mirror of
https://github.com/langchain-ai/langgraphjs.git
synced 2026-07-22 00:55:26 -04:00
@langchain/angular@1.0.16
451 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
28fbf1dc4e |
chore: version packages (#2490)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph@1.3.5 ### Patch Changes - [#2489](https://github.com/langchain-ai/langgraphjs/pull/2489) [`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(core): keep stream chunks as three-element tuples Emit lightweight checkpoint envelopes as separate `[namespace, "checkpoints", envelope]` chunks before paired `values` chunks. Public `stream()` always yields `[namespace, mode, payload]`; the v3 protocol path surfaces envelopes via `convertToProtocolEvent`. - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/langgraph-sdk@1.9.16 ### Patch Changes - [#2486](https://github.com/langchain-ai/langgraphjs/pull/2486) [`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): surface resumed run failures on stream.error Route `respond()` and `respondAll()` through a coordinator dispatch path that writes the reactive `rootStore.error` slot when a resumed run reaches a failed terminal or when `input.respond` dispatch fails, matching submit() behavior so framework consumers (e.g. API-key retry UIs) observe resume failures via `stream.error` instead of only `isLoading` transitions. ## @langchain/angular@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/react@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/svelte@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/vue@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @example/ai-elements@0.1.31 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## @examples/assistant-ui-claude@0.1.31 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## @examples/ui-angular@0.0.41 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f), [`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph-sdk@1.9.16 - @langchain/langgraph@1.3.5 - @langchain/angular@1.0.16 ## @examples/ui-multimodal@0.0.17 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## @examples/ui-react@0.0.17 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f), [`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph-sdk@1.9.16 - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## langgraph@1.0.37 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
e3a1933a88 |
fix(core): keep stream() on 3-tuple shape (#2489)
## Summary
- Fixes `ValueError: too many values to unpack (expected 3)` when JS
graphs on `@langchain/langgraph` >=1.3 stream through the legacy path
(plain `stream()` / `streamEvents` v2 → `on_chain_stream`), which
affected deepagents 1.10.x and similar stacks on runtimes that expect
Python's 3-tuple stream shape.
- **Root cause:** `_streamIterator` always yielded a 4-element
`[namespace, mode, payload, meta]` when `subgraphs` + multi-mode and a
checkpointer were active, even though `StreamChunkMeta` is only for the
native v3 protocol stream (`streamEvents(..., { version: "v3" })` /
`pump()`).
- **Fix:** Introduce `isV3` and only append `meta` when `options.version
=== "v3"`; all other consumers get the Python-aligned 3-tuple
`[namespace, mode, payload]`.
- **Tests:** Add `stream() shape parity with Python` regression coverage
(3-tuples for subgraphs + multi-mode with checkpointer; v3 still emits
companion `checkpoints` events).
|
||
|
|
244c24eacc |
fix(sdk): surface resumed run failures on stream.error (#2486)
## Summary - Route `respond()` / `respondAll()` through `SubmitCoordinator.dispatchResume()` so resumed runs write failures to the reactive `rootStore.error` slot (same path `submit()` uses), instead of only toggling `isLoading` via the lifecycle listener. - Arm a background terminal watch before dispatch so `respond()` still resolves on `input.respond` while a later `failed` lifecycle populates `stream.error`. - Add controller tests for failed resume, dispatch failure, and batched `respondAll()` failure. |
||
|
|
34b7f6cfc5 |
chore: version packages (#2485)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.15 ### Patch Changes - [#2484](https://github.com/langchain-ai/langgraphjs/pull/2484) [`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): claim in-flight slot before root pump wait for enqueue Move `#runAbort` and `isLoading` setup ahead of `waitForRootPumpReady()` so `multitaskStrategy: "enqueue"` submits in the same tick land in `queueStore` instead of bypassing the client queue. ## @langchain/angular@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @langchain/react@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @langchain/svelte@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @langchain/vue@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @example/ai-elements@0.1.30 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.15 ## @examples/assistant-ui-claude@0.1.30 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.15 ## @examples/ui-angular@0.0.40 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 - @langchain/angular@1.0.15 ## @examples/ui-multimodal@0.0.16 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.15 ## @examples/ui-react@0.0.16 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 - @langchain/react@1.0.15 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
9861f42cc4 |
fix(sdk): claim in-flight slot before root pump wait for enqueue (#2484)
## Summary - Fix a race in `SubmitCoordinator.submit()` where `multitaskStrategy: "enqueue"` follow-ups fired in the same tick as the first dispatch could miss `hasActiveRun` and skip the client `queueStore`. - Claim the in-flight slot (`#runAbort`, `isLoading`) before `waitForRootPumpReady()` so concurrent enqueues are recorded client-side and drain sequentially as intended. - Add a regression test for same-tick enqueue behavior. |
||
|
|
540656afd0 |
chore: version packages (#2483)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.14 ### Patch Changes - [#2482](https://github.com/langchain-ai/langgraphjs/pull/2482) [`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): keep subgraph status complete when values arrives late `SubgraphDiscovery` no longer downgrades a terminal subgraph back to `running` when a host-namespace `values` snapshot is observed after its `completed` or `failed` lifecycle event. The content pump and lifecycle watcher are independent streams, so this reordering could strand nodes as perpetually running in `useStream` subgraph UIs. ## @langchain/angular@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @langchain/react@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @langchain/svelte@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @langchain/vue@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @example/ai-elements@0.1.29 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.14 ## @examples/assistant-ui-claude@0.1.29 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.14 ## @examples/ui-angular@0.0.39 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 - @langchain/angular@1.0.14 ## @examples/ui-multimodal@0.0.15 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.14 ## @examples/ui-react@0.0.15 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 - @langchain/react@1.0.14 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
ba583b601d |
fix(sdk): keep subgraph status complete when values arrives late (#2482)
## Summary - Fix `SubgraphDiscovery` so late host-namespace `values` snapshots do not reset subgraph status from `complete`/`error` back to `running`. - Root cause: the SDK’s content pump (`values`) and lifecycle watcher (`lifecycle`) are separate streams; `onEvent` can deliver a final `values` event after terminal `lifecycle`, which left some nodes stuck as “running” in `useStream` subgraph UIs (e.g. graph-execution-cards). - Add regression tests for completed and failed subgraphs receiving a late `values` event. |
||
|
|
e5bd490c52 |
chore: version packages (#2470)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.13 ### Patch Changes - [#2469](https://github.com/langchain-ai/langgraphjs/pull/2469) [`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): normalize HITL edit decisions for Python servers `StreamController.respond()` now mirrors camelCase and snake_case on edit decisions (`editedAction` / `edited_action`) so JS clients can resume human-in-the-loop interrupts against Python LangGraph servers. ## @langchain/angular@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @langchain/react@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @langchain/svelte@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @langchain/vue@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @example/ai-elements@0.1.28 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.13 ## @examples/assistant-ui-claude@0.1.28 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.13 ## @examples/ui-angular@0.0.38 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 - @langchain/angular@1.0.13 ## @examples/ui-multimodal@0.0.14 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.13 ## @examples/ui-react@0.0.14 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 - @langchain/react@1.0.13 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
0bbe66e31d |
fix(sdk): normalize HITL edit decisions for Python servers (#2469)
## Summary - Normalize HITL resume payloads in `StreamController.respond()` and `respondAll()` so edit decisions include both `editedAction` and `edited_action`. - Add `normalizeHitlResponseForServer` in the SDK UI layer and export it for direct use. - Cover normalization with unit tests on the payload helper and on `respond()` wiring. |
||
|
|
c6b29fb040 |
chore: version packages (#2465)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-mongodb@1.3.3 ### Patch Changes - [#2260](https://github.com/langchain-ai/langgraphjs/pull/2260) [`4d03dcb`](https://github.com/langchain-ai/langgraphjs/commit/4d03dcbc28bbfdf4c0f0ac065b9853652836d2f9) Thanks [@venkat22022202](https://github.com/venkat22022202)! - fix(mongodb): include pendingWrites in list() results ## @langchain/langgraph@1.3.4 ### Patch Changes - [#2035](https://github.com/langchain-ai/langgraphjs/pull/2035) [`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51) Thanks [@JadenKim-dev](https://github.com/JadenKim-dev)! - fix(core): prevent Zod schema defaults from overwriting checkpoint state in Command.update - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/langgraph-sdk@1.9.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. ## @langchain/angular@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/react@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/svelte@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/vue@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @example/ai-elements@0.1.27 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/react@1.0.12 ## @examples/assistant-ui-claude@0.1.27 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/react@1.0.12 ## @examples/ui-angular@0.0.37 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/langgraph-sdk@1.9.12 - @langchain/angular@1.0.12 ## @examples/ui-multimodal@0.0.13 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/react@1.0.12 ## @examples/ui-react@0.0.13 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/langgraph-sdk@1.9.12 - @langchain/react@1.0.12 ## langgraph@1.0.36 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51)]: - @langchain/langgraph@1.3.4 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
0491534712 |
fix(sdk): route headless tool resumes through respond on v1 stream (#2467)
## Summary
- Fix headless-tool resume on the v1 stream protocol by routing resume
payloads through `applyHeadlessToolResumeCommand` (`respond` /
`respondAll`) instead of `submit(null, { command })`.
