mirror of
https://github.com/langchain-ai/langgraphjs.git
synced 2026-07-22 00:55:26 -04:00
@langchain/angular@1.0.18
457 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
133d0bd52e |
chore: version packages (#2501)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.18 ### Patch Changes - [#2500](https://github.com/langchain-ai/langgraphjs/pull/2500) [`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): resume useChannel subscriptions across serial runs Enable `resumeOnPause` on the channel projection so `useChannel` keeps accumulating events across prompts on the same thread. Clarify selector docs and JSDoc: `useChannel` for the full event stream, `useExtension` for the latest payload. ## @langchain/angular@1.0.18 ### Patch Changes - [#2500](https://github.com/langchain-ai/langgraphjs/pull/2500) [`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): resume useChannel subscriptions across serial runs Enable `resumeOnPause` on the channel projection so `useChannel` keeps accumulating events across prompts on the same thread. Clarify selector docs and JSDoc: `useChannel` for the full event stream, `useExtension` for the latest payload. - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/langgraph-sdk@1.9.18 ## @langchain/react@1.0.18 ### Patch Changes - [#2500](https://github.com/langchain-ai/langgraphjs/pull/2500) [`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): resume useChannel subscriptions across serial runs Enable `resumeOnPause` on the channel projection so `useChannel` keeps accumulating events across prompts on the same thread. Clarify selector docs and JSDoc: `useChannel` for the full event stream, `useExtension` for the latest payload. - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/langgraph-sdk@1.9.18 ## @langchain/svelte@1.0.18 ### Patch Changes - [#2500](https://github.com/langchain-ai/langgraphjs/pull/2500) [`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): resume useChannel subscriptions across serial runs Enable `resumeOnPause` on the channel projection so `useChannel` keeps accumulating events across prompts on the same thread. Clarify selector docs and JSDoc: `useChannel` for the full event stream, `useExtension` for the latest payload. - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/langgraph-sdk@1.9.18 ## @langchain/vue@1.0.18 ### Patch Changes - [#2500](https://github.com/langchain-ai/langgraphjs/pull/2500) [`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): resume useChannel subscriptions across serial runs Enable `resumeOnPause` on the channel projection so `useChannel` keeps accumulating events across prompts on the same thread. Clarify selector docs and JSDoc: `useChannel` for the full event stream, `useExtension` for the latest payload. - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/langgraph-sdk@1.9.18 ## @example/ai-elements@0.1.33 ### Patch Changes - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/react@1.0.18 ## @examples/assistant-ui-claude@0.1.33 ### Patch Changes - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/react@1.0.18 ## @examples/ui-angular@0.0.43 ### Patch Changes - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/langgraph-sdk@1.9.18 - @langchain/angular@1.0.18 ## @examples/ui-multimodal@0.0.19 ### Patch Changes - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/react@1.0.18 ## @examples/ui-react@0.0.19 ### Patch Changes - Updated dependencies \[[`f67772f`](https://github.com/langchain-ai/langgraphjs/commit/f67772ff3f7ac13d81576d395d7529de4eb4390b)]: - @langchain/langgraph-sdk@1.9.18 - @langchain/react@1.0.18 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
f67772ff3f |
fix(sdk): resume useChannel subscriptions across serial runs (#2500)
## Summary - Fix `channelProjection` to pass `resumeOnPause: true`, matching `extensionProjection`, so `useChannel` continues receiving events after each run's terminal lifecycle event instead of going silent after the first prompt on a thread. - Add a unit test that simulates a paused subscription resuming with a second event batch, and a React browser integration test asserting `useChannel` event count grows across two serial submits (3 → 6). - Update selector JSDoc and `selectors.md` / `selector-composables.md` across React, Vue, Svelte, and Angular to document the complementary roles: `useChannel` = full bounded event history across runs; `useExtension` = latest payload only. |
||
|
|
c418781870 |
chore: version packages (#2495)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-api@1.2.5 ### Patch Changes - [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph): forward named custom stream channels consistently Forward remote `StreamChannel` emissions as `custom:<name>` protocol events and normalize them back to custom-channel payloads in the API session. This aligns JavaScript stream-channel forwarding with the protocol subscription shape used by remote clients, so `custom:<name>` subscriptions receive extension channel data consistently. - Updated dependencies \[]: - @langchain/langgraph-ui@1.2.5 ## @langchain/langgraph-cli@1.2.5 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f)]: - @langchain/langgraph-api@1.2.5 ## @langchain/langgraph@1.3.6 ### Patch Changes - [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph): forward named custom stream channels consistently Forward remote `StreamChannel` emissions as `custom:<name>` protocol events and normalize them back to custom-channel payloads in the API session. This aligns JavaScript stream-channel forwarding with the protocol subscription shape used by remote clients, so `custom:<name>` subscriptions receive extension channel data consistently. - Updated dependencies \[[`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph-sdk@1.9.17 ## @langchain/langgraph-sdk@1.9.17 ### Patch Changes - [#2494](https://github.com/langchain-ai/langgraphjs/pull/2494) [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): revive automatic optimistic submit echo Echo `submit()` input into `values` / `messages` immediately with client-side id minting and id-based reconciliation as the server streams back. Expose per-message `optimisticStatus` via message metadata (`pending` → `sent` / `failed`), shallow-merge non-message keys with rollback when no `values` arrive, and add an `optimistic: false` hook opt-out. Plumb through React, Vue, Svelte, and Angular with browser e2e coverage. - [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): coalesce duplicate thread read requests Coalesce concurrent identical `threads.getState()` and `threads.getHistory()` reads within the SDK client so transient remounts do not issue duplicate hydrate requests. Request identity includes the prepared URL, body, method, and headers, and coalescing is skipped for caller-provided abort signals, raw response reads, and `onRequest` hooks to preserve auth and cancellation isolation. - [#2497](https://github.com/langchain-ai/langgraphjs/pull/2497) [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): reconcile subagents and subgraphs on thread reconnect Seed deep-agent subagent cards from checkpoint messages and subgraph hosts from a single bounded `getHistory` read during `hydrate()`, so parallel fan-out discovery reappears immediately on refresh instead of waiting for SSE replay. Subagent execution namespaces are promoted through the existing guarded discovery state machine (bulk at hydrate, lazily per opened card via the selector layer). The getHistory cost is O(1) in requests regardless of fan-out width. ## @langchain/angular@1.0.17 ### Patch Changes - [#2494](https://github.com/langchain-ai/langgraphjs/pull/2494) [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): revive automatic optimistic submit echo Echo `submit()` input into `values` / `messages` immediately with client-side id minting and id-based reconciliation as the server streams back. Expose per-message `optimisticStatus` via message metadata (`pending` → `sent` / `failed`), shallow-merge non-message keys with rollback when no `values` arrive, and add an `optimistic: false` hook opt-out. Plumb through React, Vue, Svelte, and Angular with browser e2e coverage. - [#2497](https://github.com/langchain-ai/langgraphjs/pull/2497) [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): reconcile subagents and subgraphs on thread reconnect Seed deep-agent subagent cards from checkpoint messages and subgraph hosts from a single bounded `getHistory` read during `hydrate()`, so parallel fan-out discovery reappears immediately on refresh instead of waiting for SSE replay. Subagent execution namespaces are promoted through the existing guarded discovery state machine (bulk at hydrate, lazily per opened card via the selector layer). The getHistory cost is O(1) in requests regardless of fan-out width. - Updated dependencies \[[`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph-sdk@1.9.17 ## @langchain/react@1.0.17 ### Patch Changes - [#2494](https://github.com/langchain-ai/langgraphjs/pull/2494) [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): revive automatic optimistic submit echo Echo `submit()` input into `values` / `messages` immediately with client-side id minting and id-based reconciliation as the server streams back. Expose per-message `optimisticStatus` via message metadata (`pending` → `sent` / `failed`), shallow-merge non-message keys with rollback when no `values` arrive, and add an `optimistic: false` hook opt-out. Plumb through React, Vue, Svelte, and Angular with browser e2e coverage. - [#2497](https://github.com/langchain-ai/langgraphjs/pull/2497) [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): reconcile subagents and subgraphs on thread reconnect Seed deep-agent subagent cards from checkpoint messages and subgraph