Commit Graph

1752 Commits

Author SHA1 Message Date
github-actions[bot] 381a9f64d0 chore: version packages (#2445)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint@1.0.3

### Patch Changes

- [#2352](https://github.com/langchain-ai/langgraphjs/pull/2352)
[`14f2a79`](https://github.com/langchain-ai/langgraphjs/commit/14f2a796912e81d7f52f0a4f16747f6d0a269209)
Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! -
fix(langgraph-checkpoint): block prototype pollution in MemorySaver via
reserved storage keys

    `MemorySaver` previously embedded `thread_id`, `checkpoint_ns`,
`checkpoint_id`, and `task_id` directly into property accesses on the
nested plain objects `this.storage` and `this.writes`. A caller able to
shape any of those fields (every quickstart, tutorial, and test fixture
    uses `MemorySaver` by default) could pass `"__proto__"`,
    `"constructor"`, or `"prototype"` and have the subsequent assignment
    mutate `Object.prototype`. From that point every plain object in the
    process inherits the injected property, breaking `for...in` loops,
truthy short-circuits, and downstream serializers across unrelated code
    paths. CWE-1321.

Adds an `assertSafeStorageKey` chokepoint applied at every public entry
that touches `storage` or `writes` (`put`, `putWrites`, `deleteThread`,
    `getTuple`, `list`). The guard rejects non-string values, the empty
string (unless explicitly opted-in for `checkpoint_ns`), and the three
    prototype-pollution keys. Behaviour for valid string identifiers is
    unchanged.

## @langchain/langgraph-checkpoint-redis@1.0.6

### Patch Changes

- [#2350](https://github.com/langchain-ai/langgraphjs/pull/2350)
[`1e73c6b`](https://github.com/langchain-ai/langgraphjs/commit/1e73c6b4630bbc4aa976eea4bfc33c4f753b7ee9)
Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! -
fix(checkpoint-redis): block Redis KEYS / SCAN pattern injection via
top-level identifiers

`RedisSaver` and `ShallowRedisSaver` previously embedded `thread_id`,
`checkpoint_ns`, `checkpoint_id`, and `task_id` directly into Redis keys
and `client.keys(pattern)` calls with no validation. A caller able to
    shape any of those fields (multi-tenant SDK deployments where the
`RunnableConfig` originates from request input, or webhook payloads that
flow into a persisted thread) could promote a string identifier into a
    glob pattern (`*`, `?`, `[...]`) or escape character (`\`).

    The most severe sink is `deleteThread`: a `threadId` of `*` issues
`client.keys("checkpoint:*:*")` followed by `client.del(...)`, deleting
    every checkpoint in the database across every tenant. `getTuple`,
    `list`, and `loadPendingWrites` are exposed to the same pattern via
the fallback paths that bypass the existing `escapeRediSearchTagValue`
    defense.

    Adds a single `assertSafeKeyComponent` helper exported from
    `./utils.js` and applies it at every key-building site. The guard
    asserts the value is a non-empty string (the empty `checkpoint_ns`
    default is opt-in via `{ allowEmpty: true }`) and rejects the Redis
pattern meta-characters `* ? [ ] \`. The `:` delimiter is intentionally
    permitted because LangGraph emits it as a legitimate part of
    `checkpoint_ns` for subgraphs / nested graphs, where it only ever
appears as a literal in the key. Behavior for valid string identifiers
    is unchanged.

## @langchain/langgraph-api@1.2.3

### Patch Changes

- [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447)
[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: fold forkFrom client-side and honor per-run
multitaskStrategy

    The SDK now folds the ergonomic `forkFrom` option into
`config.configurable.checkpoint_id` before sending `run.start`, so the
agent server only ever accepts the single, legacy-compliant fork field
(`forkFrom` no longer hits the wire). The protocol-v2 reference servers
    drop their top-level `forkFrom` normalization accordingly.

The protocol-v2 servers now honor the caller's `multitaskStrategy` per
run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead
of
hardcoding it, falling back to `enqueue` when omitted or unrecognized.

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)]:
    -   @langchain/langgraph-ui@1.2.3

## @langchain/langgraph-cli@1.2.3

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-api@1.2.3

## @langchain/langgraph-ui@1.2.3

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

## @langchain/langgraph-sdk@1.9.10

### Patch Changes

- [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447)
[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: fold forkFrom client-side and honor per-run
multitaskStrategy

    The SDK now folds the ergonomic `forkFrom` option into
`config.configurable.checkpoint_id` before sending `run.start`, so the
agent server only ever accepts the single, legacy-compliant fork field
(`forkFrom` no longer hits the wire). The protocol-v2 reference servers
    drop their top-level `forkFrom` normalization accordingly.

The protocol-v2 servers now honor the caller's `multitaskStrategy` per
run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead
of
hardcoding it, falling back to `enqueue` when omitted or unrecognized.

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

## @langchain/angular@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @langchain/react@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @langchain/svelte@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @langchain/vue@1.0.10

### Patch Changes

- [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443)
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom

    Remove the misleading submit({ command }) surface from protocol-v2
StreamController; HITL resume is respond() only. Accept forkFrom as a
    plain checkpoint id string and align protocol-v2 servers and docs.

- [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448)
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
protocol-v2: add `respondAll()` and run config/metadata on interrupt
resume

The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a
`respondAll(responsesById, options)` method to resume several interrupts
pending at the same checkpoint in a single command — required for runs
that
pause on multiple interrupts at once (e.g. parallel tool-authorization
      prompts), which sequential `respond()` calls cannot handle.

`respond()` now takes an options object (`{ interruptId?, namespace?,
config?, metadata? }`) so a resumed run can carry the same run-level
config
(model, user context, …) and metadata (trigger source, test flags, …) a
fresh `submit()` would. The protocol-v2 reference servers read the new
`responses` batch and `config` / `metadata` fields leniently and fold
them
      onto the run that services the `input.respond` command.

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10

## @example/ai-elements@0.1.25

### Patch Changes

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/react@1.0.10

## @examples/assistant-ui-claude@0.1.25

### Patch Changes

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/react@1.0.10

## @examples/ui-angular@0.0.35

### Patch Changes

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10
    -   @langchain/angular@1.0.10

## @examples/ui-multimodal@0.0.11

### Patch Changes

- Updated dependencies
\[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/react@1.0.10

## @examples/ui-react@0.0.11

### Patch Changes

- Updated dependencies
\[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9),
[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532),
[`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]:
    -   @langchain/langgraph-sdk@1.9.10
    -   @langchain/react@1.0.10

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-29 00:08:20 -07:00
Christian Bromann 4d12fe0233 docs: more readme cleanups 2026-05-29 00:06:14 -07:00
Christian Bromann 517500356d docs: update readme further 2026-05-29 00:02:44 -07:00
Christian Bromann 4c5fea793d fix(docs): update links in readme 2026-05-28 23:55:36 -07:00
Christian Bromann 313f060654 fix(sdk): fix type issue in tests 2026-05-28 23:49:47 -07:00
Christian Bromann 737b4ade89 fix(sdk): fix lint issues 2026-05-28 17:36:39 -07:00
Christian Bromann ac66625c30 fix(sdk): add browser tests for multi interrupt use case 2026-05-28 17:30:03 -07:00
Christian Bromann 2c14b12a80 fix(sdk): add back respondAll and respond config/metadata (#2448)
## Summary
- Add `respondAll(responsesById, options)` to the stream controller and
the React/Angular/Svelte/Vue wrappers, resuming multiple interrupts
pending at the same checkpoint in a single `Command({ resume })`. This
is required for runs that pause on several interrupts at once (e.g.
parallel tool-authorization prompts), which sequential `respond()` calls
cannot service.
- Change `respond()` to take an options object (`{ interruptId?,
namespace?, config?, metadata? }`), folding run-level
`config`/`metadata` onto the resumed run so it applies the same
configurable values and metadata a fresh `submit()` would.
- Extend `ThreadStream.respondInput()` to accept a `responses` batch
(mutually exclusive with the single `interrupt_id`/`response`) and clear
all responded interrupts from local state.
- Update the protocol-v2 reference servers (`embed/protocol.mts`,
`protocol/service.mts`) to read the `responses` batch plus
`config`/`metadata` leniently and fold them onto the run servicing
`input.respond`.
- Update docs (interrupts/use-stream) across all framework packages and
add controller tests for batched resume.
2026-05-28 16:53:09 -07:00
Nagendhra Madishetti 14f2a79691 fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys (#2352)
## Summary

Closes a prototype-pollution sink (CWE-1321) in `MemorySaver`. A caller
able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or
`task_id` (every quickstart, tutorial, and test fixture uses
`MemorySaver` by default) can pass `\"__proto__\"`, `\"constructor\"`,
or `\"prototype\"` and have the subsequent property assignment mutate
`Object.prototype`.

The audit posted in #2346 (cc @etairl) listed *`__proto__` prototype
pollution in `MemorySaver`* among the unfiled findings from the same
security-review pass that produced #2337. This PR confirms the finding
and closes it across all five entry points.

## Vulnerable sinks

`libs/checkpoint/src/memory.ts`:

| Method | Sink |
|---|---|
| `put` | `this.storage[threadId][checkpointNamespace][checkpoint.id] =
...` |
| `putWrites` | `this.writes[outerKey][innerKeyStr] = ...` (with
caller-controlled `taskId` flowing into `innerKeyStr`) |
| `deleteThread` | `delete this.storage[threadId]` |
| `getTuple` |
`this.storage[thread_id]?.[checkpoint_ns]?.[checkpoint_id]` |
| `list` | `this.storage[threadId]?.[checkpointNamespace]` plus
`Object.keys(this.storage[threadId] ?? {})` |

## Proof of concept

\`\`\`ts
import { MemorySaver } from \"@langchain/langgraph-checkpoint\";

const saver = new MemorySaver();

await saver.put(
  { configurable: { thread_id: \"__proto__\", checkpoint_ns: \"\" } },
  /* checkpoint */ { id: \"cp-1\", v: 4, ts: new Date().toISOString(),
channel_values: {}, channel_versions: {}, versions_seen: {} } as any,
  /* metadata  */ { source: \"input\", step: 0, parents: {} } as any,
  {}
);

// Object.prototype is now polluted; every plain object in the process
// inherits the injected key.
const probe: Record<string, unknown> = {};
console.log(\"polluted\" in probe); // true
console.log(probe[\"\"]); // the (formerly per-tenant) saved checkpoint
\`\`\`

Same shape works for `\"constructor\"` and `\"prototype\"`. Non-string
identifiers (`{ \$ne: null }`, arrays, numbers, booleans) reach the same
sinks unchecked.

## Severity

Proposed CVSS 3.1: **High**. `MemorySaver` is the default in every
quickstart and tutorial, and prototype pollution in Node.js is a
documented stepping stone to RCE through gadget chains in downstream
serializers, template engines, and dependency-resolution helpers.
Network-reachable, low-complexity, only the privilege the SDK already
grants to a caller.

