjs/pull/613)
[`0ae10d7`](https://github.com/langchain-ai/deepagentsjs/commit/0ae10d7e26c84203a5273939c9ad7a9c8c8661c6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(deepagents): declare LangChain runtime packages as peer dependencies

Move `@langchain/core`, `@langchain/langgraph`,
`@langchain/langgraph-sdk`, and
`langchain` from `dependencies` to `peerDependencies`, and also declare
`@langchain/langgraph-checkpoint` as a peer (its
`BaseCheckpointSaver`/`BaseStore`
types are part of the public API), so they resolve to a single shared
instance in
  the consumer's tree. Previously they were bundled as regular
dependencies, which let a consumer end up with two copies of
`@langchain/core`
(e.g. `1.2.0` vs `1.2.1`). Because these packages ship classes with
private/
protected fields, the duplicate copies are treated as nominally distinct
types,
producing errors like passing a `ChatOpenAI` model to `createDeepAgent`
or a
compiled graph to the local protocol helpers. As peers, the app controls
the
version and bumping `@langchain/core` no longer requires a `deepagents`
release.
## @langchain/daytona@0.2.1

### Patch Changes

- [#614](https://github.com/langchain-ai/deepagentsjs/pull/614)
[`5b462f2`](https://github.com/langchain-ai/deepagentsjs/commit/5b462f2ab2400fba52906e8f1485a500ec5b6e17)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
Replace deprecated `@daytonaio/sdk` dependency with `@daytona/sdk`.
## @langchain/modal@0.1.5

### Patch Changes

- [#657](https://github.com/langchain-ai/deepagentsjs/pull/657)
[`5f93c11`](https://github.com/langchain-ai/deepagentsjs/commit/5f93c114759399002a3981a93e3df13981514b1d)
Thanks [@colifran](https://github.com/colifran)! - fix(modal): modal low
level file handle api `sandbox.open` has been removed
## @deepagents/evals@0.0.15

### Patch Changes

- Updated dependencies
[[`d7ecab2`](https://github.com/langchain-ai/deepagentsjs/commit/d7ecab2d9f9d41321a043eed6edc3366a1381a67),
[`1a2b2df`](https://github.com/langchain-ai/deepagentsjs/commit/1a2b2df5528f0f61870b054fff8291355f6a2a0b),
[`42f34b6`](https://github.com/langchain-ai/deepagentsjs/commit/42f34b65ededf4a1fbf3cd4bbff486ddfeb320e9),
[`0ae10d7`](https://github.com/langchain-ai/deepagentsjs/commit/0ae10d7e26c84203a5273939c9ad7a9c8c8661c6)]:
  - deepagents@1.10.6

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Colin Francis <colin.francis@langchain.dev>
2026-07-08 09:16:25 -07:00
Colin Francis 1a2b2df552 fix(deepagents): default unknown file extensions to text/plain (#656)
### Summary

`read_file` couldn't read many common text files and with Anthropic it
crashes the whole run. `getMimeType()` mapped any unrecognized extension
to `application/octet-stream`, which `isTextMimeType()` treats as
binary, so the file got base64-encoded into a document block.

This defaults unknown extensions to `text/plain` instead. Known binaries
(images, audio, video, PDF/PPT) stay explicitly mapped, so image and PDF
handling is unchanged. Files like `.properties`, `.scss`, `.tf`,
`.lock`, and extension-less files like `Dockerfile` now read as text.

