mirror of
https://github.com/langchain-ai/langgraphjs.git
synced 2026-07-22 00:55:26 -04:00
@langchain/angular@1.0.16
30 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
d2ca90f8e2 |
chore: version packages (#2453)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-checkpoint-mongodb@1.3.2 ### Patch Changes - [#2186](https://github.com/langchain-ai/langgraphjs/pull/2186) [`26c2e32`](https://github.com/langchain-ai/langgraphjs/commit/26c2e325f435a2c061d6b78a7bd6af089cb1e0e6) Thanks [@jackjin1997](https://github.com/jackjin1997)! - fix: metadata filter in list() now works by querying a plain JSON shadow copy instead of the serialized binary blob ## @langchain/langgraph-checkpoint-postgres@1.0.2 ### Patch Changes - [#2255](https://github.com/langchain-ai/langgraphjs/pull/2255) [`e82a50b`](https://github.com/langchain-ai/langgraphjs/commit/e82a50b961a9413dab1ad2248747d5c73a6a1e58) Thanks [@leesta24](https://github.com/leesta24)! - fix(checkpoint-postgres): move serialization outside transaction in put() ## @langchain/langgraph-checkpoint-redis@1.0.7 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-api@1.2.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. - Updated dependencies \[]: - @langchain/langgraph-ui@1.2.4 ## @langchain/langgraph-cli@1.2.4 ### Patch Changes - [#1925](https://github.com/langchain-ai/langgraphjs/pull/1925) [`6503319`](https://github.com/langchain-ai/langgraphjs/commit/65033191cc3dd671d64dfac78ccdad453fdfbda2) Thanks [@jbrody-nexxa](https://github.com/jbrody-nexxa)! - fix(cli): add --no-reload flag to dev command - Updated dependencies \[[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-api@1.2.4 ## @langchain/langgraph@1.3.3 ### Patch Changes - [#2037](https://github.com/langchain-ai/langgraphjs/pull/2037) [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f) Thanks [@pawel-twardziak](https://github.com/pawel-twardziak)! - Decouple `ContextType` generic from `configurable` in `PregelOptions` so that providing a custom context type no longer incorrectly narrows the configurable parameter. - [#2457](https://github.com/langchain-ai/langgraphjs/pull/2457) [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph): pass context with stateful RemoteGraph runs Pop `thread_id` from run `config.configurable` and forward `context` to the SDK so checkpointed remote runs accept user context without a 400 from ambiguous parameters. Closes [#1922](https://github.com/langchain-ai/langgraphjs/issues/1922). - [#1988](https://github.com/langchain-ai/langgraphjs/pull/1988) [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7) Thanks [@Axadali](https://github.com/Axadali)! - Fix race condition in IterableReadableWritableStream.push() that caused ERR_INVALID_STATE errors when streaming with multiple parallel nodes and aborting the stream. - [#2409](https://github.com/langchain-ai/langgraphjs/pull/2409) [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3) Thanks [@pragnyanramtha](https://github.com/pragnyanramtha)! - Preserve non-plain objects passed through `Send` and `Command` argument deserialization. - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph-checkpoint@1.0.4 ## @langchain/langgraph-supervisor@1.0.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-sdk@1.9.11 ### Patch Changes - [#2455](https://github.com/langchain-ai/langgraphjs/pull/2455) [`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856) Thanks [@JHSeo-git](https://github.com/JHSeo-git)! - fix(sdk): prefer completed task's direct mapping over pending checkpoint's positional guess in fetchSubagentHistory - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/angular@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/react@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/svelte@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/vue@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/langgraph-ui@1.2.4 ## @example/ai-elements@0.1.26 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/assistant-ui-claude@0.1.26 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/ui-angular@0.0.36 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph@1.3.3 - @langchain/angular@1.0.11 ## @examples/ui-multimodal@0.0.12 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/ui-react@0.0.12 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## langgraph@1.0.35 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
0125920a2c |
chore(deps): bump uuid from 10.0.0 to 14.0.0 (#2344)