hosts from a single bounded `getHistory` read during `hydrate()`, so parallel fan-out discovery reappears immediately on refresh instead of waiting for SSE replay. Subagent execution namespaces are promoted through the existing guarded discovery state machine (bulk at hydrate, lazily per opened card via the selector layer). The getHistory cost is O(1) in requests regardless of fan-out width. - Updated dependencies \[[`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph-sdk@1.9.17 ## @langchain/svelte@1.0.17 ### Patch Changes - [#2494](https://github.com/langchain-ai/langgraphjs/pull/2494) [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): revive automatic optimistic submit echo Echo `submit()` input into `values` / `messages` immediately with client-side id minting and id-based reconciliation as the server streams back. Expose per-message `optimisticStatus` via message metadata (`pending` → `sent` / `failed`), shallow-merge non-message keys with rollback when no `values` arrive, and add an `optimistic: false` hook opt-out. Plumb through React, Vue, Svelte, and Angular with browser e2e coverage. - [#2497](https://github.com/langchain-ai/langgraphjs/pull/2497) [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): reconcile subagents and subgraphs on thread reconnect Seed deep-agent subagent cards from checkpoint messages and subgraph hosts from a single bounded `getHistory` read during `hydrate()`, so parallel fan-out discovery reappears immediately on refresh instead of waiting for SSE replay. Subagent execution namespaces are promoted through the existing guarded discovery state machine (bulk at hydrate, lazily per opened card via the selector layer). The getHistory cost is O(1) in requests regardless of fan-out width. - Updated dependencies \[[`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph-sdk@1.9.17 ## @langchain/vue@1.0.17 ### Patch Changes - [#2494](https://github.com/langchain-ai/langgraphjs/pull/2494) [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): revive automatic optimistic submit echo Echo `submit()` input into `values` / `messages` immediately with client-side id minting and id-based reconciliation as the server streams back. Expose per-message `optimisticStatus` via message metadata (`pending` → `sent` / `failed`), shallow-merge non-message keys with rollback when no `values` arrive, and add an `optimistic: false` hook opt-out. Plumb through React, Vue, Svelte, and Angular with browser e2e coverage. - [#2497](https://github.com/langchain-ai/langgraphjs/pull/2497) [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): reconcile subagents and subgraphs on thread reconnect Seed deep-agent subagent cards from checkpoint messages and subgraph hosts from a single bounded `getHistory` read during `hydrate()`, so parallel fan-out discovery reappears immediately on refresh instead of waiting for SSE replay. Subagent execution namespaces are promoted through the existing guarded discovery state machine (bulk at hydrate, lazily per opened card via the selector layer). The getHistory cost is O(1) in requests regardless of fan-out width. - Updated dependencies \[[`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph-sdk@1.9.17 ## @langchain/langgraph-ui@1.2.5 ## @example/ai-elements@0.1.32 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph@1.3.6 - @langchain/react@1.0.17 ## @examples/assistant-ui-claude@0.1.32 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph@1.3.6 - @langchain/react@1.0.17 ## @examples/ui-angular@0.0.42 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph@1.3.6 - @langchain/langgraph-sdk@1.9.17 - @langchain/angular@1.0.17 ## @examples/ui-multimodal@0.0.18 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph@1.3.6 - @langchain/react@1.0.17 ## @examples/ui-react@0.0.18 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`0a0e04e`](https://github.com/langchain-ai/langgraphjs/commit/0a0e04e9ff7e82fd08411cc0094e1f94729a1e1e), [`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f), [`a9aa8d6`](https://github.com/langchain-ai/langgraphjs/commit/a9aa8d6a9b23f5f7d4c56889fa68697b1e076b31)]: - @langchain/langgraph@1.3.6 - @langchain/langgraph-sdk@1.9.17 - @langchain/react@1.0.17 ## langgraph@1.0.38 ### Patch Changes - Updated dependencies \[[`658a076`](https://github.com/langchain-ai/langgraphjs/commit/658a076d5b50af9f5b96ab99f26ed629da6e182f)]: - @langchain/langgraph@1.3.6 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
658a076d5b | chore: update changesets | ||
|
|
a9aa8d6a9b |
fix(sdk): reconcile subagents and subgraphs on thread reconnect (#2497)
## Summary - Subagent cards are seeded from checkpoint messages and subgraph hosts from a single bounded `getHistory` during `hydrate()`, so reconnecting to a thread restores parallel fan-out discovery immediately instead of waiting for full SSE replay. - Subagent execution namespaces are resolved from history through the existing guarded discovery state machine — bulk-promoted at hydrate, and lazily per opened card via a selector-layer trigger added to React/Vue/Svelte/Angular. - `getHistory` usage is bounded (one page + at most one `before`-cursor fallback) and O(1) in requests regardless of how many subagents/subgraphs ran in parallel. --------- Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com> |
||
|
|
0a0e04e9ff |
fix(sdk): revive automatic optimistic submit echo (#2494)
## Summary - revive automatic optimistic updates to `@langchain/langgraph-sdk`: `submit()` input is echoed into `values` / `messages` immediately, messages without ids get client-minted ids for server reconciliation, and non-message keys are shallow-merged with rollback when no `values` snapshot arrives. - Track per-message lifecycle via `useMessageMetadata(...).optimisticStatus` (`pending` → `sent` / `failed`); failed optimistic messages are kept for retry UX and dropped on `hydrate()`. - Plumb `optimistic?: boolean` through React, Vue, Svelte, and Angular `useStream` hooks (defaults to enabled) and document the v1 migration path replacing legacy `optimisticValues`. - Add browser e2e tests across all four framework SDKs covering message happy path, id reconciliation, failure handling, opt-out, and non-message state convergence/rollback. |
||
|
|
28fbf1dc4e |
chore: version packages (#2490)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph@1.3.5 ### Patch Changes - [#2489](https://github.com/langchain-ai/langgraphjs/pull/2489) [`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(core): keep stream chunks as three-element tuples Emit lightweight checkpoint envelopes as separate `[namespace, "checkpoints", envelope]` chunks before paired `values` chunks. Public `stream()` always yields `[namespace, mode, payload]`; the v3 protocol path surfaces envelopes via `convertToProtocolEvent`. - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/langgraph-sdk@1.9.16 ### Patch Changes - [#2486](https://github.com/langchain-ai/langgraphjs/pull/2486) [`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): surface resumed run failures on stream.error Route `respond()` and `respondAll()` through a coordinator dispatch path that writes the reactive `rootStore.error` slot when a resumed run reaches a failed terminal or when `input.respond` dispatch fails, matching submit() behavior so framework consumers (e.g. API-key retry UIs) observe resume failures via `stream.error` instead of only `isLoading` transitions. ## @langchain/angular@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/react@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/svelte@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @langchain/vue@1.0.16 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f)]: - @langchain/langgraph-sdk@1.9.16 ## @example/ai-elements@0.1.31 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## @examples/assistant-ui-claude@0.1.31 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## @examples/ui-angular@0.0.41 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f), [`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph-sdk@1.9.16 - @langchain/langgraph@1.3.5 - @langchain/angular@1.0.16 ## @examples/ui-multimodal@0.0.17 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## @examples/ui-react@0.0.17 ### Patch Changes - Updated dependencies \[[`244c24e`](https://github.com/langchain-ai/langgraphjs/commit/244c24eaccff4009df7d83e4320e51a4b310b15f), [`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph-sdk@1.9.16 - @langchain/langgraph@1.3.5 - @langchain/react@1.0.16 ## langgraph@1.0.37 ### Patch Changes - Updated dependencies \[[`e3a1933`](https://github.com/langchain-ai/langgraphjs/commit/e3a1933a8825a515d847b38b24a0743f4d418646)]: - @langchain/langgraph@1.3.5 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
e3a1933a88 |
fix(core): keep stream() on 3-tuple shape (#2489)
## Summary
- Fixes `ValueError: too many values to unpack (expected 3)` when JS
graphs on `@langchain/langgraph` >=1.3 stream through the legacy path
(plain `stream()` / `streamEvents` v2 → `on_chain_stream`), which
affected deepagents 1.10.x and similar stacks on runtimes that expect
Python's 3-tuple stream shape.
- **Root cause:** `_streamIterator` always yielded a 4-element
`[namespace, mode, payload, meta]` when `subgraphs` + multi-mode and a
checkpointer were active, even though `StreamChunkMeta` is only for the
native v3 protocol stream (`streamEvents(..., { version: "v3" })` /
`pump()`).
- **Fix:** Introduce `isV3` and only append `meta` when `options.version
=== "v3"`; all other consumers get the Python-aligned 3-tuple
`[namespace, mode, payload]`.
- **Tests:** Add `stream() shape parity with Python` regression coverage
(3-tuples for subgraphs + multi-mode with checkpointer; v3 still emits
companion `checkpoints` events).