  ### Tests
  
Flipped the unknown-extension unit test to expect `text/plain`.
2026-07-08 09:04:32 -07:00
Colin Francis 5f93c11475 fix(modal): modal sandboxes fail to upload files (#657)
### Summary

Modal v0.8.0 released the following breaking change:
```
Breaking: Removed the deprecated low-level file-handle API: Sandbox.Open / SandboxFile (Go), and sandbox.open / SandboxFile (JS). Use the Sandbox Filesystem API instead: sandbox.Filesystem() (Go) / sandbox.filesystem (JS).
```
Ref:
https://github.com/modal-labs/modal-client/blob/main/CHANGELOG_GO_JS.md

This PR updates our implementation to use the sandbox filesystem api

### Tests

Updated `sandbox.test.ts` mocks to model `sandbox.filesystem`
2026-07-08 08:52:34 -07:00
Christian Bromann 5b462f2ab2 fix: migrate Daytona SDK dependency [closes #609] (#614)
## Description
Closes #609 by updating `@langchain/daytona` to the maintained
`@daytona/sdk` at `^0.184.0` while preserving the same SDK API usage.
Added a patch changeset; `@daytona/sdk` is Apache-2.0 and maintained by
Daytona as the direct replacement for deprecated `@daytonaio/sdk`.

## Self-Hosted Release Note
`@langchain/daytona` now depends on `@daytona/sdk` instead of deprecated
`@daytonaio/sdk`.

## Test Plan
- [ ] Verify package publish metadata resolves `@daytona/sdk`
`^0.184.0`.

Made by [Open
SWE](https://openswe.vercel.app/agents/d6f434c5-39c6-eef7-6cc6-670cf092bb67)

Co-authored-by: Christian Bromann <731337+christian-bromann@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-06-29 08:25:57 -07:00
Christian Bromann 0ae10d7e26 fix(deepagents): declare LangChain runtime packages as peer dependencies (#613)
Updates to `@langchain/core` can cause downstream friction with
TypeScript:

```
Type 'ChatOpenAI<ChatOpenAICallOptions>' is not assignable to type 'string | BaseLanguageModel<any, BaseLanguageModelCallOptions> | undefined'.
  Type 'ChatOpenAI<ChatOpenAICallOptions>' is not assignable to type 'BaseLanguageModel<any, BaseLanguageModelCallOptions>'.
    Types of property 'getGraph' are incompatible.
      Type '(_?: import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/runnables/types").RunnableConfig<Record<string, any>> | undefined) => import("/Users/christian.bromann/Sites/L...' is not assignable to type '(_?: import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/runnables/types").RunnableConfig<Record<string, any>> | undefined) => import("/Users/christian.bromann/Sites/L...'.
        Types of parameters '_' and '_' are incompatible.
          Type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/runnables/types").RunnableConfig<Record<string, any>> | undefined' is not assignable to type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/runnables/types").RunnableConfig<Record<string, any>> | undefined'.
            Type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/runnables/types").RunnableConfig<Record<string, any>>' is not assignable to type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/runnables/types").RunnableConfig<Record<string, any>>'.
              Types of property 'callbacks' are incompatible.
                Type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").Callbacks | undefined' is not assignable to type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").Callbacks | undefined'.
                  Type 'CallbackManager' is not assignable to type 'Callbacks | undefined'.
                    Type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManager' is not assignable to type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManager'.
                      The types returned by 'handleLLMStart(...)' are incompatible between these types.
                        Type 'Promise<import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManagerForLLMRun[]>' is not assignable to type 'Promise<import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManagerForLLMRun[]>'.
                          Type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManagerForLLMRun[]' is not assignable to type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManagerForLLMRun[]'.
                            Type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.0_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManagerForLLMRun' is not assignable to type 'import("/Users/christian.bromann/Sites/LangChain/deployment-cookbook/js-langsmith/node_modules/.pnpm/@langchain+core@1.2.1_openai@6.44.0_ws@8.21.0_zod@4.4.3__ws@8.21.0/node_modules/@langchain/core/dist/callbacks/manager").CallbackManagerForLLMRun'.
                              Property 'inheritableHandlers' is protected but type 'BaseRunManager' is not a class derived from 'BaseRunManager'.ts(2322)
```

to avoid this we should move the LangChain dependency to become peer
deps.

