Commit Graph

2909 Commits

Author SHA1 Message Date
github-actions[bot] e5bd490c52 chore: version packages (#2470)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.13

### Patch Changes

- [#2469](https://github.com/langchain-ai/langgraphjs/pull/2469)
[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): normalize HITL edit decisions for Python servers

`StreamController.respond()` now mirrors camelCase and snake_case on
edit
decisions (`editedAction` / `edited_action`) so JS clients can resume
    human-in-the-loop interrupts against Python LangGraph servers.

## @langchain/angular@1.0.13

### Patch Changes

- Updated dependencies
\[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]:
    -   @langchain/langgraph-sdk@1.9.13

## @langchain/react@1.0.13

### Patch Changes

- Updated dependencies
\[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]:
    -   @langchain/langgraph-sdk@1.9.13

## @langchain/svelte@1.0.13

### Patch Changes

- Updated dependencies
\[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]:
    -   @langchain/langgraph-sdk@1.9.13

## @langchain/vue@1.0.13

### Patch Changes

- Updated dependencies
\[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]:
    -   @langchain/langgraph-sdk@1.9.13

## @example/ai-elements@0.1.28

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.13

## @examples/assistant-ui-claude@0.1.28

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.13

## @examples/ui-angular@0.0.38

### Patch Changes

- Updated dependencies
\[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]:
    -   @langchain/langgraph-sdk@1.9.13
    -   @langchain/angular@1.0.13

## @examples/ui-multimodal@0.0.14

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.13

## @examples/ui-react@0.0.14

### Patch Changes

- Updated dependencies
\[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]:
    -   @langchain/langgraph-sdk@1.9.13
    -   @langchain/react@1.0.13

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.13 @langchain/langgraph-sdk@1.9.13 @langchain/react@1.0.13 @langchain/svelte@1.0.13 @langchain/vue@1.0.13
2026-06-02 11:34:58 -07:00
Christian Bromann 0bbe66e31d fix(sdk): normalize HITL edit decisions for Python servers (#2469)
## Summary
- Normalize HITL resume payloads in `StreamController.respond()` and
`respondAll()` so edit decisions include both `editedAction` and
`edited_action`.
- Add `normalizeHitlResponseForServer` in the SDK UI layer and export it
for direct use.
- Cover normalization with unit tests on the payload helper and on
`respond()` wiring.
2026-06-02 11:30:15 -07:00
github-actions[bot] c6b29fb040 chore: version packages (#2465)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint-mongodb@1.3.3

### Patch Changes

- [#2260](https://github.com/langchain-ai/langgraphjs/pull/2260)
[`4d03dcb`](https://github.com/langchain-ai/langgraphjs/commit/4d03dcbc28bbfdf4c0f0ac065b9853652836d2f9)
Thanks [@venkat22022202](https://github.com/venkat22022202)! -
fix(mongodb): include pendingWrites in list() results

## @langchain/langgraph@1.3.4

### Patch Changes

- [#2035](https://github.com/langchain-ai/langgraphjs/pull/2035)
[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51)
Thanks [@JadenKim-dev](https://github.com/JadenKim-dev)! - fix(core):
prevent Zod schema defaults from overwriting checkpoint state in
Command.update

- Updated dependencies
\[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph-sdk@1.9.12

## @langchain/langgraph-sdk@1.9.12

### Patch Changes

- [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467)
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): route headless tool resumes through respond on v1 stream

`useStream` was calling `submit(null, { command })` for headless-tool
resumes,
    which dispatches `run.start` without delivering the tool result. Add
`applyHeadlessToolResumeCommand` to route payloads through `respond` /
`respondAll`, and tighten headless-tool browser tests to assert
end-to-end
    resume and graph completion.

## @langchain/angular@1.0.12

### Patch Changes

- [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467)
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): route headless tool resumes through respond on v1 stream

`useStream` was calling `submit(null, { command })` for headless-tool
resumes,
    which dispatches `run.start` without delivering the tool result. Add
`applyHeadlessToolResumeCommand` to route payloads through `respond` /
`respondAll`, and tighten headless-tool browser tests to assert
end-to-end
    resume and graph completion.

- Updated dependencies
\[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph-sdk@1.9.12

## @langchain/react@1.0.12

### Patch Changes

- [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467)
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): route headless tool resumes through respond on v1 stream

`useStream` was calling `submit(null, { command })` for headless-tool
resumes,
    which dispatches `run.start` without delivering the tool result. Add
`applyHeadlessToolResumeCommand` to route payloads through `respond` /
`respondAll`, and tighten headless-tool browser tests to assert
end-to-end
    resume and graph completion.

- Updated dependencies
\[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph-sdk@1.9.12

## @langchain/svelte@1.0.12

### Patch Changes

- [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467)
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): route headless tool resumes through respond on v1 stream

`useStream` was calling `submit(null, { command })` for headless-tool
resumes,
    which dispatches `run.start` without delivering the tool result. Add
`applyHeadlessToolResumeCommand` to route payloads through `respond` /
`respondAll`, and tighten headless-tool browser tests to assert
end-to-end
    resume and graph completion.

- Updated dependencies
\[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph-sdk@1.9.12

## @langchain/vue@1.0.12

### Patch Changes

- [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467)
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): route headless tool resumes through respond on v1 stream

`useStream` was calling `submit(null, { command })` for headless-tool
resumes,
    which dispatches `run.start` without delivering the tool result. Add
`applyHeadlessToolResumeCommand` to route payloads through `respond` /
`respondAll`, and tighten headless-tool browser tests to assert
end-to-end
    resume and graph completion.

- Updated dependencies
\[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph-sdk@1.9.12

## @example/ai-elements@0.1.27

### Patch Changes

- Updated dependencies
\[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51),
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph@1.3.4
    -   @langchain/react@1.0.12

## @examples/assistant-ui-claude@0.1.27

### Patch Changes

- Updated dependencies
\[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51),
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph@1.3.4
    -   @langchain/react@1.0.12

## @examples/ui-angular@0.0.37

### Patch Changes

- Updated dependencies
\[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51),
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph@1.3.4
    -   @langchain/langgraph-sdk@1.9.12
    -   @langchain/angular@1.0.12

## @examples/ui-multimodal@0.0.13

### Patch Changes

- Updated dependencies
\[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51),
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph@1.3.4
    -   @langchain/react@1.0.12

## @examples/ui-react@0.0.13

### Patch Changes

- Updated dependencies
\[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51),
[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]:
    -   @langchain/langgraph@1.3.4
    -   @langchain/langgraph-sdk@1.9.12
    -   @langchain/react@1.0.12

## langgraph@1.0.36

### Patch Changes

- Updated dependencies
\[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51)]:
    -   @langchain/langgraph@1.3.4

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.12 @langchain/langgraph-checkpoint-mongodb@1.3.3 @langchain/langgraph-sdk@1.9.12 @langchain/langgraph@1.3.4 @langchain/react@1.0.12 @langchain/svelte@1.0.12 @langchain/vue@1.0.12
2026-06-02 10:57:53 -07:00
Christian Bromann 0491534712 fix(sdk): route headless tool resumes through respond on v1 stream (#2467)
## Summary

- Fix headless-tool resume on the v1 stream protocol by routing resume
payloads through `applyHeadlessToolResumeCommand` (`respond` /
`respondAll`) instead of `submit(null, { command })`.
- Export `applyHeadlessToolResumeCommand` and
`HeadlessToolResumeController` from `@langchain/langgraph-sdk` and
re-export from `@langchain/react`.
- Strengthen headless-tool browser tests across React, Vue, Angular, and
Svelte to assert tool result values, final agent message, idle loading
state, and no lingering interrupts.
2026-06-02 10:53:27 -07:00
Venkata Krishnan S 4d03dcbc28 fix(langgraph-checkpoint-mongodb): include pendingWrites in list() results (#2260)
## Summary

Fixes #2205
Fixes #589

`MongoDBSaver.list()` does not query or return `pendingWrites` in the
yielded `CheckpointTuple` objects. This is inconsistent with
`getTuple()` (which correctly queries the writes collection) and with
other checkpointer implementations like Postgres.

## Fix

Added the same `pendingWrites` query from `getTuple()` into `list()`,
ensuring each yielded checkpoint tuple includes its pending writes.

## Test Plan

- Store checkpoints with pending writes via MongoDBSaver
- Call `list()` and verify `pendingWrites` are populated
- Compare with `getTuple()` output to confirm consistency

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 22:17:40 -07:00
Youngho Kim 7c3a98b23a fix(core): prevent Zod schema defaults from overwriting checkpoint state in Command.update (#2035)
Fixes #2031

When using `Command({ update })` with a Zod schema that has `.default()`
on fields, Zod's `parse()` injects default values for missing fields
into the update object. These injected keys then overwrite values
restored from the checkpoint.

**Root cause:** `_validateInput` passes `Command.update` through
`interopParse(schema, input.update)`, which triggers Zod defaults for
any field not present in the update.

**Fix:** After parsing, filter the result to only include keys that were
present in the original update input — matching the behavior of
`StateSchema.validateInput` which already iterates only over
`Object.entries(data)`.

Added regression tests for both Zod v3 and v4.

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-06-01 22:14:09 -07:00
Kimaswa Emmanuel Yusufu bc3b98e1bd docs: import messagesStateReducer in low_level.md example (#2464)
The `messagesStateReducer` example on the Low Level concepts page uses
`messagesStateReducer` as its reducer, but the import only brings in
`Annotation` and the `Messages` type. Copy-pasting it as-is fails to
compile with `Cannot find name 'messagesStateReducer'`. This adds it to
the import. The equivalent example just below already imports it the
same way.
2026-06-01 21:46:23 -07:00
github-actions[bot] d2ca90f8e2 chore: version packages (#2453)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint@1.0.4

### Patch Changes

- [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344)
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)
Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps):
bump uuid to 14.0.0 and keep checkpoint ID ordering stable

Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid
11, `v6({ clockseq })` no longer advances the sub-millisecond time
counter when an explicit `clockseq` is passed, so checkpoint IDs created
within the same millisecond were ordered only by `clockseq`. Since
checkpoint IDs are sorted lexicographically, this broke ordering — most
visibly for the negative `clockseq` used by the first ("input")
checkpoint, which sorted as the newest.

`uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock
(mirroring uuid 10's internal v1 behavior) so the time component is
always strictly increasing and checkpoint ordering no longer depends on
the `clockseq` value. `emptyCheckpoint()` also uses a non-negative
`clockseq`.

## @langchain/langgraph-checkpoint-mongodb@1.3.2

### Patch Changes

- [#2186](https://github.com/langchain-ai/langgraphjs/pull/2186)
[`26c2e32`](https://github.com/langchain-ai/langgraphjs/commit/26c2e325f435a2c061d6b78a7bd6af089cb1e0e6)
Thanks [@jackjin1997](https://github.com/jackjin1997)! - fix: metadata
filter in list() now works by querying a plain JSON shadow copy instead
of the serialized binary blob

## @langchain/langgraph-checkpoint-postgres@1.0.2

### Patch Changes

- [#2255](https://github.com/langchain-ai/langgraphjs/pull/2255)
[`e82a50b`](https://github.com/langchain-ai/langgraphjs/commit/e82a50b961a9413dab1ad2248747d5c73a6a1e58)
Thanks [@leesta24](https://github.com/leesta24)! -
fix(checkpoint-postgres): move serialization outside transaction in
put()

## @langchain/langgraph-checkpoint-redis@1.0.7

### Patch Changes

- [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344)
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)
Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps):
bump uuid to 14.0.0 and keep checkpoint ID ordering stable

Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid
11, `v6({ clockseq })` no longer advances the sub-millisecond time
counter when an explicit `clockseq` is passed, so checkpoint IDs created
within the same millisecond were ordered only by `clockseq`. Since
checkpoint IDs are sorted lexicographically, this broke ordering — most
visibly for the negative `clockseq` used by the first ("input")
checkpoint, which sorted as the newest.

`uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock
(mirroring uuid 10's internal v1 behavior) so the time component is
always strictly increasing and checkpoint ordering no longer depends on
the `clockseq` value. `emptyCheckpoint()` also uses a non-negative
`clockseq`.

## @langchain/langgraph-api@1.2.4

### Patch Changes

- [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344)
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)
Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps):
bump uuid to 14.0.0 and keep checkpoint ID ordering stable

Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid
11, `v6({ clockseq })` no longer advances the sub-millisecond time
counter when an explicit `clockseq` is passed, so checkpoint IDs created
within the same millisecond were ordered only by `clockseq`. Since
checkpoint IDs are sorted lexicographically, this broke ordering — most
visibly for the negative `clockseq` used by the first ("input")
checkpoint, which sorted as the newest.

`uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock
(mirroring uuid 10's internal v1 behavior) so the time component is
always strictly increasing and checkpoint ordering no longer depends on
the `clockseq` value. `emptyCheckpoint()` also uses a non-negative
`clockseq`.

-   Updated dependencies \[]:
    -   @langchain/langgraph-ui@1.2.4

## @langchain/langgraph-cli@1.2.4

### Patch Changes

- [#1925](https://github.com/langchain-ai/langgraphjs/pull/1925)
[`6503319`](https://github.com/langchain-ai/langgraphjs/commit/65033191cc3dd671d64dfac78ccdad453fdfbda2)
Thanks [@jbrody-nexxa](https://github.com/jbrody-nexxa)! - fix(cli): add
--no-reload flag to dev command

- Updated dependencies
\[[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-api@1.2.4

## @langchain/langgraph@1.3.3

### Patch Changes

- [#2037](https://github.com/langchain-ai/langgraphjs/pull/2037)
[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f)
Thanks [@pawel-twardziak](https://github.com/pawel-twardziak)! -
Decouple `ContextType` generic from `configurable` in `PregelOptions` so
that providing a custom context type no longer incorrectly narrows the
configurable parameter.

- [#2457](https://github.com/langchain-ai/langgraphjs/pull/2457)
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(langgraph): pass context with stateful RemoteGraph runs

Pop `thread_id` from run `config.configurable` and forward `context` to
the SDK so checkpointed remote runs accept user context without a 400
from ambiguous parameters. Closes
[#1922](https://github.com/langchain-ai/langgraphjs/issues/1922).

- [#1988](https://github.com/langchain-ai/langgraphjs/pull/1988)
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7)
Thanks [@Axadali](https://github.com/Axadali)! - Fix race condition in
IterableReadableWritableStream.push() that caused ERR_INVALID_STATE
errors when streaming with multiple parallel nodes and aborting the
stream.

- [#2409](https://github.com/langchain-ai/langgraphjs/pull/2409)
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3)
Thanks [@pragnyanramtha](https://github.com/pragnyanramtha)! - Preserve
non-plain objects passed through `Send` and `Command` argument
deserialization.

- [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344)
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)
Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps):
bump uuid to 14.0.0 and keep checkpoint ID ordering stable

Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid
11, `v6({ clockseq })` no longer advances the sub-millisecond time
counter when an explicit `clockseq` is passed, so checkpoint IDs created
within the same millisecond were ordered only by `clockseq`. Since
checkpoint IDs are sorted lexicographically, this broke ordering — most
visibly for the negative `clockseq` used by the first ("input")
checkpoint, which sorted as the newest.

`uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock
(mirroring uuid 10's internal v1 behavior) so the time component is
always strictly increasing and checkpoint ordering no longer depends on
the `clockseq` value. `emptyCheckpoint()` also uses a non-negative
`clockseq`.

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11
    -   @langchain/langgraph-checkpoint@1.0.4

## @langchain/langgraph-supervisor@1.0.4

### Patch Changes

- [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344)
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)
Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps):
bump uuid to 14.0.0 and keep checkpoint ID ordering stable

Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid
11, `v6({ clockseq })` no longer advances the sub-millisecond time
counter when an explicit `clockseq` is passed, so checkpoint IDs created
within the same millisecond were ordered only by `clockseq`. Since
checkpoint IDs are sorted lexicographically, this broke ordering — most
visibly for the negative `clockseq` used by the first ("input")
checkpoint, which sorted as the newest.

`uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock
(mirroring uuid 10's internal v1 behavior) so the time component is
always strictly increasing and checkpoint ordering no longer depends on
the `clockseq` value. `emptyCheckpoint()` also uses a non-negative
`clockseq`.

## @langchain/langgraph-sdk@1.9.11

### Patch Changes

- [#2455](https://github.com/langchain-ai/langgraphjs/pull/2455)
[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856)
Thanks [@JHSeo-git](https://github.com/JHSeo-git)! - fix(sdk): prefer
completed task's direct mapping over pending checkpoint's positional
guess in fetchSubagentHistory

- [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344)
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)
Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps):
bump uuid to 14.0.0 and keep checkpoint ID ordering stable

Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid
11, `v6({ clockseq })` no longer advances the sub-millisecond time
counter when an explicit `clockseq` is passed, so checkpoint IDs created
within the same millisecond were ordered only by `clockseq`. Since
checkpoint IDs are sorted lexicographically, this broke ordering — most
visibly for the negative `clockseq` used by the first ("input")
checkpoint, which sorted as the newest.

`uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock
(mirroring uuid 10's internal v1 behavior) so the time component is
always strictly increasing and checkpoint ordering no longer depends on
the `clockseq` value. `emptyCheckpoint()` also uses a non-negative
`clockseq`.

## @langchain/angular@1.0.11

### Patch Changes

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11

## @langchain/react@1.0.11

### Patch Changes

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11

## @langchain/svelte@1.0.11

### Patch Changes

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11

## @langchain/vue@1.0.11

### Patch Changes

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11

## @langchain/langgraph-ui@1.2.4



## @example/ai-elements@0.1.26

### Patch Changes

- Updated dependencies
\[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f),
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999),
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7),
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph@1.3.3
    -   @langchain/react@1.0.11

## @examples/assistant-ui-claude@0.1.26

### Patch Changes

- Updated dependencies
\[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f),
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999),
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7),
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph@1.3.3
    -   @langchain/react@1.0.11

## @examples/ui-angular@0.0.36

### Patch Changes

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f),
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999),
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7),
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11
    -   @langchain/langgraph@1.3.3
    -   @langchain/angular@1.0.11

## @examples/ui-multimodal@0.0.12

### Patch Changes

- Updated dependencies
\[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f),
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999),
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7),
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph@1.3.3
    -   @langchain/react@1.0.11

## @examples/ui-react@0.0.12

### Patch Changes

- Updated dependencies
\[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856),
[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f),
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999),
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7),
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph-sdk@1.9.11
    -   @langchain/langgraph@1.3.3
    -   @langchain/react@1.0.11

## langgraph@1.0.35

### Patch Changes

- Updated dependencies
\[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f),
[`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999),
[`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7),
[`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3),
[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]:
    -   @langchain/langgraph@1.3.3

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.11 @langchain/langgraph-api@1.2.4 @langchain/langgraph-checkpoint-mongodb@1.3.2 @langchain/langgraph-checkpoint-postgres@1.0.2 @langchain/langgraph-checkpoint-redis@1.0.7 @langchain/langgraph-checkpoint@1.0.4 @langchain/langgraph-cli@1.2.4 @langchain/langgraph-sdk@1.9.11 @langchain/langgraph-supervisor@1.0.4 @langchain/langgraph-ui@1.2.4 @langchain/langgraph@1.3.3 @langchain/react@1.0.11 @langchain/svelte@1.0.11 @langchain/vue@1.0.11
2026-06-01 09:20:26 -07:00
Jackjin 26c2e325f4 fix(langgraph-checkpoint-mongodb): MongoDB checkpointer metadata filter (#2186)
## Summary
- The `list()` method's metadata filter queried `metadata.${key}`
against a serialized binary blob, making it silently nonfunctional (dead
code)
- Added a plain JSON `metadata_search` field alongside the serialized
`metadata` in `put()`, and updated `list()` to query against it
- This is consistent with how Postgres (native JSONB `@>`) and SQLite
(`jsonb(CAST(...))`) handle metadata filtering

## Test plan
- [x] Existing unit tests pass (6/6)
- [ ] Integration test with real MongoDB to verify filter works against
`metadata_search`

Fixes #1591

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 23:59:11 -07:00
Pragnyan Ramtha 101b70aa8d fix: preserve non-plain Send args (#2409)
## Summary
- preserve non-plain object instances while deserializing
`Send`/`Command` argument trees
- keep recursive reconstruction for arrays, plain object records,
serialized `Command`, and serialized `Send` payloads
- add a regression test covering `Set`, `Map`, `Date`, and a custom
class instance passed through `Send`

Fixes part of #1142.

## Test plan
- `pnpm install --frozen-lockfile`
- `pnpm --filter @langchain/langgraph exec vitest run
src/tests/constants.test.ts --testNamePattern "preserves non-plain
objects"`
- `pnpm --filter @langchain/langgraph exec vitest run
src/tests/constants.test.ts`
- `pnpm exec oxfmt --check libs/langgraph-core/src/constants.ts
libs/langgraph-core/src/tests/constants.test.ts`
- `pnpm exec oxlint libs/langgraph-core/src/constants.ts
libs/langgraph-core/src/tests/constants.test.ts`
- `git diff --check`
- `pnpm --filter @langchain/langgraph build`