|
||
|
|
244c24eacc |
fix(sdk): surface resumed run failures on stream.error (#2486)
## Summary - Route `respond()` / `respondAll()` through `SubmitCoordinator.dispatchResume()` so resumed runs write failures to the reactive `rootStore.error` slot (same path `submit()` uses), instead of only toggling `isLoading` via the lifecycle listener. - Arm a background terminal watch before dispatch so `respond()` still resolves on `input.respond` while a later `failed` lifecycle populates `stream.error`. - Add controller tests for failed resume, dispatch failure, and batched `respondAll()` failure. |
||
|
|
34b7f6cfc5 |
chore: version packages (#2485)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.15 ### Patch Changes - [#2484](https://github.com/langchain-ai/langgraphjs/pull/2484) [`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): claim in-flight slot before root pump wait for enqueue Move `#runAbort` and `isLoading` setup ahead of `waitForRootPumpReady()` so `multitaskStrategy: "enqueue"` submits in the same tick land in `queueStore` instead of bypassing the client queue. ## @langchain/angular@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @langchain/react@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @langchain/svelte@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @langchain/vue@1.0.15 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 ## @example/ai-elements@0.1.30 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.15 ## @examples/assistant-ui-claude@0.1.30 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.15 ## @examples/ui-angular@0.0.40 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 - @langchain/angular@1.0.15 ## @examples/ui-multimodal@0.0.16 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.15 ## @examples/ui-react@0.0.16 ### Patch Changes - Updated dependencies \[[`9861f42`](https://github.com/langchain-ai/langgraphjs/commit/9861f42cc4fa23d9e80ae45a76d511d7618cda07)]: - @langchain/langgraph-sdk@1.9.15 - @langchain/react@1.0.15 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
9861f42cc4 |
fix(sdk): claim in-flight slot before root pump wait for enqueue (#2484)
## Summary - Fix a race in `SubmitCoordinator.submit()` where `multitaskStrategy: "enqueue"` follow-ups fired in the same tick as the first dispatch could miss `hasActiveRun` and skip the client `queueStore`. - Claim the in-flight slot (`#runAbort`, `isLoading`) before `waitForRootPumpReady()` so concurrent enqueues are recorded client-side and drain sequentially as intended. - Add a regression test for same-tick enqueue behavior. |
||
|
|
540656afd0 |
chore: version packages (#2483)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.14 ### Patch Changes - [#2482](https://github.com/langchain-ai/langgraphjs/pull/2482) [`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): keep subgraph status complete when values arrives late `SubgraphDiscovery` no longer downgrades a terminal subgraph back to `running` when a host-namespace `values` snapshot is observed after its `completed` or `failed` lifecycle event. The content pump and lifecycle watcher are independent streams, so this reordering could strand nodes as perpetually running in `useStream` subgraph UIs. ## @langchain/angular@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @langchain/react@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @langchain/svelte@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @langchain/vue@1.0.14 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 ## @example/ai-elements@0.1.29 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.14 ## @examples/assistant-ui-claude@0.1.29 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.14 ## @examples/ui-angular@0.0.39 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 - @langchain/angular@1.0.14 ## @examples/ui-multimodal@0.0.15 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.14 ## @examples/ui-react@0.0.15 ### Patch Changes - Updated dependencies \[[`ba583b6`](https://github.com/langchain-ai/langgraphjs/commit/ba583b601d284c689bbfc15397686f1aa7481fba)]: - @langchain/langgraph-sdk@1.9.14 - @langchain/react@1.0.14 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
ba583b601d |
fix(sdk): keep subgraph status complete when values arrives late (#2482)
## Summary - Fix `SubgraphDiscovery` so late host-namespace `values` snapshots do not reset subgraph status from `complete`/`error` back to `running`. - Root cause: the SDK’s content pump (`values`) and lifecycle watcher (`lifecycle`) are separate streams; `onEvent` can deliver a final `values` event after terminal `lifecycle`, which left some nodes stuck as “running” in `useStream` subgraph UIs (e.g. graph-execution-cards). - Add regression tests for completed and failed subgraphs receiving a late `values` event. |
||
|
|
e5bd490c52 |
chore: version packages (#2470)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.13 ### Patch Changes - [#2469](https://github.com/langchain-ai/langgraphjs/pull/2469) [`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): normalize HITL edit decisions for Python servers `StreamController.respond()` now mirrors camelCase and snake_case on edit decisions (`editedAction` / `edited_action`) so JS clients can resume human-in-the-loop interrupts against Python LangGraph servers. ## @langchain/angular@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @langchain/react@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @langchain/svelte@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @langchain/vue@1.0.13 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 ## @example/ai-elements@0.1.28 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.13 ## @examples/assistant-ui-claude@0.1.28 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.13 ## @examples/ui-angular@0.0.38 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 - @langchain/angular@1.0.13 ## @examples/ui-multimodal@0.0.14 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.13 ## @examples/ui-react@0.0.14 ### Patch Changes - Updated dependencies \[[`0bbe66e`](https://github.com/langchain-ai/langgraphjs/commit/0bbe66e31de3abe7526c7810755a40c31bc60e0d)]: - @langchain/langgraph-sdk@1.9.13 - @langchain/react@1.0.13 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
0bbe66e31d |
fix(sdk): normalize HITL edit decisions for Python servers (#2469)
## Summary - Normalize HITL resume payloads in `StreamController.respond()` and `respondAll()` so edit decisions include both `editedAction` and `edited_action`. - Add `normalizeHitlResponseForServer` in the SDK UI layer and export it for direct use. - Cover normalization with unit tests on the payload helper and on `respond()` wiring. |
||
|
|
c6b29fb040 |
chore: version packages (#2465)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-mongodb@1.3.3 ### Patch Changes - [#2260](https://github.com/langchain-ai/langgraphjs/pull/2260) [`4d03dcb`](https://github.com/langchain-ai/langgraphjs/commit/4d03dcbc28bbfdf4c0f0ac065b9853652836d2f9) Thanks [@venkat22022202](https://github.com/venkat22022202)! - fix(mongodb): include pendingWrites in list() results ## @langchain/langgraph@1.3.4 ### Patch Changes - [#2035](https://github.com/langchain-ai/langgraphjs/pull/2035) [`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51) Thanks [@JadenKim-dev](https://github.com/JadenKim-dev)! - fix(core): prevent Zod schema defaults from overwriting checkpoint state in Command.update - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/langgraph-sdk@1.9.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. ## @langchain/angular@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/react@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/svelte@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @langchain/vue@1.0.12 ### Patch Changes - [#2467](https://github.com/langchain-ai/langgraphjs/pull/2467) [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): route headless tool resumes through respond on v1 stream `useStream` was calling `submit(null, { command })` for headless-tool resumes, which dispatches `run.start` without delivering the tool result. Add `applyHeadlessToolResumeCommand` to route payloads through `respond` / `respondAll`, and tighten headless-tool browser tests to assert end-to-end resume and graph completion. - Updated dependencies \[[`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph-sdk@1.9.12 ## @example/ai-elements@0.1.27 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/react@1.0.12 ## @examples/assistant-ui-claude@0.1.27 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/react@1.0.12 ## @examples/ui-angular@0.0.37 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/langgraph-sdk@1.9.12 - @langchain/angular@1.0.12 ## @examples/ui-multimodal@0.0.13 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/react@1.0.12 ## @examples/ui-react@0.0.13 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51), [`0491534`](https://github.com/langchain-ai/langgraphjs/commit/04915347128e40fc9617647cadba6b472a357d36)]: - @langchain/langgraph@1.3.4 - @langchain/langgraph-sdk@1.9.12 - @langchain/react@1.0.12 ## langgraph@1.0.36 ### Patch Changes - Updated dependencies \[[`7c3a98b`](https://github.com/langchain-ai/langgraphjs/commit/7c3a98b23af29fee0d9f064942abb71044ed0e51)]: - @langchain/langgraph@1.3.4 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
0491534712 |
fix(sdk): route headless tool resumes through respond on v1 stream (#2467)
## Summary
- Fix headless-tool resume on the v1 stream protocol by routing resume
payloads through `applyHeadlessToolResumeCommand` (`respond` /
`respondAll`) instead of `submit(null, { command })`.
- Export `applyHeadlessToolResumeCommand` and
`HeadlessToolResumeController` from `@langchain/langgraph-sdk` and
re-export from `@langchain/react`.
- Strengthen headless-tool browser tests across React, Vue, Angular, and
Svelte to assert tool result values, final agent message, idle loading
state, and no lingering interrupts.
|
||
|
|
4d03dcbc28 |
fix(langgraph-checkpoint-mongodb): include pendingWrites in list() results (#2260)
## Summary Fixes #2205 Fixes #589 `MongoDBSaver.list()` does not query or return `pendingWrites` in the yielded `CheckpointTuple` objects. This is inconsistent with `getTuple()` (which correctly queries the writes collection) and with other checkpointer implementations like Postgres. ## Fix Added the same `pendingWrites` query from `getTuple()` into `list()`, ensuring each yielded checkpoint tuple includes its pending writes. ## Test Plan - Store checkpoints with pending writes via MongoDBSaver - Call `list()` and verify `pendingWrites` are populated - Compare with `getTuple()` output to confirm consistency 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
7c3a98b23a |
fix(core): prevent Zod schema defaults from overwriting checkpoint state in Command.update (#2035)
Fixes #2031 When using `Command({ update })` with a Zod schema that has `.default()` on fields, Zod's `parse()` injects default values for missing fields into the update object. These injected keys then overwrite values restored from the checkpoint. **Root cause:** `_validateInput` passes `Command.update` through `interopParse(schema, input.update)`, which triggers Zod defaults for any field not present in the update. **Fix:** After parsing, filter the result to only include keys that were present in the original update input — matching the behavior of `StateSchema.validateInput` which already iterates only over `Object.entries(data)`. Added regression tests for both Zod v3 and v4. --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
d2ca90f8e2 |
