mirror of
https://github.com/langchain-ai/langgraphjs.git
synced 2026-07-21 16:45:24 -04:00
@langchain/react@1.0.10
1752 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
381a9f64d0 |
chore: version packages (#2445)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint@1.0.3 ### Patch Changes - [#2352](https://github.com/langchain-ai/langgraphjs/pull/2352) [`14f2a79`](https://github.com/langchain-ai/langgraphjs/commit/14f2a796912e81d7f52f0a4f16747f6d0a269209) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys `MemorySaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into property accesses on the nested plain objects `this.storage` and `this.writes`. A caller able to shape any of those fields (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) could pass `"__proto__"`, `"constructor"`, or `"prototype"` and have the subsequent assignment mutate `Object.prototype`. From that point every plain object in the process inherits the injected property, breaking `for...in` loops, truthy short-circuits, and downstream serializers across unrelated code paths. CWE-1321. Adds an `assertSafeStorageKey` chokepoint applied at every public entry that touches `storage` or `writes` (`put`, `putWrites`, `deleteThread`, `getTuple`, `list`). The guard rejects non-string values, the empty string (unless explicitly opted-in for `checkpoint_ns`), and the three prototype-pollution keys. Behaviour for valid string identifiers is unchanged. ## @langchain/langgraph-checkpoint-redis@1.0.6 ### Patch Changes - [#2350](https://github.com/langchain-ai/langgraphjs/pull/2350) [`1e73c6b`](https://github.com/langchain-ai/langgraphjs/commit/1e73c6b4630bbc4aa976eea4bfc33c4f753b7ee9) Thanks [@Nagendhra-web](https://github.com/Nagendhra-web)! - fix(checkpoint-redis): block Redis KEYS / SCAN pattern injection via top-level identifiers `RedisSaver` and `ShallowRedisSaver` previously embedded `thread_id`, `checkpoint_ns`, `checkpoint_id`, and `task_id` directly into Redis keys and `client.keys(pattern)` calls with no validation. A caller able to shape any of those fields (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) could promote a string identifier into a glob pattern (`*`, `?`, `[...]`) or escape character (`\`). The most severe sink is `deleteThread`: a `threadId` of `*` issues `client.keys("checkpoint:*:*")` followed by `client.del(...)`, deleting every checkpoint in the database across every tenant. `getTuple`, `list`, and `loadPendingWrites` are exposed to the same pattern via the fallback paths that bypass the existing `escapeRediSearchTagValue` defense. Adds a single `assertSafeKeyComponent` helper exported from `./utils.js` and applies it at every key-building site. The guard asserts the value is a non-empty string (the empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`) and rejects the Redis pattern meta-characters `* ? [ ] \`. The `:` delimiter is intentionally permitted because LangGraph emits it as a legitimate part of `checkpoint_ns` for subgraphs / nested graphs, where it only ever appears as a literal in the key. Behavior for valid string identifiers is unchanged. ## @langchain/langgraph-api@1.2.3 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532)]: - @langchain/langgraph-ui@1.2.3 ## @langchain/langgraph-cli@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-api@1.2.3 ## @langchain/langgraph-ui@1.2.3 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. ## @langchain/langgraph-sdk@1.9.10 ### Patch Changes - [#2447](https://github.com/langchain-ai/langgraphjs/pull/2447) [`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: fold forkFrom client-side and honor per-run multitaskStrategy The SDK now folds the ergonomic `forkFrom` option into `config.configurable.checkpoint_id` before sending `run.start`, so the agent server only ever accepts the single, legacy-compliant fork field (`forkFrom` no longer hits the wire). The protocol-v2 reference servers drop their top-level `forkFrom` normalization accordingly. The protocol-v2 servers now honor the caller's `multitaskStrategy` per run (one of `reject` \| `rollback` \| `interrupt` \| `enqueue`) instead of hardcoding it, falling back to `enqueue` when omitted or