## Fix

A single private `assertSafeStorageKey` helper in `memory.ts`, applied
at every public entry that touches `storage` or `writes` (15 call sites
across 5 methods). The guard:

* Asserts the value is a non-empty string (the documented empty
`checkpoint_ns` default is opt-in via `{ allowEmpty: true }`).
* Rejects the three prototype-pollution keys `__proto__`, `constructor`,
`prototype`.
* The `getTuple` and `list` read paths intentionally allow an empty or
undefined `checkpoint_id` so the documented \"fetch latest\" behaviour
continues to work; both paths still reject the magic keys.

\`\`\`ts
const POLLUTION_KEYS = new Set([\"__proto__\", \"constructor\",
\"prototype\"]);

function assertSafeStorageKey(
  field: string,
  value: unknown,
  options: { allowEmpty?: boolean } = {}
): asserts value is string {
/* type check, empty check, pollution check, all with precise
diagnostics */
}
\`\`\`

The guard is a TypeScript `asserts` predicate so call-sites get type
narrowing for free and the compiler enforces that no later code path
uses an unvalidated identifier.

## Why this design

* Mirrors the chokepoint pattern used in PR #2349 (`MongoDBSaver`) and
PR #2350 (`RedisSaver` / `ShallowRedisSaver`). All three savers now
share the same defensive posture at their boundary.
* Single private function: it is impossible for a future call-site to
forget validation, and the `asserts` annotation surfaces missed sites at
compile time.
* No new dependencies, no API changes for valid inputs, no behaviour
change for any documented happy path.

## Test plan

* [x] 22 new tests in
`libs/checkpoint/src/tests/memory-pollution.test.ts` under
`describe(\"MemorySaver prototype-pollution guard\")`, parameterised
across all three pollution keys plus type / empty / accept paths for
every entry point. Includes a cross-test invariant (`afterEach`
snapshots `Object.getOwnPropertyNames(Object.prototype)`) that asserts
pollution did not actually occur even if the guard had been absent.
* [x] Existing checkpoint suite green (\`pnpm --filter
@langchain/langgraph-checkpoint test\`, 93 of 93 including the 22 new
ones).
* [x] Lint clean (\`oxlint\`, 0 warnings, 0 errors on the changed
files).
* [x] Format clean (\`oxfmt --check\`).
* [x] No new dependencies, no public API changes, no behaviour change
for valid string identifiers.

## Disclosure

Original finding credited to @etairl (audit posted in #2346). This PR
was prepared for coordinated public disclosure since the audit list is
already public. Happy to coordinate timing with a private GHSA if the
maintainers prefer.

Pairs with the two earlier sibling fixes from the same audit pass:
* PR #2349 / GHSA-98xf-r82g-9mhx (MongoDB NoSQL injection)
* PR #2350 / GHSA-x3wm-3wx7-g6xm (Redis KEYS / SCAN injection)

---------

Co-authored-by: Nagendhra <nagendhra405@gmail.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 13:23:15 -07:00
Christian Bromann 80c2806cb2 fix(sdk): fold forkFrom client-side and honor multitaskStrategy (#2447)
## Summary
- Fold the SDK's top-level `forkFrom` into
`config.configurable.checkpoint_id` client-side before sending
`run.start`, so `forkFrom` never reaches the server and the fork target
travels via the single legacy-compliant field used by the existing run
endpoints.
- Drop the server-side `forkFrom` normalization/promotion in both
protocol-v2 reference servers (`ProtocolService.createOrResumeRun` and
the embed protocol routes), reading the fork target solely from
`config.configurable.checkpoint_id`.
- Honor the caller's per-run `multitaskStrategy` (`reject` | `rollback`
| `interrupt` | `enqueue`) instead of hardcoding `interrupt`, falling
back to `enqueue` (the legacy stream-endpoint default, matching the
Python protocol-v2 server) when omitted or unrecognized.
2026-05-28 12:59:49 -07:00
Nagendhra Madishetti 1e73c6b463 fix(langgraph-checkpoint-redis): block KEYS / SCAN pattern injection via top-level identifiers (#2350)
## Summary

Closes a Redis pattern-injection sink (CWE-77, CWE-943) in `RedisSaver`
and `ShallowRedisSaver`. A caller able to shape `thread_id`,
`checkpoint_ns`, `checkpoint_id`, or `task_id` (multi-tenant SDK
deployments where the `RunnableConfig` originates from request input, or
webhook payloads that flow into a persisted thread) can promote a string
identifier into a Redis glob (`*`, `?`, `[...]`) and read, overwrite, or
wipe checkpoints belonging to other tenants.

The audit posted in #2346 (cc @etairl) listed *Redis key/glob injection
in `RedisSaver` / `ShallowRedisSaver`* among the unfiled findings from
the same security-review pass. This PR confirms the finding and extends
the fix to all key-building sites in both savers.

## Vulnerable sinks

`RedisSaver` (`libs/checkpoint-redis/src/index.ts`):

| Method | Sinks |
|---|---|
| `getTuple` | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`
plus the direct \`json.get\` key |
| `list` (fallback paths) |
`keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`,
`keys(\"checkpoint:*:\${checkpointNs}:*\")` |
| `put` |
`\`checkpoint:\${threadId}:\${checkpointNs}:\${checkpointId}\`` plus the
zset key |
| `putWrites` | per-write key, zset key, checkpoint key |
| `deleteThread` | `keys(\"checkpoint:\${threadId}:*\")`,
`keys(\"writes:\${threadId}:*\")` |
| `loadPendingWrites` |
`keys(\"checkpoint_write:\${threadId}:\${checkpointNs}:\${checkpointId}:*\")`
|

`ShallowRedisSaver` (`libs/checkpoint-redis/src/shallow.ts`) has the
same five public entry points plus the equivalent helper.

## Proof of concept

```ts
import { createClient } from \"redis\";
import { RedisSaver } from \"@langchain/langgraph-checkpoint-redis\";

const client = createClient({ url: process.env.REDIS_URL! });
await client.connect();
const saver = new RedisSaver(client);

// Tenant A and Tenant B persist checkpoints normally.
await saver.put(
  { configurable: { thread_id: \"tenant-a\", checkpoint_ns: \"\" } },
  /* checkpoint */ { id: \"cp-a\", v: 4, ts: new Date().toISOString(),
                     channel_values: {}, channel_versions: {}, versions_seen: {} } as any,
  /* metadata  */ { source: \"input\", step: 0, parents: {} } as any,
  {}
);
await saver.put(
  { configurable: { thread_id: \"tenant-b\", checkpoint_ns: \"\" } },
  { id: \"cp-b\", v: 4, ts: new Date().toISOString(),
    channel_values: {}, channel_versions: {}, versions_seen: {} } as any,
  { source: \"input\", step: 0, parents: {} } as any,
  {}
);

// Attacker controls only the thread_id of their own request.
// Without the guard, deleteThread expands the KEYS pattern to a glob
// and deletes BOTH tenants' checkpoints.
await saver.deleteThread(\"*\");
// Both \`cp-a\` and \`cp-b\` are gone.
```

The same shape (`\"*\"`, `\"tenant-?\"`, `\"tenant-[ab]\"`, `\"a\\b\"`)
is accepted by every Redis pattern site in the table above.

## Severity

Proposed CVSS 3.1: **High**. The most severe sink is `deleteThread`,
which gives full availability impact across every tenant in the
database, with confidentiality (`getTuple`, `list`) and integrity
(`put`, `putWrites`) impacts on the other paths. Network-reachable,
low-complexity, only the privilege the SDK already grants to a caller.

## Fix

A single `assertSafeKeyComponent` helper exported from `./utils.js`,
applied at every key-building site (27 calls across 2 saver files plus
the helper export). The guard:

* Asserts the value is a non-empty string (the documented empty
`checkpoint_ns` default is opt-in via `{ allowEmpty: true }`).
* Rejects the Redis pattern meta-characters `* ? [ ] \`.
* Rejects the `:` delimiter that would otherwise corrupt the
colon-delimited key structure.

\`\`\`ts
export function assertSafeKeyComponent(
  field: string,
  value: unknown,
  options: { allowEmpty?: boolean } = {}
): asserts value is string {
  const { allowEmpty = false } = options;
if (typeof value !== \"string\") { /* precise diagnostic */ throw ... }
  if (!allowEmpty && value === \"\") { throw ... }
  if (REDIS_KEY_FORBIDDEN.test(value)) { throw ... }
}
\`\`\`

The guard is a TypeScript \`asserts\` predicate so call-sites get type
narrowing for free and the compiler enforces that no later code path
uses an unvalidated identifier.

## Why this design

* Mirrors the maintainers' existing primitive-only pattern
(\`escapeRediSearchTagValue\`) in the same file.
* Single chokepoint: it is impossible for a future call-site to forget
validation.
* No new dependencies, no API changes for valid inputs, no behavior
change for any documented happy path.
* Pairs with PR #2349 (NoSQL injection in MongoDBSaver) so both backends
now share the same defensive posture at the saver boundary.

## Test plan

* [x] 11 new tests under \`describe(\"assertSafeKeyComponent\")\` in
\`libs/checkpoint-redis/src/tests/utils.test.ts\` covering accept and
reject paths for every input shape (normal string, empty with and
without \`allowEmpty\`, every Redis meta-character, colon delimiter,
every wrong type).
* [x] Existing \`escapeRediSearchTagValue\` suite still green
(regression).
* [x] Full suite green (\`pnpm --filter
@langchain/langgraph-checkpoint-redis test\`, 21 of 21).
* [x] Format clean on all 4 changed files (\`oxfmt\`).
* [x] No new dependencies, no public API changes, no behavior change for
valid string identifiers.

## Disclosure

Original finding credited to @etairl (audit posted in #2346). This PR
was prepared for coordinated public disclosure since the audit list is
already public. Happy to coordinate timing with a private GHSA if the
maintainers prefer.

---------

Co-authored-by: Nagendhra <nagendhra405@gmail.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 12:58:54 -07:00
Christian Bromann 80a8c1200a refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom (#2443)
## Summary
- Remove `command` from `StreamSubmitOptions` and the
`submit-coordinator` resume-via-`submit` path so HITL resume goes
through `stream.respond()` only.
- Simplify `forkFrom` from `{ checkpointId: string }` to a plain
checkpoint id string across the SDK, protocol-v2 services, and docs.
- Update interrupt tests, examples (`HumanInTheLoopView`, branching
views), and React/Vue/Svelte/Angular JSDoc and migration/interrupt docs
to match.
2026-05-28 09:52:05 -07:00
github-actions[bot] 2f0010e3a5 chore: version packages (#2442)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.9

### Patch Changes

- [#2441](https://github.com/langchain-ai/langgraphjs/pull/2441)
[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): preserve apiUrl path prefix in stream transport URLs

Use BaseClient-style URL concatenation in `toAbsoluteUrl` so SSE and
WebSocket
subscriptions work when the SDK is pointed at a proxied apiUrl with a
path
    prefix (e.g. `/api/chat-langchain`).