- Export `applyHeadlessToolResumeCommand` and
`HeadlessToolResumeController` from `@langchain/langgraph-sdk` and
re-export from `@langchain/react`.
- Strengthen headless-tool browser tests across React, Vue, Angular, and
Svelte to assert tool result values, final agent message, idle loading
state, and no lingering interrupts.
|
||
|
|
4d03dcbc28 |
fix(langgraph-checkpoint-mongodb): include pendingWrites in list() results (#2260)
## Summary Fixes #2205 Fixes #589 `MongoDBSaver.list()` does not query or return `pendingWrites` in the yielded `CheckpointTuple` objects. This is inconsistent with `getTuple()` (which correctly queries the writes collection) and with other checkpointer implementations like Postgres. ## Fix Added the same `pendingWrites` query from `getTuple()` into `list()`, ensuring each yielded checkpoint tuple includes its pending writes. ## Test Plan - Store checkpoints with pending writes via MongoDBSaver - Call `list()` and verify `pendingWrites` are populated - Compare with `getTuple()` output to confirm consistency 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
7c3a98b23a |
fix(core): prevent Zod schema defaults from overwriting checkpoint state in Command.update (#2035)
Fixes #2031 When using `Command({ update })` with a Zod schema that has `.default()` on fields, Zod's `parse()` injects default values for missing fields into the update object. These injected keys then overwrite values restored from the checkpoint. **Root cause:** `_validateInput` passes `Command.update` through `interopParse(schema, input.update)`, which triggers Zod defaults for any field not present in the update. **Fix:** After parsing, filter the result to only include keys that were present in the original update input — matching the behavior of `StateSchema.validateInput` which already iterates only over `Object.entries(data)`. Added regression tests for both Zod v3 and v4. --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
d2ca90f8e2 |
chore: version packages (#2453)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-checkpoint-mongodb@1.3.2 ### Patch Changes - [#2186](https://github.com/langchain-ai/langgraphjs/pull/2186) [`26c2e32`](https://github.com/langchain-ai/langgraphjs/commit/26c2e325f435a2c061d6b78a7bd6af089cb1e0e6) Thanks [@jackjin1997](https://github.com/jackjin1997)! - fix: metadata filter in list() now works by querying a plain JSON shadow copy instead of the serialized binary blob ## @langchain/langgraph-checkpoint-postgres@1.0.2 ### Patch Changes - [#2255](https://github.com/langchain-ai/langgraphjs/pull/2255) [`e82a50b`](https://github.com/langchain-ai/langgraphjs/commit/e82a50b961a9413dab1ad2248747d5c73a6a1e58) Thanks [@leesta24](https://github.com/leesta24)! - fix(checkpoint-postgres): move serialization outside transaction in put() ## @langchain/langgraph-checkpoint-redis@1.0.7 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-api@1.2.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. - Updated dependencies \[]: - @langchain/langgraph-ui@1.2.4 ## @langchain/langgraph-cli@1.2.4 ### Patch Changes - [#1925](https://github.com/langchain-ai/langgraphjs/pull/1925) [`6503319`](https://github.com/langchain-ai/langgraphjs/commit/65033191cc3dd671d64dfac78ccdad453fdfbda2) Thanks [@jbrody-nexxa](https://github.com/jbrody-nexxa)! - fix(cli): add --no-reload flag to dev command - Updated dependencies \[[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-api@1.2.4 ## @langchain/langgraph@1.3.3 ### Patch Changes - [#2037](https://github.com/langchain-ai/langgraphjs/pull/2037) [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f) Thanks [@pawel-twardziak](https://github.com/pawel-twardziak)! - Decouple `ContextType` generic from `configurable` in `PregelOptions` so that providing a custom context type no longer incorrectly narrows the configurable parameter. - [#2457](https://github.com/langchain-ai/langgraphjs/pull/2457) [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph): pass context with stateful RemoteGraph runs Pop `thread_id` from run `config.configurable` and forward `context` to the SDK so checkpointed remote runs accept user context without a 400 from ambiguous parameters. Closes [#1922](https://github.com/langchain-ai/langgraphjs/issues/1922). - [#1988](https://github.com/langchain-ai/langgraphjs/pull/1988) [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7) Thanks [@Axadali](https://github.com/Axadali)! - Fix race condition in IterableReadableWritableStream.push() that caused ERR_INVALID_STATE errors when streaming with multiple parallel nodes and aborting the stream. - [#2409](https://github.com/langchain-ai/langgraphjs/pull/2409) [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3) Thanks [@pragnyanramtha](https://github.com/pragnyanramtha)! - Preserve non-plain objects passed through `Send` and `Command` argument deserialization. - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph-checkpoint@1.0.4 ## @langchain/langgraph-supervisor@1.0.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-sdk@1.9.11 ### Patch Changes - [#2455](https://github.com/langchain-ai/langgraphjs/pull/2455) [`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856) Thanks [@JHSeo-git](https://github.com/JHSeo-git)! - fix(sdk): prefer completed task's direct mapping over pending checkpoint's positional guess in fetchSubagentHistory - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/angular@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/react@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/svelte@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/vue@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/langgraph-ui@1.2.4 ## @example/ai-elements@0.1.26 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/assistant-ui-claude@0.1.26 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/ui-angular@0.0.36 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph@1.3.3 - @langchain/angular@1.0.11 ## @examples/ui-multimodal@0.0.12 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/ui-react@0.0.12 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## langgraph@1.0.35 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
26c2e325f4 |
fix(langgraph-checkpoint-mongodb): MongoDB checkpointer metadata filter (#2186)
## Summary
- The `list()` method's metadata filter queried `metadata.${key}`
against a serialized binary blob, making it silently nonfunctional (dead
code)
- Added a plain JSON `metadata_search` field alongside the serialized
`metadata` in `put()`, and updated `list()` to query against it
- This is consistent with how Postgres (native JSONB `@>`) and SQLite
(`jsonb(CAST(...))`) handle metadata filtering
## Test plan
- [x] Existing unit tests pass (6/6)
- [ ] Integration test with real MongoDB to verify filter works against
`metadata_search`
Fixes #1591
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
|
||
|
|
101b70aa8d |
fix: preserve non-plain Send args (#2409)
## Summary - preserve non-plain object instances while deserializing `Send`/`Command` argument trees - keep recursive reconstruction for arrays, plain object records, serialized `Command`, and serialized `Send` payloads - add a regression test covering `Set`, `Map`, `Date`, and a custom class instance passed through `Send` Fixes part of #1142. ## Test plan - `pnpm install --frozen-lockfile` - `pnpm --filter @langchain/langgraph exec vitest run src/tests/constants.test.ts --testNamePattern "preserves non-plain objects"` - `pnpm --filter @langchain/langgraph exec vitest run src/tests/constants.test.ts` - `pnpm exec oxfmt --check libs/langgraph-core/src/constants.ts libs/langgraph-core/src/tests/constants.test.ts` - `pnpm exec oxlint libs/langgraph-core/src/constants.ts libs/langgraph-core/src/tests/constants.test.ts` - `git diff --check` - `pnpm --filter @langchain/langgraph build` --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
0125920a2c |
chore(deps): bump uuid from 10.0.0 to 14.0.0 (#2344)