Bumps [uuid](https://github.com/uuidjs/uuid) from 10.0.0 to 14.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/uuidjs/uuid/releases">uuid's releases</a>.</em></p> <blockquote> <h2>v14.0.0</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a> (2026-04-19)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> </ul> <h3>Features</h3> <ul> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>) (<a href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3">dc4ddb8</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>) (<a href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4">f2c235f</a>)</li> <li>Use GITHUB_TOKEN for release-please and enable npm provenance (<a href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>) (<a href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c">ffa3138</a>)</li> </ul> <h2>v13.0.2</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.1...v13.0.2">13.0.2</a> (2026-05-04)</h2> <h3>Bug Fixes</h3> <ul> <li>rerelease to fix provenance. (<a href="https://github.com/uuidjs/uuid/commit/49ccb35f78c0c4ce1409dd2f1d89f83caadba10b">49ccb35</a>)</li> </ul> <h2>v13.0.1</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v13.0.1">13.0.1</a> (2026-04-27)</h2> <h3>Bug Fixes</h3> <ul> <li>backport fix for GHSA-w5hq-g745-h8pq (<a href="https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a">9d27ddf</a>)</li> </ul> <h2>v13.0.0</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a> (2025-09-08)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li> </ul> <h2>v12.0.1</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v12.0.1">12.0.1</a> (2026-04-29)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md">uuid's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a> (2026-04-19)</h2> <h3>Security</h3> <ul> <li>Fixes <a href="https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq">GHSA-w5hq-g745-h8pq</a>: <code>v3()</code>, <code>v5()</code>, and <code>v6()</code> did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid <code>offset</code> was provided. A <code>RangeError</code> is now thrown if <code>offset < 0</code> or <code>offset + 16 > buf.length</code>.</li> </ul> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><code>crypto</code> is now expected to be globally defined (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> <li>upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a> (2025-09-08)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v11.1.0...v12.0.0">12.0.0</a> (2025-09-05)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>update to typescript@5.2 (<a href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>)</li> <li>remove CommonJS support (<a href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>)</li> <li>drop node@16 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>)</li> </ul> <h3>Features</h3> <ul> <li>add node@24 to ci matrix (<a href="https://redirect.github.com/uuidjs/uuid/issues/879">#879</a>) (<a href="https://github.com/uuidjs/uuid/commit/42b6178aa21a593257f0a72abacd220f0b7b8a92">42b6178</a>)</li> <li>drop node@16 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>) (<a href="https://github.com/uuidjs/uuid/commit/0f38cf10366ab074f9328ae2021eea04d5f2e530">0f38cf1</a>)</li> <li>remove CommonJS support (<a href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>) (<a href="https://github.com/uuidjs/uuid/commit/ae786e27265f50bcf7cead196c29f1869297c42f">ae786e2</a>)</li> <li>update to typescript@5.2 (<a href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>) (<a href="https://github.com/uuidjs/uuid/commit/c7ee40598ed78584d81ab78dffded9fe5ff20b01">c7ee405</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>improve v4() performance (<a href="https://redirect.github.com/uuidjs/uuid/issues/894">#894</a>) (<a href="https://github.com/uuidjs/uuid/commit/5fd974c12718c8848035650b69b8948f12ace197">5fd974c</a>)</li> <li>restore node: prefix (<a href="https://redirect.github.com/uuidjs/uuid/issues/889">#889</a>) (<a href="https://github.com/uuidjs/uuid/commit/e1f42a354593093ba0479f0b4047dae82d28c507">e1f42a3</a>)</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v11.0.5...v11.1.0">11.1.0</a> (2025-02-19)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/uuidjs/uuid/commit/7c1ea087a8149b57380fc8bb7f68c3a215cb6e4b"><code>7c1ea08</code></a> chore(main): release 14.0.0 (<a href="https://redirect.github.com/uuidjs/uuid/issues/926">#926</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34"><code>3d2c5b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4"><code>f2c235f</code></a> fix!: expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/529ef0899f5dd503d2ee90d690585d63d78bc212"><code>529ef08</code></a> chore: upgrade TypeScript and fixup types (<a href="https://redirect.github.com/uuidjs/uuid/issues/927">#927</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/086fd7976f11433edf9ac80be876b3ad243fe087"><code>086fd79</code></a> chore: update dependencies (<a href="https://redirect.github.com/uuidjs/uuid/issues/933">#933</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3"><code>dc4ddb8</code></a> feat!: drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/0f1f9c9c9cedbae5a1d363d5406c5dfbabe81404"><code>0f1f9c9</code></a> chore: switch to Biome for parsing and linting (<a href="https://redirect.github.com/uuidjs/uuid/issues/932">#932</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/e2879e64bf125add903c1eff6e0860542c605013"><code>e2879e6</code></a> chore: use maintained version of npm-run-all (<a href="https://redirect.github.com/uuidjs/uuid/issues/930">#930</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c"><code>ffa3138</code></a> fix: Use GITHUB_TOKEN for release-please and enable npm provenance (<a href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/0423d49df2dc8efc300c804731d25f4d7e0fccc4"><code>0423d49</code></a> docs: remove obsolete v1 option notes (<a href="https://redirect.github.com/uuidjs/uuid/issues/915">#915</a>)</li> <li>Additional commits viewable in <a href="https://github.com/uuidjs/uuid/compare/v10.0.0...v14.0.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for uuid since your current version.</p> </details> <details> <summary>Install script changes</summary> <p>This version adds <code>prepare</code> script that runs during installation. Review the package contents before updating.</p> </details> <br /> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