## @langchain/angular@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @langchain/react@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @langchain/svelte@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @langchain/vue@1.0.9

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9

## @example/ai-elements@0.1.24

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.9

## @examples/assistant-ui-claude@0.1.24

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.9

## @examples/ui-angular@0.0.34

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9
    -   @langchain/angular@1.0.9

## @examples/ui-multimodal@0.0.10

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.9

## @examples/ui-react@0.0.10

### Patch Changes

- Updated dependencies
\[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]:
    -   @langchain/langgraph-sdk@1.9.9
    -   @langchain/react@1.0.9

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-27 12:21:25 -07:00
Christian Bromann dbbcb636e7 fix(sdk): preserve apiUrl path prefix in stream transport URLs (#2441)
## Summary
- Fix `toAbsoluteUrl` to concatenate `apiUrl` and path instead of using
`new URL(path, base)`, which dropped path prefixes on proxied
deployments.
- Route WebSocket stream URL construction through `toAbsoluteUrl` for
consistency with SSE transport.
- Add unit and integration tests for proxied apiUrl paths, plus shared
transport test helpers.
2026-05-27 12:16:42 -07:00
github-actions[bot] 4e71ace65a chore: version packages (#2439)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

## @langchain/angular@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @langchain/react@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @langchain/svelte@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @langchain/vue@1.0.8

### Patch Changes

- [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438)
[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): cancel runs on stop by default and add disconnect()

`stream.stop()` now calls `client.runs.cancel` for the active run before
disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs
can call `stream.disconnect()` or `stop({ cancel: false })` to leave the
agent running server-side.

    This fills a missing gap we found when migrating to v1.

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8

## @example/ai-elements@0.1.23

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/react@1.0.8

## @examples/assistant-ui-claude@0.1.23

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/react@1.0.8

## @examples/ui-angular@0.0.33

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8
    -   @langchain/angular@1.0.8

## @examples/ui-multimodal@0.0.9

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/react@1.0.8

## @examples/ui-react@0.0.9

### Patch Changes

- Updated dependencies
\[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]:
    -   @langchain/langgraph-sdk@1.9.8
    -   @langchain/react@1.0.8

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-26 17:05:03 -07:00
Christian Bromann 29d2bde235 fix(sdk): cancel runs on stop by default and add disconnect() (#2438)
## Summary

- `stream.stop()` now cancels the active run server-side by default
(`client.runs.cancel`) before disconnecting the client transport.
- Added `stream.disconnect()` as an alias for `stop({ cancel: false })`
for join/rejoin UIs.
- Introduced `StreamStopOptions` (`{ cancel?: boolean }`) on
`StreamController` and all v1 framework bindings (React, Vue, Svelte,
Angular).
- Updated `use-stream.md` and added controller unit tests for
cancel-on-stop and no-cancel-on-disconnect.
2026-05-26 17:02:20 -07:00
github-actions[bot] 39ce52f248 chore: version packages (#2436)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- [#2434](https://github.com/langchain-ai/langgraphjs/pull/2434)
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)
Thanks [@hntrl](https://github.com/hntrl)! - fix(react): avoid eager
stream getter evaluation during object spread

Mark optional `useStream` accessors as non-enumerable so object
spread/rest destructuring does not accidentally read guarded fields like
`history` or opt into additional stream modes.

## @langchain/angular@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @langchain/react@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @langchain/svelte@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @langchain/vue@1.0.7

### Patch Changes

- [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435)
[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): unwrap Command tool outputs and hide scoped task tools

    Filter wrapper `task` dispatch events from subagent-scoped tool-call
    projections and parse embedded ToolMessage results from LangGraph
    `Command` payloads on `tool-finished`.

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7

## @example/ai-elements@0.1.22

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]:
    -   @langchain/react@1.0.7

## @examples/assistant-ui-claude@0.1.22

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]:
    -   @langchain/react@1.0.7

## @examples/ui-angular@0.0.32

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7
    -   @langchain/angular@1.0.7

## @examples/ui-multimodal@0.0.8

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]:
    -   @langchain/react@1.0.7

## @examples/ui-react@0.0.8

### Patch Changes

- Updated dependencies
\[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e),
[`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]:
    -   @langchain/langgraph-sdk@1.9.7
    -   @langchain/react@1.0.7

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-26 14:09:43 -07:00
Hunter Lovell 6b188e80ab fix(sdk): avoid eager stream getter evaluation (#2434)
## Summary

fix(sdk): avoid eager stream getter evaluation during spread

This fixes a React `useStream` development-mode failure where passing
the stream handle through components that clone or rest-spread props
could accidentally read lazy getters. The guarded `history` getter still
throws when explicitly accessed with `fetchStateHistory: false`, but
object spread no longer trips that path or widens `streamMode` by
touching optional accessors.

## Changes

`@langchain/langgraph-sdk`

- Marks optional `useStream` accessors (`history`,
`experimental_branchTree`, `toolProgress`, `subagents`,
`activeSubagents`) as non-enumerable on the returned stream handle.
- Preserves explicit access behavior for those accessors, including the
existing `history` guard and stream mode opt-in for
`toolProgress`/`subagents`.
- Adds React hook regression coverage for object spread, explicit getter
access, and stream mode inference.
2026-05-26 14:07:07 -07:00
Christian Bromann cfc8d274e4 fix(sdk): unwrap Command tool outputs and hide scoped task tools (#2435)
## Summary

- Filter scoped deep-agent `task` dispatch events out of `sub.toolCalls`
so subagent tool streams only show real worker tools.
- Unwrap LangGraph `Command` payloads in `parseToolOutput` when they
carry an embedded `ToolMessage`, so `tc.output` resolves to the actual
tool result instead of raw graph state.
- Share the scoped-task filter between client subagent handles and
framework tool-call projections.
2026-05-26 14:05:16 -07:00
github-actions[bot] 9c9da48ae2 chore: version packages (#2433)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

## @langchain/angular@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @langchain/react@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @langchain/svelte@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @langchain/vue@1.0.6

### Patch Changes

- [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430)
[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): clear subgraph and subagent discovery on thread swap

Reset discovery stores in `StreamController.#teardownThread()` so
starting a
new thread does not leave stale subgraph cards or subagent entries from
the
    previous run.

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6

## @example/ai-elements@0.1.21

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/react@1.0.6

## @examples/assistant-ui-claude@0.1.21

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/react@1.0.6

## @examples/ui-angular@0.0.31

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6
    -   @langchain/angular@1.0.6

## @examples/ui-multimodal@0.0.7

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/react@1.0.6

## @examples/ui-react@0.0.7

### Patch Changes

- Updated dependencies
\[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]:
    -   @langchain/langgraph-sdk@1.9.6
    -   @langchain/react@1.0.6

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-25 00:54:21 -07:00
Christian Bromann f99941f5fe fix(sdk): clear subgraph and subagent discovery on thread swap (#2430)
## Summary
- Add `reset()` to `SubgraphDiscovery` and `SubagentDiscovery` to clear
internal maps and committed store snapshots.
- Call both resets from `StreamController.#teardownThread()` alongside
existing per-thread resets (messages, tools, metadata).
- Add unit tests for discovery `reset()` and a controller test that
`hydrate(null)` clears subgraphs after lifecycle events.
2026-05-25 00:50:31 -07:00
github-actions[bot] 7788dceb85 chore: version packages (#2424)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint-redis@1.0.5

### Patch Changes

- [#2208](https://github.com/langchain-ai/langgraphjs/pull/2208)
[`ebeb145`](https://github.com/langchain-ai/langgraphjs/commit/ebeb1452d27fcca100cd63bdfd4a7f020949412c)
Thanks [@jackjin1997](https://github.com/jackjin1997)! - Fix
`deleteThread()` using wrong key pattern (`writes:` instead of
`checkpoint_write:`) and add missing cleanup of `write_keys_zset:`
entries.

## @langchain/langgraph-supervisor@1.0.3

### Patch Changes

- [#2317](https://github.com/langchain-ai/langgraphjs/pull/2317)
[`c088c76`](https://github.com/langchain-ai/langgraphjs/commit/c088c7659c18edf26091813ff384f48f5335bef6)
Thanks [@fish895623](https://github.com/fish895623)! - feat(supervisor):
widen agents type to accept createAgent graphs

## @langchain/langgraph-sdk@1.9.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

## @langchain/angular@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @langchain/react@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @langchain/svelte@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @langchain/vue@1.0.5

### Patch Changes

- [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421)
[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(stream): align AssembledToolCall typing with pre-v1 expectations

Make `InferToolCalls` resolve to generic `AssembledToolCall` unions,
expose
sync `status`/`error` for reactive bindings, and align type tests across
    React, Vue, Svelte, and Angular SDK packages.

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5

## @example/ai-elements@0.1.20

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/react@1.0.5

## @examples/assistant-ui-claude@0.1.20

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/react@1.0.5

## @examples/ui-angular@0.0.30

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5
    -   @langchain/angular@1.0.5

## @examples/ui-multimodal@0.0.6

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/react@1.0.5

## @examples/ui-react@0.0.6

### Patch Changes

- Updated dependencies
\[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]:
    -   @langchain/langgraph-sdk@1.9.5
    -   @langchain/react@1.0.5