Bumps [uuid](https://github.com/uuidjs/uuid) from 10.0.0 to 14.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/uuidjs/uuid/releases">uuid's releases</a>.</em></p> <blockquote> <h2>v14.0.0</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a> (2026-04-19)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> </ul> <h3>Features</h3> <ul> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>) (<a href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3">dc4ddb8</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>) (<a href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4">f2c235f</a>)</li> <li>Use GITHUB_TOKEN for release-please and enable npm provenance (<a href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>) (<a href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c">ffa3138</a>)</li> </ul> <h2>v13.0.2</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.1...v13.0.2">13.0.2</a> (2026-05-04)</h2> <h3>Bug Fixes</h3> <ul> <li>rerelease to fix provenance. (<a href="https://github.com/uuidjs/uuid/commit/49ccb35f78c0c4ce1409dd2f1d89f83caadba10b">49ccb35</a>)</li> </ul> <h2>v13.0.1</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v13.0.1">13.0.1</a> (2026-04-27)</h2> <h3>Bug Fixes</h3> <ul> <li>backport fix for GHSA-w5hq-g745-h8pq (<a href="https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a">9d27ddf</a>)</li> </ul> <h2>v13.0.0</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a> (2025-09-08)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li> </ul> <h2>v12.0.1</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v12.0.1">12.0.1</a> (2026-04-29)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md">uuid's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a> (2026-04-19)</h2> <h3>Security</h3> <ul> <li>Fixes <a href="https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq">GHSA-w5hq-g745-h8pq</a>: <code>v3()</code>, <code>v5()</code>, and <code>v6()</code> did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid <code>offset</code> was provided. A <code>RangeError</code> is now thrown if <code>offset < 0</code> or <code>offset + 16 > buf.length</code>.</li> </ul> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><code>crypto</code> is now expected to be globally defined (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> <li>upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a> (2025-09-08)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v11.1.0...v12.0.0">12.0.0</a> (2025-09-05)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>update to typescript@5.2 (<a href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>)</li> <li>remove CommonJS support (<a href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>)</li> <li>drop node@16 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>)</li> </ul> <h3>Features</h3> <ul> <li>add node@24 to ci matrix (<a href="https://redirect.github.com/uuidjs/uuid/issues/879">#879</a>) (<a href="https://github.com/uuidjs/uuid/commit/42b6178aa21a593257f0a72abacd220f0b7b8a92">42b6178</a>)</li> <li>drop node@16 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>) (<a href="https://github.com/uuidjs/uuid/commit/0f38cf10366ab074f9328ae2021eea04d5f2e530">0f38cf1</a>)</li> <li>remove CommonJS support (<a href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>) (<a href="https://github.com/uuidjs/uuid/commit/ae786e27265f50bcf7cead196c29f1869297c42f">ae786e2</a>)</li> <li>update to typescript@5.2 (<a href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>) (<a href="https://github.com/uuidjs/uuid/commit/c7ee40598ed78584d81ab78dffded9fe5ff20b01">c7ee405</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>improve v4() performance (<a href="https://redirect.github.com/uuidjs/uuid/issues/894">#894</a>) (<a href="https://github.com/uuidjs/uuid/commit/5fd974c12718c8848035650b69b8948f12ace197">5fd974c</a>)</li> <li>restore node: prefix (<a href="https://redirect.github.com/uuidjs/uuid/issues/889">#889</a>) (<a href="https://github.com/uuidjs/uuid/commit/e1f42a354593093ba0479f0b4047dae82d28c507">e1f42a3</a>)</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v11.0.5...v11.1.0">11.1.0</a> (2025-02-19)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/uuidjs/uuid/commit/7c1ea087a8149b57380fc8bb7f68c3a215cb6e4b"><code>7c1ea08</code></a> chore(main): release 14.0.0 (<a href="https://redirect.github.com/uuidjs/uuid/issues/926">#926</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34"><code>3d2c5b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4"><code>f2c235f</code></a> fix!: expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/529ef0899f5dd503d2ee90d690585d63d78bc212"><code>529ef08</code></a> chore: upgrade TypeScript and fixup types (<a href="https://redirect.github.com/uuidjs/uuid/issues/927">#927</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/086fd7976f11433edf9ac80be876b3ad243fe087"><code>086fd79</code></a> chore: update dependencies (<a href="https://redirect.github.com/uuidjs/uuid/issues/933">#933</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3"><code>dc4ddb8</code></a> feat!: drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/0f1f9c9c9cedbae5a1d363d5406c5dfbabe81404"><code>0f1f9c9</code></a> chore: switch to Biome for parsing and linting (<a href="https://redirect.github.com/uuidjs/uuid/issues/932">#932</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/e2879e64bf125add903c1eff6e0860542c605013"><code>e2879e6</code></a> chore: use maintained version of npm-run-all (<a href="https://redirect.github.com/uuidjs/uuid/issues/930">#930</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c"><code>ffa3138</code></a> fix: Use GITHUB_TOKEN for release-please and enable npm provenance (<a href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/0423d49df2dc8efc300c804731d25f4d7e0fccc4"><code>0423d49</code></a> docs: remove obsolete v1 option notes (<a href="https://redirect.github.com/uuidjs/uuid/issues/915">#915</a>)</li> <li>Additional commits viewable in <a href="https://github.com/uuidjs/uuid/compare/v10.0.0...v14.0.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for uuid since your current version.</p> </details> <details> <summary>Install script changes</summary> <p>This version adds <code>prepare</code> script that runs during installation. Review the package contents before updating.</p> </details> <br /> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
65033191cc |
fix(langgraph-api): port --no-reload option to js CLI to match python implementation (#1925)
Implement a CLI option --no-reload that bypasses the watcher from restarting the server when changes to file contents are detected. This implementation matches the python CLI option implemented here: https://github.com/langchain-ai/langgraph/blob/main/libs/cli/langgraph_cli/cli.py#L620 fixes https://github.com/langchain-ai/langgraphjs/issues/1942 --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
91a5494715 |
fix(langgraph): pass context with stateful RemoteGraph runs (#2457)
## Summary - Fix [#1922](https://github.com/langchain-ai/langgraphjs/issues/1922) by porting the Python [langgraph#6497](https://github.com/langchain-ai/langgraph/pull/6497) behavior: `RemoteGraph` pops `thread_id` from `config.configurable` (it stays in the URL path) and passes `context` as a top-level field to `client.runs.stream()`. - Stateful remote runs can now combine checkpointing (`thread_id`) with `context` for middleware / `contextSchema` without the server rejecting ambiguous parameters. fixes #1922 |
||
|
|
6d4bf927e5 |
fix(langgraph): StreamMessagesHandler throws "Controller is already closed" errors during parallel streaming with abort #1908 (#1988)
<h2>Fix Race Condition in <code>IterableReadableWritableStream.push()</code></h2> Fixes #1908 <h3>Summary</h3> <p>This PR addresses a critical race condition in <code>IterableReadableWritableStream.push()</code> that was causing <code>TypeError [ERR_INVALID_STATE]: Invalid state: Controller is already closed</code> errors when streaming a graph with multiple parallel LLM nodes and aborting the stream (or when it completes naturally).</p> <h3>Problem</h3> <p>Users were experiencing numerous <code>ERR_INVALID_STATE</code> errors in production when:</p> <ul> <li>Streaming graphs with multiple parallel LLM nodes</li> <li>Aborting the stream or when it completes naturally</li> <li>In-flight token callbacks from LLMs are asynchronous and may still execute after stream closure</li> <li>Calling <code>enqueue()</code> on a closed controller throws the error</li> <li>This race condition causes console flooding in production environments</li> </ul> <h3>Solution</h3> <p>The fix implements a robust two-layer approach to handle the race condition:</p> <ol> <li><strong>Pre-checking State:</strong> Checking <code>this._closed</code> and <code>this.controller</code> existence before attempting <code>enqueue</code></li> <li><strong>Try-Catch Protection:</strong> Wrapping the <code>enqueue</code> operation to catch any remaining race conditions</li> <li><strong>Specific Error Handling:</strong> Only suppressing the "Controller is already closed" error while allowing other errors to propagate</li> <li><strong>Maintaining Semantics:</strong> Preserving all existing functionality while preventing the problematic errors</li> </ol> <h3>Code Changes</h3> <p>Modified <code>push()</code> method in <code>libs/langgraph-core/src/pregel/stream.ts</code>:</p> <pre><code>push(chunk: StreamChunk) { // Prevent pushing to a closed stream to avoid race condition errors if (this._closed || !this.controller) { // Silently drop chunks when stream is closed - this is expected behavior // when async operations try to push after stream termination return; } try { // Forward chunk to passthrough function if provided this.passthroughFn?.