381a9f64d0 |
chore: version packages (#2445)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.3 ### Patch Changes - [#2352](https://github.com/langchain-ai/langgraphjs/pull/2352) [`14f2a79`](https://github.com/langchain-ai/langgraphjs/commit/14f2a796912e81d7f52f0a4f16747f6d0a269209) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys `MemorySaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into property accesses on the nested plain objects `this.storage` and `this.writes`. A caller able to shape any of those fields (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) could pass `"__proto__"`, `"constructor"`, or `"prototype"` and have the subsequent assignment mutate `Object.prototype`. From that point every plain object in the process inherits the injected property, breaking `for...in` loops, truthy short-circuits, and downstream serializers across unrelated code paths. CWE-1321. Adds an `assertSafeStorageKey` chokepoint applied at every public entry that touches `storage` or `writes` (`put`, `putWrites`, `deleteThread`, `getTuple`, `list`). The guard rejects non-string values, the empty string (unless explicitly opted-in for `checkpoint_ns`), and the three prototype-pollution keys. Behaviour for valid string identifiers is unchanged. ## @langchain/langgraph-checkpoint-redis@1.0.6 ### Patch Changes - [#2350](https://github.com/langchain-ai/langgraphjs/pull/2350) [`1e73c6b`](https://github.com/langchain-ai/langgraphjs/commit/1e73c6b4630bbc4aa976eea4bfc33c4f753b7ee9) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(checkpoint-redis): block Redis KEYS / SCAN pattern injection via top-level identifiers `RedisSaver` and `ShallowRedisSaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into Redis keys and `client.keys(pattern)` calls with no validation. A caller able to shape any of those fields (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) could promote a string identifier into a glob pattern (`*`, `?`, `[...]`) or escape character (`\`). The most severe sink is `deleteThread`: a `threadId` of `*` issues `client.keys("checkpoint:*:*")` followed by `client.del(...)`, deleting every checkpoint in the database across every tenant. `getTuple`, `list`, and `loadPendingWrites` are exposed to the same pattern via the fallback paths that bypass the existing `escapeRediSearchTagValue` defense. Adds a single `assertSafeKeyComponent` helper exported from `./utils.js` and applies it at every key-building site. The guard asserts the value is a non-empty string (the empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`) and rejects the Redis pattern meta-characters `* ? [ ] \`. The `:` delimiter is intentionally permitted because LangGraph emits it as a legitimate part of `checkpoint_ns` for subgraphs / nested graphs, where it only ever appears as a literal in the key. Behavior for valid string identifiers is unchanged. ## @langchain/langgraph-api@1.2.3 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)]: - @langchain/langgraph-ui@1.2.3 ## @langchain/langgraph-cli@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-api@1.2.3 ## @langchain/langgraph-ui@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. ## @langchain/langgraph-sdk@1.9.10 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. ## @langchain/angular@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/react@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/svelte@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/vue@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @example/ai-elements@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/assistant-ui-claude@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-angular@0.0.35 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/angular@1.0.10 ## @examples/ui-multimodal@0.0.11 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-react@0.0.11 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/react@1.0.10 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
1e73c6b463 |
fix(langgraph-checkpoint-redis): block KEYS / SCAN pattern injection via top-level identifiers (#2350)