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-22 07:16:17 -07:00
Christian Bromann b1d307ab84 ci(infra): run framework browser tests only when paths change (#2425)
## Summary
- Add a `detect-changes` job to the browser test workflow using
`dorny/paths-filter@v3.0.2`.
- Run all four framework browser jobs when `libs/sdk/**` changes or when
this workflow file changes.
- Run only the matching job when `libs/sdk-react`, `libs/sdk-angular`,
`libs/sdk-vue`, or `libs/sdk-svelte` changes.
- Keep the full matrix on `workflow_dispatch` (manual runs and CI
dispatched via workflow_dispatch).
2026-05-22 07:15:30 -07:00
dependabot[bot] 674173b8ac chore(deps-dev): bump turbo from 2.8.15 to 2.9.14 (#2428)
Bumps [turbo](https://github.com/vercel/turborepo) from 2.8.15 to
2.9.14.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/turborepo/releases">turbo's
releases</a>.</em></p>
<blockquote>
<h2>Turborepo v2.9.14</h2>
<blockquote>
<p>[!NOTE]
This release contains important security fixes.</p>
</blockquote>
<h3>High:</h3>
<ul>
<li><a
href="https://github.com/vercel/turborepo/security/advisories/GHSA-5xc8-49mv-x4mm">GHSA-5xc8-49mv-x4mm:
Turborepo VSCode Extension command injection</a></li>
</ul>
<h3>Low:</h3>
<ul>
<li><a
href="https://github.com/vercel/turborepo/security/advisories/GHSA-hcf7-66rw-9f5r">GHSA-hcf7-66rw-9f5r:
Login callback CSRF/session fixation</a></li>
<li><a
href="https://github.com/vercel/turborepo/security/advisories/GHSA-3qcw-2rhx-2726">GHSA-3qcw-2rhx-2726:
Unexpected local code execution during Yarn Berry detection</a></li>
</ul>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>release(turborepo): 2.9.12 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li>
<li>fix: Restore docs mobile menu by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li>
<li>ci: Use <code>pull_request</code> for PR title linting by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li>
<li>ci: Scope GitHub Actions caches by branch by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li>
<li>test: Validate lockfiles without dependency downloads by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li>
<li>Removed unneeded import form hash creation script in docs by <a
href="https://github.com/dancrumb"><code>@​dancrumb</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li>
<li>fix: Validate auth callback state by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li>
<li>fix: Harden VS Code extension command execution by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li>
<li>fix: Avoid project-local Yarn during detection by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li>
<li>chore: Release 2.9.13 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12803">vercel/turborepo#12803</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/dancrumb"><code>@​dancrumb</code></a>
made their first contribution in <a
href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14">https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14</a></p>
<h2>Turborepo v2.9.13-canary.1</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>release(turborepo): 2.9.11-canary.7 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12768">vercel/turborepo#12768</a></li>
<li>fix: Allow <code>$TURBO_EXTENDS$</code> in LSP diagnostics by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12770">vercel/turborepo#12770</a></li>
<li>release(turborepo): 2.9.11 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12771">vercel/turborepo#12771</a></li>
<li>fix: Allow transit nodes in LSP diagnostics by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12773">vercel/turborepo#12773</a></li>
<li>release(turborepo): 2.9.12 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li>
<li>fix: Restore docs mobile menu by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li>
<li>ci: Use <code>pull_request</code> for PR title linting by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li>
<li>ci: Scope GitHub Actions caches by branch by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li>
<li>test: Validate lockfiles without dependency downloads by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li>
<li>Removed unneeded import form hash creation script in docs by <a
href="https://github.com/dancrumb"><code>@​dancrumb</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li>
<li>fix: Validate auth callback state by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li>
<li>fix: Harden VS Code extension command execution by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li>
<li>fix: Avoid project-local Yarn during detection by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/turborepo/commit/fc62fe0d9c347d1d24f0ed8946284856593ddb93"><code>fc62fe0</code></a>
publish 2.9.14 to registry</li>
<li><a
href="https://github.com/vercel/turborepo/commit/fb8c9aec0f9e83f95783659a5ce9c4478cf62cb9"><code>fb8c9ae</code></a>
chore: Release 2.9.13 (<a
href="https://redirect.github.com/vercel/turborepo/issues/12803">#12803</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/e8e629da4e1fb75231089e91b19be9d327a3e649"><code>e8e629d</code></a>
fix: Avoid project-local Yarn during detection (<a
href="https://redirect.github.com/vercel/turborepo/issues/12801">#12801</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/91c90cbf12f524c5c29b713d6472dd5fcdecb309"><code>91c90cb</code></a>
fix: Harden VS Code extension command execution (<a
href="https://redirect.github.com/vercel/turborepo/issues/12800">#12800</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/84f450894e87da1eed864d51f6f637f26980d560"><code>84f4508</code></a>
fix: Validate auth callback state (<a
href="https://redirect.github.com/vercel/turborepo/issues/12802">#12802</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/1779ad7901384f106236a6e196059e4929745514"><code>1779ad7</code></a>
Removed unneeded import form hash creation script in docs (<a
href="https://redirect.github.com/vercel/turborepo/issues/12799">#12799</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/71f8c90a807ffb9b9876ea8a04f523f473bf5c8d"><code>71f8c90</code></a>
test: Validate lockfiles without dependency downloads (<a
href="https://redirect.github.com/vercel/turborepo/issues/12789">#12789</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/5fcb96024d503127bb0ed760ebe159b7716c52b3"><code>5fcb960</code></a>
ci: Scope GitHub Actions caches by branch (<a
href="https://redirect.github.com/vercel/turborepo/issues/12788">#12788</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/4cf9fabc9a6f6c99fe4e2f2da9f35be631be062a"><code>4cf9fab</code></a>
ci: Use <code>pull_request</code> for PR title linting (<a
href="https://redirect.github.com/vercel/turborepo/issues/12787">#12787</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/859c629bc401f239ac7980a132746ca90478e17c"><code>859c629</code></a>
fix: Restore docs mobile menu (<a
href="https://redirect.github.com/vercel/turborepo/issues/12782">#12782</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/turborepo/compare/v2.8.15...v2.9.14">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=turbo&package-manager=npm_and_yarn&previous-version=2.8.15&new-version=2.9.14)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-22 07:07:17 -07:00
배성훈 c088c7659c feat(supervisor): widen agents type to accept createAgent graphs (#2317)
## Summary

- Add a broader `CompiledStateGraph<any, any, string, any, any>` to the
`agents` union in `CreateSupervisorParams`
- Graphs produced by `createAgent` from `langchain` (via `.graph`) are
now accepted alongside existing `createReactAgent` graphs and
`RemoteGraph`
- The original `AnnotationRootT`-parameterized `CompiledStateGraph` type
is preserved for backward compatibility

## Motivation

The new `createAgent` API in the `langchain` package returns a
`ReactAgent` whose `.graph` property is a `CompiledStateGraph` with a
different state schema (`BuiltInState`) than the
`MessagesAnnotation`-based state from `createReactAgent`. Since
`createReactAgent` is deprecated in favor of `createAgent`,
`createSupervisor` needs to accept both graph types.

At runtime this already works — `makeCallAgent` types its `agent`
parameter as `any` and only accesses `.name`, `.invoke()`, and
optionally `.description`. The type constraint on the `agents` parameter
was simply too narrow for the new API.

## Changes

### `@langchain/langgraph-supervisor` (`libs/langgraph-supervisor`)

- Updated `CreateSupervisorParams.agents` type to include
`CompiledStateGraph<any, any, string, any, any>` in the union alongside
the existing strictly-typed `CompiledStateGraph` and `RemoteGraph`

## Test plan

- [x] `pnpm build` passes for `@langchain/langgraph-supervisor`
- [x] Consuming project using `createAgent` + `createSupervisor`
compiles without errors
- [x] Existing supervisor tests still pass

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-22 06:58:38 -07:00
Jackjin ebeb1452d2 fix(langgraph-checkpoint-redis): fix deleteThread using wrong key pattern for writes (#2208)
## Summary

Fixes #2207

- Fix `deleteThread()` using incorrect `writes:` prefix instead of
`checkpoint_write:` for write key deletion
- Add missing cleanup of `write_keys_zset:` entries, matching the
correct implementation in `ShallowRedisSaver`

The bug was found by comparing `RedisSaver.deleteThread()` with
`ShallowRedisSaver.deleteThread()` in `shallow.ts`, which correctly uses
`checkpoint_write:` prefix and also cleans up zset keys.

## AI Disclosure

This bug was identified through code review with AI assistance. The fix
aligns the standard `RedisSaver` implementation with the existing
correct `ShallowRedisSaver` implementation.

---------

Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-22 06:57:22 -07:00
Christian Bromann 3529e3831a fix(sdk): align AssembledToolCall typing with pre-v1 expectations (#2421)
## Summary
- Split tool-call handles by consumer:
- **Client SDK** (`ThreadStream.toolCalls`, subgraph/subagent
projections): `ClientAssembledToolCall` with a promise-only `output`
(resolves on success, rejects on error). Still exported as
`AssembledToolCall` from `@langchain/langgraph-sdk/client` for script
usage.
- **Framework SDKs** (`stream.toolCalls`, `useToolCalls`,
`injectToolCalls`): `AssembledToolCall` with plain reactive fields —
`output: T | null`, `status`, and `error` — updated in place as events
arrive so React/Vue/Svelte/Angular can render from snapshots without
`await`, effects, or Suspense around promises.
- Add generic `AssembledToolCall<TName, TInput, TOutput>` plus
`id`/`args` aliases; point `InferToolCalls` at assembled streaming
handles and add `AssembledToolCallFromTool` (exported as
`ToolCallFromTool` from `@langchain/react`, `@langchain/vue`,
`@langchain/svelte`, and `@langchain/angular`).
- Rework `ToolCallAssembler` around a mutable internal handle and
`toClientAssembledToolCall()` for client projections; framework stores
the reactive handle directly.
- Remove redundant `InferAssembledToolCalls` and deprecated `StateOf`;
wire typed `toolCalls` / selector generics across all four framework
packages.
- Expand and align `createAgent`, `createDeepAgent`, and `langgraph`
type tests across React, Vue, Svelte, and Angular; update examples,
protocol-v2 integration tests, and Vue migration docs.
2026-05-22 06:38:06 -07:00
github-actions[bot] 4a7d9a7c5d chore: version packages (#2416)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph@1.3.2

### Patch Changes

- [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415)
[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
Move `@langchain/core` from a runtime dependency back to a required peer
dependency so installing the SDK alone no longer pulls in
`@langchain/core` (and `js-tiktoken`, etc.). Consumers that use
streaming or message coercion must install `@langchain/core` explicitly
or via `@langchain/langgraph`.

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/langgraph-sdk@1.9.4

### Patch Changes

- [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415)
[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
Move `@langchain/core` from a runtime dependency back to a required peer
dependency so installing the SDK alone no longer pulls in
`@langchain/core` (and `js-tiktoken`, etc.). Consumers that use
streaming or message coercion must install `@langchain/core` explicitly
or via `@langchain/langgraph`.

## @langchain/angular@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/react@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/svelte@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @langchain/vue@1.0.4

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4

## @example/ai-elements@0.1.19

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## @examples/assistant-ui-claude@0.1.19

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## @examples/ui-angular@0.0.29

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4
    -   @langchain/langgraph@1.3.2
    -   @langchain/angular@1.0.4

## @examples/ui-multimodal@0.0.5

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## @examples/ui-react@0.0.5

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph-sdk@1.9.4
    -   @langchain/langgraph@1.3.2
    -   @langchain/react@1.0.4

## langgraph@1.0.34

### Patch Changes

- Updated dependencies
\[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]:
    -   @langchain/langgraph@1.3.2

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-19 00:02:58 -07:00
Christian Bromann 9d3c9dd318 fix(core): move @langchain/core back into being a peer dep (#2415)
`@langchain/langgraph-sdk@1.9.0` promoted `@langchain/core` from a dev
dependency to a **runtime dependency**, which caused install-size
metrics for `@langchain/langgraph` to jump from ~6 MB to ~40 MB for
consumers who did not already have core installed (or who use
`--legacy-peer-deps`). That happened because core pulls in heavy
transitive deps such as `js-tiktoken` (~21 MB) and `zod` (~6 MB), even
though `@langchain/langgraph` already lists core as a peer.

This PR moves `@langchain/core` back to a **required peer dependency**
on the SDK, matching `@langchain/langgraph` and the pre-1.9.0 SDK
layout. Runtime behavior is unchanged for typical LangGraph apps that
already install core; SDK-only installs no longer force core into the
tree.