unrecognized. - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. ## @langchain/angular@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/react@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/svelte@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @langchain/vue@1.0.10 ### Patch Changes - [#2443](https://github.com/langchain-ai/langgraphjs/pull/2443) [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532) Thanks [@christian-bromann](https://github.com/christian-bromann)! - refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom Remove the misleading submit({ command }) surface from protocol-v2 StreamController; HITL resume is respond() only. Accept forkFrom as a plain checkpoint id string and align protocol-v2 servers and docs. - [#2448](https://github.com/langchain-ai/langgraphjs/pull/2448) [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d) Thanks [@christian-bromann](https://github.com/christian-bromann)! - protocol-v2: add `respondAll()` and run config/metadata on interrupt resume The stream controller (and the React/Angular/Svelte/Vue wrappers) gain a `respondAll(responsesById, options)` method to resume several interrupts pending at the same checkpoint in a single command — required for runs that pause on multiple interrupts at once (e.g. parallel tool-authorization prompts), which sequential `respond()` calls cannot handle. `respond()` now takes an options object (`{ interruptId?, namespace?, config?, metadata? }`) so a resumed run can carry the same run-level config (model, user context, …) and metadata (trigger source, test flags, …) a fresh `submit()` would. The protocol-v2 reference servers read the new `responses` batch and `config` / `metadata` fields leniently and fold them onto the run that services the `input.respond` command. - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 ## @example/ai-elements@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/assistant-ui-claude@0.1.25 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-angular@0.0.35 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/angular@1.0.10 ## @examples/ui-multimodal@0.0.11 ### Patch Changes - Updated dependencies \[[`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/react@1.0.10 ## @examples/ui-react@0.0.11 ### Patch Changes - Updated dependencies \[[`80c2806`](https://github.com/langchain-ai/langgraphjs/commit/80c2806cb2da93745a640664bd0cf603c2361da9), [`80a8c12`](https://github.com/langchain-ai/langgraphjs/commit/80a8c1200a240fd984edc4deb26a7787d08c7532), [`2c14b12`](https://github.com/langchain-ai/langgraphjs/commit/2c14b12a80c306578563e77595943037c7c4844d)]: - @langchain/langgraph-sdk@1.9.10 - @langchain/react@1.0.10 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
4d12fe0233 | docs: more readme cleanups | ||
|
|
517500356d | docs: update readme further | ||
|
|
4c5fea793d | fix(docs): update links in readme | ||
|
|
313f060654 | fix(sdk): fix type issue in tests | ||
|
|
737b4ade89 | fix(sdk): fix lint issues | ||
|
|
ac66625c30 | fix(sdk): add browser tests for multi interrupt use case | ||
|
|
2c14b12a80 |
fix(sdk): add back respondAll and respond config/metadata (#2448)
## Summary
- Add `respondAll(responsesById, options)` to the stream controller and
the React/Angular/Svelte/Vue wrappers, resuming multiple interrupts
pending at the same checkpoint in a single `Command({ resume })`. This
is required for runs that pause on several interrupts at once (e.g.
parallel tool-authorization prompts), which sequential `respond()` calls
cannot service.
- Change `respond()` to take an options object (`{ interruptId?,
namespace?, config?, metadata? }`), folding run-level
`config`/`metadata` onto the resumed run so it applies the same
configurable values and metadata a fresh `submit()` would.
- Extend `ThreadStream.respondInput()` to accept a `responses` batch
(mutually exclusive with the single `interrupt_id`/`response`) and clear
all responded interrupts from local state.
- Update the protocol-v2 reference servers (`embed/protocol.mts`,
`protocol/service.mts`) to read the `responses` batch plus
`config`/`metadata` leniently and fold them onto the run servicing
`input.respond`.
- Update docs (interrupts/use-stream) across all framework packages and
add controller tests for batched resume.