chore: version packages (#2453)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-checkpoint-mongodb@1.3.2 ### Patch Changes - [#2186](https://github.com/langchain-ai/langgraphjs/pull/2186) [`26c2e32`](https://github.com/langchain-ai/langgraphjs/commit/26c2e325f435a2c061d6b78a7bd6af089cb1e0e6) Thanks [@jackjin1997](https://github.com/jackjin1997)! - fix: metadata filter in list() now works by querying a plain JSON shadow copy instead of the serialized binary blob ## @langchain/langgraph-checkpoint-postgres@1.0.2 ### Patch Changes - [#2255](https://github.com/langchain-ai/langgraphjs/pull/2255) [`e82a50b`](https://github.com/langchain-ai/langgraphjs/commit/e82a50b961a9413dab1ad2248747d5c73a6a1e58) Thanks [@leesta24](https://github.com/leesta24)! - fix(checkpoint-postgres): move serialization outside transaction in put() ## @langchain/langgraph-checkpoint-redis@1.0.7 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-api@1.2.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. - Updated dependencies \[]: - @langchain/langgraph-ui@1.2.4 ## @langchain/langgraph-cli@1.2.4 ### Patch Changes - [#1925](https://github.com/langchain-ai/langgraphjs/pull/1925) [`6503319`](https://github.com/langchain-ai/langgraphjs/commit/65033191cc3dd671d64dfac78ccdad453fdfbda2) Thanks [@jbrody-nexxa](https://github.com/jbrody-nexxa)! - fix(cli): add --no-reload flag to dev command - Updated dependencies \[[`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-api@1.2.4 ## @langchain/langgraph@1.3.3 ### Patch Changes - [#2037](https://github.com/langchain-ai/langgraphjs/pull/2037) [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f) Thanks [@pawel-twardziak](https://github.com/pawel-twardziak)! - Decouple `ContextType` generic from `configurable` in `PregelOptions` so that providing a custom context type no longer incorrectly narrows the configurable parameter. - [#2457](https://github.com/langchain-ai/langgraphjs/pull/2457) [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph): pass context with stateful RemoteGraph runs Pop `thread_id` from run `config.configurable` and forward `context` to the SDK so checkpointed remote runs accept user context without a 400 from ambiguous parameters. Closes [#1922](https://github.com/langchain-ai/langgraphjs/issues/1922). - [#1988](https://github.com/langchain-ai/langgraphjs/pull/1988) [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7) Thanks [@Axadali](https://github.com/Axadali)! - Fix race condition in IterableReadableWritableStream.push() that caused ERR_INVALID_STATE errors when streaming with multiple parallel nodes and aborting the stream. - [#2409](https://github.com/langchain-ai/langgraphjs/pull/2409) [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3) Thanks [@pragnyanramtha](https://github.com/pragnyanramtha)! - Preserve non-plain objects passed through `Send` and `Command` argument deserialization. - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph-checkpoint@1.0.4 ## @langchain/langgraph-supervisor@1.0.4 ### Patch Changes - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/langgraph-sdk@1.9.11 ### Patch Changes - [#2455](https://github.com/langchain-ai/langgraphjs/pull/2455) [`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856) Thanks [@JHSeo-git](https://github.com/JHSeo-git)! - fix(sdk): prefer completed task's direct mapping over pending checkpoint's positional guess in fetchSubagentHistory - [#2344](https://github.com/langchain-ai/langgraphjs/pull/2344) [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842) Thanks [@dependabot](https://github.com/apps/dependabot)! - chore(deps): bump uuid to 14.0.0 and keep checkpoint ID ordering stable Bump `uuid` from 10.x/13.x to 14.0.0 across packages. Starting with uuid 11, `v6({ clockseq })` no longer advances the sub-millisecond time counter when an explicit `clockseq` is passed, so checkpoint IDs created within the same millisecond were ordered only by `clockseq`. Since checkpoint IDs are sorted lexicographically, this broke ordering — most visibly for the negative `clockseq` used by the first ("input") checkpoint, which sorted as the newest. `uuid6()` now maintains its own monotonic `(msecs, nsecs)` clock (mirroring uuid 10's internal v1 behavior) so the time component is always strictly increasing and checkpoint ordering no longer depends on the `clockseq` value. `emptyCheckpoint()` also uses a non-negative `clockseq`. ## @langchain/angular@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/react@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/svelte@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/vue@1.0.11 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 ## @langchain/langgraph-ui@1.2.4 ## @example/ai-elements@0.1.26 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/assistant-ui-claude@0.1.26 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/ui-angular@0.0.36 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph@1.3.3 - @langchain/angular@1.0.11 ## @examples/ui-multimodal@0.0.12 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## @examples/ui-react@0.0.12 ### Patch Changes - Updated dependencies \[[`863b555`](https://github.com/langchain-ai/langgraphjs/commit/863b555346de02c2c0be290e877b7d260a3f8856), [`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph-sdk@1.9.11 - @langchain/langgraph@1.3.3 - @langchain/react@1.0.11 ## langgraph@1.0.35 ### Patch Changes - Updated dependencies \[[`9eb478f`](https://github.com/langchain-ai/langgraphjs/commit/9eb478ffeeda2ad9c3bff2cd0f0ac602b0a79f4f), [`91a5494`](https://github.com/langchain-ai/langgraphjs/commit/91a54947155b3fad3234001e63e20099a63ed999), [`6d4bf92`](https://github.com/langchain-ai/langgraphjs/commit/6d4bf927e5cf3744034205528bcd09964949d6d7), [`101b70a`](https://github.com/langchain-ai/langgraphjs/commit/101b70aa8d7ec26ec1654ef814689b832f1e17f3), [`0125920`](https://github.com/langchain-ai/langgraphjs/commit/0125920a2c4a87dc1d66aaf541ea16146f8cf842)]: - @langchain/langgraph@1.3.3 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
26c2e325f4 |
fix(langgraph-checkpoint-mongodb): MongoDB checkpointer metadata filter (#2186)
## Summary
- The `list()` method's metadata filter queried `metadata.${key}`
against a serialized binary blob, making it silently nonfunctional (dead
code)
- Added a plain JSON `metadata_search` field alongside the serialized
`metadata` in `put()`, and updated `list()` to query against it
- This is consistent with how Postgres (native JSONB `@>`) and SQLite
(`jsonb(CAST(...))`) handle metadata filtering
## Test plan
- [x] Existing unit tests pass (6/6)
- [ ] Integration test with real MongoDB to verify filter works against
`metadata_search`
Fixes #1591
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
|
||
|
|
101b70aa8d |
fix: preserve non-plain Send args (#2409)
## Summary - preserve non-plain object instances while deserializing `Send`/`Command` argument trees - keep recursive reconstruction for arrays, plain object records, serialized `Command`, and serialized `Send` payloads - add a regression test covering `Set`, `Map`, `Date`, and a custom class instance passed through `Send` Fixes part of #1142. ## Test plan - `pnpm install --frozen-lockfile` - `pnpm --filter @langchain/langgraph exec vitest run src/tests/constants.test.ts --testNamePattern "preserves non-plain objects"` - `pnpm --filter @langchain/langgraph exec vitest run src/tests/constants.test.ts` - `pnpm exec oxfmt --check libs/langgraph-core/src/constants.ts libs/langgraph-core/src/tests/constants.test.ts` - `pnpm exec oxlint libs/langgraph-core/src/constants.ts libs/langgraph-core/src/tests/constants.test.ts` - `git diff --check` - `pnpm --filter @langchain/langgraph build` --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
0125920a2c |
chore(deps): bump uuid from 10.0.0 to 14.0.0 (#2344)
Bumps [uuid](https://github.com/uuidjs/uuid) from 10.0.0 to 14.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/uuidjs/uuid/releases">uuid's releases</a>.</em></p> <blockquote> <h2>v14.0.0</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a> (2026-04-19)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> </ul> <h3>Features</h3> <ul> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>) (<a href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3">dc4ddb8</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>) (<a href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4">f2c235f</a>)</li> <li>Use GITHUB_TOKEN for release-please and enable npm provenance (<a href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>) (<a href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c">ffa3138</a>)</li> </ul> <h2>v13.0.2</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.1...v13.0.2">13.0.2</a> (2026-05-04)</h2> <h3>Bug Fixes</h3> <ul> <li>rerelease to fix provenance. (<a href="https://github.com/uuidjs/uuid/commit/49ccb35f78c0c4ce1409dd2f1d89f83caadba10b">49ccb35</a>)</li> </ul> <h2>v13.0.1</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v13.0.1">13.0.1</a> (2026-04-27)</h2> <h3>Bug Fixes</h3> <ul> <li>backport fix for GHSA-w5hq-g745-h8pq (<a href="https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a">9d27ddf</a>)</li> </ul> <h2>v13.0.0</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a> (2025-09-08)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li> </ul> <h2>v12.0.1</h2> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v12.0.1">12.0.1</a> (2026-04-29)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md">uuid's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0">14.0.0</a> (2026-04-19)</h2> <h3>Security</h3> <ul> <li>Fixes <a href="https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq">GHSA-w5hq-g745-h8pq</a>: <code>v3()</code>, <code>v5()</code>, and <code>v6()</code> did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid <code>offset</code> was provided. A <code>RangeError</code> is now thrown if <code>offset < 0</code> or <code>offset + 16 > buf.length</code>.</li> </ul> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><code>crypto</code> is now expected to be globally defined (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li>drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> <li>upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0">13.0.0</a> (2025-09-08)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>make browser exports the default (<a href="https://redirect.github.com/uuidjs/uuid/issues/901">#901</a>) (<a href="https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a">bce9d72</a>)</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v11.1.0...v12.0.0">12.0.0</a> (2025-09-05)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li>update to typescript@5.2 (<a href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>)</li> <li>remove CommonJS support (<a href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>)</li> <li>drop node@16 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>)</li> </ul> <h3>Features</h3> <ul> <li>add node@24 to ci matrix (<a href="https://redirect.github.com/uuidjs/uuid/issues/879">#879</a>) (<a href="https://github.com/uuidjs/uuid/commit/42b6178aa21a593257f0a72abacd220f0b7b8a92">42b6178</a>)</li> <li>drop node@16 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/883">#883</a>) (<a href="https://github.com/uuidjs/uuid/commit/0f38cf10366ab074f9328ae2021eea04d5f2e530">0f38cf1</a>)</li> <li>remove CommonJS support (<a href="https://redirect.github.com/uuidjs/uuid/issues/886">#886</a>) (<a href="https://github.com/uuidjs/uuid/commit/ae786e27265f50bcf7cead196c29f1869297c42f">ae786e2</a>)</li> <li>update to typescript@5.2 (<a href="https://redirect.github.com/uuidjs/uuid/issues/887">#887</a>) (<a href="https://github.com/uuidjs/uuid/commit/c7ee40598ed78584d81ab78dffded9fe5ff20b01">c7ee405</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>improve v4() performance (<a href="https://redirect.github.com/uuidjs/uuid/issues/894">#894</a>) (<a href="https://github.com/uuidjs/uuid/commit/5fd974c12718c8848035650b69b8948f12ace197">5fd974c</a>)</li> <li>restore