Also switches `LangChainTracer` in `types.ts` to a type-only import so
the tracer subpath is not pulled as a value import.
2026-05-18 23:48:19 -07:00
github-actions[bot] 1b5ce0fca0 chore: version packages (#2405)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint-mongodb@1.3.1

### Patch Changes

- [#2397](https://github.com/langchain-ai/langgraphjs/pull/2397)
[`284226c`](https://github.com/langchain-ai/langgraphjs/commit/284226c7ca164b3c81fe2d9e32b10f1fc6b99a3c)
Thanks [@hntrl](https://github.com/hntrl)! - fix(checkpoint-mongodb):
validate configurable checkpoint identifiers before queries

Add runtime validation for `thread_id`, `checkpoint_ns`, and
`checkpoint_id` in
`MongoDBSaver` methods that read and write checkpoints. This prevents
object-based
operator payloads from being passed into MongoDB query filters and
ensures invalid
    configurable values fail fast with explicit errors.

## @langchain/langgraph-api@1.2.2

### Patch Changes

- [#2396](https://github.com/langchain-ai/langgraphjs/pull/2396)
[`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8)
Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph-cli): accept
hyphenated prerelease tags in `api_version` values.

-   Updated dependencies \[]:
    -   @langchain/langgraph-ui@1.2.2

## @langchain/langgraph-cli@1.2.2

### Patch Changes

- [#2389](https://github.com/langchain-ai/langgraphjs/pull/2389)
[`40bcdab`](https://github.com/langchain-ai/langgraphjs/commit/40bcdab38fa495028d8eba68062e48079dbe9208)
Thanks [@jdrogers940](https://github.com/jdrogers940)! - Adding support
for pre-release versions in api_version.

- [#2396](https://github.com/langchain-ai/langgraphjs/pull/2396)
[`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8)
Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph-cli): accept
hyphenated prerelease tags in `api_version` values.

- Updated dependencies
\[[`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8)]:
    -   @langchain/langgraph-api@1.2.2

## @langchain/langgraph@1.3.1

### Patch Changes

- [#2339](https://github.com/langchain-ai/langgraphjs/pull/2339)
[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f)
Thanks [@vigneshpatel14](https://github.com/vigneshpatel14)! -
fix(langgraph): surface structuredResponse parse failures in
createReactAgent

- [#2406](https://github.com/langchain-ai/langgraphjs/pull/2406)
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(langgraph-core): keep tool results out of v3 message streams

- [#2376](https://github.com/langchain-ai/langgraphjs/pull/2376)
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)
Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph): prefer
configurable assistant and graph IDs for runtime server info

Update runtime `serverInfo` construction to read `assistant_id` and
`graph_id` from
`config.configurable` first, with fallback to `config.metadata` for
compatibility.
Also expands `execution_info` tests to cover configurable sourcing,
precedence,
    and metadata fallback behavior.

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3

## @langchain/langgraph-sdk@1.9.3

### Patch Changes

- [#2387](https://github.com/langchain-ai/langgraphjs/pull/2387)
[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Coalesce
`RootMessageProjection` store writes through a single `setTimeout(0)`
flush so long `messages`-channel replays (on refresh, mid-run join, or
rapid subagent streaming) no longer drain as a per-event microtask chain
that trips React's `Maximum update depth exceeded` guard. Replaces the
previous `MessageChannel`-based batching, which deferred initial-submit
events past the first render and left the UI looking frozen until
refresh.

- [#2372](https://github.com/langchain-ai/langgraphjs/pull/2372)
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7)
Thanks [@ahmed-z0](https://github.com/ahmed-z0)! - Fix subagent message
routing to prefer the stream event namespace over checkpoint metadata
when filtering subagent messages.

- [#2384](https://github.com/langchain-ai/langgraphjs/pull/2384)
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - batch
RootMessageProjection store writes through a macrotask

- [#2388](https://github.com/langchain-ai/langgraphjs/pull/2388)
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c)
Thanks [@hntrl](https://github.com/hntrl)! - fix(sdk): retry connection
failures before throwing ConnectionError

- [#2381](https://github.com/langchain-ai/langgraphjs/pull/2381)
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - fix(sdk):
forward config + metadata on respondInput for resume submits

- [#2379](https://github.com/langchain-ai/langgraphjs/pull/2379)
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - filter
SSE-replayed input.requested events through a hydrated interrupt
allowlist

- [#2390](https://github.com/langchain-ai/langgraphjs/pull/2390)
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Bind
deepagents subagent discovery to the execution namespace via taskInput
so `useMessages(stream, subagent)` resolves the streaming scope instead
of the trigger tool-call namespace.

## @langchain/angular@1.0.3

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3

## @langchain/react@1.0.3

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3

## @langchain/svelte@1.0.3

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3

## @langchain/vue@1.0.3

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3

## @langchain/langgraph-cua@1.0.2



## @langchain/langgraph-supervisor@1.0.2



## @langchain/langgraph-swarm@1.0.2



## @langchain/langgraph-ui@1.2.2



## @example/ai-elements@0.1.18

### Patch Changes

- Updated dependencies
\[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f),
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1
    -   @langchain/react@1.0.3

## @examples/assistant-ui-claude@0.1.18

### Patch Changes

- Updated dependencies
\[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f),
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1
    -   @langchain/react@1.0.3

## @examples/ui-angular@0.0.28

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f),
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3
    -   @langchain/langgraph@1.3.1
    -   @langchain/angular@1.0.3

## @examples/ui-multimodal@0.0.4

### Patch Changes

- Updated dependencies
\[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f),
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1
    -   @langchain/react@1.0.3

## @examples/ui-react@0.0.4

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f),
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3
    -   @langchain/langgraph@1.3.1
    -   @langchain/react@1.0.3

## langgraph@1.0.33

### Patch Changes

- Updated dependencies
\[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f),
[`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1

## docs@null

# docs

## null

## null

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-05-18 22:47:09 +00:00
Hunter Lovell 284226c7ca fix(langgraph-checkpoint-mongodb): validate configurable checkpoint IDs (#2397)
## Summary

Fixes #2351

This change hardens `@langchain/langgraph-checkpoint-mongodb` against
object-based configurable input in checkpoint identifiers. It adds
runtime validation for `thread_id`, `checkpoint_ns`, and `checkpoint_id`
before any MongoDB query/write path uses these values, so operator-like
payloads are rejected early with explicit errors.

## Changes

### `@langchain/langgraph-checkpoint-mongodb`

- Added a shared `getStringConfigValue` runtime validator in
[`libs/checkpoint-mongodb/src/checkpoint.ts`](libs/checkpoint-mongodb/src/checkpoint.ts).
- Applied validation to `getTuple`, `list`, `put`, `putWrites`, and
`deleteThread`.
- Preserved existing behavior where `getTuple` returns `undefined` when
`thread_id` is missing, while now rejecting non-string values.
- Added regression tests in
[`libs/checkpoint-mongodb/src/tests/checkpoints.test.ts`](libs/checkpoint-mongodb/src/tests/checkpoints.test.ts)
for object/operator payloads across the affected methods.
- Added a patch changeset for `@langchain/langgraph-checkpoint-mongodb`.

Co-authored-by: Itay <9601971+etairl@users.noreply.github.com>
2026-05-18 14:47:00 -07:00
Christian Bromann e54ae901e1 fix(core): keep tool results out of v3 message streams (#2406)
## Summary
- Prevent v3 `run.messages` from surfacing `ToolMessage` outputs as
assistant text.
- Skip tool-role message lifecycles in the messages transformer while
preserving tool messages in state snapshots.
- Add regression coverage for tool-result message leakage.

fixes https://github.com/langchain-ai/deepagentsjs/issues/534
2026-05-18 13:06:22 -07:00
Hunter Lovell 01dd0462ed fix(sdk): retry connection failures before throwing ConnectionError (#2388)
## Summary

This change updates SDK retry behavior so connection-related failures
are retried instead of immediately aborting inside `onFailedAttempt`.
When retries are exhausted, the final surfaced error is still coalesced
to a `ConnectionError` with the existing LangGraph-specific guidance.
A focused unit test was added to lock in this behavior.

## Changes

### @langchain/langgraph-sdk

- Updated `AsyncCaller` connection-error handling to only throw
`ConnectionError` on the final failed attempt (`retriesLeft === 0`),
while allowing retries on earlier attempts.
- Added a regression test covering retry count plus final
`ConnectionError` coalescing for connection-refused/fetch-failed style
errors.
- Added a patch changeset for `@langchain/langgraph-sdk` documenting the
retry/coalescing fix.
2026-05-18 10:27:49 -07:00
Vignesh 2b88da497b fix(langgraph): surface structuredResponse parse failures in createReactAgent (#2339)
Closes  Issue #2338

## Problem
When `createReactAgent` is called with `responseFormat`, the
`generate_structured_response` node calls
`model.withStructuredOutput(schema).invoke(...)`. Some parsers return
`null`/`undefined` (instead of throwing) when the LLM produces JSON that
is
syntactically valid but does not satisfy the schema (e.g. a missing
required field). The result was unconditionally assigned to the
`structuredResponse` channel, so the agent silently resolved with
`structuredResponse: undefined` — no error, no warning, no log.

## Fix
Detect the `null`/`undefined` case in `generate_structured_response` and
throw a descriptive error stating that the structured-output parser
returned null/undefined and the model output did not satisfy the schema.
This converts the silent failure into an explicit, debuggable error.

The error does not include the raw model completion. The existing call
shape (`withStructuredOutput(schema, options).invoke(...)`) returns only
the parsed value. Switching to `{ includeRaw: true }` would surface the
completion but (a) overrides any caller-supplied `includeRaw` in the
existing options object and (b) relies on every chat-model
implementation
honoring `includeRaw` consistently, so it's left as a possible
follow-up.

## Test
Added `Throws when structured output parser returns null` in
`libs/langgraph-core/src/tests/prebuilt.test.ts`. It spies on
`withStructuredOutput` to return `null` (simulating the silent failure)
and asserts the agent rejects with the new error message. The test runs
inside the existing `describe.each([["v1"], ["v2"]])` block, so both
agent versions are covered.

---------

Co-authored-by: Voddam Vignesh <vignesh.voddam@gep.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-05-16 02:06:46 -07:00
github-actions[bot] 22c4541b53 chore: version packages (rc) (#2385)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`main` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `main`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @langchain/langgraph-api@1.2.2-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0
    -   @langchain/langgraph@1.3.1-rc.0
    -   @langchain/langgraph-ui@1.2.2-rc.0

## @langchain/langgraph-cli@1.2.2-rc.0

### Patch Changes

- [#2389](https://github.com/langchain-ai/langgraphjs/pull/2389)
[`40bcdab`](https://github.com/langchain-ai/langgraphjs/commit/40bcdab38fa495028d8eba68062e48079dbe9208)
Thanks [@jdrogers940](https://github.com/jdrogers940)! - Adding support
for pre-release versions in api_version.