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 23:51:59 -07:00
dependabot[bot] 0125920a2c chore(deps): bump uuid from 10.0.0 to 14.0.0 (#2344)
Bumps [uuid](https://github.com/uuidjs/uuid) from 10.0.0 to 14.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/uuidjs/uuid/releases">uuid's
releases</a>.</em></p>
<blockquote>
<h2>v14.0.0</h2>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a>
(2026-04-19)</h2>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li>expect <code>crypto</code> to be global everywhere (requires
node@20+) (<a
href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li>
<li>drop node@18 support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>drop node@18 support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>) (<a
href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3">dc4ddb8</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>expect <code>crypto</code> to be global everywhere (requires
node@20+) (<a
href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>) (<a
href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4">f2c235f</a>)</li>
<li>Use GITHUB_TOKEN for release-please and enable npm provenance (<a
href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>) (<a
href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c">ffa3138</a>)</li>
</ul>
<h2>v13.0.2</h2>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v13.0.1...v13.0.2">13.0.2</a>
(2026-05-04)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>rerelease to fix provenance. (<a
href="https://github.com/uuidjs/uuid/commit/49ccb35f78c0c4ce1409dd2f1d89f83caadba10b">49ccb35</a>)</li>
</ul>
<h2>v13.0.1</h2>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v13.0.0...v13.0.1">13.0.1</a>
(2026-04-27)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>backport fix for GHSA-w5hq-g745-h8pq (<a
href="https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a">9d27ddf</a>)</li>
</ul>
<h2>v13.0.0</h2>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a>
(2025-09-08)</h2>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li>make browser exports the default (<a
href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>make browser exports the default (<a
href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a
href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li>
</ul>
<h2>v12.0.1</h2>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v12.0.0...v12.0.1">12.0.1</a>
(2026-04-29)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md">uuid's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a>
(2026-04-19)</h2>
<h3>Security</h3>
<ul>
<li>Fixes <a
href="https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq">GHSA-w5hq-g745-h8pq</a>:
<code>v3()</code>, <code>v5()</code>, and <code>v6()</code> did not
validate that writes would remain within the bounds of a caller-supplied
buffer, allowing out-of-bounds writes when an invalid
<code>offset</code> was provided. A <code>RangeError</code> is now
thrown if <code>offset &lt; 0</code> or <code>offset + 16 &gt;
buf.length</code>.</li>
</ul>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li><code>crypto</code> is now expected to be globally defined (requires
node@20+) (<a
href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li>
<li>drop node@18 support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li>
<li>upgrade minimum supported TypeScript version to 5.4.3, in keeping
with the project's policy of supporting TypeScript versions released
within the last two years</li>
</ul>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a>
(2025-09-08)</h2>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li>make browser exports the default (<a
href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>make browser exports the default (<a
href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a
href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li>
</ul>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v11.1.0...v12.0.0">12.0.0</a>
(2025-09-05)</h2>
<h3>⚠ BREAKING CHANGES</h3>
<ul>
<li>update to typescript@5.2 (<a
href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>)</li>
<li>remove CommonJS support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>)</li>
<li>drop node@16 support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li>add node@24 to ci matrix (<a
href="https://redirect.github.com/uuidjs/uuid/issues/879">#879</a>) (<a
href="https://github.com/uuidjs/uuid/commit/42b6178aa21a593257f0a72abacd220f0b7b8a92">42b6178</a>)</li>
<li>drop node@16 support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>) (<a
href="https://github.com/uuidjs/uuid/commit/0f38cf10366ab074f9328ae2021eea04d5f2e530">0f38cf1</a>)</li>
<li>remove CommonJS support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>) (<a
href="https://github.com/uuidjs/uuid/commit/ae786e27265f50bcf7cead196c29f1869297c42f">ae786e2</a>)</li>
<li>update to typescript@5.2 (<a
href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>) (<a
href="https://github.com/uuidjs/uuid/commit/c7ee40598ed78584d81ab78dffded9fe5ff20b01">c7ee405</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>improve v4() performance (<a
href="https://redirect.github.com/uuidjs/uuid/issues/894">#894</a>) (<a
href="https://github.com/uuidjs/uuid/commit/5fd974c12718c8848035650b69b8948f12ace197">5fd974c</a>)</li>
<li>restore node: prefix (<a
href="https://redirect.github.com/uuidjs/uuid/issues/889">#889</a>) (<a
href="https://github.com/uuidjs/uuid/commit/e1f42a354593093ba0479f0b4047dae82d28c507">e1f42a3</a>)</li>
</ul>
<h2><a
href="https://github.com/uuidjs/uuid/compare/v11.0.5...v11.1.0">11.1.0</a>
(2025-02-19)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/uuidjs/uuid/commit/7c1ea087a8149b57380fc8bb7f68c3a215cb6e4b"><code>7c1ea08</code></a>
chore(main): release 14.0.0 (<a
href="https://redirect.github.com/uuidjs/uuid/issues/926">#926</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34"><code>3d2c5b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4"><code>f2c235f</code></a>
fix!: expect <code>crypto</code> to be global everywhere (requires
node@20+) (<a
href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/529ef0899f5dd503d2ee90d690585d63d78bc212"><code>529ef08</code></a>
chore: upgrade TypeScript and fixup types (<a
href="https://redirect.github.com/uuidjs/uuid/issues/927">#927</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/086fd7976f11433edf9ac80be876b3ad243fe087"><code>086fd79</code></a>
chore: update dependencies (<a
href="https://redirect.github.com/uuidjs/uuid/issues/933">#933</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3"><code>dc4ddb8</code></a>
feat!: drop node@18 support (<a
href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/0f1f9c9c9cedbae5a1d363d5406c5dfbabe81404"><code>0f1f9c9</code></a>
chore: switch to Biome for parsing and linting (<a
href="https://redirect.github.com/uuidjs/uuid/issues/932">#932</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/e2879e64bf125add903c1eff6e0860542c605013"><code>e2879e6</code></a>
chore: use maintained version of npm-run-all (<a
href="https://redirect.github.com/uuidjs/uuid/issues/930">#930</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c"><code>ffa3138</code></a>
fix: Use GITHUB_TOKEN for release-please and enable npm provenance (<a
href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>)</li>
<li><a
href="https://github.com/uuidjs/uuid/commit/0423d49df2dc8efc300c804731d25f4d7e0fccc4"><code>0423d49</code></a>
docs: remove obsolete v1 option notes (<a
href="https://redirect.github.com/uuidjs/uuid/issues/915">#915</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/uuidjs/uuid/compare/v10.0.0...v14.0.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for uuid since your current version.</p>
</details>
<details>
<summary>Install script changes</summary>
<p>This version adds <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />


> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 23:19:01 -07:00
jbrody-nexxa 65033191cc fix(langgraph-api): port --no-reload option to js CLI to match python implementation (#1925)
Implement a CLI option --no-reload that bypasses the watcher from
restarting the server when changes to file contents are detected. This
implementation matches the python CLI option implemented here:
https://github.com/langchain-ai/langgraph/blob/main/libs/cli/langgraph_cli/cli.py#L620

fixes https://github.com/langchain-ai/langgraphjs/issues/1942

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 22:45:35 -07:00
Christian Bromann 91a5494715 fix(langgraph): pass context with stateful RemoteGraph runs (#2457)
## Summary
- Fix [#1922](https://github.com/langchain-ai/langgraphjs/issues/1922)
by porting the Python
[langgraph#6497](https://github.com/langchain-ai/langgraph/pull/6497)
behavior: `RemoteGraph` pops `thread_id` from `config.configurable` (it
stays in the URL path) and passes `context` as a top-level field to
`client.runs.stream()`.
- Stateful remote runs can now combine checkpointing (`thread_id`) with
`context` for middleware / `contextSchema` without the server rejecting
ambiguous parameters.

fixes #1922
2026-05-31 22:28:35 -07:00
Asad Ali 6d4bf927e5 fix(langgraph): StreamMessagesHandler throws "Controller is already closed" errors during parallel streaming with abort #1908 (#1988)
<h2>Fix Race Condition in
<code>IterableReadableWritableStream.push()</code></h2>

Fixes #1908

<h3>Summary</h3>
<p>This PR addresses a critical race condition in
<code>IterableReadableWritableStream.push()</code> that was causing
<code>TypeError [ERR_INVALID_STATE]: Invalid state: Controller is
already closed</code> errors when streaming a graph with multiple
parallel LLM nodes and aborting the stream (or when it completes
naturally).</p>

<h3>Problem</h3>
<p>Users were experiencing numerous <code>ERR_INVALID_STATE</code>
errors in production when:</p>
<ul>
  <li>Streaming graphs with multiple parallel LLM nodes</li>
  <li>Aborting the stream or when it completes naturally</li>
<li>In-flight token callbacks from LLMs are asynchronous and may still
execute after stream closure</li>
<li>Calling <code>enqueue()</code> on a closed controller throws the
error</li>
<li>This race condition causes console flooding in production
environments</li>
</ul>

<h3>Solution</h3>
<p>The fix implements a robust two-layer approach to handle the race
condition:</p>
<ol>
<li><strong>Pre-checking State:</strong> Checking
<code>this._closed</code> and <code>this.controller</code> existence
before attempting <code>enqueue</code></li>
<li><strong>Try-Catch Protection:</strong> Wrapping the
<code>enqueue</code> operation to catch any remaining race
conditions</li>
<li><strong>Specific Error Handling:</strong> Only suppressing the
"Controller is already closed" error while allowing other errors to
propagate</li>
<li><strong>Maintaining Semantics:</strong> Preserving all existing
functionality while preventing the problematic errors</li>
</ol>

<h3>Code Changes</h3>
<p>Modified <code>push()</code> method in
<code>libs/langgraph-core/src/pregel/stream.ts</code>:</p>

<pre><code>push(chunk: StreamChunk) {
  // Prevent pushing to a closed stream to avoid race condition errors
  if (this._closed || !this.controller) {
// Silently drop chunks when stream is closed - this is expected
behavior
    // when async operations try to push after stream termination
    return;
  }

  try {
    // Forward chunk to passthrough function if provided
    this.passthroughFn?.(chunk);

    // Attempt to enqueue the chunk to the underlying stream
    this.controller.enqueue(chunk);
  } catch (error) {
// Handle the specific case where controller was closed between check
and enqueue
    // This race condition can occur with parallel async operations
    if (error instanceof TypeError && 
        error.message.includes('Controller is already closed')) {
// Silently ignore - this is expected during stream closure with
concurrent pushes
      return;
    }
// Re-throw any other unexpected errors to maintain proper error
reporting
    throw error;
  }
}
</code></pre>

<h3>Enhanced Test Coverage</h3>
<p>Added comprehensive test scenarios covering:</p>
<ul>
  <li>Basic race condition handling</li>
  <li>Concurrent pushes during closure</li>
  <li>Rapid successive operations</li>
  <li>Passthrough function integration during race conditions</li>
  <li>Multiple close calls</li>
  <li>Parallel node simulation mimicking the original issue</li>
</ul>

<h3>Backwards Compatibility</h3>
<ul>
  <li> No changes to public API</li>
  <li> No changes to stream behavior during normal operation</li>
  <li> Maintains all existing functionality</li>
  <li> Only affects the error case (pushes after stream closure)</li>
</ul>

<h3>Testing</h3>
<p>The fix has been validated across multiple scenarios:</p>
<ul>
  <li>Basic race condition scenarios</li>
  <li>Concurrent operations during stream closure</li>
  <li>Multiple parallel nodes simulating the original issue</li>
  <li>Edge cases with multiple close calls</li>
  <li>Passthrough function integration</li>
</ul>

<h3>Impact</h3>
<ul>
<li> Eliminates console flooding with <code>ERR_INVALID_STATE</code>
errors</li>
<li> Improves stability in production environments with parallel
streaming</li>
<li> Maintains performance and functionality of normal stream
operations</li>
  <li> Safe for use with multiple parallel LLM nodes</li>
</ul>

<p>This fix resolves the race condition issue while maintaining full
backward compatibility and following best practices for error handling
in async environments.</p>

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 21:55:55 -07:00
Ibrahim Arshad c5dcbd176d fix(langgraph): handle null thread checkpoint in RemoteGraph.getState (#2331)
Fixes #2328

## Summary
This PR fixes a crash in `RemoteGraph.getState()` when the backend
returns thread state with `checkpoint: null` (for example, an existing
thread before any checkpoint-producing run).