node: prefix (<a href="https://redirect.github.com/uuidjs/uuid/issues/889">#889</a>) (<a href="https://github.com/uuidjs/uuid/commit/e1f42a354593093ba0479f0b4047dae82d28c507">e1f42a3</a>)</li> </ul> <h2><a href="https://github.com/uuidjs/uuid/compare/v11.0.5...v11.1.0">11.1.0</a> (2025-02-19)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/uuidjs/uuid/commit/7c1ea087a8149b57380fc8bb7f68c3a215cb6e4b"><code>7c1ea08</code></a> chore(main): release 14.0.0 (<a href="https://redirect.github.com/uuidjs/uuid/issues/926">#926</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34"><code>3d2c5b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4"><code>f2c235f</code></a> fix!: expect <code>crypto</code> to be global everywhere (requires node@20+) (<a href="https://redirect.github.com/uuidjs/uuid/issues/935">#935</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/529ef0899f5dd503d2ee90d690585d63d78bc212"><code>529ef08</code></a> chore: upgrade TypeScript and fixup types (<a href="https://redirect.github.com/uuidjs/uuid/issues/927">#927</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/086fd7976f11433edf9ac80be876b3ad243fe087"><code>086fd79</code></a> chore: update dependencies (<a href="https://redirect.github.com/uuidjs/uuid/issues/933">#933</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3"><code>dc4ddb8</code></a> feat!: drop node@18 support (<a href="https://redirect.github.com/uuidjs/uuid/issues/934">#934</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/0f1f9c9c9cedbae5a1d363d5406c5dfbabe81404"><code>0f1f9c9</code></a> chore: switch to Biome for parsing and linting (<a href="https://redirect.github.com/uuidjs/uuid/issues/932">#932</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/e2879e64bf125add903c1eff6e0860542c605013"><code>e2879e6</code></a> chore: use maintained version of npm-run-all (<a href="https://redirect.github.com/uuidjs/uuid/issues/930">#930</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c"><code>ffa3138</code></a> fix: Use GITHUB_TOKEN for release-please and enable npm provenance (<a href="https://redirect.github.com/uuidjs/uuid/issues/925">#925</a>)</li> <li><a href="https://github.com/uuidjs/uuid/commit/0423d49df2dc8efc300c804731d25f4d7e0fccc4"><code>0423d49</code></a> docs: remove obsolete v1 option notes (<a href="https://redirect.github.com/uuidjs/uuid/issues/915">#915</a>)</li> <li>Additional commits viewable in <a href="https://github.com/uuidjs/uuid/compare/v10.0.0...v14.0.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for uuid since your current version.</p> </details> <details> <summary>Install script changes</summary> <p>This version adds <code>prepare</code> script that runs during installation. Review the package contents before updating.</p> </details> <br /> > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
65033191cc |
fix(langgraph-api): port --no-reload option to js CLI to match python implementation (#1925)
Implement a CLI option --no-reload that bypasses the watcher from restarting the server when changes to file contents are detected. This implementation matches the python CLI option implemented here: https://github.com/langchain-ai/langgraph/blob/main/libs/cli/langgraph_cli/cli.py#L620 fixes https://github.com/langchain-ai/langgraphjs/issues/1942 --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
91a5494715 |
fix(langgraph): pass context with stateful RemoteGraph runs (#2457)
## Summary - Fix [#1922](https://github.com/langchain-ai/langgraphjs/issues/1922) by porting the Python [langgraph#6497](https://github.com/langchain-ai/langgraph/pull/6497) behavior: `RemoteGraph` pops `thread_id` from `config.configurable` (it stays in the URL path) and passes `context` as a top-level field to `client.runs.stream()`. - Stateful remote runs can now combine checkpointing (`thread_id`) with `context` for middleware / `contextSchema` without the server rejecting ambiguous parameters. fixes #1922 |
||
|
|
6d4bf927e5 |
fix(langgraph): StreamMessagesHandler throws "Controller is already closed" errors during parallel streaming with abort #1908 (#1988)
<h2>Fix Race Condition in <code>IterableReadableWritableStream.push()</code></h2> Fixes #1908 <h3>Summary</h3> <p>This PR addresses a critical race condition in <code>IterableReadableWritableStream.push()</code> that was causing <code>TypeError [ERR_INVALID_STATE]: Invalid state: Controller is already closed</code> errors when streaming a graph with multiple parallel LLM nodes and aborting the stream (or when it completes naturally).</p> <h3>Problem</h3> <p>Users were experiencing numerous <code>ERR_INVALID_STATE</code> errors in production when:</p> <ul> <li>Streaming graphs with multiple parallel LLM nodes</li> <li>Aborting the stream or when it completes naturally</li> <li>In-flight token callbacks from LLMs are asynchronous and may still execute after stream closure</li> <li>Calling <code>enqueue()</code> on a closed controller throws the error</li> <li>This race condition causes console flooding in production environments</li> </ul> <h3>Solution</h3> <p>The fix implements a robust two-layer approach to handle the race condition:</p> <ol> <li><strong>Pre-checking State:</strong> Checking <code>this._closed</code> and <code>this.controller</code> existence before attempting <code>enqueue</code></li> <li><strong>Try-Catch Protection:</strong> Wrapping the <code>enqueue</code> operation to catch any remaining race conditions</li> <li><strong>Specific Error Handling:</strong> Only suppressing the "Controller is already closed" error while allowing other errors to propagate</li> <li><strong>Maintaining Semantics:</strong> Preserving all existing functionality while preventing the problematic errors</li> </ol> <h3>Code Changes</h3> <p>Modified <code>push()</code> method in <code>libs/langgraph-core/src/pregel/stream.ts</code>:</p> <pre><code>push(chunk: StreamChunk) { // Prevent pushing to a closed stream to avoid race condition errors if (this._closed || !this.controller) { // Silently drop chunks when stream is closed - this is expected behavior // when async operations try to push after stream termination return; } try { // Forward chunk to passthrough function if provided this.passthroughFn?.(chunk); // Attempt to enqueue the chunk to the underlying stream this.controller.enqueue(chunk); } catch (error) { // Handle the specific case where controller was closed between check and enqueue // This race condition can occur with parallel async operations if (error instanceof TypeError && error.message.includes('Controller is already closed')) { // Silently ignore - this is expected during stream closure with concurrent pushes return; } // Re-throw any other unexpected errors to maintain proper error reporting throw error; } } </code></pre> <h3>Enhanced Test Coverage</h3> <p>Added comprehensive test scenarios covering:</p> <ul> <li>Basic race condition handling</li> <li>Concurrent pushes during closure</li> <li>Rapid successive operations</li> <li>Passthrough function integration during race conditions</li> <li>Multiple close calls</li> <li>Parallel node simulation mimicking the original issue</li> </ul> <h3>Backwards Compatibility</h3> <ul> <li>✅ No changes to public API</li> <li>✅ No changes to stream behavior during normal operation</li> <li>✅ Maintains all existing functionality</li> <li>✅ Only affects the error case (pushes after stream closure)</li> </ul> <h3>Testing</h3> <p>The fix has been validated across multiple scenarios:</p> <ul> <li>Basic race condition scenarios</li> <li>Concurrent operations during stream closure</li> <li>Multiple parallel nodes simulating the original issue</li> <li>Edge cases with multiple close calls</li> <li>Passthrough function integration</li> </ul> <h3>Impact</h3> <ul> <li>✅ Eliminates console flooding with <code>ERR_INVALID_STATE</code> errors</li> <li>✅ Improves stability in production environments with parallel streaming</li> <li>✅ Maintains performance and functionality of normal stream operations</li> <li>✅ Safe for use with multiple parallel LLM nodes</li> </ul> <p>This fix resolves the race condition issue while maintaining full backward compatibility and following best practices for error handling in async environments.</p> --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
863b555346 |
fix(sdk): prefer completed task's direct mapping over pending checkpoint's positional guess in fetchSubagentHistory (#2455)
Fixes #2454 ## Problem `StreamManager.fetchSubagentHistory` (`libs/sdk/src/ui/manager.ts`) restores each subagent's conversation from its subgraph checkpoint by first resolving every subagent `tool_call_id` to its subgraph `checkpoint_ns`. It scans the parent thread's history **newest-first** and, per checkpoint, tries two strategies: 1. **Direct mapping** — read the `tool_call_id` straight off a completed PUSH task's result `ToolMessage` (`task.name + ":" + task.id`). The code comments correctly call this *"more robust than positional alignment ... preferred"*. 2. **Positional fallback** — when task results aren't populated yet, align push tasks to the AI message's subagent tool calls by Send index (`task.path[1]`). The loop **breaks on the first checkpoint that yields any mapping** (direct *or* positional). That break is the bug. When the most recent checkpoint is a still-pending PUSH task — e.g. a run stopped at an interrupt — its task has no result, so the direct map is empty and the **positional fallback runs against the head checkpoint instead**. The fallback's backward scan of `values.messages` then latches onto a *stale* AI message whose subagent actually **completed in an older checkpoint**, positionally aligns it to the head's unrelated pending task, and breaks — before the loop ever reaches the older checkpoint whose task result holds the **correct** direct mapping. Net effect: the subagent's history is reconstructed from the **wrong subgraph namespace** (or not at all). A newer, lower-confidence positional guess silently shadows an older, authoritative direct mapping — the opposite of the code's stated intent. ## Fix Split namespace resolution into two phases: 1. **Phase 1 — direct mapping across the _entire_ history first.** Collect all `tool_call_id → namespace` mappings from completed task results before attempting any fallback. These are unambiguous, so no pending head checkpoint can pre-empt them. 2. **Phase 2 — positional fallback only for tool calls still unmapped** after phase 1 (the genuinely live/pending case). This preserves the existing behavior for in-flight runs while guaranteeing a correct direct mapping is never overwritten by a positional guess. No backend/protocol change is required — the server already serializes the correct material (the completed task result with the matching `tool_call_id`); only the client-side resolution order was wrong. ## Testing - Added a regression test (`fetchSubagentHistory namespace resolution`): a pending head checkpoint sitting in front of an older checkpoint that holds the correct completed mapping. Verified it **fails on the pre-fix code** (`expected [ 'Stale pending result' ] to include 'Correct research result'`) and **passes with this change**. - `vitest run` (SDK): **595 passed**, no type errors. - `oxlint`: 0 warnings / 0 errors · `oxfmt --check`: clean · `tsc -p libs/sdk/tsconfig.json --noEmit`: clean. --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
e82a50b961 | fix(langgraph-checkpoint-postgres): move serialization outside transaction in put() (#2255) | ||
|
|
9eb478ffee |
fix(langgraph): decouple ContextType from configurable in PregelOptions (#2037)
## Summary
When a `StateGraph` is created with a `contextSchema` (Zod), two
TypeScript errors occur:
1. **TS2589** ("excessively deep type instantiation") on the
`StateGraph` constructor
2. **TS2322** on `invoke()`/`stream()` - context schema fields (e.g.