|
||
|
|
14f2a79691 |
fix(langgraph-checkpoint): block prototype pollution in MemorySaver via reserved storage keys (#2352)
## Summary Closes a prototype-pollution sink (CWE-1321) in `MemorySaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (every quickstart, tutorial, and test fixture uses `MemorySaver` by default) can pass `\"__proto__\"`, `\"constructor\"`, or `\"prototype\"` and have the subsequent property assignment mutate `Object.prototype`. The audit posted in #2346 (cc @etairl) listed *`__proto__` prototype pollution in `MemorySaver`* among the unfiled findings from the same security-review pass that produced #2337. This PR confirms the finding and closes it across all five entry points. ## Vulnerable sinks `libs/checkpoint/src/memory.ts`: | Method | Sink | |---|---| | `put` | `this.storage[threadId][checkpointNamespace][checkpoint.id] = ...` | | `putWrites` | `this.writes[outerKey][innerKeyStr] = ...` (with caller-controlled `taskId` flowing into `innerKeyStr`) | | `deleteThread` | `delete this.storage[threadId]` | | `getTuple` | `this.storage[thread_id]?.[checkpoint_ns]?.[checkpoint_id]` | | `list` | `this.storage[threadId]?.[checkpointNamespace]` plus `Object.keys(this.storage[threadId] ?? {})` | ## Proof of concept \`\`\`ts import { MemorySaver } from \"@langchain/langgraph-checkpoint\"; const saver = new MemorySaver(); await saver.put( { configurable: { thread_id: \"__proto__\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-1\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); // Object.prototype is now polluted; every plain object in the process // inherits the injected key. const probe: Record<string, unknown> = {}; console.log(\"polluted\" in probe); // true console.log(probe[\"\"]); // the (formerly per-tenant) saved checkpoint \`\`\` Same shape works for `\"constructor\"` and `\"prototype\"`. Non-string identifiers (`{ \$ne: null }`, arrays, numbers, booleans) reach the same sinks unchecked. ## Severity Proposed CVSS 3.1: **High**. `MemorySaver` is the default in every quickstart and tutorial, and prototype pollution in Node.js is a documented stepping stone to RCE through gadget chains in downstream serializers, template engines, and dependency-resolution helpers. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single private `assertSafeStorageKey` helper in `memory.ts`, applied at every public entry that touches `storage` or `writes` (15 call sites across 5 methods). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the three prototype-pollution keys `__proto__`, `constructor`, `prototype`. * The `getTuple` and `list` read paths intentionally allow an empty or undefined `checkpoint_id` so the documented \"fetch latest\" behaviour continues to work; both paths still reject the magic keys. \`\`\`ts const POLLUTION_KEYS = new Set([\"__proto__\", \"constructor\", \"prototype\"]); function assertSafeStorageKey( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { /* type check, empty check, pollution check, all with precise diagnostics */ } \`\`\` The guard is a TypeScript `asserts` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the chokepoint pattern used in PR #2349 (`MongoDBSaver`) and PR #2350 (`RedisSaver` / `ShallowRedisSaver`). All three savers now share the same defensive posture at their boundary. * Single private function: it is impossible for a future call-site to forget validation, and the `asserts` annotation surfaces missed sites at compile time. * No new dependencies, no API changes for valid inputs, no behaviour change for any documented happy path. ## Test plan * [x] 22 new tests in `libs/checkpoint/src/tests/memory-pollution.test.ts` under `describe(\"MemorySaver prototype-pollution guard\")`, parameterised across all three pollution keys plus type / empty / accept paths for every entry point. Includes a cross-test invariant (`afterEach` snapshots `Object.getOwnPropertyNames(Object.prototype)`) that asserts pollution did not actually occur even if the guard had been absent. * [x] Existing checkpoint suite green (\`pnpm --filter @langchain/langgraph-checkpoint test\`, 93 of 93 including the 22 new ones). * [x] Lint clean (\`oxlint\`, 0 warnings, 0 errors on the changed files). * [x] Format clean (\`oxfmt --check\`). * [x] No new dependencies, no public API changes, no behaviour change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. Pairs with the two earlier sibling fixes from the same audit pass: * PR #2349 / GHSA-98xf-r82g-9mhx (MongoDB NoSQL injection) * PR #2350 / GHSA-x3wm-3wx7-g6xm (Redis KEYS / SCAN injection) --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
80c2806cb2 |
fix(sdk): fold forkFrom client-side and honor multitaskStrategy (#2447)
## Summary - Fold the SDK's top-level `forkFrom` into `config.configurable.checkpoint_id` client-side before sending `run.start`, so `forkFrom` never reaches the server and the fork target travels via the single legacy-compliant field used by the existing run endpoints. - Drop the server-side `forkFrom` normalization/promotion in both protocol-v2 reference servers (`ProtocolService.createOrResumeRun` and the embed protocol routes), reading the fork target solely from `config.configurable.checkpoint_id`. - Honor the caller's per-run `multitaskStrategy` (`reject` | `rollback` | `interrupt` | `enqueue`) instead of hardcoding `interrupt`, falling back to `enqueue` (the legacy stream-endpoint default, matching the Python protocol-v2 server) when omitted or unrecognized. |
||
|
|
1e73c6b463 |
fix(langgraph-checkpoint-redis): block KEYS / SCAN pattern injection via top-level identifiers (#2350)