Previously, `_createStateSnapshot` assumed `state.checkpoint` was always
present and dereferenced `state.checkpoint.thread_id`, causing:

`TypeError: Cannot read properties of null (reading 'thread_id')`

## What changed
- Added null-safe checkpoint handling in `RemoteGraph`:
- Introduced checkpoint-to-config conversion with fallback behavior when
checkpoint is null/missing.
- Falls back to the caller-provided config (e.g. `thread_id`) when
server checkpoint is absent.
- Updated state snapshot creation paths (`getState`, `getStateHistory`,
and nested task state snapshots) to use the null-safe conversion.
- Added a regression test:
- `getState handles null checkpoint` in
`libs/langgraph-core/src/tests/remote.test.ts`

## Result
`RemoteGraph.getState()` no longer throws for valid thread states where
`checkpoint` is null, and returns a usable `StateSnapshot` with fallback
config instead.

## Validation
- Added and passed targeted regression test in `remote.test.ts`.
- Ran local preflight checks:
  - formatting, lint, build passed.
- broad unit sweep passed except container-runtime-dependent suites in
`checkpoint-validation` (environment/Testcontainers limitation).

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 21:22:38 -07:00
JHSeo 863b555346 fix(sdk): prefer completed task's direct mapping over pending checkpoint's positional guess in fetchSubagentHistory (#2455)
Fixes #2454

## Problem

`StreamManager.fetchSubagentHistory` (`libs/sdk/src/ui/manager.ts`)
restores each subagent's conversation from its subgraph checkpoint by
first resolving every subagent `tool_call_id` to its subgraph
`checkpoint_ns`. It scans the parent thread's history **newest-first**
and, per checkpoint, tries two strategies:

1. **Direct mapping** — read the `tool_call_id` straight off a completed
PUSH task's result `ToolMessage` (`task.name + ":" + task.id`). The code
comments correctly call this *"more robust than positional alignment ...
preferred"*.
2. **Positional fallback** — when task results aren't populated yet,
align push tasks to the AI message's subagent tool calls by Send index
(`task.path[1]`).

The loop **breaks on the first checkpoint that yields any mapping**
(direct *or* positional). That break is the bug.

When the most recent checkpoint is a still-pending PUSH task — e.g. a
run stopped at an interrupt — its task has no result, so the direct map
is empty and the **positional fallback runs against the head checkpoint
instead**. The fallback's backward scan of `values.messages` then
latches onto a *stale* AI message whose subagent actually **completed in
an older checkpoint**, positionally aligns it to the head's unrelated
pending task, and breaks — before the loop ever reaches the older
checkpoint whose task result holds the **correct** direct mapping.

Net effect: the subagent's history is reconstructed from the **wrong
subgraph namespace** (or not at all). A newer, lower-confidence
positional guess silently shadows an older, authoritative direct mapping
— the opposite of the code's stated intent.

## Fix

Split namespace resolution into two phases:

1. **Phase 1 — direct mapping across the _entire_ history first.**
Collect all `tool_call_id → namespace` mappings from completed task
results before attempting any fallback. These are unambiguous, so no
pending head checkpoint can pre-empt them.
2. **Phase 2 — positional fallback only for tool calls still unmapped**
after phase 1 (the genuinely live/pending case). This preserves the
existing behavior for in-flight runs while guaranteeing a correct direct
mapping is never overwritten by a positional guess.

No backend/protocol change is required — the server already serializes
the correct material (the completed task result with the matching
`tool_call_id`); only the client-side resolution order was wrong.

## Testing

- Added a regression test (`fetchSubagentHistory namespace resolution`):
a pending head checkpoint sitting in front of an older checkpoint that
holds the correct completed mapping. Verified it **fails on the pre-fix
code** (`expected [ 'Stale pending result' ] to include 'Correct
research result'`) and **passes with this change**.
- `vitest run` (SDK): **595 passed**, no type errors.
- `oxlint`: 0 warnings / 0 errors · `oxfmt --check`: clean · `tsc -p
libs/sdk/tsconfig.json --noEmit`: clean.

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-31 20:54:44 -07:00
Juyi Wu e82a50b961 fix(langgraph-checkpoint-postgres): move serialization outside transaction in put() (#2255) 2026-05-29 17:47:22 -07:00
pawel-twardziak 9eb478ffee fix(langgraph): decouple ContextType from configurable in PregelOptions (#2037)
## Summary

When a `StateGraph` is created with a `contextSchema` (Zod), two
TypeScript errors occur:

1. **TS2589** ("excessively deep type instantiation") on the
`StateGraph` constructor
2. **TS2322** on `invoke()`/`stream()` - context schema fields (e.g.
`userName`, `userId`) are incorrectly required inside `configurable`
instead of top-level `context`

**Root cause:** `PregelOptions` extends `RunnableConfig<ContextType>`,
which maps the context type onto `configurable?` at the invoke/stream
level. The deep generic chain `StateGraph → Pregel → PregelOptions →
RunnableConfig<ContextType>` causes TS2589 with complex context schemas.
And TS2322 forces users to put context fields in `configurable` instead
of top-level `context`.

**Fix:** Remove the `<ContextType>` generic parameter from
`RunnableConfig` in `PregelOptions` only. This breaks the deep generic
chain at the invoke/stream boundary while preserving typed
`configurable` and `context` inside node callbacks (via
`LangGraphRunnableConfig<T>` / `Runtime<T>`).

## Changes

- **`libs/langgraph-core/src/pregel/types.ts`** - `PregelOptions` now
extends `RunnableConfig` (default) instead of
`RunnableConfig<ContextType>`. This is the only production code change.
- **`libs/langgraph-core/src/pregel/runnable_types.ts`** - Restored
`Runtime.configurable` to `ContextType` and `LangGraphRunnableConfig` to
extend `RunnableConfig<ContextType>` (reverting a previous attempt that
broke backward compat).
- **`libs/langgraph-core/src/tests/pregel.test-d.ts`** - Removed two
`@ts-expect-error` directives for invoke-level configurable (now
`Record<string, any>`, validated at runtime by Zod).
- **`libs/langgraph-core/src/tests/issue_10270_repro.test-d.ts`** -
Regression test reproducing both bugs from the issue.

## Trade-off

| Aspect | Before | After |
|--------|--------|-------|
| `graph.invoke({}, { configurable: { bad: 123 } })` | Compile error |
Compiles, validated at runtime |
| `graph.invoke({}, { context: { ... } })` | Compile error (TS2322) |
Compiles correctly ✓ |
| Node callback `config.configurable` / `config.context` | Typed as `T`
| Typed as `T` (unchanged) ✓ |
| `new StateGraph({ state, context: zodSchema })` | TS2589 | Compiles ✓
|

The only loss is compile-time validation of `configurable` content at
invoke level - mitigated by runtime Zod schema validation which the
codebase already performs.

Fixes [#10270](https://github.com/langchain-ai/langchainjs/issues/10270)

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-29 17:31:28 -07:00
dependabot[bot] 0fc86c27c5 chore(deps): bump protobufjs from 6.11.6 to 7.6.0 (#2429)
Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from
6.11.6 to 7.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/protobufjs/protobuf.js/releases">protobufjs's
releases</a>.</em></p>
<blockquote>
<h2>protobufjs: v7.6.0</h2>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.9...protobufjs-v7.6.0">7.6.0</a>
(2026-05-18)</h2>
<h3>Features</h3>
<ul>
<li>Support BigInt conversions (7.x) (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2258">#2258</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/f76924244504b159efe1bb13b154fd17be3c13e7">f769242</a>)</li>
</ul>
<h2>protobufjs: v7.5.9</h2>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.8...protobufjs-v7.5.9">7.5.9</a>
(2026-05-17)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Backport bundler-safe optional module lookups (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2254">#2254</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/0853a625680f9247596b84ef48082b8f4e554797">0853a62</a>)</li>
</ul>
<h2>protobufjs: v7.5.8</h2>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.7...protobufjs-v7.5.8">7.5.8</a>
(2026-05-12)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Backport parser hardening to 7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2245">#2245</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/54b593ffd960f7fe4b0c448a12542c3de0a0cf26">54b593f</a>)</li>
</ul>
<h2>protobufjs: v7.5.7</h2>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.6...protobufjs-v7.5.7">7.5.7</a>
(2026-05-09)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Restore first-match namespace lookup (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2236">#2236</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/cc7d59559d4e8c533a35218310c67f4a5dda54f5">cc7d595</a>)</li>
</ul>
<h2>protobufjs: v7.5.6</h2>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.5...protobufjs-v7.5.6">7.5.6</a>
(2026-04-27)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Backport input hardening and CLI fixes to 7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2173">#2173</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/75392ea1b78bdc4faba027b5db44ad7c50e9c454">75392ea</a>)</li>
</ul>
<h2>v7.5.5</h2>
<p>This release backports two reported security issues to 7.x
branch.</p>
<ul>
<li>fix: do not allow setting <code>__proto__</code> in Message
constructor (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2126">#2126</a>)</li>
<li>fix: filter invalid characters from the type name (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2127">#2127</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.4...protobufjs-v7.5.5">https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.4...protobufjs-v7.5.5</a></p>
<h2>protobufjs: v7.5.4</h2>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.3...protobufjs-v7.5.4">7.5.4</a>
(2025-08-15)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/protobufjs/protobuf.js/blob/protobufjs-v7.6.0/CHANGELOG.md">protobufjs's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.9...protobufjs-v7.6.0">7.6.0</a>
(2026-05-18)</h2>
<h3>Features</h3>
<ul>
<li>Support BigInt conversions (7.x) (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2258">#2258</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/f76924244504b159efe1bb13b154fd17be3c13e7">f769242</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.8...protobufjs-v7.5.9">7.5.9</a>
(2026-05-17)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Backport bundler-safe optional module lookups (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2254">#2254</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/0853a625680f9247596b84ef48082b8f4e554797">0853a62</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.7...protobufjs-v7.5.8">7.5.8</a>
(2026-05-12)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Backport parser hardening to 7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2245">#2245</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/54b593ffd960f7fe4b0c448a12542c3de0a0cf26">54b593f</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.6...protobufjs-v7.5.7">7.5.7</a>
(2026-05-09)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Restore first-match namespace lookup (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2236">#2236</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/cc7d59559d4e8c533a35218310c67f4a5dda54f5">cc7d595</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.5...protobufjs-v7.5.6">7.5.6</a>
(2026-04-27)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Backport input hardening and CLI fixes to 7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2173">#2173</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/75392ea1b78bdc4faba027b5db44ad7c50e9c454">75392ea</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.3...protobufjs-v7.5.4">7.5.4</a>
(2025-08-15)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>invalid syntax in descriptor.proto (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2092">#2092</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/5a3769a465fead089a533ad55c21d069299df760">5a3769a</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.2...protobufjs-v7.5.3">7.5.3</a>
(2025-05-28)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>descriptor extensions handling post-editions (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2075">#2075</a>)
(<a
href="https://github.com/protobufjs/protobuf.js/commit/6e255d4ad6982cc857f26e1731c2cedcf5796f68">6e255d4</a>)</li>
</ul>
<h2><a
href="https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.5.1...protobufjs-v7.5.2">7.5.2</a>
(2025-05-14)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/e30c3341382b504a975d0d83f19170218cb461c3"><code>e30c334</code></a>
chore: release protobufjs-v7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2260">#2260</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/f76924244504b159efe1bb13b154fd17be3c13e7"><code>f769242</code></a>
feat: Support BigInt conversions (7.x) (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2258">#2258</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/ab3862d133ab9b824f12eab5f993784333543dbf"><code>ab3862d</code></a>
chore: release protobufjs-v7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2255">#2255</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/0853a625680f9247596b84ef48082b8f4e554797"><code>0853a62</code></a>
fix: Backport bundler-safe optional module lookups (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2254">#2254</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/d7035f9b7f06210ea343cab1f2f1cc18ee5cc1d6"><code>d7035f9</code></a>
chore: release protobufjs-v7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2248">#2248</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/54b593ffd960f7fe4b0c448a12542c3de0a0cf26"><code>54b593f</code></a>
fix: Backport parser hardening to 7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2245">#2245</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/e88fcea1635f79c414e8a070e164d38ea99e104a"><code>e88fcea</code></a>
chore: release protobufjs-v7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2239">#2239</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/cc7d59559d4e8c533a35218310c67f4a5dda54f5"><code>cc7d595</code></a>
fix: Restore first-match namespace lookup (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2236">#2236</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/3abc9b54d67a7102785c6dfd8bf6610f545d445b"><code>3abc9b5</code></a>
chore: release protobufjs-v7.x (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2190">#2190</a>)</li>
<li><a
href="https://github.com/protobufjs/protobuf.js/commit/a0bf2dfdd8a75aa62ce5a1ff47a52b9b8f1ea793"><code>a0bf2df</code></a>
fix: Update CLI peer dependency (7.x) (<a
href="https://redirect.github.com/protobufjs/protobuf.js/issues/2189">#2189</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/protobufjs/protobuf.js/compare/v6.11.6...protobufjs-v7.6.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Install script changes</summary>
<p>This version modifies <code>prepublish</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=protobufjs&package-manager=npm_and_yarn&previous-version=6.11.6&new-version=7.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-29 17:31:00 -07:00
dependabot[bot] afa946ca04 chore(deps): bump js-cookie from 3.0.5 to 3.0.7 (#2422)
Bumps [js-cookie](https://github.com/js-cookie/js-cookie) from 3.0.5 to
3.0.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/js-cookie/js-cookie/releases">js-cookie's
releases</a>.</em></p>
<blockquote>
<h2>v3.0.7</h2>
<ul>
<li>Prevent cookie attribute injection: CVE-2026-46625 (eb3c40e)</li>
<li>Add <code>Partitioned</code> attribute to readme (b994768)</li>
<li>Publish to npm registry via trusted publisher exclusively
(4dc71be)</li>
<li>Ensure consistent behaviour for <code>get('name')</code> +
<code>get()</code> (1953d30)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/17bacba0171dd022728d8fdeba3203c60791bf58"><code>17bacba</code></a>
Craft v3.0.7 release</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/adb823cb7e95ead47f3af4d4951e589acbde2077"><code>adb823c</code></a>
Fix release workflow halting at <code>git tag</code></li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/5f9e759b07d2752e8407a3a43fb5f879bf384c5e"><code>5f9e759</code></a>
May remove Git user config from release workflow</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/6ac921184c7b3b7d9431c88707f56521acd72ab4"><code>6ac9211</code></a>
Fix release workflow not able to push commit + tag</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/2278bc55e1804c4c2d9bd2110a9b449949a52751"><code>2278bc5</code></a>
Fix missing package version bump</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/eb3c40e89731e99b8970faaf35ddad249c6c0020"><code>eb3c40e</code></a>
Prevent cookie attribute injection</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/f6f157f430d707d2ffd0c9c9138227a6cea564e5"><code>f6f157f</code></a>
Bump globals from 17.5.0 to 17.6.0</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/f409d022da50a0c6fa8724f087fbc50fab9a9533"><code>f409d02</code></a>
Bump eslint from 10.2.0 to 10.3.0</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/a686883c03a754c04546cfc1653911a70a640b40"><code>a686883</code></a>
Bump protobufjs in the npm_and_yarn group across 1 directory</li>
<li><a
href="https://github.com/js-cookie/js-cookie/commit/c6112d2d4f2881a12aaf89d9e2996ef6870eb6d0"><code>c6112d2</code></a>
Bump <code>@​protobufjs/utf8</code> in the npm_and_yarn group across 1
directory</li>
<li>Additional commits viewable in <a
href="https://github.com/js-cookie/js-cookie/compare/v3.0.5...v3.0.7">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for js-cookie since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-cookie&package-manager=npm_and_yarn&previous-version=3.0.5&new-version=3.0.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 00:17:46 +00:00
github-actions[bot] 381a9f64d0 chore: version packages (#2445)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint@1.0.3