(chunk); // Attempt to enqueue the chunk to the underlying stream this.controller.enqueue(chunk); } catch (error) { // Handle the specific case where controller was closed between check and enqueue // This race condition can occur with parallel async operations if (error instanceof TypeError && error.message.includes('Controller is already closed')) { // Silently ignore - this is expected during stream closure with concurrent pushes return; } // Re-throw any other unexpected errors to maintain proper error reporting throw error; } } </code></pre> <h3>Enhanced Test Coverage</h3> <p>Added comprehensive test scenarios covering:</p> <ul> <li>Basic race condition handling</li> <li>Concurrent pushes during closure</li> <li>Rapid successive operations</li> <li>Passthrough function integration during race conditions</li> <li>Multiple close calls</li> <li>Parallel node simulation mimicking the original issue</li> </ul> <h3>Backwards Compatibility</h3> <ul> <li>✅ No changes to public API</li> <li>✅ No changes to stream behavior during normal operation</li> <li>✅ Maintains all existing functionality</li> <li>✅ Only affects the error case (pushes after stream closure)</li> </ul> <h3>Testing</h3> <p>The fix has been validated across multiple scenarios:</p> <ul> <li>Basic race condition scenarios</li> <li>Concurrent operations during stream closure</li> <li>Multiple parallel nodes simulating the original issue</li> <li>Edge cases with multiple close calls</li> <li>Passthrough function integration</li> </ul> <h3>Impact</h3> <ul> <li>✅ Eliminates console flooding with <code>ERR_INVALID_STATE</code> errors</li> <li>✅ Improves stability in production environments with parallel streaming</li> <li>✅ Maintains performance and functionality of normal stream operations</li> <li>✅ Safe for use with multiple parallel LLM nodes</li> </ul> <p>This fix resolves the race condition issue while maintaining full backward compatibility and following best practices for error handling in async environments.</p> --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
863b555346 |
fix(sdk): prefer completed task's direct mapping over pending checkpoint's positional guess in fetchSubagentHistory (#2455)
Fixes #2454 ## Problem `StreamManager.fetchSubagentHistory` (`libs/sdk/src/ui/manager.ts`) restores each subagent's conversation from its subgraph checkpoint by first resolving every subagent `tool_call_id` to its subgraph `checkpoint_ns`. It scans the parent thread's history **newest-first** and, per checkpoint, tries two strategies: 1. **Direct mapping** — read the `tool_call_id` straight off a completed PUSH task's result `ToolMessage` (`task.name + ":" + task.id`). The code comments correctly call this *"more robust than positional alignment ... preferred"*. 2. **Positional fallback** — when task results aren't populated yet, align push tasks to the AI message's subagent tool calls by Send index (`task.path[1]`). The loop **breaks on the first checkpoint that yields any mapping** (direct *or* positional). That break is the bug. When the most recent checkpoint is a still-pending PUSH task — e.g. a run stopped at an interrupt — its task has no result, so the direct map is empty and the **positional fallback runs against the head checkpoint instead**. The fallback's backward scan of `values.messages` then latches onto a *stale* AI message whose subagent actually **completed in an older checkpoint**, positionally aligns it to the head's unrelated pending task, and breaks — before the loop ever reaches the older checkpoint whose task result holds the **correct** direct mapping. Net effect: the subagent's history is reconstructed from the **wrong subgraph namespace** (or not at all). A newer, lower-confidence positional guess silently shadows an older, authoritative direct mapping — the opposite of the code's stated intent. ## Fix Split namespace resolution into two phases: 1. **Phase 1 — direct mapping across the _entire_ history first.** Collect all `tool_call_id → namespace` mappings from completed task results before attempting any fallback. These are unambiguous, so no pending head checkpoint can pre-empt them. 2. **Phase 2 — positional fallback only for tool calls still unmapped** after phase 1 (the genuinely live/pending case). This preserves the existing behavior for in-flight runs while guaranteeing a correct direct mapping is never overwritten by a positional guess. No backend/protocol change is required — the server already serializes the correct material (the completed task result with the matching `tool_call_id`); only the client-side resolution order was wrong. ## Testing - Added a regression test (`fetchSubagentHistory namespace resolution`): a pending head checkpoint sitting in front of an older checkpoint that holds the correct completed mapping. Verified it **fails on the pre-fix code** (`expected [ 'Stale pending result' ] to include 'Correct research result'`) and **passes with this change**. - `vitest run` (SDK): **595 passed**, no type errors. - `oxlint`: 0 warnings / 0 errors · `oxfmt --check`: clean · `tsc -p libs/sdk/tsconfig.json --noEmit`: clean. --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
e82a50b961 | fix(langgraph-checkpoint-postgres): move serialization outside transaction in put() (#2255) | ||
|
|
9eb478ffee |
fix(langgraph): decouple ContextType from configurable in PregelOptions (#2037)
## Summary
When a `StateGraph` is created with a `contextSchema` (Zod), two
TypeScript errors occur:
1. **TS2589** ("excessively deep type instantiation") on the
`StateGraph` constructor
2. **TS2322** on `invoke()`/`stream()` - context schema fields (e.g.
`userName`, `userId`) are incorrectly required inside `configurable`
instead of top-level `context`
**Root cause:** `PregelOptions` extends `RunnableConfig<ContextType>`,
which maps the context type onto `configurable?` at the invoke/stream
level. The deep generic chain `StateGraph → Pregel → PregelOptions →
RunnableConfig<ContextType>` causes TS2589 with complex context schemas.
And TS2322 forces users to put context fields in `configurable` instead
of top-level `context`.
**Fix:** Remove the `<ContextType>` generic parameter from
`RunnableConfig` in `PregelOptions` only. This breaks the deep generic
chain at the invoke/stream boundary while preserving typed
`configurable` and `context` inside node callbacks (via
`LangGraphRunnableConfig<T>` / `Runtime<T>`).
## Changes
- **`libs/langgraph-core/src/pregel/types.ts`** - `PregelOptions` now
extends `RunnableConfig` (default) instead of
`RunnableConfig<ContextType>`. This is the only production code change.
- **`libs/langgraph-core/src/pregel/runnable_types.ts`** - Restored
`Runtime.configurable` to `ContextType` and `LangGraphRunnableConfig` to
extend `RunnableConfig<ContextType>` (reverting a previous attempt that
broke backward compat).
- **`libs/langgraph-core/src/tests/pregel.test-d.ts`** - Removed two
`@ts-expect-error` directives for invoke-level configurable (now
`Record<string, any>`, validated at runtime by Zod).
- **`libs/langgraph-core/src/tests/issue_10270_repro.test-d.ts`** -
Regression test reproducing both bugs from the issue.
## Trade-off
| Aspect | Before | After |
|--------|--------|-------|
| `graph.invoke({}, { configurable: { bad: 123 } })` | Compile error |
Compiles, validated at runtime |
| `graph.invoke({}, { context: { ... } })` | Compile error (TS2322) |
Compiles correctly ✓ |
| Node callback `config.configurable` / `config.context` | Typed as `T`
| Typed as `T` (unchanged) ✓ |
| `new StateGraph({ state, context: zodSchema })` | TS2589 | Compiles ✓
|
The only loss is compile-time validation of `configurable` content at
invoke level - mitigated by runtime Zod schema validation which the
codebase already performs.