## Summary Closes a Redis pattern-injection sink (CWE-77, CWE-943) in `RedisSaver` and `ShallowRedisSaver`. A caller able to shape `thread_id`, `checkpoint_ns`, `checkpoint_id`, or `task_id` (multi-tenant SDK deployments where the `RunnableConfig` originates from request input, or webhook payloads that flow into a persisted thread) can promote a string identifier into a Redis glob (`*`, `?`, `[...]`) and read, overwrite, or wipe checkpoints belonging to other tenants. The audit posted in #2346 (cc @etairl) listed *Redis key/glob injection in `RedisSaver` / `ShallowRedisSaver`* among the unfiled findings from the same security-review pass. This PR confirms the finding and extends the fix to all key-building sites in both savers. ## Vulnerable sinks `RedisSaver` (`libs/checkpoint-redis/src/index.ts`): | Method | Sinks | |---|---| | `getTuple` | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")` plus the direct \`json.get\` key | | `list` (fallback paths) | `keys(\"checkpoint:\${threadId}:\${checkpointNs}:*\")`, `keys(\"checkpoint:*:\${checkpointNs}:*\")` | | `put` | `\`checkpoint:\${threadId}:\${checkpointNs}:\${checkpointId}\`` plus the zset key | | `putWrites` | per-write key, zset key, checkpoint key | | `deleteThread` | `keys(\"checkpoint:\${threadId}:*\")`, `keys(\"writes:\${threadId}:*\")` | | `loadPendingWrites` | `keys(\"checkpoint_write:\${threadId}:\${checkpointNs}:\${checkpointId}:*\")` | `ShallowRedisSaver` (`libs/checkpoint-redis/src/shallow.ts`) has the same five public entry points plus the equivalent helper. ## Proof of concept ```ts import { createClient } from \"redis\"; import { RedisSaver } from \"@langchain/langgraph-checkpoint-redis\"; const client = createClient({ url: process.env.REDIS_URL! }); await client.connect(); const saver = new RedisSaver(client); // Tenant A and Tenant B persist checkpoints normally. await saver.put( { configurable: { thread_id: \"tenant-a\", checkpoint_ns: \"\" } }, /* checkpoint */ { id: \"cp-a\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, /* metadata */ { source: \"input\", step: 0, parents: {} } as any, {} ); await saver.put( { configurable: { thread_id: \"tenant-b\", checkpoint_ns: \"\" } }, { id: \"cp-b\", v: 4, ts: new Date().toISOString(), channel_values: {}, channel_versions: {}, versions_seen: {} } as any, { source: \"input\", step: 0, parents: {} } as any, {} ); // Attacker controls only the thread_id of their own request. // Without the guard, deleteThread expands the KEYS pattern to a glob // and deletes BOTH tenants' checkpoints. await saver.deleteThread(\"*\"); // Both \`cp-a\` and \`cp-b\` are gone. ``` The same shape (`\"*\"`, `\"tenant-?\"`, `\"tenant-[ab]\"`, `\"a\\b\"`) is accepted by every Redis pattern site in the table above. ## Severity Proposed CVSS 3.1: **High**. The most severe sink is `deleteThread`, which gives full availability impact across every tenant in the database, with confidentiality (`getTuple`, `list`) and integrity (`put`, `putWrites`) impacts on the other paths. Network-reachable, low-complexity, only the privilege the SDK already grants to a caller. ## Fix A single `assertSafeKeyComponent` helper exported from `./utils.js`, applied at every key-building site (27 calls across 2 saver files plus the helper export). The guard: * Asserts the value is a non-empty string (the documented empty `checkpoint_ns` default is opt-in via `{ allowEmpty: true }`). * Rejects the Redis pattern meta-characters `* ? [ ] \`. * Rejects the `:` delimiter that would otherwise corrupt the colon-delimited key structure. \`\`\`ts export function assertSafeKeyComponent( field: string, value: unknown, options: { allowEmpty?: boolean } = {} ): asserts value is string { const { allowEmpty = false } = options; if (typeof value !== \"string\") { /* precise diagnostic */ throw ... } if (!allowEmpty && value === \"\") { throw ... } if (REDIS_KEY_FORBIDDEN.test(value)) { throw ... } } \`\`\` The guard is a TypeScript \`asserts\` predicate so call-sites get type narrowing for free and the compiler enforces that no later code path uses an unvalidated identifier. ## Why this design * Mirrors the maintainers' existing primitive-only pattern (\`escapeRediSearchTagValue\`) in the same file. * Single chokepoint: it is impossible for a future call-site to forget validation. * No new dependencies, no API changes for valid inputs, no behavior change for any documented happy path. * Pairs with PR #2349 (NoSQL injection in MongoDBSaver) so both backends now share the same defensive posture at the saver boundary. ## Test plan * [x] 11 new tests under \`describe(\"assertSafeKeyComponent\")\` in \`libs/checkpoint-redis/src/tests/utils.test.ts\` covering accept and reject paths for every input shape (normal string, empty with and without \`allowEmpty\`, every Redis meta-character, colon delimiter, every wrong type). * [x] Existing \`escapeRediSearchTagValue\` suite still green (regression). * [x] Full suite green (\`pnpm --filter @langchain/langgraph-checkpoint-redis test\`, 21 of 21). * [x] Format clean on all 4 changed files (\`oxfmt\`). * [x] No new dependencies, no public API changes, no behavior change for valid string identifiers. ## Disclosure Original finding credited to @etairl (audit posted in #2346). This PR was prepared for coordinated public disclosure since the audit list is already public. Happy to coordinate timing with a private GHSA if the maintainers prefer. --------- Co-authored-by: Nagendhra <nagendhra405@gmail.com> Co-authored-by: Christian Bromann <git@bromann.dev> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
80a8c1200a |
refactor(sdk): drop StreamSubmitOptions.command and simplify forkFrom (#2443)
## Summary
- Remove `command` from `StreamSubmitOptions` and the
`submit-coordinator` resume-via-`submit` path so HITL resume goes
through `stream.respond()` only.