### Patch Changes

- [#2352](https://github.com/langchain-ai/langgraphjs/pull/2352)
[`14f2a79`](https://github.com/langchain-ai/langgraphjs/commit/14f2a796912e81d7f52f0a4f16747f6d0a269209)
Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! -
fix(langgraph-checkpoint): block prototype pollution in MemorySaver via
reserved storage keys

    `MemorySaver` previously embedded `thread_id`, `checkpoint_ns`,
`checkpoint_id`, and `task_id` directly into property accesses on the
nested plain objects `this.storage` and `this.writes`. A caller able to
shape any of those fields (every quickstart, tutorial, and test fixture
    uses `MemorySaver` by default) could pass `"__proto__"`,
    `"constructor"`, or `"prototype"` and have the subsequent assignment
    mutate `Object.prototype`. From that point every plain object in the
    process inherits the injected property, breaking `for...in` loops,
truthy short-circuits, and downstream serializers across unrelated code
    paths. CWE-1321.

Adds an `assertSafeStorageKey` chokepoint applied at every public entry
that touches `storage` or `writes` (`put`, `putWrites`, `deleteThread`,
    `getTuple`, `list`). The guard rejects non-string values, the empty
string (unless explicitly opted-in for `checkpoint_ns`), and the three
    prototype-pollution keys. Behaviour for valid string identifiers is
    unchanged.

## @langchain/langgraph-checkpoint-redis@1.0.6

### Patch Changes

- [#2350](https://github.com/langchain-ai/langgraphjs/pull/2350)
[`1e73c6b`](https://github.com/langchain-ai/langgraphjs/commit/1e73c6b4630bbc4aa976eea4bfc33c4f753b7ee9)
Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! -
fix(checkpoint-redis): block Redis KEYS / SCAN pattern injection via
top-level identifiers

`RedisSaver` and `ShallowRedisSaver` previously embedded `thread_id`,
`checkpoint_ns`, `checkpoint_id`, and `task_id` directly into Redis keys
and `client.keys(pattern)` calls with no validation. A caller able to
    shape any of those fields (multi-tenant SDK deployments where the
`RunnableConfig` originates from request input, or webhook payloads that
flow into a persisted thread) could promote a string identifier into a
    glob pattern (`*`, `?`, `[...]`) or escape character (`\`).

    The most severe sink is `deleteThread`: a `threadId` of `*` issues
`client.keys("checkpoint:*:*")` followed by `client.del(...)`, deleting
    every checkpoint in the database across every tenant. `getTuple`,
    `list`, and `loadPendingWrites` are exposed to the same pattern via
the fallback paths that bypass the existing `escapeRediSearchTagValue`
    defense.

    Adds a single `assertSafeKeyComponent` helper exported from
    `./utils.js` and applies it at every key-building site. The guard
    asserts the value is a non-empty string (the empty `checkpoint_ns`
    default is opt-in via `{ allowEmpty: true }`) and rejects the Redis
pattern meta-characters `* ? [ ] \`. The `:` delimiter is intentionally
    permitted because LangGraph emits it as a legitimate part of
    `checkpoint_ns` for subgraphs / nested graphs, where it only ever
appears as a literal in the key. Behavior for valid string identifiers
    is unchanged.

## @langchain/langgraph-api@1.2.3

### Patch Changes

- [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447)
[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: fold forkFrom client-side and honor per-run
multitaskStrategy

    The SDK now folds the ergonomic `forkFrom` option into
`config.configurable.checkpoint_id` before sending `run.start`, so the
agent server only ever accepts the single, legacy-compliant fork field
(`forkFrom` no longer hits the wire). The protocol-v2 reference servers
    drop their top-level `forkFrom` normalization accordingly.

The protocol-v2 servers now honor the caller's `multitaskStrategy` per
run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead
of
hardcoding it, falling back to `enqueue` when omitted or unrecognized.

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)]:
    -   @langchain/langgraph-ui@1.2.3

## @langchain/langgraph-cli@1.2.3

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-api@1.2.3

## @langchain/langgraph-ui@1.2.3

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

## @langchain/langgraph-sdk@1.9.10

### Patch Changes

- [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447)
[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: fold forkFrom client-side and honor per-run
multitaskStrategy

    The SDK now folds the ergonomic `forkFrom` option into
`config.configurable.checkpoint_id` before sending `run.start`, so the
agent server only ever accepts the single, legacy-compliant fork field
(`forkFrom` no longer hits the wire). The protocol-v2 reference servers
    drop their top-level `forkFrom` normalization accordingly.

The protocol-v2 servers now honor the caller's `multitaskStrategy` per
run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead
of
hardcoding it, falling back to `enqueue` when omitted or unrecognized.

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

## @langchain/angular@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @langchain/react@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @langchain/svelte@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @langchain/vue@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @example/ai-elements@0.1.25

### Patch Changes

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/react@1.0.10

## @examples/assistant-ui-claude@0.1.25

### Patch Changes

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/react@1.0.10

## @examples/ui-angular@0.0.35

### Patch Changes

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10
    -   @langchain/angular@1.0.10

## @examples/ui-multimodal@0.0.11

### Patch Changes

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/react@1.0.10

## @examples/ui-react@0.0.11

### Patch Changes

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10
    -   @langchain/react@1.0.10

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.10 @langchain/langgraph-api@1.2.3 @langchain/langgraph-checkpoint-redis@1.0.6 @langchain/langgraph-checkpoint@1.0.3 @langchain/langgraph-cli@1.2.3 @langchain/langgraph-sdk@1.9.10 @langchain/langgraph-ui@1.2.3 @langchain/react@1.0.10 @langchain/svelte@1.0.10 @langchain/vue@1.0.10
2026-05-29 00:08:20 -07:00
Christian Bromann 4d12fe0233 docs: more readme cleanups 2026-05-29 00:06:14 -07:00
Christian Bromann 517500356d docs: update readme further 2026-05-29 00:02:44 -07:00
Christian Bromann 4c5fea793d fix(docs): update links in readme 2026-05-28 23:55:36 -07:00
Christian Bromann 313f060654 fix(sdk): fix type issue in tests 2026-05-28 23:49:47 -07:00
Christian Bromann 737b4ade89 fix(sdk): fix lint issues 2026-05-28 17:36:39 -07:00
Christian Bromann ac66625c30 fix(sdk): add browser tests for multi interrupt use case 2026-05-28 17:30:03 -07:00
Christian Bromann 2c14b12a80 fix(sdk): add back respondAll and respond config/metadata (#2448)
## Summary
- Add `respondAll(responsesById, options)` to the stream controller and
the React/Angular/Svelte/Vue wrappers, resuming multiple interrupts
pending at the same checkpoint in a single `Command({ resume })`. This
is required for runs that pause on several interrupts at once (e.g.
parallel tool-authorization prompts), which sequential `respond()` calls
cannot service.
- Change `respond()` to take an options object (`{ interruptId?,
namespace?, config?, metadata? }`), folding run-level
`config`/`metadata` onto the resumed run so it applies the same
configurable values and metadata a fresh `submit()` would.
- Extend `ThreadStream.respondInput()` to accept a `responses` batch
(mutually exclusive with the single `interrupt_id`/`response`) and clear
all responded interrupts from local state.
- Update the protocol-v2 reference servers (`embed/protocol.mts`,
`protocol/service.mts`) to read the `responses` batch plus
`config`/`metadata` leniently and fold them onto the run servicing
`input.respond`.
- Update docs (interrupts/use-stream) across all framework packages and
add controller tests for batched resume.
2026-05-28 16:53:09 -07:00
Nagendhra Madishetti 14f2a79691 fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys (#2352)
## Summary

Closes a prototype-pollution sink (CWE-1321) in `MemorySaver`. A caller
able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or
`task_id` (every quickstart, tutorial, and test fixture uses
`MemorySaver` by default) can pass `\"__proto__\"`, `\"constructor\"`,
or `\"prototype\"` and have the subsequent property assignment mutate
`Object.prototype`.