Fixes [#10270](https://github.com/langchain-ai/langchainjs/issues/10270)
---------
Co-authored-by: Christian Bromann <git@bromann.dev>
|
||
|
|
381a9f64d0 |
chore: version packages (#2445)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.3 ### Patch Changes - [#2352](https://github.com/langchain-ai/langgraphjs/pull/2352) [`14f2a79`](https://github.com/langchain-ai/langgraphjs/commit/14f2a796912e81d7f52f0a4f16747f6d0a269209) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys `MemorySaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into property accesses on the nested plain objects `this.storage` and `this.writes`. A caller able to shape any of those fields (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) could pass `"__proto__"`, `"constructor"`, or `"prototype"` and have the subsequent assignment mutate `Object.prototype`. From that point every plain object in the process inherits the injected property, breaking `for...in` loops, truthy short-circuits, and downstream serializers across unrelated code paths. CWE-1321. Adds an `assertSafeStorageKey` chokepoint applied at every public entry that touches `storage` or `writes` (`put`, `putWrites`, `deleteThread`, `getTuple`, `list`). The guard rejects non-string values, the empty string (unless explicitly opted-in for `checkpoint_ns`), and the three prototype-pollution keys. Behaviour for valid string identifiers is unchanged. ## @langchain/langgraph-checkpoint-redis@1.0.6 ### Patch Changes - [#2350](https://github.com/langchain-ai/langgraphjs/pull/2350) [`1e73c6b`](https://github.com/langchain-ai/langgraphjs/commit/1e73c6b4630bbc4aa976eea4bfc33c4f753b7ee9) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(checkpoint-redis): block Redis KEYS / SCAN pattern injection via top-level identifiers `RedisSaver` and `ShallowRedisSaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into Redis keys and `client.keys(pattern)` calls with no validation. A caller able to shape any of those fields (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) could promote a string identifier into a glob pattern (`*`, `?`, `[...]`) or escape character (`\`). The most severe sink is `deleteThread`: a `threadId` of `*` issues `client.keys("checkpoint:*:*")` followed by `client.del(...)`, deleting every checkpoint in the database across every tenant. `getTuple`, `list`, and `loadPendingWrites` are exposed to the same pattern via the fallback paths that bypass the existing `escapeRediSearchTagValue` defense. Adds a single `assertSafeKeyComponent` helper exported from `./utils.js` and applies it at every key-building site. The guard asserts the value is a non-empty string (the empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`) and rejects the Redis pattern meta-characters `* ? [ ] \`. The `:` delimiter is intentionally permitted because LangGraph emits it as a legitimate part of `checkpoint_ns` for subgraphs / nested graphs, where it only ever appears as a literal in the key. Behavior for valid string identifiers is unchanged. ## @langchain/langgraph-api@1.2.3 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)]: - @langchain/langgraph-ui@1.2.3 ## @langchain/langgraph-cli@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-api@1.2.3 ## @langchain/langgraph-ui@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. ## @langchain/langgraph-sdk@1.9.10 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. ## @langchain/angular@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/react@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/svelte@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/vue@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @example/ai-elements@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/assistant-ui-claude@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-angular@0.0.35 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/angular@1.0.10 ## @examples/ui-multimodal@0.0.11 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-react@0.0.11 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/react@1.0.10 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
2c14b12a80 |
fix(sdk): add back respondAll and respond config/metadata (#2448)
## Summary
- Add `respondAll(responsesById, options)` to the stream controller and
the React/Angular/Svelte/Vue wrappers, resuming multiple interrupts
pending at the same checkpoint in a single `Command({ resume })`. This
is required for runs that pause on several interrupts at once (e.g.
parallel tool-authorization prompts), which sequential `respond()` calls
cannot service.
- Change `respond()` to take an options object (`{ interruptId?,
namespace?, config?, metadata? }`), folding run-level
`config`/`metadata` onto the resumed run so it applies the same
configurable values and metadata a fresh `submit()` would.
- Extend `ThreadStream.respondInput()` to accept a `responses` batch
(mutually exclusive with the single `interrupt_id`/`response`) and clear
all responded interrupts from local state.
- Update the protocol-v2 reference servers (`embed/protocol.mts`,
`protocol/service.mts`) to read the `responses` batch plus
`config`/`metadata` leniently and fold them onto the run servicing
`input.respond`.
- Update docs (interrupts/use-stream) across all framework packages and
add controller tests for batched resume.
|
||
|
|
14f2a79691 |
fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys (#2352)
## Summary Closes a prototype-pollution sink (CWE-1321) in `MemorySaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) can pass `\"__proto__\"`, `\"constructor\"`, or `\"prototype\"` and have the subsequent property assignment mutate `Object.prototype`. The audit posted in #2346 (cc @etairl) listed *`__proto__` prototype pollution in `MemorySaver`* among the unfiled findings from the same security-review pass that produced #2337. This PR confirms the finding and closes it across all five entry points. ## Vulnerable sinks `libs/checkpoint/src/memory.ts`: | Method | Sink | |---|---| | `put` | `this.storage[threadId][checkpointNamespace][checkpoint.id] = ...` | | `putWrites` | `this.writes[outerKey][innerKeyStr] = ...` (with caller-controlled `taskId` flowing into `innerKeyStr`) | | `deleteThread` | `delete this.storage[threadId]` | | `getTuple` | `this.storage[thread_id]?.[checkpoint_ns]?.[checkpoint_id]` | | `list` | `this.storage[threadId]?.[checkpointNamespace]` plus `Object.keys(this.storage[threadId] ?? {})` | ## Proof of concept \`\`\`ts import { MemorySaver } from \"@langchain/langgraph-checkpoint\"; const saver = new MemorySaver(); await saver.put( { configurable: { thread_id: \"__proto__\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-1\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); // Object.prototype is now polluted; every plain object in the process // inherits the injected key. const probe: Record<string, unknown> = {}; console.log(\"polluted\" in probe); // true console.log(probe[\"\"]); // the (formerly per-tenant) saved checkpoint \`\`\` Same shape works for `\"constructor\"` and `\"prototype\"`. Non-string identifiers (`{ \$ne: null }`, arrays, numbers, booleans) reach the same sinks unchecked. ## Severity Proposed CVSS 3.1: **High**. `MemorySaver` is the default in every quickstart and tutorial, and prototype pollution in Node.js is a documented stepping stone to RCE through gadget chains in downstream serializers, template engines, and dependency-resolution helpers. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single private `assertSafeStorageKey` helper in `memory.ts`, applied at every public entry that touches `storage` or `writes` (15 call sites across 5 methods). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the three prototype-pollution keys `__proto__`, `constructor`, `prototype`. * The `getTuple` and `list` read paths intentionally allow an empty or undefined `checkpoint_id` so the documented \"fetch latest\" behaviour continues to work; both paths still reject the magic keys. \`\`\`ts const POLLUTION_KEYS = new Set([\"__proto__\", \"constructor\", \"prototype\"]); function assertSafeStorageKey( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { /* type check, empty check, pollution check, all with precise diagnostics */ } \`\`\` The guard is a TypeScript `asserts` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the chokepoint pattern used in PR #2349 (`MongoDBSaver`) and PR #2350 (`RedisSaver` / `ShallowRedisSaver`). All three savers now share the same defensive posture at their boundary. * Single private function: it is impossible for a future call-site to forget validation, and the `asserts` annotation surfaces missed sites at compile time. * No new dependencies, no API changes for valid inputs, no behaviour change for any documented happy path. ## Test plan * [x] 22 new tests in `libs/checkpoint/src/tests/memory-pollution.test.ts` under `describe(\"MemorySaver prototype-pollution guard\")`, parameterised across all three pollution keys plus type / empty / accept paths for every entry point. Includes a cross-test invariant (`afterEach` snapshots `Object.getOwnPropertyNames(Object.prototype)`) that asserts pollution did not actually occur even if the guard had been absent. * [x] Existing checkpoint suite green (\`pnpm --filter @langchain/langgraph-checkpoint test\`, 93 of 93 including the 22 new ones). * [x] Lint clean (\`oxlint\`, 0 warnings, 0 errors on the changed files). * [x] Format clean (\`oxfmt --check\`). * [x] No new dependencies, no public API changes, no behaviour change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. Pairs with the two earlier sibling fixes from the same audit pass: * PR #2349 / GHSA-98xf-r82g-9mhx (MongoDB NoSQL injection) * PR #2350 / GHSA-x3wm-3wx7-g6xm (Redis KEYS / SCAN injection) --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
80c2806cb2 |