-   Updated dependencies \[]:
    -   @langchain/langgraph-api@1.2.2-rc.0

## @langchain/langgraph@1.3.1-rc.0

### Patch Changes

- [#2376](https://github.com/langchain-ai/langgraphjs/pull/2376)
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)
Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph): prefer
configurable assistant and graph IDs for runtime server info

Update runtime `serverInfo` construction to read `assistant_id` and
`graph_id` from
`config.configurable` first, with fallback to `config.metadata` for
compatibility.
Also expands `execution_info` tests to cover configurable sourcing,
precedence,
    and metadata fallback behavior.

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0

## @langchain/langgraph-cua@1.0.2-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0

## @langchain/langgraph-supervisor@1.0.2-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0

## @langchain/langgraph-swarm@1.0.2-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0

## @langchain/langgraph-sdk@1.9.3-rc.0

### Patch Changes

- [#2387](https://github.com/langchain-ai/langgraphjs/pull/2387)
[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Coalesce
`RootMessageProjection` store writes through a single `setTimeout(0)`
flush so long `messages`-channel replays (on refresh, mid-run join, or
rapid subagent streaming) no longer drain as a per-event microtask chain
that trips React's `Maximum update depth exceeded` guard. Replaces the
previous `MessageChannel`-based batching, which deferred initial-submit
events past the first render and left the UI looking frozen until
refresh.

- [#2372](https://github.com/langchain-ai/langgraphjs/pull/2372)
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7)
Thanks [@ahmed-z0](https://github.com/ahmed-z0)! - Fix subagent message
routing to prefer the stream event namespace over checkpoint metadata
when filtering subagent messages.

- [#2384](https://github.com/langchain-ai/langgraphjs/pull/2384)
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - batch
RootMessageProjection store writes through a macrotask

- [#2381](https://github.com/langchain-ai/langgraphjs/pull/2381)
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - fix(sdk):
forward config + metadata on respondInput for resume submits

- [#2379](https://github.com/langchain-ai/langgraphjs/pull/2379)
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - filter
SSE-replayed input.requested events through a hydrated interrupt
allowlist

- [#2390](https://github.com/langchain-ai/langgraphjs/pull/2390)
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)
Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Bind
deepagents subagent discovery to the execution namespace via taskInput
so `useMessages(stream, subagent)` resolves the streaming scope instead
of the trigger tool-call namespace.

## @langchain/angular@1.0.3-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0

## @langchain/react@1.0.3-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0

## @langchain/svelte@1.0.3-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0

## @langchain/vue@1.0.3-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0

## @langchain/langgraph-ui@1.2.2-rc.0



## @example/ai-elements@0.1.18-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0
    -   @langchain/react@1.0.3-rc.0

## @examples/assistant-ui-claude@0.1.18-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0
    -   @langchain/react@1.0.3-rc.0

## @examples/ui-angular@0.0.28-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0
    -   @langchain/langgraph@1.3.1-rc.0
    -   @langchain/angular@1.0.3-rc.0

## @examples/ui-multimodal@0.0.4-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0
    -   @langchain/react@1.0.3-rc.0

## @examples/ui-react@0.0.4-rc.0

### Patch Changes

- Updated dependencies
\[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113),
[`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7),
[`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad),
[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280),
[`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15),
[`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe),
[`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]:
    -   @langchain/langgraph-sdk@1.9.3-rc.0
    -   @langchain/langgraph@1.3.1-rc.0
    -   @langchain/react@1.0.3-rc.0

## langgraph@1.0.33-rc.0

### Patch Changes

- Updated dependencies
\[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]:
    -   @langchain/langgraph@1.3.1-rc.0

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-05-16 06:37:11 +00:00
dependabot[bot] 67831afa7f chore(deps-dev): bump svelte from 5.55.5 to 5.55.7 (#2394)
Bumps
[svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte)
from 5.55.5 to 5.55.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/svelte/releases">svelte's
releases</a>.</em></p>
<blockquote>
<h2>svelte@5.55.7</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: prevent XSS on <code>hydratable</code> from user contents (<a
href="https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"><code>a16ebc67bbcf8f708360195687e1b2719463e1a4</code></a>)</p>
</li>
<li>
<p>chore: bump devalue (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18219">#18219</a>)</p>
</li>
<li>
<p>fix: disallow empty attribute names during SSR (<a
href="https://github.com/sveltejs/svelte/commit/547853e2406a2147ad7fb5ffeba95b01bd9642da"><code>547853e2406a2147ad7fb5ffeba95b01bd9642da</code></a>)</p>
</li>
<li>
<p>fix: harden regex (<a
href="https://github.com/sveltejs/svelte/commit/d2375e2ebcab5c88feb5652f1a9d621b8f06b259"><code>d2375e2ebcab5c88feb5652f1a9d621b8f06b259</code></a>)</p>
</li>
<li>
<p>fix: move Svelte runtime properties to symbols (<a
href="https://github.com/sveltejs/svelte/commit/e1cbbd96441e82c9eb8a23a2903c0d06d3cda991"><code>e1cbbd96441e82c9eb8a23a2903c0d06d3cda991</code></a>)</p>
</li>
</ul>
<h2>svelte@5.55.6</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: leave stale promises to wait for a later resolution, instead of
rejecting (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18180">#18180</a>)</p>
</li>
<li>
<p>fix: keep dependencies of <code>$state.eager/pending</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18218">#18218</a>)</p>
</li>
<li>
<p>fix: reapply context after transforming error during SSR (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18099">#18099</a>)</p>
</li>
<li>
<p>fix: don't rebase just-created batches (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18117">#18117</a>)</p>
</li>
<li>
<p>chore: allow <code>null</code> for <code>pending</code> in typings
(<a
href="https://redirect.github.com/sveltejs/svelte/pull/18201">#18201</a>)</p>
</li>
<li>
<p>fix: flush eager effects in production (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18107">#18107</a>)</p>
</li>
<li>
<p>fix: rethrow error of failed iterable after calling
<code>return()</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18169">#18169</a>)</p>
</li>
<li>
<p>fix: account for proxified instance when updating
<code>bind:this</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18147">#18147</a>)</p>
</li>
<li>
<p>fix: ensure scheduled batch is flushed if not obsolete (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18131">#18131</a>)</p>
</li>
<li>
<p>fix: resolve stale deriveds with latest value (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18167">#18167</a>)</p>
</li>
<li>
<p>chore: remove unnecessary <code>increment_pending</code> calls (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18183">#18183</a>)</p>
</li>
<li>
<p>fix: correctly compile component member expressions for SSR (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18192">#18192</a>)</p>
</li>
<li>
<p>fix: reset <code>source.updated</code> stack traces after
<code>flush</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18196">#18196</a>)</p>
</li>
<li>
<p>fix: replacing async 'blocking' strategy with 'merging' (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18205">#18205</a>)</p>
</li>
<li>
<p>fix: allow <code>@debug</code> tags to reference awaited variables
(<a
href="https://redirect.github.com/sveltejs/svelte/pull/18138">#18138</a>)</p>
</li>
<li>
<p>fix: re-run fallback props if dependencies update (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18146">#18146</a>)</p>
</li>
<li>
<p>fix: abort running obsolete async branches (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18118">#18118</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md">svelte's
changelog</a>.</em></p>
<blockquote>
<h2>5.55.7</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: prevent XSS on <code>hydratable</code> from user contents (<a
href="https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"><code>a16ebc67bbcf8f708360195687e1b2719463e1a4</code></a>)</p>
</li>
<li>
<p>chore: bump devalue (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18219">#18219</a>)</p>
</li>
<li>
<p>fix: disallow empty attribute names during SSR (<a
href="https://github.com/sveltejs/svelte/commit/547853e2406a2147ad7fb5ffeba95b01bd9642da"><code>547853e2406a2147ad7fb5ffeba95b01bd9642da</code></a>)</p>
</li>
<li>
<p>fix: harden regex (<a
href="https://github.com/sveltejs/svelte/commit/d2375e2ebcab5c88feb5652f1a9d621b8f06b259"><code>d2375e2ebcab5c88feb5652f1a9d621b8f06b259</code></a>)</p>
</li>
<li>
<p>fix: move Svelte runtime properties to symbols (<a
href="https://github.com/sveltejs/svelte/commit/e1cbbd96441e82c9eb8a23a2903c0d06d3cda991"><code>e1cbbd96441e82c9eb8a23a2903c0d06d3cda991</code></a>)</p>
</li>
</ul>
<h2>5.55.6</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: leave stale promises to wait for a later resolution, instead of
rejecting (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18180">#18180</a>)</p>
</li>
<li>
<p>fix: keep dependencies of <code>$state.eager/pending</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18218">#18218</a>)</p>
</li>
<li>
<p>fix: reapply context after transforming error during SSR (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18099">#18099</a>)</p>
</li>
<li>
<p>fix: don't rebase just-created batches (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18117">#18117</a>)</p>
</li>
<li>
<p>chore: allow <code>null</code> for <code>pending</code> in typings
(<a
href="https://redirect.github.com/sveltejs/svelte/pull/18201">#18201</a>)</p>
</li>
<li>
<p>fix: flush eager effects in production (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18107">#18107</a>)</p>
</li>
<li>
<p>fix: rethrow error of failed iterable after calling
<code>return()</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18169">#18169</a>)</p>
</li>
<li>
<p>fix: account for proxified instance when updating
<code>bind:this</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18147">#18147</a>)</p>
</li>
<li>
<p>fix: ensure scheduled batch is flushed if not obsolete (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18131">#18131</a>)</p>
</li>
<li>
<p>fix: resolve stale deriveds with latest value (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18167">#18167</a>)</p>
</li>
<li>
<p>chore: remove unnecessary <code>increment_pending</code> calls (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18183">#18183</a>)</p>
</li>
<li>
<p>fix: correctly compile component member expressions for SSR (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18192">#18192</a>)</p>
</li>
<li>
<p>fix: reset <code>source.updated</code> stack traces after
<code>flush</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18196">#18196</a>)</p>
</li>
<li>
<p>fix: replacing async 'blocking' strategy with 'merging' (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18205">#18205</a>)</p>
</li>
<li>
<p>fix: allow <code>@debug</code> tags to reference awaited variables
(<a
href="https://redirect.github.com/sveltejs/svelte/pull/18138">#18138</a>)</p>
</li>
<li>
<p>fix: re-run fallback props if dependencies update (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18146">#18146</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sveltejs/svelte/commit/4d8f99a2709e3c02e48d8bc6c77458f4ba49d0e3"><code>4d8f99a</code></a>
Version Packages (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18220">#18220</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/05523088173e10af0753877af6936088de924833"><code>0552308</code></a>
chore: bump devalue (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18219">#18219</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/e1cbbd96441e82c9eb8a23a2903c0d06d3cda991"><code>e1cbbd9</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"><code>a16ebc6</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/d2375e2ebcab5c88feb5652f1a9d621b8f06b259"><code>d2375e2</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/547853e2406a2147ad7fb5ffeba95b01bd9642da"><code>547853e</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/55f9c85c09d625c3dd80c71ce7542f57386fafb4"><code>55f9c85</code></a>
Version Packages (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18158">#18158</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/a10e8e47a5946623a60a1e36b9023c23926eae87"><code>a10e8e4</code></a>
fix: keep dependencies of <code>$state.eager</code>/<code>pending</code>
(alternative approach) (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/1">#1</a>...</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/ef4b97dfabfd7a23b27933e18f7393587c343d66"><code>ef4b97d</code></a>
fix: duplicated &quot;of&quot; in events.js comment (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18217">#18217</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/5122936edb3c14e9a602e579727479b49cbd3239"><code>5122936</code></a>
fix: treat batches as a linked list (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18205">#18205</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/sveltejs/svelte/commits/svelte@5.55.7/packages/svelte">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=svelte&package-manager=npm_and_yarn&previous-version=5.55.5&new-version=5.55.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-15 23:19:22 -07:00
Hunter Lovell 9b20df081a fix(langgraph-cli): allow hyphenated prerelease api_version (#2396) 2026-05-15 20:13:50 -07:00
Nick Hollon f1d651ae14 fix(sdk): bind subagent namespace to execution scope via taskInput (#2390)
## Summary

When the SDK consumes a deepagents run over protocol-v2, the parent's
`task` tool call registers a subagent under `tools:<tool_call_id>` (e.g.
`tools:toolu_*`), but the subagent's pregel execution emits its
`values`/`messages`/`lifecycle` events at a **sibling** namespace
`tools:<pregel-uuid>` — not nested, no shared segment.
`SubagentDiscovery` tracked the trigger namespace, so
`useMessages(stream, subagent)` filtered the wrong scope and consumers
saw empty subagent cards while content streamed server-side.