The audit posted in #2346 (cc @etairl) listed *`__proto__` prototype
pollution in `MemorySaver`* among the unfiled findings from the same
security-review pass that produced #2337. This PR confirms the finding
and closes it across all five entry points.

## Vulnerable sinks

`libs/checkpoint/src/memory.ts`:

| Method | Sink |
|---|---|
| `put` | `this.storage[threadId][checkpointNamespace][checkpoint.id] =
...` |
| `putWrites` | `this.writes[outerKey][innerKeyStr] = ...` (with
caller-controlled `taskId` flowing into `innerKeyStr`) |
| `deleteThread` | `delete this.storage[threadId]` |
| `getTuple` |
`this.storage[thread_id]?.[checkpoint_ns]?.[checkpoint_id]` |
| `list` | `this.storage[threadId]?.[checkpointNamespace]` plus
`Object.keys(this.storage[threadId] ?? {})` |

## Proof of concept

\`\`\`ts
import { MemorySaver } from \"@langchain/langgraph-checkpoint\";

const saver = new MemorySaver();

await saver.put(
  { configurable: { thread_id: \"__proto__\", checkpoint_ns: \"\" } },
  /* checkpoint */ { id: \"cp-1\", v: 4, ts: new Date().toISOString(),
channel_values: {}, channel_versions: {}, versions_seen: {} } as any,
  /* metadata  */ { source: \"input\", step: 0, parents: {} } as any,
  {}
);

// Object.prototype is now polluted; every plain object in the process
// inherits the injected key.
const probe: Record<string, unknown> = {};
console.log(\"polluted\" in probe); // true
console.log(probe[\"\"]); // the (formerly per-tenant) saved checkpoint
\`\`\`

Same shape works for `\"constructor\"` and `\"prototype\"`. Non-string
identifiers (`{ \$ne: null }`, arrays, numbers, booleans) reach the same
sinks unchecked.

## Severity

Proposed CVSS 3.1: **High**. `MemorySaver` is the default in every
quickstart and tutorial, and prototype pollution in Node.js is a
documented stepping stone to RCE through gadget chains in downstream
serializers, template engines, and dependency-resolution helpers.
Network-reachable, low-complexity, only the privilege the SDK already
grants to a caller.

## Fix

A single private `assertSafeStorageKey` helper in `memory.ts`, applied
at every public entry that touches `storage` or `writes` (15 call sites
across 5 methods). The guard:

* Asserts the value is a non-empty string (the documented empty
`checkpoint_ns` default is opt-in via `{ allowEmpty: true }`).
* Rejects the three prototype-pollution keys `__proto__`, `constructor`,
`prototype`.
* The `getTuple` and `list` read paths intentionally allow an empty or
undefined `checkpoint_id` so the documented \"fetch latest\" behaviour
continues to work; both paths still reject the magic keys.

\`\`\`ts
const POLLUTION_KEYS = new Set([\"__proto__\", \"constructor\",
\"prototype\"]);

function assertSafeStorageKey(
  field: string,
  value: unknown,
  options: { allowEmpty?: boolean } = {}
): asserts value is string {
/* type check, empty check, pollution check, all with precise
diagnostics */
}
\`\`\`

The guard is a TypeScript `asserts` predicate so call-sites get type
narrowing for free and the compiler enforces that no later code path
uses an unvalidated identifier.

## Why this design

* Mirrors the chokepoint pattern used in PR #2349 (`MongoDBSaver`) and
PR #2350 (`RedisSaver` / `ShallowRedisSaver`). All three savers now
share the same defensive posture at their boundary.
* Single private function: it is impossible for a future call-site to
forget validation, and the `asserts` annotation surfaces missed sites at
compile time.
* No new dependencies, no API changes for valid inputs, no behaviour
change for any documented happy path.

## Test plan

* [x] 22 new tests in
`libs/checkpoint/src/tests/memory-pollution.test.ts` under
`describe(\"MemorySaver prototype-pollution guard\")`, parameterised
across all three pollution keys plus type / empty / accept paths for
every entry point. Includes a cross-test invariant (`afterEach`
snapshots `Object.getOwnPropertyNames(Object.prototype)`) that asserts
pollution did not actually occur even if the guard had been absent.
* [x] Existing checkpoint suite green (\`pnpm --filter
@langchain/langgraph-checkpoint test\`, 93 of 93 including the 22 new
ones).
* [x] Lint clean (\`oxlint\`, 0 warnings, 0 errors on the changed
files).
* [x] Format clean (\`oxfmt --check\`).
* [x] No new dependencies, no public API changes, no behaviour change
for valid string identifiers.

## Disclosure

Original finding credited to @etairl (audit posted in #2346). This PR
was prepared for coordinated public disclosure since the audit list is
already public. Happy to coordinate timing with a private GHSA if the
maintainers prefer.

Pairs with the two earlier sibling fixes from the same audit pass:
* PR #2349 / GHSA-98xf-r82g-9mhx (MongoDB NoSQL injection)
* PR #2350 / GHSA-x3wm-3wx7-g6xm (Redis KEYS / SCAN injection)

---------

Co-authored-by: Nagendhra <nagendhra405@gmail.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 13:23:15 -07:00
Christian Bromann 80c2806cb2 fix(sdk): fold forkFrom client-side and honor multitaskStrategy (#2447)
## Summary
- Fold the SDK's top-level `forkFrom` into
`config.configurable.checkpoint_id` client-side before sending
`run.start`, so `forkFrom` never reaches the server and the fork target
travels via the single legacy-compliant field used by the existing run
endpoints.
- Drop the server-side `forkFrom` normalization/promotion in both
protocol-v2 reference servers (`ProtocolService.createOrResumeRun` and
the embed protocol routes), reading the fork target solely from
`config.configurable.checkpoint_id`.
- Honor the caller's per-run `multitaskStrategy` (`reject` | `rollback`
| `interrupt` | `enqueue`) instead of hardcoding `interrupt`, falling
back to `enqueue` (the legacy stream-endpoint default, matching the
Python protocol-v2 server) when omitted or unrecognized.
2026-05-28 12:59:49 -07:00
Nagendhra Madishetti 1e73c6b463 fix(langgraph-checkpoint-redis): block KEYS / SCAN pattern injection via top-level identifiers (#2350)
## Summary

Closes a Redis pattern-injection sink (CWE-77, CWE-943) in `RedisSaver`
and `ShallowRedisSaver`. A caller able to shape `thread_id`,
`checkpoint_ns`, `checkpoint_id`, or `task_id` (multi-tenant SDK
deployments where the `RunnableConfig` originates from request input, or
webhook payloads that flow into a persisted thread) can promote a string
identifier into a Redis glob (`*`, `?`, `[...]`) and read, overwrite, or
wipe checkpoints belonging to other tenants.

The audit posted in #2346 (cc @etairl) listed *Redis key/glob injection
in `RedisSaver` / `ShallowRedisSaver`* among the unfiled findings from
the same security-review pass. This PR confirms the finding and extends
the fix to all key-building sites in both savers.

## Vulnerable sinks

`RedisSaver` (`libs/checkpoint-redis/src/index.ts`):

| Method | Sinks |
|---|---|
| `getTuple` | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`
plus the direct \`json.get\` key |
| `list` (fallback paths) |
`keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`,
`keys(\"checkpoint:*:\${checkpointNs}:*\")` |
| `put` |
`\`checkpoint:\${threadId}:\${checkpointNs}:\${checkpointId}\`` plus the
zset key |
| `putWrites` | per-write key, zset key, checkpoint key |
| `deleteThread` | `keys(\"checkpoint:\${threadId}:*\")`,
`keys(\"writes:\${threadId}:*\")` |
| `loadPendingWrites` |
`keys(\"checkpoint_write:\${threadId}:\${checkpointNs}:\${checkpointId}:*\")`
|

`ShallowRedisSaver` (`libs/checkpoint-redis/src/shallow.ts`) has the
same five public entry points plus the equivalent helper.

## Proof of concept

```ts
import { createClient } from \"redis\";
import { RedisSaver } from \"@langchain/langgraph-checkpoint-redis\";

const client = createClient({ url: process.env.REDIS_URL! });
await client.connect();
const saver = new RedisSaver(client);

// Tenant A and Tenant B persist checkpoints normally.
await saver.put(
  { configurable: { thread_id: \"tenant-a\", checkpoint_ns: \"\" } },
  /* checkpoint */ { id: \"cp-a\", v: 4, ts: new Date().toISOString(),
                     channel_values: {}, channel_versions: {}, versions_seen: {} } as any,
  /* metadata  */ { source: \"input\", step: 0, parents: {} } as any,
  {}
);
await saver.put(
  { configurable: { thread_id: \"tenant-b\", checkpoint_ns: \"\" } },
  { id: \"cp-b\", v: 4, ts: new Date().toISOString(),
    channel_values: {}, channel_versions: {}, versions_seen: {} } as any,
  { source: \"input\", step: 0, parents: {} } as any,
  {}
);

// Attacker controls only the thread_id of their own request.
// Without the guard, deleteThread expands the KEYS pattern to a glob
// and deletes BOTH tenants' checkpoints.
await saver.deleteThread(\"*\");
// Both \`cp-a\` and \`cp-b\` are gone.
```

The same shape (`\"*\"`, `\"tenant-?\"`, `\"tenant-[ab]\"`, `\"a\\b\"`)
is accepted by every Redis pattern site in the table above.

## Severity

Proposed CVSS 3.1: **High**. The most severe sink is `deleteThread`,
which gives full availability impact across every tenant in the
database, with confidentiality (`getTuple`, `list`) and integrity
(`put`, `putWrites`) impacts on the other paths. Network-reachable,
low-complexity, only the privilege the SDK already grants to a caller.

## Fix

A single `assertSafeKeyComponent` helper exported from `./utils.js`,
applied at every key-building site (27 calls across 2 saver files plus
the helper export). The guard:

* Asserts the value is a non-empty string (the documented empty
`checkpoint_ns` default is opt-in via `{ allowEmpty: true }`).
* Rejects the Redis pattern meta-characters `* ? [ ] \`.
* Rejects the `:` delimiter that would otherwise corrupt the
colon-delimited key structure.

\`\`\`ts
export function assertSafeKeyComponent(
  field: string,
  value: unknown,
  options: { allowEmpty?: boolean } = {}
): asserts value is string {
  const { allowEmpty = false } = options;
if (typeof value !== \"string\") { /* precise diagnostic */ throw ... }
  if (!allowEmpty && value === \"\") { throw ... }
  if (REDIS_KEY_FORBIDDEN.test(value)) { throw ... }
}
\`\`\`

The guard is a TypeScript \`asserts\` predicate so call-sites get type
narrowing for free and the compiler enforces that no later code path
uses an unvalidated identifier.