fix(sdk): fold forkFrom client-side and honor multitaskStrategy (#2447)
## Summary - Fold the SDK's top-level `forkFrom` into `config.configurable.checkpoint_id` client-side before sending `run.start`, so `forkFrom` never reaches the server and the fork target travels via the single legacy-compliant field used by the existing run endpoints. - Drop the server-side `forkFrom` normalization/promotion in both protocol-v2 reference servers (`ProtocolService.createOrResumeRun` and the embed protocol routes), reading the fork target solely from `config.configurable.checkpoint_id`. - Honor the caller's per-run `multitaskStrategy` (`reject` | `rollback` | `interrupt` | `enqueue`) instead of hardcoding `interrupt`, falling back to `enqueue` (the legacy stream-endpoint default, matching the Python protocol-v2 server) when omitted or unrecognized. |
||
|
|
1e73c6b463 |
fix(langgraph-checkpoint-redis): block KEYS / SCAN pattern injection via top-level identifiers (#2350)
## Summary Closes a Redis pattern-injection sink (CWE-77, CWE-943) in `RedisSaver` and `ShallowRedisSaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) can promote a string identifier into a Redis glob (`*`, `?`, `[...]`) and read, overwrite, or wipe checkpoints belonging to other tenants. The audit posted in #2346 (cc @etairl) listed *Redis key/glob injection in `RedisSaver` / `ShallowRedisSaver`* among the unfiled findings from the same security-review pass. This PR confirms the finding and extends the fix to all key-building sites in both savers. ## Vulnerable sinks `RedisSaver` (`libs/checkpoint-redis/src/index.ts`): | Method | Sinks | |---|---| | `getTuple` | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")` plus the direct \`json.get\` key | | `list` (fallback paths) | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`, `keys(\"checkpoint:*:\${checkpointNs}:*\")` | | `put` | `\`checkpoint:\${threadId}:\${checkpointNs}:\${checkpointId}\`` plus the zset key | | `putWrites` | per-write key, zset key, checkpoint key | | `deleteThread` | `keys(\"checkpoint:\${threadId}:*\")`, `keys(\"writes:\${threadId}:*\")` | | `loadPendingWrites` | `keys(\"checkpoint_write:\${threadId}:\${checkpointNs}:\${checkpointId}:*\")` | `ShallowRedisSaver` (`libs/checkpoint-redis/src/shallow.ts`) has the same five public entry points plus the equivalent helper. ## Proof of concept ```ts import { createClient } from \"redis\"; import { RedisSaver } from \"@langchain/langgraph-checkpoint-redis\"; const client = createClient({ url: process.env.REDIS_URL! }); await client.connect(); const saver = new RedisSaver(client); // Tenant A and Tenant B persist checkpoints normally. await saver.put( { configurable: { thread_id: \"tenant-a\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-a\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); await saver.put( { configurable: { thread_id: \"tenant-b\", checkpoint_ns: \"\" } }, { id: \"cp-b\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, { source: \"input\", step: 0, parents: {} } as any, {} ); // Attacker controls only the thread_id of their own request. // Without the guard, deleteThread expands the KEYS pattern to a glob // and deletes BOTH tenants' checkpoints. await saver.deleteThread(\"*\"); // Both \`cp-a\` and \`cp-b\` are gone. ``` The same shape (`\"*\"`, `\"tenant-?\"`, `\"tenant-[ab]\"`, `\"a\\b\"`) is accepted by every Redis pattern site in the table above. ## Severity Proposed CVSS 3.1: **High**. The most severe sink is `deleteThread`, which gives full availability impact across every tenant in the database, with confidentiality (`getTuple`, `list`) and integrity (`put`, `putWrites`) impacts on the other paths. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single `assertSafeKeyComponent` helper exported from `./utils.js`, applied at every key-building site (27 calls across 2 saver files plus the helper export). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the Redis pattern meta-characters `* ? [ ] \`. * Rejects the `:` delimiter that would otherwise corrupt the colon-delimited key structure. \`\`\`ts export function assertSafeKeyComponent( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { const { allowEmpty = false } = options; if (typeof value !== \"string\") { /* precise diagnostic */ throw ... } if (!allowEmpty && value === \"\") { throw ... } if (REDIS_KEY_FORBIDDEN.test(value)) { throw ... } } \`\`\` The guard is a TypeScript \`asserts\` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the maintainers' existing primitive-only pattern (\`escapeRediSearchTagValue\`) in the same file. * Single chokepoint: it is impossible for a future call-site to forget validation. * No new dependencies, no API changes for valid inputs, no behavior change for any documented happy path. * Pairs with PR #2349 (NoSQL injection in MongoDBSaver) so both backends now share the same defensive posture at the saver boundary. ## Test plan * [x] 11 new tests under \`describe(\"assertSafeKeyComponent\")\` in \`libs/checkpoint-redis/src/tests/utils.test.ts\` covering accept and reject paths for every input shape (normal string, empty with and without \`allowEmpty\`, every Redis meta-character, colon delimiter, every wrong type). * [x] Existing \`escapeRediSearchTagValue\` suite still green (regression). * [x] Full suite green (\`pnpm --filter @langchain/langgraph-checkpoint-redis test\`, 21 of 21). * [x] Format clean on all 4 changed files (\`oxfmt\`). * [x] No new dependencies, no public API changes, no behavior change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
80a8c1200a |
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom (#2443)
## Summary
- Remove `command` from `StreamSubmitOptions` and the
`submit-coordinator` resume-via-`submit` path so HITL resume goes
through `stream.respond()` only.
- Simplify `forkFrom` from `{ checkpointId: string }` to a plain
checkpoint id string across the SDK, protocol-v2 services, and docs.
- Update interrupt tests, examples (`HumanInTheLoopView`, branching
views), and React/Vue/Svelte/Angular JSDoc and migration/interrupt docs
to match.
|
||
|
|
2f0010e3a5 |
chore: version packages (#2442)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.9 ### Patch Changes - [#2441](https://github.com/langchain-ai/langgraphjs/pull/2441) [`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): preserve apiUrl path prefix in stream transport URLs Use BaseClient-style URL concatenation in `toAbsoluteUrl` so SSE and WebSocket subscriptions work when the SDK is pointed at a proxied apiUrl with a path prefix (e.g. `/api/chat-langchain`). ## @langchain/angular@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/react@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/svelte@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/vue@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @example/ai-elements@0.1.24 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/assistant-ui-claude@0.1.24 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/ui-angular@0.0.34 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 - @langchain/angular@1.0.9 ## @examples/ui-multimodal@0.0.10 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/ui-react@0.0.10 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 - @langchain/react@1.0.9 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
dbbcb636e7 |
fix(sdk): preserve apiUrl path prefix in stream transport URLs (#2441)
## Summary - Fix `toAbsoluteUrl` to concatenate `apiUrl` and path instead of using `new URL(path, base)`, which dropped path prefixes on proxied deployments. - Route WebSocket stream URL construction through `toAbsoluteUrl` for consistency with SSE transport. - Add unit and integration tests for proxied apiUrl paths, plus shared transport test helpers. |
||
|
|
4e71ace65a |
chore: version packages (#2439)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. ## @langchain/angular@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/react@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/svelte@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/vue@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @example/ai-elements@0.1.23 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/assistant-ui-claude@0.1.23 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/ui-angular@0.0.33 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 - @langchain/angular@1.0.8 ## @examples/ui-multimodal@0.0.9 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/ui-react@0.0.9 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 - @langchain/react@1.0.8 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
29d2bde235 |
fix(sdk): cancel runs on stop by default and add disconnect() (#2438)
## Summary
- `stream.stop()` now cancels the active run server-side by default
(`client.runs.cancel`) before disconnecting the client transport.
- Added `stream.disconnect()` as an alias for `stop({ cancel: false })`
for join/rejoin UIs.
- Introduced `StreamStopOptions` (`{ cancel?: boolean }`) on
`StreamController` and all v1 framework bindings (React, Vue, Svelte,
Angular).