- Moved `@langchain/core`, `@langchain/langgraph`,
`@langchain/langgraph-sdk`, and `langchain` from `dependencies` to
`peerDependencies` in `libs/deepagents`, keeping dev copies for isolated
build/test.
- Lets consumers bump `@langchain/core` without requiring a new
`deepagents` release; a release is only needed to widen the peer range
across a major.
- Note on install contract: npm 7+ and pnpm 8+ auto-install peers; Yarn
only warns, so Yarn users must add the four packages explicitly (worth a
README follow-up).

---------

Signed-off-by: Christian Bromann <git@bromann.dev>
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
2026-06-22 17:25:00 -07:00
Alexander Olsen d7ecab2d9f fix(deepagents): forward subagent results as text (#608)
## Summary

A deep agent that delegates to a subagent 400s when that subagent uses
an Anthropic server-side tool (web search, web fetch, code execution,
MCP). The subagent's final-message content blocks e.g.
server_tool_use/..._tool_result were forwarded verbatim as the task
ToolMessage content. On the parent agent's next request they serialize
into a tool_result, which Anthropic rejects:

`400 invalid_request_error
messages.N.content.0.tool_result.content.0: Input tag 'server_tool_use'
found using 'type'
does not match any of the expected tags:
'document','image','search_result','text','tool_reference'`

## Solution

Now matches the Python impl: forward only the subagent's text answer.
returnCommandWithStateUpdate now walks back to the last AIMessage with
non-empty text and uses that text (a string) as the ToolMessage content.

- Confirmed the Python deepagents impl is not affected (it forwards
.text); this aligns JS with Python.
- Reproduced the 400 across {web_search, code_execution, web_fetch} ×
{claude-haiku-4-5, claude-sonnet-4-6} on the latest published packages;
all green after the fix.

## Tests
- New: subagent server-tool blocks are filtered from forwarded content.
- New: walk-back uses the last non-empty AIMessage, skipping a trailing
empty message.
- Updated the #239/#245 tests to assert the (now string) ToolMessage
content.
- No regressions in subagent-related tests in the evals suite

---------

Signed-off-by: Alexander Olsen <aolsenjazz@gmail.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-06-22 11:43:03 -04:00
Alexander Olsen 42f34b65ed feat(deepagents): add bedrockPromptCachingMiddleware to default stack (#611)
## Summary

- Adds `bedrockPromptCachingMiddleware` to the default middleware stack
- Adds unit tests for the Bedrock model detection util function covering
the different formats of model strings/`ChatModel`s
2026-06-22 11:12:59 -04:00
Colin Francis 3c8f8b2ea6 chore(quickjs): disallow task as a configurable ptc tool (#606)
### Summary

The code interpreter now comes with a global `task` tool out of the box.
As a result, we should disallow specifying the `task` tool for ptc. This
PR implements logic that forbids the task tool as in ptc and throws with
a detailed error message if found. This PR also updates the RLM agent
example and READMEs.

### Tests

Unit tests validating expected behavior for task by name and tool
instance with "task" name.
2026-06-18 15:07:53 -07:00
github-actions[bot] a9e1ba1b89 chore: version packages (#605)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents-acp@0.1.15

### Patch Changes

- Updated dependencies
[[`7c4a11e`](https://github.com/langchain-ai/deepagentsjs/commit/7c4a11eacc11c3720b70d802068300ac3b4d8651)]:
  - deepagents@1.10.5
## deepagents@1.10.5

### Patch Changes

- [#598](https://github.com/langchain-ai/deepagentsjs/pull/598)
[`7c4a11e`](https://github.com/langchain-ai/deepagentsjs/commit/7c4a11eacc11c3720b70d802068300ac3b4d8651)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(stream): use langchain `run.subagents` instead of bespoke
transformer

Remove deepagents' custom `createSubagentTransformer` and rely on the
native
  subagent stream that `createAgent` registers (langchain#37739). Keep
`DeepAgentRunStream` as a compile-time overlay that narrows
`run.subagents` to
declared subagent specs. Update streaming tests for `cause` and
per-subagent
  message coverage.
## @langchain/quickjs@0.5.1