- Simplify `forkFrom` from `{ checkpointId: string }` to a plain
checkpoint id string across the SDK, protocol-v2 services, and docs.
- Update interrupt tests, examples (`HumanInTheLoopView`, branching
views), and React/Vue/Svelte/Angular JSDoc and migration/interrupt docs
to match.
|
||
|
|
2f0010e3a5 |
chore: version packages (#2442)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.9 ### Patch Changes - [#2441](https://github.com/langchain-ai/langgraphjs/pull/2441) [`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): preserve apiUrl path prefix in stream transport URLs Use BaseClient-style URL concatenation in `toAbsoluteUrl` so SSE and WebSocket subscriptions work when the SDK is pointed at a proxied apiUrl with a path prefix (e.g. `/api/chat-langchain`). ## @langchain/angular@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/react@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/svelte@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @langchain/vue@1.0.9 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 ## @example/ai-elements@0.1.24 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/assistant-ui-claude@0.1.24 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/ui-angular@0.0.34 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 - @langchain/angular@1.0.9 ## @examples/ui-multimodal@0.0.10 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.9 ## @examples/ui-react@0.0.10 ### Patch Changes - Updated dependencies \[[`dbbcb63`](https://github.com/langchain-ai/langgraphjs/commit/dbbcb636e742c38e89854a8ae7ef4e1566d44343)]: - @langchain/langgraph-sdk@1.9.9 - @langchain/react@1.0.9 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
dbbcb636e7 |
fix(sdk): preserve apiUrl path prefix in stream transport URLs (#2441)
## Summary - Fix `toAbsoluteUrl` to concatenate `apiUrl` and path instead of using `new URL(path, base)`, which dropped path prefixes on proxied deployments. - Route WebSocket stream URL construction through `toAbsoluteUrl` for consistency with SSE transport. - Add unit and integration tests for proxied apiUrl paths, plus shared transport test helpers. |
||
|
|
4e71ace65a |
chore: version packages (#2439)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. ## @langchain/angular@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/react@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/svelte@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @langchain/vue@1.0.8 ### Patch Changes - [#2438](https://github.com/langchain-ai/langgraphjs/pull/2438) [`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): cancel runs on stop by default and add disconnect() `stream.stop()` now calls `client.runs.cancel` for the active run before disconnecting the client (default `{ cancel: true }`). Join/rejoin UIs can call `stream.disconnect()` or `stop({ cancel: false })` to leave the agent running server-side. This fills a missing gap we found when migrating to v1. - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 ## @example/ai-elements@0.1.23 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/assistant-ui-claude@0.1.23 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/ui-angular@0.0.33 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 - @langchain/angular@1.0.8 ## @examples/ui-multimodal@0.0.9 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/react@1.0.8 ## @examples/ui-react@0.0.9 ### Patch Changes - Updated dependencies \[[`29d2bde`](https://github.com/langchain-ai/langgraphjs/commit/29d2bde235bf85e8a5e1dd59a997266ff894484b)]: - @langchain/langgraph-sdk@1.9.8 - @langchain/react@1.0.8 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
29d2bde235 |
fix(sdk): cancel runs on stop by default and add disconnect() (#2438)
## Summary
- `stream.stop()` now cancels the active run server-side by default
(`client.runs.cancel`) before disconnecting the client transport.