`userName`, `userId`) are incorrectly required inside `configurable`
instead of top-level `context`
**Root cause:** `PregelOptions` extends `RunnableConfig<ContextType>`,
which maps the context type onto `configurable?` at the invoke/stream
level. The deep generic chain `StateGraph → Pregel → PregelOptions →
RunnableConfig<ContextType>` causes TS2589 with complex context schemas.
And TS2322 forces users to put context fields in `configurable` instead
of top-level `context`.
**Fix:** Remove the `<ContextType>` generic parameter from
`RunnableConfig` in `PregelOptions` only. This breaks the deep generic
chain at the invoke/stream boundary while preserving typed
`configurable` and `context` inside node callbacks (via
`LangGraphRunnableConfig<T>` / `Runtime<T>`).
## Changes
- **`libs/langgraph-core/src/pregel/types.ts`** - `PregelOptions` now
extends `RunnableConfig` (default) instead of
`RunnableConfig<ContextType>`. This is the only production code change.
- **`libs/langgraph-core/src/pregel/runnable_types.ts`** - Restored
`Runtime.configurable` to `ContextType` and `LangGraphRunnableConfig` to
extend `RunnableConfig<ContextType>` (reverting a previous attempt that
broke backward compat).
- **`libs/langgraph-core/src/tests/pregel.test-d.ts`** - Removed two
`@ts-expect-error` directives for invoke-level configurable (now
`Record<string, any>`, validated at runtime by Zod).
- **`libs/langgraph-core/src/tests/issue_10270_repro.test-d.ts`** -
Regression test reproducing both bugs from the issue.
## Trade-off
| Aspect | Before | After |
|--------|--------|-------|
| `graph.invoke({}, { configurable: { bad: 123 } })` | Compile error |
Compiles, validated at runtime |
| `graph.invoke({}, { context: { ... } })` | Compile error (TS2322) |
Compiles correctly ✓ |
| Node callback `config.configurable` / `config.context` | Typed as `T`
| Typed as `T` (unchanged) ✓ |
| `new StateGraph({ state, context: zodSchema })` | TS2589 | Compiles ✓
|
The only loss is compile-time validation of `configurable` content at
invoke level - mitigated by runtime Zod schema validation which the
codebase already performs.
Fixes [#10270](https://github.com/langchain-ai/langchainjs/issues/10270)
---------
Co-authored-by: Christian Bromann <git@bromann.dev>
|
||
|
|
381a9f64d0 |
chore: version packages (#2445)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.3 ### Patch Changes - [#2352](https://github.com/langchain-ai/langgraphjs/pull/2352) [`14f2a79`](https://github.com/langchain-ai/langgraphjs/commit/14f2a796912e81d7f52f0a4f16747f6d0a269209) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys `MemorySaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into property accesses on the nested plain objects `this.storage` and `this.writes`. A caller able to shape any of those fields (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) could pass `"__proto__"`, `"constructor"`, or `"prototype"` and have the subsequent assignment mutate `Object.prototype`. From that point every plain object in the process inherits the injected property, breaking `for...in` loops, truthy short-circuits, and downstream serializers across unrelated code paths. CWE-1321. Adds an `assertSafeStorageKey` chokepoint applied at every public entry that touches `storage` or `writes` (`put`, `putWrites`, `deleteThread`, `getTuple`, `list`). The guard rejects non-string values, the empty string (unless explicitly opted-in for `checkpoint_ns`), and the three prototype-pollution keys. Behaviour for valid string identifiers is unchanged. ## @langchain/langgraph-checkpoint-redis@1.0.6 ### Patch Changes - [#2350](https://github.com/langchain-ai/langgraphjs/pull/2350) [`1e73c6b`](https://github.com/langchain-ai/langgraphjs/commit/1e73c6b4630bbc4aa976eea4bfc33c4f753b7ee9) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(checkpoint-redis): block Redis KEYS / SCAN pattern injection via top-level identifiers `RedisSaver` and `ShallowRedisSaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into Redis keys and `client.keys(pattern)` calls with no validation. A caller able to shape any of those fields (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) could promote a string identifier into a glob pattern (`*`, `?`, `[...]`) or escape character (`\`). The most severe sink is `deleteThread`: a `threadId` of `*` issues `client.keys("checkpoint:*:*")` followed by `client.del(...)`, deleting every checkpoint in the database across every tenant. `getTuple`, `list`, and `loadPendingWrites` are exposed to the same pattern via the fallback paths that bypass the existing `escapeRediSearchTagValue` defense. Adds a single `assertSafeKeyComponent` helper exported from `./utils.js` and applies it at every key-building site. The guard asserts the value is a non-empty string (the empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`) and rejects the Redis pattern meta-characters `* ? [ ] \`. The `:` delimiter is intentionally permitted because LangGraph emits it as a legitimate part of `checkpoint_ns` for subgraphs / nested graphs, where it only ever appears as a literal in the key. Behavior for valid string identifiers is unchanged. ## @langchain/langgraph-api@1.2.3 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)]: - @langchain/langgraph-ui@1.2.3 ## @langchain/langgraph-cli@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-api@1.2.3 ## @langchain/langgraph-ui@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. ## @langchain/langgraph-sdk@1.9.10 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. ## @langchain/angular@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/react@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/svelte@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/vue@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @example/ai-elements@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/assistant-ui-claude@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-angular@0.0.35 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/angular@1.0.10 ## @examples/ui-multimodal@0.0.11 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-react@0.0.11 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/react@1.0.10 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
2c14b12a80 |
fix(sdk): add back respondAll and respond config/metadata (#2448)
## Summary
- Add `respondAll(responsesById, options)` to the stream controller and
the React/Angular/Svelte/Vue wrappers, resuming multiple interrupts
pending at the same checkpoint in a single `Command({ resume })`. This
is required for runs that pause on several interrupts at once (e.g.
parallel tool-authorization prompts), which sequential `respond()` calls
cannot service.
- Change `respond()` to take an options object (`{ interruptId?,
namespace?, config?, metadata? }`), folding run-level
`config`/`metadata` onto the resumed run so it applies the same
configurable values and metadata a fresh `submit()` would.
- Extend `ThreadStream.respondInput()` to accept a `responses` batch
(mutually exclusive with the single `interrupt_id`/`response`) and clear
all responded interrupts from local state.
- Update the protocol-v2 reference servers (`embed/protocol.mts`,
`protocol/service.mts`) to read the `responses` batch plus
`config`/`metadata` leniently and fold them onto the run servicing
`input.respond`.
- Update docs (interrupts/use-stream) across all framework packages and
add controller tests for batched resume.