The wire carries no first-class link between the two namespaces — the
lifecycle event's `trigger_call_id` is the Pregel UUID, not the
Anthropic `tool_call_id`.

## Approach

The server seeds the subagent's first state with
`HumanMessage(content=description)`, so an exact-equality match against
`taskInput` is deterministic. Adds:

- `#toolCallIdByTaskInput: Map<string, string[]>` — FIFO queue keyed by
taskInput, populated when a `task` tool call is registered.
- `#bindNamespaceByTaskInput` — on the first `values` event at a
`tools:<id>` namespace, look up the first HumanMessage text, shift the
matching `tool_call_id`, and seed `#taskIdByObservedNamespace`.
`#recordObservedWorkNamespace` promotes the namespace as before.

The queue handles parallel dispatches that share a description. Pregel
preserves dispatch order across executions, so FIFO pop attributes them
correctly.

## Known cliff edges (all silent — card stays empty)

- Wrapper middleware mutates the seeded HumanMessage before it reaches
the subagent.
- The HumanMessage uses multimodal content blocks instead of a string.
- A custom \`CompiledSubAgent\` state doesn't include a HumanMessage.

The upstream fix that eliminates the whole class is for langgraph's
\`_TasksLifecycleBase\` (or deepagents) to enrich the subagent's
lifecycle payload with \`cause: { tool_call_id }\`. That would replace
this bridge with a flat lookup.
2026-05-15 13:28:18 -07:00
Nick Hollon 44746b1a3b fix(sdk): coalesce RootMessageProjection writes via setTimeout(0) (#2387)
## Summary

Reworks `RootMessageProjection` batching to fix two regressions at once.

The freeze that #2384 originally addressed: on refresh, mid-run join, or
a rapidly-streaming subagent, many `messages`-channel events drain
through the controller's `for await` pump as a microtask chain.
Per-event `store.setState` calls fire `useSyncExternalStore`
notifications per event, and after ~50 React's `nestedUpdateCount` guard
trips with "Maximum update depth exceeded", permanently freezing the UI
on the first few messages.

The new regression #2384 introduced: its `MessageChannel`-based
scheduler deferred the first event of every streaming burst past React's
initial render. Initial submit looked frozen — no user message, no AI
response — until refresh.

This change keeps the coalescing (so the freeze stays fixed) but swaps
the scheduler to `setTimeout(0)` with a `#flushScheduled` idempotency
guard:

- `handleMessage` / `applyValues` compute new `messages` / `values`
synchronously and stage them in `#pendingMessages` / `#pendingValues`.
`#indexById` and `#valuesMessageIds` mutate synchronously so subsequent
same-tick calls see up-to-date positions.
- One `setTimeout(0)` flush per tick commits the staged values to the
store in a single `setState`. Bursts collapse to one notification;
streaming events separated by network latency each flush on their own
boundary.
- `reset()` drops pending writes so thread swaps can't bleed staged
state.

No test-only flush flag on the projection — the existing tests gained
`await drainFlush()` between mutations and assertions.

### New regression coverage

A `scheduling` describe block guards both contracts:

- streamed event commits within one macrotask (would fail on a
deferral-chain scheduler — initial-submit freeze)
- values snapshot commits within one macrotask (would fail on hydrate
freeze)
- 200-delta synchronous burst → fewer than 10 store notifications (would
fail on per-event `setState` — long-replay freeze)
- 50 sequential `applyValues` calls → fewer than 10 store notifications
(would fail on hydrate per-event freeze)

Both coalesce tests fail on a sync projection; both single-event tests
fail on a multi-macrotask deferral chain.

## Release Note

None
2026-05-15 13:27:47 -07:00
Josh Rogers 40bcdab38f fix: support pre-release versions in api_version (#2389)
<!--
Thank you for contributing to LangGraph.js! Your PR will appear in our
next release under the title you set above. Please make sure it
highlights your valuable contribution.

To help streamline the review process, please make sure you read our
contribution guidelines:
https://github.com/langchain-ai/langgraphjs/blob/main/CONTRIBUTING.md

Replace this block with a description of the change, the issue it fixes
(if applicable), and relevant context.

Finally, we'd love to show appreciation for your contribution - if you'd
like us to shout you out on Twitter, please also include your handle
below!
-->

<!-- Remove if not applicable -->

Fixing api_version in langgraph.json to support PEP compatible versions
(e.g. `0.9.0rc1`). Today we support JS compatible versions (e.g.
`0.9.0-rc1` but langgraph-api is a python package so the versioning
doesn't make sense and runs into issues with the image names.
2026-05-14 08:38:48 -07:00
Nick Hollon 75e651b9cf fix(sdk): filter SSE-replayed input.requested events through a hydrated interrupt allowlist (#2379)
SSE replay of past \`input.requested\` events was re-adding historically
requested (and since-resolved) interrupts to the UI on every page
navigation back to the thread. The protocol has no \`input.responded\`
event, so the SDK has no signal to distinguish replay from live for an
idle thread — it would add anything replayed to
\`rootStore.interrupts\`.

Adds \`StreamController.#hydratedActiveInterruptIds\`: a \`Set\`
populated
during \`hydrate()\` from \`client.threads.getState()\`'s
\`tasks[].interrupts\`. Used as a strict allowlist when processing
replayed \`input.requested\` events. \`null\` outside the hydrate window
so genuinely-new live interrupts on an active run aren't filtered;
cleared at the start of \`submit()\` for the same reason.

Also drops the unused \`subagents\` constructor param from
\`RootMessageProjection\` — it was only ever read to forward events to a
discovery instance that the controller already feeds directly, so the
param had no behavioral effect. Included here because the matching
call-site change lives in \`controller.ts\`.

## Release Note

None

---------

Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
2026-05-12 13:30:33 -07:00
Nick Hollon 2ad1aa48c6 fix(sdk): subscription plumbing — dedicated SSE streams, run.start ordering, WS pre-register (#2381)
Three subscription-lifecycle correctness fixes; all share
\`client/stream/index.ts\` and are thematically the same surface.

### 1. \`subscribeDedicated\` + dedicated SSE event stream for narrow
projections

Selector hook consumers (\`useMessages\`, \`useToolCalls\`) scoped to a
subagent namespace would otherwise widen the shared content pump's
\`(channels, namespaces)\` union and pull every channel for every active
namespace onto the wire just to satisfy a single narrow consumer. SSE
transports get a fresh \`openEventStream\`; WS falls back to the shared
command stream (no union-widening cost on WS since all events flow on
one connection).

### 2. \`run.start\` lifecycle ordering

The lifecycle watcher and the values projection both open subscriptions
on \`/threads/{id}/stream/events\`; if either lands before \`run.start\`
commits the thread server-side, the server emits a
\`404: Thread not found\` protocol error and the client waits forever
for terminal events. Reorder so \`run.start\` awaits first, then
watchers attach. Also adds \`config\` + \`metadata\` to \`respondInput\`
signature so resume submits can carry per-run configuration overrides
(the v2 server already forwards both).

### 3. Pre-register subscription under a placeholder id before sending
\`subscription.subscribe\`

The WebSocket server replays buffered events through
\`install_subscription_with_replay\` before returning the success
response that carries the \`subscription_id\` — without
pre-registration,
those replayed events arrive at \`#handleIncoming\` while no matching
subscription is registered and never reach the iterator. UI symptom:
\`useMessages\` renders empty after click-to-expand on WebSocket.

## Release Note

None

---------

Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
2026-05-12 13:02:17 -07:00
ahmed-z0 4cc6491844 fix(sdk): route subagent messages by stream event namespace (#2372)
## Summary

Fix `StreamManager` subagent message routing so `messages|...` stream
events prefer the SSE event namespace when it identifies a subagent,
falling back to `metadata.langgraph_checkpoint_ns` /
`metadata.checkpoint_ns` only when there is no subagent event namespace.

This prevents subagent message chunks from being buffered under the
wrong namespace when the event name and message metadata disagree.

## Motivation

When streaming DeepAgent subgraphs from a deployed LangGraph server, the
stream can contain events shaped like:

```text
event: messages|tools:<stream-task-id>
data: [{...}, { checkpoint_ns: "tools:<metadata-task-id>" }]
```

`updates|tools:<stream-task-id>` and `values|tools:<stream-task-id>`
establish the visible subagent using the event namespace, but the
`messages` handler currently derives the subagent id from metadata. If
the metadata namespace differs, the subagent's internal AI/tool messages
are queued under a namespace that never maps to the visible subagent, so
`getSubagentsByMessage(...)` returns the subagent without its tool-call
history.

The stream event namespace is already parsed and passed to other
subagent event handlers, so message events should use it when available.

## Tests

```bash
pnpm --filter @langchain/langgraph-sdk test -- src/ui/manager.test.ts
```

Result: 37 files passed, 512 tests passed, no type errors.
2026-05-12 12:58:09 -07:00
Nick Hollon ae8af2d75a fix(sdk): batch RootMessageProjection store writes through a macrotask (#2384)
Mirrors the \`MessageChannel\`-batching pattern that the
namespace-scoped messages projection (\`projections/messages.ts\`)
already uses, applied to the root namespace.

When a long thread replays through the \`messages\` channel — on
refresh, on resume of an in-flight run, or on a rapidly-streaming
subagent — dozens of \`messages\`-channel events can land within a
single SSE parse. They drain through the \`for await\` pump as a long
microtask chain, and calling \`store.setState\` per event fires
\`useSyncExternalStore\` notifications per event. After ~50 React's
\`nestedUpdateCount\` guard trips with "Maximum update depth exceeded"
and the UI freezes, permanently stuck at the first few messages.