## Why this design

* Mirrors the maintainers' existing primitive-only pattern
(\`escapeRediSearchTagValue\`) in the same file.
* Single chokepoint: it is impossible for a future call-site to forget
validation.
* No new dependencies, no API changes for valid inputs, no behavior
change for any documented happy path.
* Pairs with PR #2349 (NoSQL injection in MongoDBSaver) so both backends
now share the same defensive posture at the saver boundary.

## Test plan

* [x] 11 new tests under \`describe(\"assertSafeKeyComponent\")\` in
\`libs/checkpoint-redis/src/tests/utils.test.ts\` covering accept and
reject paths for every input shape (normal string, empty with and
without \`allowEmpty\`, every Redis meta-character, colon delimiter,
every wrong type).
* [x] Existing \`escapeRediSearchTagValue\` suite still green
(regression).
* [x] Full suite green (\`pnpm --filter
@langchain/langgraph-checkpoint-redis test\`, 21 of 21).
* [x] Format clean on all 4 changed files (\`oxfmt\`).
* [x] No new dependencies, no public API changes, no behavior change for
valid string identifiers.

## Disclosure

Original finding credited to @etairl (audit posted in #2346). This PR
was prepared for coordinated public disclosure since the audit list is
already public. Happy to coordinate timing with a private GHSA if the
maintainers prefer.

---------

Co-authored-by: Nagendhra <nagendhra405@gmail.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 12:58:54 -07:00
Christian Bromann 80a8c1200a refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom (#2443)
## Summary
- Remove `command` from `StreamSubmitOptions` and the
`submit-coordinator` resume-via-`submit` path so HITL resume goes
through `stream.respond()` only.
- Simplify `forkFrom` from `{ checkpointId: string }` to a plain
checkpoint id string across the SDK, protocol-v2 services, and docs.
- Update interrupt tests, examples (`HumanInTheLoopView`, branching
views), and React/Vue/Svelte/Angular JSDoc and migration/interrupt docs
to match.
2026-05-28 09:52:05 -07:00
github-actions[bot] 2f0010e3a5 chore: version packages (#2442)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.9

### Patch Changes

- [#2441](https://github.com/langchain-ai/langgraphjs/pull/2441)
[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): preserve apiUrl path prefix in stream transport URLs

Use BaseClient-style URL concatenation in `toAbsoluteUrl` so SSE and
WebSocket
subscriptions work when the SDK is pointed at a proxied apiUrl with a
path
    prefix (e.g. `/api/chat-langchain`).

## @langchain/angular@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @langchain/react@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @langchain/svelte@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @langchain/vue@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @example/ai-elements@0.1.24

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.9

## @examples/assistant-ui-claude@0.1.24

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.9

## @examples/ui-angular@0.0.34

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9
    -   @langchain/angular@1.0.9

## @examples/ui-multimodal@0.0.10

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.9

## @examples/ui-react@0.0.10

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9
    -   @langchain/react@1.0.9

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.9 @langchain/langgraph-sdk@1.9.9 @langchain/react@1.0.9 @langchain/svelte@1.0.9 @langchain/vue@1.0.9
2026-05-27 12:21:25 -07:00
Christian Bromann dbbcb636e7 fix(sdk): preserve apiUrl path prefix in stream transport URLs (#2441)
## Summary
- Fix `toAbsoluteUrl` to concatenate `apiUrl` and path instead of using
`new URL(path, base)`, which dropped path prefixes on proxied
deployments.
- Route WebSocket stream URL construction through `toAbsoluteUrl` for
consistency with SSE transport.
- Add unit and integration tests for proxied apiUrl paths, plus shared
transport test helpers.
2026-05-27 12:16:42 -07:00
github-actions[bot] 4e71ace65a chore: version packages (#2439)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

## @langchain/angular@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @langchain/react@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @langchain/svelte@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @langchain/vue@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @example/ai-elements@0.1.23

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/react@1.0.8

## @examples/assistant-ui-claude@0.1.23

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/react@1.0.8

## @examples/ui-angular@0.0.33

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8
    -   @langchain/angular@1.0.8

## @examples/ui-multimodal@0.0.9

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/react@1.0.8

## @examples/ui-react@0.0.9

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8
    -   @langchain/react@1.0.8

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.8 @langchain/langgraph-sdk@1.9.8 @langchain/react@1.0.8 @langchain/svelte@1.0.8 @langchain/vue@1.0.8
2026-05-26 17:05:03 -07:00
Christian Bromann 29d2bde235 fix(sdk): cancel runs on stop by default and add disconnect() (#2438)
## Summary

- `stream.stop()` now cancels the active run server-side by default
(`client.runs.cancel`) before disconnecting the client transport.
- Added `stream.disconnect()` as an alias for `stop({ cancel: false })`
for join/rejoin UIs.
- Introduced `StreamStopOptions` (`{ cancel?: boolean }`) on
`StreamController` and all v1 framework bindings (React, Vue, Svelte,
Angular).
- Updated `use-stream.md` and added controller unit tests for
cancel-on-stop and no-cancel-on-disconnect.
2026-05-26 17:02:20 -07:00
github-actions[bot] 39ce52f248 chore: version packages (#2436)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- [#2434](https://github.com/langchain-ai/langgraphjs/pull/2434)
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)
Thanks [@hntrl](https://github.com/hntrl)! - fix(react): avoid eager
stream getter evaluation during object spread

Mark optional `useStream` accessors as non-enumerable so object
spread/rest destructuring does not accidentally read guarded fields like
`history` or opt into additional stream modes.

## @langchain/angular@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @langchain/react@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @langchain/svelte@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @langchain/vue@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @example/ai-elements@0.1.22

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]:
    -   @langchain/react@1.0.7

## @examples/assistant-ui-claude@0.1.22

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]:
    -   @langchain/react@1.0.7

## @examples/ui-angular@0.0.32

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7
    -   @langchain/angular@1.0.7

## @examples/ui-multimodal@0.0.8

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]:
    -   @langchain/react@1.0.7

## @examples/ui-react@0.0.8

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7
    -   @langchain/react@1.0.7

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.7 @langchain/langgraph-sdk@1.9.7 @langchain/react@1.0.7 @langchain/svelte@1.0.7 @langchain/vue@1.0.7
2026-05-26 14:09:43 -07:00
Hunter Lovell 6b188e80ab fix(sdk): avoid eager stream getter evaluation (#2434)
## Summary

fix(sdk): avoid eager stream getter evaluation during spread

This fixes a React `useStream` development-mode failure where passing
the stream handle through components that clone or rest-spread props
could accidentally read lazy getters. The guarded `history` getter still
throws when explicitly accessed with `fetchStateHistory: false`, but
object spread no longer trips that path or widens `streamMode` by
touching optional accessors.

## Changes

`@langchain/langgraph-sdk`

- Marks optional `useStream` accessors (`history`,
`experimental_branchTree`, `toolProgress`, `subagents`,
`activeSubagents`) as non-enumerable on the returned stream handle.
- Preserves explicit access behavior for those accessors, including the
existing `history` guard and stream mode opt-in for
`toolProgress`/`subagents`.
- Adds React hook regression coverage for object spread, explicit getter
access, and stream mode inference.
2026-05-26 14:07:07 -07:00
Christian Bromann cfc8d274e4 fix(sdk): unwrap Command tool outputs and hide scoped task tools (#2435)
## Summary

- Filter scoped deep-agent `task` dispatch events out of `sub.toolCalls`
so subagent tool streams only show real worker tools.
- Unwrap LangGraph `Command` payloads in `parseToolOutput` when they
carry an embedded `ToolMessage`, so `tc.output` resolves to the actual
tool result instead of raw graph state.
- Share the scoped-task filter between client subagent handles and
framework tool-call projections.
2026-05-26 14:05:16 -07:00
github-actions[bot] 9c9da48ae2 chore: version packages (#2433)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

## @langchain/angular@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @langchain/react@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @langchain/svelte@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @langchain/vue@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @example/ai-elements@0.1.21

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/react@1.0.6

## @examples/assistant-ui-claude@0.1.21

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/react@1.0.6

## @examples/ui-angular@0.0.31

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6
    -   @langchain/angular@1.0.6

## @examples/ui-multimodal@0.0.7

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/react@1.0.6

## @examples/ui-react@0.0.7

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6
    -   @langchain/react@1.0.6

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.6 @langchain/langgraph-sdk@1.9.6 @langchain/react@1.0.6 @langchain/svelte@1.0.6 @langchain/vue@1.0.6
2026-05-25 00:54:21 -07:00
Christian Bromann f99941f5fe fix(sdk): clear subgraph and subagent discovery on thread swap (#2430)
## Summary
- Add `reset()` to `SubgraphDiscovery` and `SubagentDiscovery` to clear
internal maps and committed store snapshots.
- Call both resets from `StreamController.#teardownThread()` alongside
existing per-thread resets (messages, tools, metadata).
- Add unit tests for discovery `reset()` and a controller test that
`hydrate(null)` clears subgraphs after lifecycle events.
2026-05-25 00:50:31 -07:00
github-actions[bot] 7788dceb85 chore: version packages (#2424)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint-redis@1.0.5

### Patch Changes

- [#2208](https://github.com/langchain-ai/langgraphjs/pull/2208)
[`ebeb145`](https://github.com/langchain-ai/langgraphjs/commit/ebeb1452d27fcca100cd63bdfd4a7f020949412c)
Thanks [@jackjin1997](https://github.com/jackjin1997)! - Fix
`deleteThread()` using wrong key pattern (`writes:` instead of
`checkpoint_write:`) and add missing cleanup of `write_keys_zset:`
entries.

## @langchain/langgraph-supervisor@1.0.3

### Patch Changes

- [#2317](https://github.com/langchain-ai/langgraphjs/pull/2317)
[`c088c76`](https://github.com/langchain-ai/langgraphjs/commit/c088c7659c18edf26091813ff384f48f5335bef6)
Thanks [@fish895623](https://github.com/fish895623)! - feat(supervisor):
widen agents type to accept createAgent graphs

## @langchain/langgraph-sdk@1.9.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

## @langchain/angular@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @langchain/react@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @langchain/svelte@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @langchain/vue@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @example/ai-elements@0.1.20

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/react@1.0.5

## @examples/assistant-ui-claude@0.1.20

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/react@1.0.5

## @examples/ui-angular@0.0.30

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5
    -   @langchain/angular@1.0.5

## @examples/ui-multimodal@0.0.6

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/react@1.0.5

## @examples/ui-react@0.0.6

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5
    -   @langchain/react@1.0.5