|
||
|
|
14f2a79691 |
fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys (#2352)
## Summary Closes a prototype-pollution sink (CWE-1321) in `MemorySaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) can pass `\"__proto__\"`, `\"constructor\"`, or `\"prototype\"` and have the subsequent property assignment mutate `Object.prototype`. The audit posted in #2346 (cc @etairl) listed *`__proto__` prototype pollution in `MemorySaver`* among the unfiled findings from the same security-review pass that produced #2337. This PR confirms the finding and closes it across all five entry points. ## Vulnerable sinks `libs/checkpoint/src/memory.ts`: | Method | Sink | |---|---| | `put` | `this.storage[threadId][checkpointNamespace][checkpoint.id] = ...` | | `putWrites` | `this.writes[outerKey][innerKeyStr] = ...` (with caller-controlled `taskId` flowing into `innerKeyStr`) | | `deleteThread` | `delete this.storage[threadId]` | | `getTuple` | `this.storage[thread_id]?.[checkpoint_ns]?.[checkpoint_id]` | | `list` | `this.storage[threadId]?.[checkpointNamespace]` plus `Object.keys(this.storage[threadId] ?? {})` | ## Proof of concept \`\`\`ts import { MemorySaver } from \"@langchain/langgraph-checkpoint\"; const saver = new MemorySaver(); await saver.put( { configurable: { thread_id: \"__proto__\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-1\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); // Object.prototype is now polluted; every plain object in the process // inherits the injected key. const probe: Record<string, unknown> = {}; console.log(\"polluted\" in probe); // true console.log(probe[\"\"]); // the (formerly per-tenant) saved checkpoint \`\`\` Same shape works for `\"constructor\"` and `\"prototype\"`. Non-string identifiers (`{ \$ne: null }`, arrays, numbers, booleans) reach the same sinks unchecked. ## Severity Proposed CVSS 3.1: **High**. `MemorySaver` is the default in every quickstart and tutorial, and prototype pollution in Node.js is a documented stepping stone to RCE through gadget chains in downstream serializers, template engines, and dependency-resolution helpers. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single private `assertSafeStorageKey` helper in `memory.ts`, applied at every public entry that touches `storage` or `writes` (15 call sites across 5 methods). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the three prototype-pollution keys `__proto__`, `constructor`, `prototype`. * The `getTuple` and `list` read paths intentionally allow an empty or undefined `checkpoint_id` so the documented \"fetch latest\" behaviour continues to work; both paths still reject the magic keys. \`\`\`ts const POLLUTION_KEYS = new Set([\"__proto__\", \"constructor\", \"prototype\"]); function assertSafeStorageKey( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { /* type check, empty check, pollution check, all with precise diagnostics */ } \`\`\` The guard is a TypeScript `asserts` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the chokepoint pattern used in PR #2349 (`MongoDBSaver`) and PR #2350 (`RedisSaver` / `ShallowRedisSaver`). All three savers now share the same defensive posture at their boundary. * Single private function: it is impossible for a future call-site to forget validation, and the `asserts` annotation surfaces missed sites at compile time. * No new dependencies, no API changes for valid inputs, no behaviour change for any documented happy path. ## Test plan * [x] 22 new tests in `libs/checkpoint/src/tests/memory-pollution.test.ts` under `describe(\"MemorySaver prototype-pollution guard\")`, parameterised across all three pollution keys plus type / empty / accept paths for every entry point. Includes a cross-test invariant (`afterEach` snapshots `Object.getOwnPropertyNames(Object.prototype)`) that asserts pollution did not actually occur even if the guard had been absent. * [x] Existing checkpoint suite green (\`pnpm --filter @langchain/langgraph-checkpoint test\`, 93 of 93 including the 22 new ones). * [x] Lint clean (\`oxlint\`, 0 warnings, 0 errors on the changed files). * [x] Format clean (\`oxfmt --check\`). * [x] No new dependencies, no public API changes, no behaviour change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. Pairs with the two earlier sibling fixes from the same audit pass: * PR #2349 / GHSA-98xf-r82g-9mhx (MongoDB NoSQL injection) * PR #2350 / GHSA-x3wm-3wx7-g6xm (Redis KEYS / SCAN injection) --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
80c2806cb2 |
fix(sdk): fold forkFrom client-side and honor multitaskStrategy (#2447)
## Summary - Fold the SDK's top-level `forkFrom` into `config.configurable.checkpoint_id` client-side before sending `run.start`, so `forkFrom` never reaches the server and the fork target travels via the single legacy-compliant field used by the existing run endpoints. - Drop the server-side `forkFrom` normalization/promotion in both protocol-v2 reference servers (`ProtocolService.createOrResumeRun` and the embed protocol routes), reading the fork target solely from `config.configurable.checkpoint_id`. - Honor the caller's per-run `multitaskStrategy` (`reject` | `rollback` | `interrupt` | `enqueue`) instead of hardcoding `interrupt`, falling back to `enqueue` (the legacy stream-endpoint default, matching the Python protocol-v2 server) when omitted or unrecognized. |
||
|
|
1e73c6b463 |
fix(langgraph-checkpoint-redis): block KEYS / SCAN pattern injection via top-level identifiers (#2350)
## Summary Closes a Redis pattern-injection sink (CWE-77, CWE-943) in `RedisSaver` and `ShallowRedisSaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) can promote a string identifier into a Redis glob (`*`, `?`, `[...]`) and read, overwrite, or wipe checkpoints belonging to other tenants. The audit posted in #2346 (cc @etairl) listed *Redis key/glob injection in `RedisSaver` / `ShallowRedisSaver`* among the unfiled findings from the same security-review pass. This PR confirms the finding and extends the fix to all key-building sites in both savers. ## Vulnerable sinks `RedisSaver` (`libs/checkpoint-redis/src/index.ts`): | Method | Sinks | |---|---| | `getTuple` | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")` plus the direct \`json.get\` key | | `list` (fallback paths) | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`, `keys(\"checkpoint:*:\${checkpointNs}:*\")` | | `put` | `\`checkpoint:\${threadId}:\${checkpointNs}:\${checkpointId}\`` plus the zset key | | `putWrites` | per-write key, zset key, checkpoint key | | `deleteThread` | `keys(\"checkpoint:\${threadId}:*\")`, `keys(\"writes:\${threadId}:*\")` | | `loadPendingWrites` | `keys(\"checkpoint_write:\${threadId}:\${checkpointNs}:\${checkpointId}:*\")` | `ShallowRedisSaver` (`libs/checkpoint-redis/src/shallow.ts`) has the same five public entry points plus the equivalent helper. ## Proof of concept ```ts import { createClient } from \"redis\"; import { RedisSaver } from \"@langchain/langgraph-checkpoint-redis\"; const client = createClient({ url: process.env.REDIS_URL! }); await client.connect(); const saver = new RedisSaver(client); // Tenant A and Tenant B persist checkpoints normally. await saver.put( { configurable: { thread_id: \"tenant-a\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-a\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); await saver.put( { configurable: { thread_id: \"tenant-b\", checkpoint_ns: \"\" } }, { id: \"cp-b\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, { source: \"input\", step: 0, parents: {} } as any, {} ); // Attacker controls only the thread_id of their own request. // Without the guard, deleteThread expands the KEYS pattern to a glob // and deletes BOTH tenants' checkpoints. await saver.deleteThread(\"*\"); // Both \`cp-a\` and \`cp-b\` are gone. ``` The same shape (`\"*\"`, `\"tenant-?\"`, `\"tenant-[ab]\"`, `\"a\\b\"`) is accepted by every Redis pattern site in the table above. ## Severity Proposed CVSS 3.1: **High**. The most severe sink is `deleteThread`, which gives full availability impact across every tenant in the database, with confidentiality (`getTuple`, `list`) and integrity (`put`, `putWrites`) impacts on the other paths. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single `assertSafeKeyComponent` helper exported from `./utils.js`, applied at every key-building site (27 calls across 2 saver files plus the helper export). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the Redis pattern meta-characters `* ? [ ] \`. * Rejects the `:` delimiter that would otherwise corrupt the colon-delimited key structure. \`\`\`ts export function assertSafeKeyComponent( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { const { allowEmpty = false } = options; if (typeof value !== \"string\") { /* precise diagnostic */ throw ... } if (!allowEmpty && value === \"\") { throw ... } if (REDIS_KEY_FORBIDDEN.test(value)) { throw ... } } \`\`\` The guard is a TypeScript \`asserts\` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the maintainers' existing primitive-only pattern (\`escapeRediSearchTagValue\`) in the same file. * Single chokepoint: it is impossible for a future call-site to forget validation. * No new dependencies, no API changes for valid inputs, no behavior change for any documented happy path. * Pairs with PR #2349 (NoSQL injection in MongoDBSaver) so both backends now share the same defensive posture at the saver boundary. ## Test plan * [x] 11 new tests under \`describe(\"assertSafeKeyComponent\")\` in \`libs/checkpoint-redis/src/tests/utils.test.ts\` covering accept and reject paths for every input shape (normal string, empty with and without \`allowEmpty\`, every Redis meta-character, colon delimiter, every wrong type). * [x] Existing \`escapeRediSearchTagValue\` suite still green (regression). * [x] Full suite green (\`pnpm --filter @langchain/langgraph-checkpoint-redis test\`, 21 of 21). * [x] Format clean on all 4 changed files (\`oxfmt\`). * [x] No new dependencies, no public API changes, no behavior change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
80a8c1200a |
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom (#2443)
## Summary
- Remove `command` from `StreamSubmitOptions` and the
`submit-coordinator` resume-via-`submit` path so HITL resume goes
through `stream.respond()` only.
- Simplify `forkFrom` from `{ checkpointId: string }` to a plain
checkpoint id string across the SDK, protocol-v2 services, and docs.
- Update interrupt tests, examples (`HumanInTheLoopView`, branching
views), and React/Vue/Svelte/Angular JSDoc and migration/interrupt docs
to match.
|
||
|
|
2f0010e3a5 |
chore: version packages (#2442)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.9 ### Patch Changes - [#2441](https://github.com/langchain-ai/langgraphjs/pull/2441) [`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): preserve apiUrl path prefix in stream transport URLs Use BaseClient-style URL concatenation in `toAbsoluteUrl` so SSE and WebSocket subscriptions work when the SDK is pointed at a proxied apiUrl with a path prefix (e.g. `/api/chat-langchain`). ## @langchain/angular@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/react@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/svelte@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/vue@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @example/ai-elements@0.1.24 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/assistant-ui-claude@0.1.24 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/ui-angular@0.0.34 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 - @langchain/angular@1.0.9 ## @examples/ui-multimodal@0.0.10 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/ui-react@0.0.10 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 - @langchain/react@1.0.9 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
dbbcb636e7 |
fix(sdk): preserve apiUrl path prefix in stream transport URLs (#2441)
## Summary - Fix `toAbsoluteUrl` to concatenate `apiUrl` and path instead of using `new URL(path, base)`, which dropped path prefixes on proxied deployments. - Route WebSocket stream URL construction through `toAbsoluteUrl` for consistency with SSE transport. - Add unit and integration tests for proxied apiUrl paths, plus shared transport test helpers. |
||
|
|
4e71ace65a |
chore: version packages (#2439)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. ## @langchain/angular@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/react@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/svelte@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/vue@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @example/ai-elements@0.1.23 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/assistant-ui-claude@0.1.23 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/ui-angular@0.0.33 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 - @langchain/angular@1.0.8 ## @examples/ui-multimodal@0.0.9 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/ui-react@0.0.9 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 - @langchain/react@1.0.8 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
29d2bde235 |
fix(sdk): cancel runs on stop by default and add disconnect() (#2438)
## Summary
- `stream.stop()` now cancels the active run server-side by default
(`client.runs.cancel`) before disconnecting the client transport.