\`handleMessage\` and \`applyValues\` now compute their new
\`messages\`/\`values\` synchronously (and keep mutating \`#indexById\`
and \`#valuesMessageIds\` in line so subsequent calls in the same tick
see up-to-date positions) but stage the result in
\`#pendingMessages\`/\`#pendingValues\`. A single
\`MessageChannel\`-backed \`#flushPending\` copies the staged values
onto the store in one \`setState\` call per tick.

Adds a test-only \`flushImmediately\` constructor flag so tests that
assert against the store immediately after each call don't need to
await a tick. Production wiring leaves it false.

## Release Note

None

---------

Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
2026-05-12 12:52:41 -07:00
Hunter Lovell 4fd1e9f572 fix(langgraph): source serverInfo ids from configurable first (#2376)
## Summary

Runtime now prefers `assistant_id` and `graph_id` from
`config.configurable`, which aligns with server-provided config, while
preserving metadata fallback for compatibility.

## Changes

### `@langchain/langgraph`
- Updated `libs/langgraph-core/src/pregel/index.ts` `_buildServerInfo`
to resolve `assistant_id` and `graph_id` from `config.configurable`
first, then fall back to `config.metadata`.
- Kept `langgraph_auth_user` sourcing unchanged from
`config.configurable`.
- Expanded `libs/langgraph-core/src/tests/execution_info.test.ts` to
cover:
  - configurable-based ID sourcing,
  - configurable-over-metadata precedence,
  - metadata fallback behavior,
  - existing auth-user serverInfo behavior with configurable IDs.
2026-05-12 11:59:28 -07:00
dependabot[bot] aa6deb60c7 chore(deps): bump hono from 4.12.14 to 4.12.18 (#2374)
Bumps [hono](https://github.com/honojs/hono) from 4.12.14 to 4.12.18.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/honojs/hono/releases">hono's
releases</a>.</em></p>
<blockquote>
<h2>v4.12.18</h2>
<h2>Security fixes</h2>
<p>This release includes fixes for the following security issues:</p>
<h3>Cache Middleware ignores Vary: Authorization / Vary: Cookie leading
to cross-user cache leakage</h3>
<p>Affects: Cache Middleware. Fixes missing cache-skip handling for
<code>Vary: Authorization</code> and <code>Vary: Cookie</code>, where a
response cached for one authenticated user could be served to other
users. GHSA-p77w-8qqv-26rm</p>
<h3>CSS Declaration Injection via Style Object Values in JSX SSR</h3>
<p>Affects: hono/jsx. Fixes a missing CSS-context escape for
<code>style</code> object values and property names, where untrusted
input could inject additional CSS declarations. The impact is limited to
CSS and does not allow JavaScript execution. GHSA-qp7p-654g-cw7p</p>
<h3>Improper validation of NumericDate claims (exp, nbf, iat) in JWT
verify()</h3>
<p>Affects: <code>hono/utils/jwt</code>. Fixes improper validation of
<code>exp</code>, <code>nbf</code>, and <code>iat</code> claims, where
falsy, non-finite, or non-numeric values could silently bypass
time-based checks instead of being rejected per RFC 7519.
GHSA-hm8q-7f3q-5f36</p>
<hr />
<p>Users who use the JWT helper, hono/jsx, or the Cache middleware are
strongly encouraged to upgrade to this version.</p>
<h2>v4.12.17</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(jsx): normalize SVG attributes on the <!-- raw HTML omitted -->
root element by <a
href="https://github.com/kfly8"><code>@​kfly8</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4893">honojs/hono#4893</a></li>
<li>fix(ssg): add <code>atom+xml</code> and <code>rss+xml</code> to
<code>defaultExtensionMap</code> by <a
href="https://github.com/yuintei"><code>@​yuintei</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4899">honojs/hono#4899</a></li>
<li>fix(cors): make origin optional in CORSOptions by <a
href="https://github.com/truffle-dev"><code>@​truffle-dev</code></a> in
<a
href="https://redirect.github.com/honojs/hono/pull/4905">honojs/hono#4905</a></li>
<li>fix(types): propagate middleware response types to app.on overloads
by <a href="https://github.com/T4ko0522"><code>@​T4ko0522</code></a> in
<a
href="https://redirect.github.com/honojs/hono/pull/4906">honojs/hono#4906</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/kfly8"><code>@​kfly8</code></a> made
their first contribution in <a
href="https://redirect.github.com/honojs/hono/pull/4893">honojs/hono#4893</a></li>
<li><a
href="https://github.com/truffle-dev"><code>@​truffle-dev</code></a>
made their first contribution in <a
href="https://redirect.github.com/honojs/hono/pull/4905">honojs/hono#4905</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.12.16...v4.12.17">https://github.com/honojs/hono/compare/v4.12.16...v4.12.17</a></p>
<h2>v4.12.16</h2>
<h2>Security fixes</h2>
<p>This release includes fixes for the following security issues:</p>
<h3>Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection</h3>
<p>Affects: hono/jsx. Fixes missing validation of JSX tag names when
using <code>jsx()</code> or <code>createElement()</code>, which could
allow HTML injection if untrusted input is used as the tag name.
GHSA-69xw-7hcm-h432</p>
<h3>bodyLimit() can be bypassed for chunked / unknown-length
requests</h3>
<p>Affects: Body Limit Middleware. Fixes late enforcement for request
bodies without a reliable Content-Length (e.g. chunked requests), where
oversized requests could reach handlers and return successful responses
before being rejected. GHSA-9vqf-7f2p-gf9v</p>
<h2>v4.12.15</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(jwt): support single-line PEM keys by <a
href="https://github.com/hiendv"><code>@​hiendv</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4889">honojs/hono#4889</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/honojs/hono/commit/f10dee89ced5956b73c1cdc416d6bc0fd54d63b7"><code>f10dee8</code></a>
4.12.18</li>
<li><a
href="https://github.com/honojs/hono/commit/a5bd9ebead279ed9d0239ecbd854f629edfc0e57"><code>a5bd9eb</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/58d3d3ad5656e007ed99da1b73865975952de5e9"><code>58d3d3a</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/568c2ecc1dd556894fad4dfa4a7ba499db6dba9c"><code>568c2ec</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/ff2b3d31df1be35f7d597a95dd3369402b6e87f2"><code>ff2b3d3</code></a>
4.12.17</li>
<li><a
href="https://github.com/honojs/hono/commit/52aaaf9714b06303ce5caa655b1d80675be687e9"><code>52aaaf9</code></a>
fix(types): propagate middleware response types to app.on overloads (<a
href="https://redirect.github.com/honojs/hono/issues/4906">#4906</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/76d5589e9b0569f4e74ec37e8dd6979455f70dfa"><code>76d5589</code></a>
fix(cors): make origin optional in CORSOptions (<a
href="https://redirect.github.com/honojs/hono/issues/4905">#4905</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/8f027e5574e91e3c7f263a728656e3888559e51a"><code>8f027e5</code></a>
fix(ssg): add <code>atom+xml</code> and <code>rss+xml</code> to
<code>defaultExtensionMap</code> (<a
href="https://redirect.github.com/honojs/hono/issues/4899">#4899</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/bfba97ca7ea3d4541a3419f1749e5a1a3e8f1727"><code>bfba97c</code></a>
fix(jsx): normalize SVG attributes on the &lt;svg&gt; root element (<a
href="https://redirect.github.com/honojs/hono/issues/4893">#4893</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/90d4182aabd328e2ec6af3f25ec62ddc574ad8cb"><code>90d4182</code></a>
4.12.16</li>
<li>Additional commits viewable in <a
href="https://github.com/honojs/hono/compare/v4.12.14...v4.12.18">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hono&package-manager=npm_and_yarn&previous-version=4.12.14&new-version=4.12.18)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-11 14:20:47 -07:00
github-actions[bot] f5b22a6f19 chore: version packages (#2373)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.9.2

### Patch Changes

- [#2370](https://github.com/langchain-ai/langgraphjs/pull/2370)
[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2)
Thanks [@open-swe](https://github.com/apps/open-swe)! - feat(sdk):
support metadata filter for crons search/count

- [#2377](https://github.com/langchain-ai/langgraphjs/pull/2377)
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): preserve AI content blocks during message projection

## @langchain/angular@1.0.2

### Patch Changes

- Updated dependencies
\[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2),
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]:
    -   @langchain/langgraph-sdk@1.9.2

## @langchain/react@1.0.2

### Patch Changes

- Updated dependencies
\[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2),
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]:
    -   @langchain/langgraph-sdk@1.9.2

## @langchain/svelte@1.0.2

### Patch Changes

- Updated dependencies
\[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2),
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]:
    -   @langchain/langgraph-sdk@1.9.2

## @langchain/vue@1.0.2

### Patch Changes

- Updated dependencies
\[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2),
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]:
    -   @langchain/langgraph-sdk@1.9.2

## @example/ai-elements@0.1.17

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.2

## @examples/assistant-ui-claude@0.1.17

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.2

## @examples/ui-angular@0.0.27

### Patch Changes

- Updated dependencies
\[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2),
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]:
    -   @langchain/langgraph-sdk@1.9.2
    -   @langchain/angular@1.0.2

## @examples/ui-multimodal@0.0.3

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.2

## @examples/ui-react@0.0.3

### Patch Changes

- Updated dependencies
\[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2),
[`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]:
    -   @langchain/langgraph-sdk@1.9.2
    -   @langchain/react@1.0.2

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-11 03:26:06 -07:00
Christian Bromann a5089cda1d fix(sdk): preserve AI content blocks during message projection (#2377)
While testing out more streaming examples, discovered some minor bugs
around reasoning. This patch:

- Preserve structured AI message content blocks when converting
assembled stream messages, so reasoning blocks are not collapsed into
plain text.
- Update message reconciliation to prefer finalized `values.messages`
tool-call args when they contain meaningful data missing from the
streamed message.
- Add coverage for mixed reasoning/text content blocks using the
reasoning token stream fixture.
2026-05-11 03:19:51 -07:00
open-swe[bot] 4c6875c1e3 feat(sdk): support metadata filter for crons search/count (#2370)
## Description
Mirror the langgraph-api change in
https://github.com/langchain-ai/langgraph-api/pull/3400 by accepting an
optional `metadata` filter on `crons.search` and `crons.count` in the JS
SDK. Matches the existing pattern used for assistants/threads search.

## Release Note
JS SDK: `crons.search` and `crons.count` now accept an optional
`metadata` filter that is forwarded to the server.

## Test Plan
- [ ] New unit tests in `libs/sdk/src/client/crons/index.test.ts` verify
metadata is forwarded for both `search` and `count`, and omitted when
not provided.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-05-08 14:22:11 -04:00
Christian Bromann 5e9f3cb532 docs(react): add missing v1 migration guide 2026-05-06 16:18:37 +02:00