- Added `stream.disconnect()` as an alias for `stop({ cancel: false })`
for join/rejoin UIs.
- Introduced `StreamStopOptions` (`{ cancel?: boolean }`) on
`StreamController` and all v1 framework bindings (React, Vue, Svelte,
Angular).
- Updated `use-stream.md` and added controller unit tests for
cancel-on-stop and no-cancel-on-disconnect.
|
||
|
|
39ce52f248 |
chore: version packages (#2436)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - [#2434](https://github.com/langchain-ai/langgraphjs/pull/2434) [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671) Thanks [@hntrl](https://github.com/hntrl)! - fix(react): avoid eager stream getter evaluation during object spread Mark optional `useStream` accessors as non-enumerable so object spread/rest destructuring does not accidentally read guarded fields like `history` or opt into additional stream modes. ## @langchain/angular@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/react@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/svelte@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @langchain/vue@1.0.7 ### Patch Changes - [#2435](https://github.com/langchain-ai/langgraphjs/pull/2435) [`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): unwrap Command tool outputs and hide scoped task tools Filter wrapper `task` dispatch events from subagent-scoped tool-call projections and parse embedded ToolMessage results from LangGraph `Command` payloads on `tool-finished`. - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 ## @example/ai-elements@0.1.22 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/assistant-ui-claude@0.1.22 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/ui-angular@0.0.32 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 - @langchain/angular@1.0.7 ## @examples/ui-multimodal@0.0.8 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e)]: - @langchain/react@1.0.7 ## @examples/ui-react@0.0.8 ### Patch Changes - Updated dependencies \[[`cfc8d27`](https://github.com/langchain-ai/langgraphjs/commit/cfc8d274e4dc99cb73ebd9abc4f971622105f08e), [`6b188e8`](https://github.com/langchain-ai/langgraphjs/commit/6b188e80ab989fc8396e1926f729d93b786ca671)]: - @langchain/langgraph-sdk@1.9.7 - @langchain/react@1.0.7 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
6b188e80ab |
fix(sdk): avoid eager stream getter evaluation (#2434)
## Summary fix(sdk): avoid eager stream getter evaluation during spread This fixes a React `useStream` development-mode failure where passing the stream handle through components that clone or rest-spread props could accidentally read lazy getters. The guarded `history` getter still throws when explicitly accessed with `fetchStateHistory: false`, but object spread no longer trips that path or widens `streamMode` by touching optional accessors. ## Changes `@langchain/langgraph-sdk` - Marks optional `useStream` accessors (`history`, `experimental_branchTree`, `toolProgress`, `subagents`, `activeSubagents`) as non-enumerable on the returned stream handle. - Preserves explicit access behavior for those accessors, including the existing `history` guard and stream mode opt-in for `toolProgress`/`subagents`. - Adds React hook regression coverage for object spread, explicit getter access, and stream mode inference. |
||
|
|
cfc8d274e4 |
fix(sdk): unwrap Command tool outputs and hide scoped task tools (#2435)
## Summary - Filter scoped deep-agent `task` dispatch events out of `sub.toolCalls` so subagent tool streams only show real worker tools. - Unwrap LangGraph `Command` payloads in `parseToolOutput` when they carry an embedded `ToolMessage`, so `tc.output` resolves to the actual tool result instead of raw graph state. - Share the scoped-task filter between client subagent handles and framework tool-call projections. |
||
|
|
9c9da48ae2 |
chore: version packages (#2433)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. ## @langchain/angular@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/react@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/svelte@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @langchain/vue@1.0.6 ### Patch Changes - [#2430](https://github.com/langchain-ai/langgraphjs/pull/2430) [`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): clear subgraph and subagent discovery on thread swap Reset discovery stores in `StreamController.#teardownThread()` so starting a new thread does not leave stale subgraph cards or subagent entries from the previous run. - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 ## @example/ai-elements@0.1.21 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/assistant-ui-claude@0.1.21 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/ui-angular@0.0.31 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 - @langchain/angular@1.0.6 ## @examples/ui-multimodal@0.0.7 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/react@1.0.6 ## @examples/ui-react@0.0.7 ### Patch Changes - Updated dependencies \[[`f99941f`](https://github.com/langchain-ai/langgraphjs/commit/f99941f5fe8671ddcb6a78e93e5e05f4028d4af4)]: - @langchain/langgraph-sdk@1.9.6 - @langchain/react@1.0.6 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