- Added `stream.disconnect()` as an alias for `stop({ cancel: false })`
for join/rejoin UIs.
- Introduced `StreamStopOptions` (`{ cancel?: boolean }`) on
`StreamController` and all v1 framework bindings (React, Vue, Svelte,
Angular).
- Updated `use-stream.md` and added controller unit tests for
cancel-on-stop and no-cancel-on-disconnect.
|
||
|
|
39ce52f248 |
chore: version packages (#2436)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - [#2434](https://github.com/langchain-ai/langgraphjs/pull/2434) [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671) Thanks [@hntrl](https://github.com/hntrl)! - fix(react): avoid eager stream getter evaluation during object spread Mark optional `useStream` accessors as non-enumerable so object spread/rest destructuring does not accidentally read guarded fields like `history` or opt into additional stream modes. ## @langchain/angular@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/react@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/svelte@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/vue@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @example/ai-elements@0.1.22 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/assistant-ui-claude@0.1.22 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/ui-angular@0.0.32 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 - @langchain/angular@1.0.7 ## @examples/ui-multimodal@0.0.8 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/ui-react@0.0.8 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 - @langchain/react@1.0.7 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
6b188e80ab |
fix(sdk): avoid eager stream getter evaluation (#2434)
## Summary fix(sdk): avoid eager stream getter evaluation during spread This fixes a React `useStream` development-mode failure where passing the stream handle through components that clone or rest-spread props could accidentally read lazy getters. The guarded `history` getter still throws when explicitly accessed with `fetchStateHistory: false`, but object spread no longer trips that path or widens `streamMode` by touching optional accessors. ## Changes `@langchain/langgraph-sdk` - Marks optional `useStream` accessors (`history`, `experimental_branchTree`, `toolProgress`, `subagents`, `activeSubagents`) as non-enumerable on the returned stream handle. - Preserves explicit access behavior for those accessors, including the existing `history` guard and stream mode opt-in for `toolProgress`/`subagents`. - Adds React hook regression coverage for object spread, explicit getter access, and stream mode inference. |
||
|
|
cfc8d274e4 |
fix(sdk): unwrap Command tool outputs and hide scoped task tools (#2435)
## Summary - Filter scoped deep-agent `task` dispatch events out of `sub.toolCalls` so subagent tool streams only show real worker tools. - Unwrap LangGraph `Command` payloads in `parseToolOutput` when they carry an embedded `ToolMessage`, so `tc.output` resolves to the actual tool result instead of raw graph state. - Share the scoped-task filter between client subagent handles and framework tool-call projections. |
||
|
|
9c9da48ae2 |
chore: version packages (#2433)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. ## @langchain/angular@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/react@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/svelte@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/vue@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @example/ai-elements@0.1.21 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/assistant-ui-claude@0.1.21 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/ui-angular@0.0.31 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 - @langchain/angular@1.0.6 ## @examples/ui-multimodal@0.0.7 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/ui-react@0.0.7 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 - @langchain/react@1.0.6 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
f99941f5fe |
fix(sdk): clear subgraph and subagent discovery on thread swap (#2430)
## Summary - Add `reset()` to `SubgraphDiscovery` and `SubagentDiscovery` to clear internal maps and committed store snapshots. - Call both resets from `StreamController.#teardownThread()` alongside existing per-thread resets (messages, tools, metadata). - Add unit tests for discovery `reset()` and a controller test that `hydrate(null)` clears subgraphs after lifecycle events. |
||
|
|
7788dceb85 |
chore: version packages (#2424)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-redis@1.0.5 ### Patch Changes - [#2208](https://github.com/langchain-ai/langgraphjs/pull/2208) [`ebeb145`](https://github.com/langchain-ai/langgraphjs/commit/ebeb1452d27fcca100cd63bdfd4a7f020949412c) Thanks [@jackjin1997](https://github.com/jackjin1997)! - Fix `deleteThread()` using wrong key pattern (`writes:` instead of `checkpoint_write:`) and add missing cleanup of `write_keys_zset:` entries. ## @langchain/langgraph-supervisor@1.0.3 ### Patch Changes - [#2317](https://github.com/langchain-ai/langgraphjs/pull/2317) [`c088c76`](https://github.com/langchain-ai/langgraphjs/commit/c088c7659c18edf26091813ff384f48f5335bef6) Thanks [@fish895623](https://github.com/fish895623)! - feat(supervisor): widen agents type to accept createAgent graphs ## @langchain/langgraph-sdk@1.9.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. ## @langchain/angular@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/react@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/svelte@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/vue@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @example/ai-elements@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/assistant-ui-claude@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-angular@0.0.30 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/angular@1.0.5 ## @examples/ui-multimodal@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-react@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/react@1.0.5 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
c088c7659c |
feat(supervisor): widen agents type to accept createAgent graphs (#2317)
## Summary - Add a broader `CompiledStateGraph<any, any, string, any, any>` to the `agents` union in `CreateSupervisorParams` - Graphs produced by `createAgent` from `langchain` (via `.graph`) are now accepted alongside existing `createReactAgent` graphs and `RemoteGraph` - The original `AnnotationRootT`-parameterized `CompiledStateGraph` type is preserved for backward compatibility ## Motivation The new `createAgent` API in the `langchain` package returns a `ReactAgent` whose `.graph` property is a `CompiledStateGraph` with a different state schema (`BuiltInState`) than the `MessagesAnnotation`-based state from `createReactAgent`. Since `createReactAgent` is deprecated in favor of `createAgent`, `createSupervisor` needs to accept both graph types. At runtime this already works — `makeCallAgent` types its `agent` parameter as `any` and only accesses `.name`, `.invoke()`, and optionally `.description`. The type constraint on the `agents` parameter was simply too narrow for the new API. ## Changes ### `@langchain/langgraph-supervisor` (`libs/langgraph-supervisor`) - Updated `CreateSupervisorParams.agents` type to include `CompiledStateGraph<any, any, string, any, any>` in the union alongside the existing strictly-typed `CompiledStateGraph` and `RemoteGraph` ## Test plan - [x] `pnpm build` passes for `@langchain/langgraph-supervisor` - [x] Consuming project using `createAgent` + `createSupervisor` compiles without errors - [x] Existing supervisor tests still pass --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
ebeb1452d2 |
fix(langgraph-checkpoint-redis): fix deleteThread using wrong key pattern for writes (#2208)
## Summary Fixes #2207 - Fix `deleteThread()` using incorrect `writes:` prefix instead of `checkpoint_write:` for write key deletion - Add missing cleanup of `write_keys_zset:` entries, matching the correct implementation in `ShallowRedisSaver` The bug was found by comparing `RedisSaver.deleteThread()` with `ShallowRedisSaver.deleteThread()` in `shallow.ts`, which correctly uses `checkpoint_write:` prefix and also cleans up zset keys. ## AI Disclosure This bug was identified through code review with AI assistance. The fix aligns the standard `RedisSaver` implementation with the existing correct `ShallowRedisSaver` implementation. --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
3529e3831a |
fix(sdk): align AssembledToolCall typing with pre-v1 expectations (#2421)
## Summary - Split tool-call handles by consumer: - **Client SDK** (`ThreadStream.toolCalls`, subgraph/subagent projections): `ClientAssembledToolCall` with a promise-only `output` (resolves on success, rejects on error). Still exported as `AssembledToolCall` from `@langchain/langgraph-sdk/client` for script usage. - **Framework SDKs** (`stream.toolCalls`, `useToolCalls`, `injectToolCalls`): `AssembledToolCall` with plain reactive fields — `output: T | null`, `status`, and `error` — updated in place as events arrive so React/Vue/Svelte/Angular can render from snapshots without `await`, effects, or Suspense around promises. - Add generic `AssembledToolCall<TName, TInput, TOutput>` plus `id`/`args` aliases; point `InferToolCalls` at assembled streaming handles and add `AssembledToolCallFromTool` (exported as `ToolCallFromTool` from `@langchain/react`, `@langchain/vue`, `@langchain/svelte`, and `@langchain/angular`). - Rework `ToolCallAssembler` around a mutable internal handle and `toClientAssembledToolCall()` for client projections; framework stores the reactive handle directly. - Remove redundant `InferAssembledToolCalls` and deprecated `StateOf`; wire typed `toolCalls` / selector generics across all four framework packages. - Expand and align `createAgent`, `createDeepAgent`, and `langgraph` type tests across React, Vue, Svelte, and Angular; update examples, protocol-v2 integration tests, and Vue migration docs. |
||
|
|
4a7d9a7c5d |
chore: version packages (#2416)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph@1.3.2 ### Patch Changes - [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415) [`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - Move `@langchain/core` from a runtime dependency back to a required peer dependency so installing the SDK alone no longer pulls in `@langchain/core` (and `js-tiktoken`, etc.). Consumers that use streaming or message coercion must install `@langchain/core` explicitly or via `@langchain/langgraph`. - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/langgraph-sdk@1.9.4 ### Patch Changes - [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415) [`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - Move `@langchain/core` from a runtime dependency back to a required peer dependency so installing the SDK alone no longer pulls in `@langchain/core` (and `js-tiktoken`, etc.). Consumers that use streaming or message coercion must install `@langchain/core` explicitly or via `@langchain/langgraph`. ## @langchain/angular@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/react@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/svelte@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/vue@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @example/ai-elements@0.1.19 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/assistant-ui-claude@0.1.19 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/ui-angular@0.0.29 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 - @langchain/langgraph@1.3.2 - @langchain/angular@1.0.4 ## @examples/ui-multimodal@0.0.5 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/ui-react@0.0.5 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## langgraph@1.0.34 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
b893dc5468 | fix: add @langchain/langgraph to changeset |