- Updated `use-stream.md` and added controller unit tests for
cancel-on-stop and no-cancel-on-disconnect.
|
||
|
|
39ce52f248 |
chore: version packages (#2436)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - [#2434](https://github.com/langchain-ai/langgraphjs/pull/2434) [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671) Thanks [@hntrl](https://github.com/hntrl)! - fix(react): avoid eager stream getter evaluation during object spread Mark optional `useStream` accessors as non-enumerable so object spread/rest destructuring does not accidentally read guarded fields like `history` or opt into additional stream modes. ## @langchain/angular@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/react@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/svelte@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/vue@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @example/ai-elements@0.1.22 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/assistant-ui-claude@0.1.22 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/ui-angular@0.0.32 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 - @langchain/angular@1.0.7 ## @examples/ui-multimodal@0.0.8 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/ui-react@0.0.8 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 - @langchain/react@1.0.7 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
6b188e80ab |
fix(sdk): avoid eager stream getter evaluation (#2434)
## Summary fix(sdk): avoid eager stream getter evaluation during spread This fixes a React `useStream` development-mode failure where passing the stream handle through components that clone or rest-spread props could accidentally read lazy getters. The guarded `history` getter still throws when explicitly accessed with `fetchStateHistory: false`, but object spread no longer trips that path or widens `streamMode` by touching optional accessors. ## Changes `@langchain/langgraph-sdk` - Marks optional `useStream` accessors (`history`, `experimental_branchTree`, `toolProgress`, `subagents`, `activeSubagents`) as non-enumerable on the returned stream handle. - Preserves explicit access behavior for those accessors, including the existing `history` guard and stream mode opt-in for `toolProgress`/`subagents`. - Adds React hook regression coverage for object spread, explicit getter access, and stream mode inference. |
||
|
|
cfc8d274e4 |
fix(sdk): unwrap Command tool outputs and hide scoped task tools (#2435)
## Summary - Filter scoped deep-agent `task` dispatch events out of `sub.toolCalls` so subagent tool streams only show real worker tools. - Unwrap LangGraph `Command` payloads in `parseToolOutput` when they carry an embedded `ToolMessage`, so `tc.output` resolves to the actual tool result instead of raw graph state. - Share the scoped-task filter between client subagent handles and framework tool-call projections. |
||
|
|
9c9da48ae2 |
chore: version packages (#2433)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. ## @langchain/angular@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/react@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/svelte@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/vue@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @example/ai-elements@0.1.21 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/assistant-ui-claude@0.1.21 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/ui-angular@0.0.31 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 - @langchain/angular@1.0.6 ## @examples/ui-multimodal@0.0.7 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/ui-react@0.0.7 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 - @langchain/react@1.0.6 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
f99941f5fe |
fix(sdk): clear subgraph and subagent discovery on thread swap (#2430)
## Summary - Add `reset()` to `SubgraphDiscovery` and `SubagentDiscovery` to clear internal maps and committed store snapshots. - Call both resets from `StreamController.#teardownThread()` alongside existing per-thread resets (messages, tools, metadata). - Add unit tests for discovery `reset()` and a controller test that `hydrate(null)` clears subgraphs after lifecycle events. |
||
|
|
7788dceb85 |
chore: version packages (#2424)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-redis@1.0.5 ### Patch Changes - [#2208](https://github.com/langchain-ai/langgraphjs/pull/2208) [`ebeb145`](https://github.com/langchain-ai/langgraphjs/commit/ebeb1452d27fcca100cd63bdfd4a7f020949412c) Thanks [@jackjin1997](https://github.com/jackjin1997)! - Fix `deleteThread()` using wrong key pattern (`writes:` instead of `checkpoint_write:`) and add missing cleanup of `write_keys_zset:` entries. ## @langchain/langgraph-supervisor@1.0.3 ### Patch Changes - [#2317](https://github.com/langchain-ai/langgraphjs/pull/2317) [`c088c76`](https://github.com/langchain-ai/langgraphjs/commit/c088c7659c18edf26091813ff384f48f5335bef6) Thanks [@fish895623](https://github.com/fish895623)! - feat(supervisor): widen agents type to accept createAgent graphs ## @langchain/langgraph-sdk@1.9.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. ## @langchain/angular@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/react@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/svelte@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/vue@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @example/ai-elements@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/assistant-ui-claude@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-angular@0.0.30 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/angular@1.0.5 ## @examples/ui-multimodal@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-react@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/react@1.0.5 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
c088c7659c |
feat(supervisor): widen agents type to accept createAgent graphs (#2317)
## Summary - Add a broader `CompiledStateGraph<any, any, string, any, any>` to the `agents` union in `CreateSupervisorParams` - Graphs produced by `createAgent` from `langchain` (via `.graph`) are now accepted alongside existing `createReactAgent` graphs and `RemoteGraph` - The original `AnnotationRootT`-parameterized `CompiledStateGraph` type is preserved for backward compatibility ## Motivation The new `createAgent` API in the `langchain` package returns a `ReactAgent` whose `.graph` property is a `CompiledStateGraph` with a different state schema (`BuiltInState`) than the `MessagesAnnotation`-based state from `createReactAgent`. Since `createReactAgent` is deprecated in favor of `createAgent`, `createSupervisor` needs to accept both graph types. At runtime this already works — `makeCallAgent` types its `agent` parameter as `any` and only accesses `.name`, `.invoke()`, and optionally `.description`. The type constraint on the `agents` parameter was simply too narrow for the new API. ## Changes ### `@langchain/langgraph-supervisor` (`libs/langgraph-supervisor`) - Updated `CreateSupervisorParams.agents` type to include `CompiledStateGraph<any, any, string, any, any>` in the union alongside the existing strictly-typed `CompiledStateGraph` and `RemoteGraph` ## Test plan - [x] `pnpm build` passes for `@langchain/langgraph-supervisor` - [x] Consuming project using `createAgent` + `createSupervisor` compiles without errors - [x] Existing supervisor tests still pass --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
ebeb1452d2 |
fix(langgraph-checkpoint-redis): fix deleteThread using wrong key pattern for writes (#2208)
## Summary Fixes #2207 - Fix `deleteThread()` using incorrect `writes:` prefix instead of `checkpoint_write:` for write key deletion - Add missing cleanup of `write_keys_zset:` entries, matching the correct implementation in `ShallowRedisSaver` The bug was found by comparing `RedisSaver.deleteThread()` with `ShallowRedisSaver.deleteThread()` in `shallow.ts`, which correctly uses `checkpoint_write:` prefix and also cleans up zset keys. ## AI Disclosure This bug was identified through code review with AI assistance. The fix aligns the standard `RedisSaver` implementation with the existing correct `ShallowRedisSaver` implementation. --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
3529e3831a |
fix(sdk): align AssembledToolCall typing with pre-v1 expectations (#2421)
## Summary - Split tool-call handles by consumer: - **Client SDK** (`ThreadStream.toolCalls`, subgraph/subagent projections): `ClientAssembledToolCall` with a promise-only `output` (resolves on success, rejects on error). Still exported as `AssembledToolCall` from `@langchain/langgraph-sdk/client` for script usage. - **Framework SDKs** (`stream.toolCalls`, `useToolCalls`, `injectToolCalls`): `AssembledToolCall` with plain reactive fields — `output: T | null`, `status`, and `error` — updated in place as events arrive so React/Vue/Svelte/Angular can render from snapshots without `await`, effects, or Suspense around promises. - Add generic `AssembledToolCall<TName, TInput, TOutput>` plus `id`/`args` aliases; point `InferToolCalls` at assembled streaming handles and add `AssembledToolCallFromTool` (exported as `ToolCallFromTool` from `@langchain/react`, `@langchain/vue`, `@langchain/svelte`, and `@langchain/angular`). - Rework `ToolCallAssembler` around a mutable internal handle and `toClientAssembledToolCall()` for client projections; framework stores the reactive handle directly. - Remove redundant `InferAssembledToolCalls` and deprecated `StateOf`; wire typed `toolCalls` / selector generics across all four framework packages. - Expand and align `createAgent`, `createDeepAgent`, and `langgraph` type tests across React, Vue, Svelte, and Angular; update examples, protocol-v2 integration tests, and Vue migration docs. |
||
|
|
4a7d9a7c5d |