## Summary Closes a Redis pattern-injection sink (CWE-77, CWE-943) in `RedisSaver` and `ShallowRedisSaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) can promote a string identifier into a Redis glob (`*`, `?`, `[...]`) and read, overwrite, or wipe checkpoints belonging to other tenants. The audit posted in #2346 (cc @etairl) listed *Redis key/glob injection in `RedisSaver` / `ShallowRedisSaver`* among the unfiled findings from the same security-review pass. This PR confirms the finding and extends the fix to all key-building sites in both savers. ## Vulnerable sinks `RedisSaver` (`libs/checkpoint-redis/src/index.ts`): | Method | Sinks | |---|---| | `getTuple` | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")` plus the direct \`json.get\` key | | `list` (fallback paths) | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`, `keys(\"checkpoint:*:\${checkpointNs}:*\")` | | `put` | `\`checkpoint:\${threadId}:\${checkpointNs}:\${checkpointId}\`` plus the zset key | | `putWrites` | per-write key, zset key, checkpoint key | | `deleteThread` | `keys(\"checkpoint:\${threadId}:*\")`, `keys(\"writes:\${threadId}:*\")` | | `loadPendingWrites` | `keys(\"checkpoint_write:\${threadId}:\${checkpointNs}:\${checkpointId}:*\")` | `ShallowRedisSaver` (`libs/checkpoint-redis/src/shallow.ts`) has the same five public entry points plus the equivalent helper. ## Proof of concept ```ts import { createClient } from \"redis\"; import { RedisSaver } from \"@langchain/langgraph-checkpoint-redis\"; const client = createClient({ url: process.env.REDIS_URL! }); await client.connect(); const saver = new RedisSaver(client); // Tenant A and Tenant B persist checkpoints normally. await saver.put( { configurable: { thread_id: \"tenant-a\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-a\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); await saver.put( { configurable: { thread_id: \"tenant-b\", checkpoint_ns: \"\" } }, { id: \"cp-b\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, { source: \"input\", step: 0, parents: {} } as any, {} ); // Attacker controls only the thread_id of their own request. // Without the guard, deleteThread expands the KEYS pattern to a glob // and deletes BOTH tenants' checkpoints. await saver.deleteThread(\"*\"); // Both \`cp-a\` and \`cp-b\` are gone. ``` The same shape (`\"*\"`, `\"tenant-?\"`, `\"tenant-[ab]\"`, `\"a\\b\"`) is accepted by every Redis pattern site in the table above. ## Severity Proposed CVSS 3.1: **High**. The most severe sink is `deleteThread`, which gives full availability impact across every tenant in the database, with confidentiality (`getTuple`, `list`) and integrity (`put`, `putWrites`) impacts on the other paths. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single `assertSafeKeyComponent` helper exported from `./utils.js`, applied at every key-building site (27 calls across 2 saver files plus the helper export). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the Redis pattern meta-characters `* ? [ ] \`. * Rejects the `:` delimiter that would otherwise corrupt the colon-delimited key structure. \`\`\`ts export function assertSafeKeyComponent( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { const { allowEmpty = false } = options; if (typeof value !== \"string\") { /* precise diagnostic */ throw ... } if (!allowEmpty && value === \"\") { throw ... } if (REDIS_KEY_FORBIDDEN.test(value)) { throw ... } } \`\`\` The guard is a TypeScript \`asserts\` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the maintainers' existing primitive-only pattern (\`escapeRediSearchTagValue\`) in the same file. * Single chokepoint: it is impossible for a future call-site to forget validation. * No new dependencies, no API changes for valid inputs, no behavior change for any documented happy path. * Pairs with PR #2349 (NoSQL injection in MongoDBSaver) so both backends now share the same defensive posture at the saver boundary. ## Test plan * [x] 11 new tests under \`describe(\"assertSafeKeyComponent\")\` in \`libs/checkpoint-redis/src/tests/utils.test.ts\` covering accept and reject paths for every input shape (normal string, empty with and without \`allowEmpty\`, every Redis meta-character, colon delimiter, every wrong type). * [x] Existing \`escapeRediSearchTagValue\` suite still green (regression). * [x] Full suite green (\`pnpm --filter @langchain/langgraph-checkpoint-redis test\`, 21 of 21). * [x] Format clean on all 4 changed files (\`oxfmt\`). * [x] No new dependencies, no public API changes, no behavior change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
7788dceb85 |
chore: version packages (#2424)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-redis@1.0.5 ### Patch Changes - [#2208](https://github.com/langchain-ai/langgraphjs/pull/2208) [`ebeb145`](https://github.com/langchain-ai/langgraphjs/commit/ebeb1452d27fcca100cd63bdfd4a7f020949412c) Thanks [@jackjin1997](https://github.com/jackjin1997)! - Fix `deleteThread()` using wrong key pattern (`writes:` instead of `checkpoint_write:`) and add missing cleanup of `write_keys_zset:` entries. ## @langchain/langgraph-supervisor@1.0.3 ### Patch Changes - [#2317](https://github.com/langchain-ai/langgraphjs/pull/2317) [`c088c76`](https://github.com/langchain-ai/langgraphjs/commit/c088c7659c18edf26091813ff384f48f5335bef6) Thanks [@fish895623](https://github.com/fish895623)! - feat(supervisor): widen agents type to accept createAgent graphs ## @langchain/langgraph-sdk@1.9.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. ## @langchain/angular@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/react@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/svelte@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/vue@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @example/ai-elements@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/assistant-ui-claude@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-angular@0.0.30 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/angular@1.0.5 ## @examples/ui-multimodal@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-react@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/react@1.0.5 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