f99941f5fe |
fix(sdk): clear subgraph and subagent discovery on thread swap (#2430)
## Summary - Add `reset()` to `SubgraphDiscovery` and `SubagentDiscovery` to clear internal maps and committed store snapshots. - Call both resets from `StreamController.#teardownThread()` alongside existing per-thread resets (messages, tools, metadata). - Add unit tests for discovery `reset()` and a controller test that `hydrate(null)` clears subgraphs after lifecycle events. |
||
|
|
7788dceb85 |
chore: version packages (#2424)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-redis@1.0.5 ### Patch Changes - [#2208](https://github.com/langchain-ai/langgraphjs/pull/2208) [`ebeb145`](https://github.com/langchain-ai/langgraphjs/commit/ebeb1452d27fcca100cd63bdfd4a7f020949412c) Thanks [@jackjin1997](https://github.com/jackjin1997)! - Fix `deleteThread()` using wrong key pattern (`writes:` instead of `checkpoint_write:`) and add missing cleanup of `write_keys_zset:` entries. ## @langchain/langgraph-supervisor@1.0.3 ### Patch Changes - [#2317](https://github.com/langchain-ai/langgraphjs/pull/2317) [`c088c76`](https://github.com/langchain-ai/langgraphjs/commit/c088c7659c18edf26091813ff384f48f5335bef6) Thanks [@fish895623](https://github.com/fish895623)! - feat(supervisor): widen agents type to accept createAgent graphs ## @langchain/langgraph-sdk@1.9.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. ## @langchain/angular@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/react@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/svelte@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @langchain/vue@1.0.5 ### Patch Changes - [#2421](https://github.com/langchain-ai/langgraphjs/pull/2421) [`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(stream): align AssembledToolCall typing with pre-v1 expectations Make `InferToolCalls` resolve to generic `AssembledToolCall` unions, expose sync `status`/`error` for reactive bindings, and align type tests across React, Vue, Svelte, and Angular SDK packages. - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 ## @example/ai-elements@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/assistant-ui-claude@0.1.20 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-angular@0.0.30 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/angular@1.0.5 ## @examples/ui-multimodal@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/react@1.0.5 ## @examples/ui-react@0.0.6 ### Patch Changes - Updated dependencies \[[`3529e38`](https://github.com/langchain-ai/langgraphjs/commit/3529e3831a488134e7dfaefa4ed7fb1140cf8bb6)]: - @langchain/langgraph-sdk@1.9.5 - @langchain/react@1.0.5 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
b1d307ab84 |
ci(infra): run framework browser tests only when paths change (#2425)
## Summary - Add a `detect-changes` job to the browser test workflow using `dorny/paths-filter@v3.0.2`. - Run all four framework browser jobs when `libs/sdk/**` changes or when this workflow file changes. - Run only the matching job when `libs/sdk-react`, `libs/sdk-angular`, `libs/sdk-vue`, or `libs/sdk-svelte` changes. - Keep the full matrix on `workflow_dispatch` (manual runs and CI dispatched via workflow_dispatch). |
||
|
|
674173b8ac |
chore(deps-dev): bump turbo from 2.8.15 to 2.9.14 (#2428)
Bumps [turbo](https://github.com/vercel/turborepo) from 2.8.15 to 2.9.14. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vercel/turborepo/releases">turbo's releases</a>.</em></p> <blockquote> <h2>Turborepo v2.9.14</h2> <blockquote> <p>[!NOTE] This release contains important security fixes.</p> </blockquote> <h3>High:</h3> <ul> <li><a href="https://github.com/vercel/turborepo/security/advisories/GHSA-5xc8-49mv-x4mm">GHSA-5xc8-49mv-x4mm: Turborepo VSCode Extension command injection</a></li> </ul> <h3>Low:</h3> <ul> <li><a href="https://github.com/vercel/turborepo/security/advisories/GHSA-hcf7-66rw-9f5r">GHSA-hcf7-66rw-9f5r: Login callback CSRF/session fixation</a></li> <li><a href="https://github.com/vercel/turborepo/security/advisories/GHSA-3qcw-2rhx-2726">GHSA-3qcw-2rhx-2726: Unexpected local code execution during Yarn Berry detection</a></li> </ul> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Changelog</h3> <ul> <li>release(turborepo): 2.9.12 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li> <li>fix: Restore docs mobile menu by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li> <li>ci: Use <code>pull_request</code> for PR title linting by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li> <li>ci: Scope GitHub Actions caches by branch by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li> <li>test: Validate lockfiles without dependency downloads by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li> <li>Removed unneeded import form hash creation script in docs by <a href="https://github.com/dancrumb"><code>@dancrumb</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li> <li>fix: Validate auth callback state