chore: version packages (#2416)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph@1.3.2 ### Patch Changes - [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415) [`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - Move `@langchain/core` from a runtime dependency back to a required peer dependency so installing the SDK alone no longer pulls in `@langchain/core` (and `js-tiktoken`, etc.). Consumers that use streaming or message coercion must install `@langchain/core` explicitly or via `@langchain/langgraph`. - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/langgraph-sdk@1.9.4 ### Patch Changes - [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415) [`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - Move `@langchain/core` from a runtime dependency back to a required peer dependency so installing the SDK alone no longer pulls in `@langchain/core` (and `js-tiktoken`, etc.). Consumers that use streaming or message coercion must install `@langchain/core` explicitly or via `@langchain/langgraph`. ## @langchain/angular@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/react@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/svelte@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/vue@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @example/ai-elements@0.1.19 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/assistant-ui-claude@0.1.19 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/ui-angular@0.0.29 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 - @langchain/langgraph@1.3.2 - @langchain/angular@1.0.4 ## @examples/ui-multimodal@0.0.5 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/ui-react@0.0.5 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## langgraph@1.0.34 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
b893dc5468 | fix: add @langchain/langgraph to changeset | ||
|
|
9d3c9dd318 |
fix(core): move @langchain/core back into being a peer dep (#2415)
`@langchain/langgraph-sdk@1.9.0` promoted `@langchain/core` from a dev dependency to a **runtime dependency**, which caused install-size metrics for `@langchain/langgraph` to jump from ~6 MB to ~40 MB for consumers who did not already have core installed (or who use `--legacy-peer-deps`). That happened because core pulls in heavy transitive deps such as `js-tiktoken` (~21 MB) and `zod` (~6 MB), even though `@langchain/langgraph` already lists core as a peer. This PR moves `@langchain/core` back to a **required peer dependency** on the SDK, matching `@langchain/langgraph` and the pre-1.9.0 SDK layout. Runtime behavior is unchanged for typical LangGraph apps that already install core; SDK-only installs no longer force core into the tree. Also switches `LangChainTracer` in `types.ts` to a type-only import so the tracer subpath is not pulled as a value import. |
||
|
|
1b5ce0fca0 |
chore: version packages (#2405)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-mongodb@1.3.1 ### Patch Changes - [#2397](https://github.com/langchain-ai/langgraphjs/pull/2397) [`284226c`](https://github.com/langchain-ai/langgraphjs/commit/284226c7ca164b3c81fe2d9e32b10f1fc6b99a3c) Thanks [@hntrl](https://github.com/hntrl)! - fix(checkpoint-mongodb): validate configurable checkpoint identifiers before queries Add runtime validation for `thread_id`, `checkpoint_ns`, and `checkpoint_id` in `MongoDBSaver` methods that read and write checkpoints. This prevents object-based operator payloads from being passed into MongoDB query filters and ensures invalid configurable values fail fast with explicit errors. ## @langchain/langgraph-api@1.2.2 ### Patch Changes - [#2396](https://github.com/langchain-ai/langgraphjs/pull/2396) [`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph-cli): accept hyphenated prerelease tags in `api_version` values. - Updated dependencies \[]: - @langchain/langgraph-ui@1.2.2 ## @langchain/langgraph-cli@1.2.2 ### Patch Changes - [#2389](https://github.com/langchain-ai/langgraphjs/pull/2389) [`40bcdab`](https://github.com/langchain-ai/langgraphjs/commit/40bcdab38fa495028d8eba68062e48079dbe9208) Thanks [@jdrogers940](https://github.com/jdrogers940)! - Adding support for pre-release versions in api_version. - [#2396](https://github.com/langchain-ai/langgraphjs/pull/2396) [`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph-cli): accept hyphenated prerelease tags in `api_version` values. - Updated dependencies \[[`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8)]: - @langchain/langgraph-api@1.2.2 ## @langchain/langgraph@1.3.1 ### Patch Changes - [#2339](https://github.com/langchain-ai/langgraphjs/pull/2339) [`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f) Thanks [@vigneshpatel14](https://github.com/vigneshpatel14)! - fix(langgraph): surface structuredResponse parse failures in createReactAgent - [#2406](https://github.com/langchain-ai/langgraphjs/pull/2406) [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph-core): keep tool results out of v3 message streams - [#2376](https://github.com/langchain-ai/langgraphjs/pull/2376) [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph): prefer configurable assistant and graph IDs for runtime server info Update runtime `serverInfo` construction to read `assistant_id` and `graph_id` from `config.configurable` first, with fallback to `config.metadata` for compatibility. Also expands `execution_info` tests to cover configurable sourcing, precedence, and metadata fallback behavior. - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/langgraph-sdk@1.9.3 ### Patch Changes - [#2387](https://github.com/langchain-ai/langgraphjs/pull/2387) [`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Coalesce `RootMessageProjection` store writes through a single `setTimeout(0)` flush so long `messages`-channel replays (on refresh, mid-run join, or rapid subagent streaming) no longer drain as a per-event microtask chain that trips React's `Maximum update depth exceeded` guard. Replaces the previous `MessageChannel`-based batching, which deferred initial-submit events past the first render and left the UI looking frozen until refresh. - [#2372](https://github.com/langchain-ai/langgraphjs/pull/2372) [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7) Thanks [@ahmed-z0](https://github.com/ahmed-z0)! - Fix subagent message routing to prefer the stream event namespace over checkpoint metadata when filtering subagent messages. - [#2384](https://github.com/langchain-ai/langgraphjs/pull/2384) [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - batch RootMessageProjection store writes through a macrotask - [#2388](https://github.com/langchain-ai/langgraphjs/pull/2388) [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c) Thanks [@hntrl](https://github.com/hntrl)! - fix(sdk): retry connection failures before throwing ConnectionError - [#2381](https://github.com/langchain-ai/langgraphjs/pull/2381) [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - fix(sdk): forward config + metadata on respondInput for resume submits - [#2379](https://github.com/langchain-ai/langgraphjs/pull/2379) [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - filter SSE-replayed input.requested events through a hydrated interrupt allowlist - [#2390](https://github.com/langchain-ai/langgraphjs/pull/2390) [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Bind deepagents subagent discovery to the execution namespace via taskInput so `useMessages(stream, subagent)` resolves the streaming scope instead of the trigger tool-call namespace. ## @langchain/angular@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/react@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/svelte@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/vue@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/langgraph-cua@1.0.2 ## @langchain/langgraph-supervisor@1.0.2 ## @langchain/langgraph-swarm@1.0.2 ## @langchain/langgraph-ui@1.2.2 ## @example/ai-elements@0.1.18 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## @examples/assistant-ui-claude@0.1.18 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## @examples/ui-angular@0.0.28 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 - @langchain/langgraph@1.3.1 - @langchain/angular@1.0.3 ## @examples/ui-multimodal@0.0.4 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## @examples/ui-react@0.0.4 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## langgraph@1.0.33 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 ## docs@null # docs ## null ## null --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
284226c7ca |
fix(langgraph-checkpoint-mongodb): validate configurable checkpoint IDs (#2397)
## Summary Fixes #2351 This change hardens `@langchain/langgraph-checkpoint-mongodb` against object-based configurable input in checkpoint identifiers. It adds runtime validation for `thread_id`, `checkpoint_ns`, and `checkpoint_id` before any MongoDB query/write path uses these values, so operator-like payloads are rejected early with explicit errors. ## Changes ### `@langchain/langgraph-checkpoint-mongodb` - Added a shared `getStringConfigValue` runtime validator in [`libs/checkpoint-mongodb/src/checkpoint.ts`](libs/checkpoint-mongodb/src/checkpoint.ts). - Applied validation to `getTuple`, `list`, `put`, `putWrites`, and `deleteThread`. - Preserved existing behavior where `getTuple` returns `undefined` when `thread_id` is missing, while now rejecting non-string values. - Added regression tests in [`libs/checkpoint-mongodb/src/tests/checkpoints.test.ts`](libs/checkpoint-mongodb/src/tests/checkpoints.test.ts) for object/operator payloads across the affected methods. - Added a patch changeset for `@langchain/langgraph-checkpoint-mongodb`. Co-authored-by: Itay <9601971+etairl@users.noreply.github.com> |
||
|
|
c6c0a58c3a | chore: exit rc (#2414) | ||
|
|
e54ae901e1 |
fix(core): keep tool results out of v3 message streams (#2406)
## Summary - Prevent v3 `run.messages` from surfacing `ToolMessage` outputs as assistant text. - Skip tool-role message lifecycles in the messages transformer while preserving tool messages in state snapshots. - Add regression coverage for tool-result message leakage. fixes https://github.com/langchain-ai/deepagentsjs/issues/534 |
||
|
|
01dd0462ed |
fix(sdk): retry connection failures before throwing ConnectionError (#2388)
## Summary This change updates SDK retry behavior so connection-related failures are retried instead of immediately aborting inside `onFailedAttempt`. When retries are exhausted, the final surfaced error is still coalesced to a `ConnectionError` with the existing LangGraph-specific guidance. A focused unit test was added to lock in this behavior. ## Changes ### @langchain/langgraph-sdk - Updated `AsyncCaller` connection-error handling to only throw `ConnectionError` on the final failed attempt (`retriesLeft === 0`), while allowing retries on earlier attempts. - Added a regression test covering retry count plus final `ConnectionError` coalescing for connection-refused/fetch-failed style errors. - Added a patch changeset for `@langchain/langgraph-sdk` documenting the retry/coalescing fix. |