ebeb1452d2 |
fix(langgraph-checkpoint-redis): fix deleteThread using wrong key pattern for writes (#2208)
## Summary Fixes #2207 - Fix `deleteThread()` using incorrect `writes:` prefix instead of `checkpoint_write:` for write key deletion - Add missing cleanup of `write_keys_zset:` entries, matching the correct implementation in `ShallowRedisSaver` The bug was found by comparing `RedisSaver.deleteThread()` with `ShallowRedisSaver.deleteThread()` in `shallow.ts`, which correctly uses `checkpoint_write:` prefix and also cleans up zset keys. ## AI Disclosure This bug was identified through code review with AI assistance. The fix aligns the standard `RedisSaver` implementation with the existing correct `ShallowRedisSaver` implementation. --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
085a07f569 |
feat(core): event based streaming (#2314)
All stream v2 changes consolidated. --------- Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
9102d526c8 |
fix(langgraph): propagate tracer metadata defaults from configurable (#2315)
## Summary This updates Pregel callback manager initialization to pass `tracerInheritableMetadata` defaults derived from `config.configurable`, and narrows `ensureLangGraphConfig` metadata mirroring to the allowlisted LangGraph identifiers used in stream/runtime metadata. ## Changes ### `@langchain/langgraph` (`libs/langgraph-core`) - Updated Pregel callback manager setup to configure core callbacks with `tracerInheritableMetadata` based on configurable primitive values, excluding internal and secret-like keys. - Hoisted tracing default logic into `_getTracingMetadataDefaults` and `_excludeAsMetadata` for parity with the Python implementation shape. - Restricted `ensureLangGraphConfig` configurable-to-metadata propagation to the identifier allowlist: - `thread_id` - `checkpoint_id` - `checkpoint_ns` - `task_id` - `run_id` - `assistant_id` - `graph_id` - Updated config tests to assert the narrowed metadata propagation behavior. |
||
|
|
d88f29ba25 |
chore(repo): migrate linting and formatting from ESLint/Prettier to oxlint/oxfmt (#2256)
Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Christian Bromann <christian-bromann@users.noreply.github.com> Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com> |
||
|
|
a1e2abff1e |
chore: version packages (#2174)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
a8f1b9d26b | fix(checkpoint-redis): fix dependency (#2181) | ||
|
|
dc37d3cd62 |
chore: version packages (#2025)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
c35c274a5d |
fix(checkpoint-redis): detect existing writes in put to preserve has_writes flag (#2026)
Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
194e5bf1e5 |
fix: use comprehensive RediSearch tag escaping (#2012)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|
|
9c0c92e121 |
fix: bump testcontainers to ^11 in checkpoint-redis to resolve CVE-2026-22036 (#1982)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
289cc95bea |
chore: version packages (#1941)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
814c76dc39 | fix(checkpoint): improve sanitization in Redis and MongoDB filters (#1943) | ||
|
|
6d5cdcbb10 | fix(chore): replace turbo:command with plain turbo (#1869) | ||
|
|
e7aeffeb72 |
chore: replace yarn with pnpm (#1862)
Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
f602df6593 |
fix(langgraph): add resumable stream support to remote graph (#1827)
Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com> |
||
|
|
52dc36b425 | fix(*): set proper url prefix for package reference (#1811) | ||
|
|
3e81549d0b |
Version Packages (#1801)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
9440d080e6 |
fix(@langchain/langgraph-checkpoint-redis): deserialize checkpointed state (#1768)
Co-authored-by: David Duong <david@duong.cz> |
||
|
|
fdd5878e89 |
chore: update dependencies (#1774)
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d4b6d9ca98 |
Version Packages (#1735)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
1e1ecbbcf8 |
feat: merge v1 (#1733)
Co-authored-by: Tat Dat Duong <david@duong.cz> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Nuno Campos <nuno@langchain.dev> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
c90a7fb74d |
Version Packages (#1714)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
926db1efe9 |
fix(langgraph-checkpoint-redis): allow alpha version of 1.0.0 (#1701)
Co-authored-by: Baptiste Jamin <baptiste@crisp.chat> Co-authored-by: David Duong <david@duong.cz> |
||
|
|
03ae1089ea | chore: remove release-it, fix dependabot for tmp (#1638) | ||
|
|
2c6cc0ac9e |
feat(checkpoint-redis): add Redis-based checkpoint and store implemen… (#1544)
Co-authored-by: Tat Dat Duong <david@duong.cz> |