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.5 @langchain/langgraph-checkpoint-redis@1.0.5 @langchain/langgraph-sdk@1.9.5 @langchain/langgraph-supervisor@1.0.3 @langchain/react@1.0.5 @langchain/svelte@1.0.5 @langchain/vue@1.0.5
2026-05-22 07:16:17 -07:00
Christian Bromann b1d307ab84 ci(infra): run framework browser tests only when paths change (#2425)
## Summary
- Add a `detect-changes` job to the browser test workflow using
`dorny/paths-filter@v3.0.2`.
- Run all four framework browser jobs when `libs/sdk/**` changes or when
this workflow file changes.
- Run only the matching job when `libs/sdk-react`, `libs/sdk-angular`,
`libs/sdk-vue`, or `libs/sdk-svelte` changes.
- Keep the full matrix on `workflow_dispatch` (manual runs and CI
dispatched via workflow_dispatch).
2026-05-22 07:15:30 -07:00
dependabot[bot] 674173b8ac chore(deps-dev): bump turbo from 2.8.15 to 2.9.14 (#2428)
Bumps [turbo](https://github.com/vercel/turborepo) from 2.8.15 to
2.9.14.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/turborepo/releases">turbo's
releases</a>.</em></p>
<blockquote>
<h2>Turborepo v2.9.14</h2>
<blockquote>
<p>[!NOTE]
This release contains important security fixes.</p>
</blockquote>
<h3>High:</h3>
<ul>
<li><a
href="https://github.com/vercel/turborepo/security/advisories/GHSA-5xc8-49mv-x4mm">GHSA-5xc8-49mv-x4mm:
Turborepo VSCode Extension command injection</a></li>
</ul>
<h3>Low:</h3>
<ul>
<li><a
href="https://github.com/vercel/turborepo/security/advisories/GHSA-hcf7-66rw-9f5r">GHSA-hcf7-66rw-9f5r:
Login callback CSRF/session fixation</a></li>
<li><a
href="https://github.com/vercel/turborepo/security/advisories/GHSA-3qcw-2rhx-2726">GHSA-3qcw-2rhx-2726:
Unexpected local code execution during Yarn Berry detection</a></li>
</ul>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>release(turborepo): 2.9.12 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li>
<li>fix: Restore docs mobile menu by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li>
<li>ci: Use <code>pull_request</code> for PR title linting by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li>
<li>ci: Scope GitHub Actions caches by branch by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li>
<li>test: Validate lockfiles without dependency downloads by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li>
<li>Removed unneeded import form hash creation script in docs by <a
href="https://github.com/dancrumb"><code>@​dancrumb</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li>
<li>fix: Validate auth callback state by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li>
<li>fix: Harden VS Code extension command execution by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li>
<li>fix: Avoid project-local Yarn during detection by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li>
<li>chore: Release 2.9.13 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12803">vercel/turborepo#12803</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/dancrumb"><code>@​dancrumb</code></a>
made their first contribution in <a
href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14">https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14</a></p>
<h2>Turborepo v2.9.13-canary.1</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>release(turborepo): 2.9.11-canary.7 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12768">vercel/turborepo#12768</a></li>
<li>fix: Allow <code>$TURBO_EXTENDS$</code> in LSP diagnostics by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12770">vercel/turborepo#12770</a></li>
<li>release(turborepo): 2.9.11 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12771">vercel/turborepo#12771</a></li>
<li>fix: Allow transit nodes in LSP diagnostics by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12773">vercel/turborepo#12773</a></li>
<li>release(turborepo): 2.9.12 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li>
<li>fix: Restore docs mobile menu by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li>
<li>ci: Use <code>pull_request</code> for PR title linting by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li>
<li>ci: Scope GitHub Actions caches by branch by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li>
<li>test: Validate lockfiles without dependency downloads by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li>
<li>Removed unneeded import form hash creation script in docs by <a
href="https://github.com/dancrumb"><code>@​dancrumb</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li>
<li>fix: Validate auth callback state by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li>
<li>fix: Harden VS Code extension command execution by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li>
<li>fix: Avoid project-local Yarn during detection by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/turborepo/commit/fc62fe0d9c347d1d24f0ed8946284856593ddb93"><code>fc62fe0</code></a>
publish 2.9.14 to registry</li>
<li><a
href="https://github.com/vercel/turborepo/commit/fb8c9aec0f9e83f95783659a5ce9c4478cf62cb9"><code>fb8c9ae</code></a>
chore: Release 2.9.13 (<a
href="https://redirect.github.com/vercel/turborepo/issues/12803">#12803</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/e8e629da4e1fb75231089e91b19be9d327a3e649"><code>e8e629d</code></a>
fix: Avoid project-local Yarn during detection (<a
href="https://redirect.github.com/vercel/turborepo/issues/12801">#12801</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/91c90cbf12f524c5c29b713d6472dd5fcdecb309"><code>91c90cb</code></a>
fix: Harden VS Code extension command execution (<a
href="https://redirect.github.com/vercel/turborepo/issues/12800">#12800</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/84f450894e87da1eed864d51f6f637f26980d560"><code>84f4508</code></a>
fix: Validate auth callback state (<a
href="https://redirect.github.com/vercel/turborepo/issues/12802">#12802</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/1779ad7901384f106236a6e196059e4929745514"><code>1779ad7</code></a>
Removed unneeded import form hash creation script in docs (<a
href="https://redirect.github.com/vercel/turborepo/issues/12799">#12799</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/71f8c90a807ffb9b9876ea8a04f523f473bf5c8d"><code>71f8c90</code></a>
test: Validate lockfiles without dependency downloads (<a
href="https://redirect.github.com/vercel/turborepo/issues/12789">#12789</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/5fcb96024d503127bb0ed760ebe159b7716c52b3"><code>5fcb960</code></a>
ci: Scope GitHub Actions caches by branch (<a
href="https://redirect.github.com/vercel/turborepo/issues/12788">#12788</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/4cf9fabc9a6f6c99fe4e2f2da9f35be631be062a"><code>4cf9fab</code></a>
ci: Use <code>pull_request</code> for PR title linting (<a
href="https://redirect.github.com/vercel/turborepo/issues/12787">#12787</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/859c629bc401f239ac7980a132746ca90478e17c"><code>859c629</code></a>
fix: Restore docs mobile menu (<a
href="https://redirect.github.com/vercel/turborepo/issues/12782">#12782</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/turborepo/compare/v2.8.15...v2.9.14">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=turbo&package-manager=npm_and_yarn&previous-version=2.8.15&new-version=2.9.14)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-22 07:07:17 -07:00
배성훈 c088c7659c feat(supervisor): widen agents type to accept createAgent graphs (#2317)
## Summary

- Add a broader `CompiledStateGraph<any, any, string, any, any>` to the
`agents` union in `CreateSupervisorParams`
- Graphs produced by `createAgent` from `langchain` (via `.graph`) are
now accepted alongside existing `createReactAgent` graphs and
`RemoteGraph`
- The original `AnnotationRootT`-parameterized `CompiledStateGraph` type
is preserved for backward compatibility

## Motivation

The new `createAgent` API in the `langchain` package returns a
`ReactAgent` whose `.graph` property is a `CompiledStateGraph` with a
different state schema (`BuiltInState`) than the
`MessagesAnnotation`-based state from `createReactAgent`. Since
`createReactAgent` is deprecated in favor of `createAgent`,
`createSupervisor` needs to accept both graph types.

At runtime this already works — `makeCallAgent` types its `agent`
parameter as `any` and only accesses `.name`, `.invoke()`, and
optionally `.description`. The type constraint on the `agents` parameter
was simply too narrow for the new API.

## Changes

### `@langchain/langgraph-supervisor` (`libs/langgraph-supervisor`)

- Updated `CreateSupervisorParams.agents` type to include
`CompiledStateGraph<any, any, string, any, any>` in the union alongside
the existing strictly-typed `CompiledStateGraph` and `RemoteGraph`

## Test plan

- [x] `pnpm build` passes for `@langchain/langgraph-supervisor`
- [x] Consuming project using `createAgent` + `createSupervisor`
compiles without errors
- [x] Existing supervisor tests still pass

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-22 06:58:38 -07:00
Jackjin ebeb1452d2 fix(langgraph-checkpoint-redis): fix deleteThread using wrong key pattern for writes (#2208)
## Summary

Fixes #2207

- Fix `deleteThread()` using incorrect `writes:` prefix instead of
`checkpoint_write:` for write key deletion
- Add missing cleanup of `write_keys_zset:` entries, matching the
correct implementation in `ShallowRedisSaver`

The bug was found by comparing `RedisSaver.deleteThread()` with
`ShallowRedisSaver.deleteThread()` in `shallow.ts`, which correctly uses
`checkpoint_write:` prefix and also cleans up zset keys.

## AI Disclosure

This bug was identified through code review with AI assistance. The fix
aligns the standard `RedisSaver` implementation with the existing
correct `ShallowRedisSaver` implementation.

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-22 06:57:22 -07:00
Christian Bromann f32a37384c fix ci 2026-05-22 15:53:53 +02:00
Christian Bromann 3529e3831a fix(sdk): align AssembledToolCall typing with pre-v1 expectations (#2421)
## Summary
- Split tool-call handles by consumer:
- **Client SDK** (`ThreadStream.toolCalls`, subgraph/subagent
projections): `ClientAssembledToolCall` with a promise-only `output`
(resolves on success, rejects on error). Still exported as
`AssembledToolCall` from `@langchain/langgraph-sdk/client` for script
usage.
- **Framework SDKs** (`stream.toolCalls`, `useToolCalls`,
`injectToolCalls`): `AssembledToolCall` with plain reactive fields —
`output: T | null`, `status`, and `error` — updated in place as events
arrive so React/Vue/Svelte/Angular can render from snapshots without
`await`, effects, or Suspense around promises.
- Add generic `AssembledToolCall<TName, TInput, TOutput>` plus
`id`/`args` aliases; point `InferToolCalls` at assembled streaming
handles and add `AssembledToolCallFromTool` (exported as
`ToolCallFromTool` from `@langchain/react`, `@langchain/vue`,
`@langchain/svelte`, and `@langchain/angular`).
- Rework `ToolCallAssembler` around a mutable internal handle and
`toClientAssembledToolCall()` for client projections; framework stores
the reactive handle directly.
- Remove redundant `InferAssembledToolCalls` and deprecated `StateOf`;
wire typed `toolCalls` / selector generics across all four framework
packages.
- Expand and align `createAgent`, `createDeepAgent`, and `langgraph`
type tests across React, Vue, Svelte, and Angular; update examples,
protocol-v2 integration tests, and Vue migration docs.
2026-05-22 06:38:06 -07:00
github-actions[bot] 4a7d9a7c5d chore: version packages (#2416)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph@1.3.2

### Patch Changes

- [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415)
[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
Move `@langchain/core` from a runtime dependency back to a required peer
dependency so installing the SDK alone no longer pulls in
`@langchain/core` (and `js-tiktoken`, etc.). Consumers that use
streaming or message coercion must install `@langchain/core` explicitly
or via `@langchain/langgraph`.

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/langgraph-sdk@1.9.4

### Patch Changes

- [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415)
[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
Move `@langchain/core` from a runtime dependency back to a required peer
dependency so installing the SDK alone no longer pulls in
`@langchain/core` (and `js-tiktoken`, etc.). Consumers that use
streaming or message coercion must install `@langchain/core` explicitly
or via `@langchain/langgraph`.

## @langchain/angular@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/react@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/svelte@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/vue@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @example/ai-elements@0.1.19

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## @examples/assistant-ui-claude@0.1.19

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## @examples/ui-angular@0.0.29

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4
    -   @langchain/langgraph@1.3.2
    -   @langchain/angular@1.0.4

## @examples/ui-multimodal@0.0.5

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## @examples/ui-react@0.0.5

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## langgraph@1.0.34

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@1.0.4 @langchain/langgraph-sdk@1.9.4 @langchain/langgraph@1.3.2 @langchain/react@1.0.4 @langchain/svelte@1.0.4 @langchain/vue@1.0.4
2026-05-19 00:02:58 -07:00
Christian Bromann b893dc5468 fix: add @langchain/langgraph to changeset 2026-05-19 08:58:21 +02:00