### Patch Changes

- [#602](https://github.com/langchain-ai/deepagentsjs/pull/602)
[`204cb27`](https://github.com/langchain-ai/deepagentsjs/commit/204cb27414c82c34a0c681c7e5a5336e1834f058)
Thanks [@colifran](https://github.com/colifran)! - chore(quickjs):
refine dynamic subagent prompt to trigger on workflow keyword and to
improve iterative eval behavior

- [#604](https://github.com/langchain-ai/deepagentsjs/pull/604)
[`0971007`](https://github.com/langchain-ai/deepagentsjs/commit/0971007ab2491e73eb1a78c5426ab934470d5620)
Thanks [@colifran](https://github.com/colifran)! - fix(quickjs): unwrap
Command/ToolMessage envelopes from tool and subagent results
## @deepagents/evals@0.0.14

### Patch Changes

- Updated dependencies
[[`7c4a11e`](https://github.com/langchain-ai/deepagentsjs/commit/7c4a11eacc11c3720b70d802068300ac3b4d8651)]:
  - deepagents@1.10.5

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-18 09:38:18 -07:00
Christian Bromann 7c4a11eacc fix(deepagents): use langchain run.subagents instead of bespoke transformer (#598)
## Summary
- Remove deepagents' bespoke `createSubagentTransformer` (~460 lines)
and wire `createDeepAgent` to langchain's native `run.subagents`
projection from `createAgent` (langchain#37739).
- Slim `stream.ts` to type-only exports: re-export `SubagentRunStream`
from langchain and keep `DeepAgentRunStream` as a compile-time narrowing
over declared subagent specs.
- Update streaming tests for `sub.cause` (replacing `taskInput`), add
single-subagent `sub.messages` coverage, and document parallel-subagent
streaming behavior.
- Pin `langchain@1.4.6-dev-1781497519109` and `@langchain/langgraph` /
`@langchain/langgraph-checkpoint` to `d2312cf` dev builds (root
`pnpm.overrides`) for end-to-end verification until published releases
are available.
- Clarify `streamTransformers` docs: custom transformers surface on
`run.extensions`; built-in streams like `run.subagents` and
`run.toolCalls` are separate.

fixes #560
2026-06-18 09:36:50 -07:00
Colin Francis 0971007ab2 fix(quickjs): unwrap Command/ToolMessage envelopes from tool and subagent results (#604)
### Summary

The deepagents `task` tool resolves to a LangGraph `Command` (and some
tools return a `ToolMessage` or a list of messages), but the quickjs
bridges passed these envelopes straight to the REPL so `task(...)` and
PTC `tools.*` calls handed the model the wrapper instead of the
subagent's actual output, breaking the contract that a `responseSchema`
dispatch resolves to a typed value.

This PR adds `unwrapToolEnvelope`: a duck-typed unwrap of `Command` /
`ToolMessage` / message-list shapes that reverse-scans `update.messages`
for the last message with content and reads both live and serialized
forms. Non-envelope values pass through unchanged.

`unwrapToolEnvelope` is wired into both bridges, i.e., the `task()`
dispatch and the PTC `tools.*` bridge.

Inspired by the Python's
[`coerce_tool_output_for_ptc`](https://github.com/langchain-ai/deepagents/blob/4c347603162e181c721e5e2a5ca8bbff6828e23c/libs/partners/quickjs/langchain_quickjs/_format.py#L93-L119).

### Tests

- `coerce.test.ts` provide unit test coverage for `unwrapToolEnvelope`:
string/null/undefined passthrough, `Command` (single + multi-message),
reverse-scan past empty trailing messages, serialized `kwargs.content`,
bare `ToolMessage`, message lists, content-block arrays and plain `{
content }` objects left untouched.
- `middleware.test.ts` provides an integration test that the `task()`
bridge returns the parsed structured value from a `Command` result.
2026-06-18 06:27:35 -07:00