by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li> <li>fix: Harden VS Code extension command execution by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li> <li>fix: Avoid project-local Yarn during detection by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li> <li>chore: Release 2.9.13 by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12803">vercel/turborepo#12803</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/dancrumb"><code>@dancrumb</code></a> made their first contribution in <a href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14">https://github.com/vercel/turborepo/compare/v2.9.12...v2.9.14</a></p> <h2>Turborepo v2.9.13-canary.1</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Changelog</h3> <ul> <li>release(turborepo): 2.9.11-canary.7 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12768">vercel/turborepo#12768</a></li> <li>fix: Allow <code>$TURBO_EXTENDS$</code> in LSP diagnostics by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12770">vercel/turborepo#12770</a></li> <li>release(turborepo): 2.9.11 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12771">vercel/turborepo#12771</a></li> <li>fix: Allow transit nodes in LSP diagnostics by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12773">vercel/turborepo#12773</a></li> <li>release(turborepo): 2.9.12 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/12774">vercel/turborepo#12774</a></li> <li>fix: Restore docs mobile menu by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12782">vercel/turborepo#12782</a></li> <li>ci: Use <code>pull_request</code> for PR title linting by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12787">vercel/turborepo#12787</a></li> <li>ci: Scope GitHub Actions caches by branch by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12788">vercel/turborepo#12788</a></li> <li>test: Validate lockfiles without dependency downloads by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12789">vercel/turborepo#12789</a></li> <li>Removed unneeded import form hash creation script in docs by <a href="https://github.com/dancrumb"><code>@dancrumb</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12799">vercel/turborepo#12799</a></li> <li>fix: Validate auth callback state by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12802">vercel/turborepo#12802</a></li> <li>fix: Harden VS Code extension command execution by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12800">vercel/turborepo#12800</a></li> <li>fix: Avoid project-local Yarn during detection by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/12801">vercel/turborepo#12801</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vercel/turborepo/commit/fc62fe0d9c347d1d24f0ed8946284856593ddb93"><code>fc62fe0</code></a> publish 2.9.14 to registry</li> <li><a href="https://github.com/vercel/turborepo/commit/fb8c9aec0f9e83f95783659a5ce9c4478cf62cb9"><code>fb8c9ae</code></a> chore: Release 2.9.13 (<a href="https://redirect.github.com/vercel/turborepo/issues/12803">#12803</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/e8e629da4e1fb75231089e91b19be9d327a3e649"><code>e8e629d</code></a> fix: Avoid project-local Yarn during detection (<a href="https://redirect.github.com/vercel/turborepo/issues/12801">#12801</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/91c90cbf12f524c5c29b713d6472dd5fcdecb309"><code>91c90cb</code></a> fix: Harden VS Code extension command execution (<a href="https://redirect.github.com/vercel/turborepo/issues/12800">#12800</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/84f450894e87da1eed864d51f6f637f26980d560"><code>84f4508</code></a> fix: Validate auth callback state (<a href="https://redirect.github.com/vercel/turborepo/issues/12802">#12802</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/1779ad7901384f106236a6e196059e4929745514"><code>1779ad7</code></a> Removed unneeded import form hash creation script in docs (<a href="https://redirect.github.com/vercel/turborepo/issues/12799">#12799</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/71f8c90a807ffb9b9876ea8a04f523f473bf5c8d"><code>71f8c90</code></a> test: Validate lockfiles without dependency downloads (<a href="https://redirect.github.com/vercel/turborepo/issues/12789">#12789</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/5fcb96024d503127bb0ed760ebe159b7716c52b3"><code>5fcb960</code></a> ci: Scope GitHub Actions caches by branch (<a href="https://redirect.github.com/vercel/turborepo/issues/12788">#12788</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/4cf9fabc9a6f6c99fe4e2f2da9f35be631be062a"><code>4cf9fab</code></a> ci: Use <code>pull_request</code> for PR title linting (<a href="https://redirect.github.com/vercel/turborepo/issues/12787">#12787</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/859c629bc401f239ac7980a132746ca90478e17c"><code>859c629</code></a> fix: Restore docs mobile menu (<a href="https://redirect.github.com/vercel/turborepo/issues/12782">#12782</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vercel/turborepo/compare/v2.8.15...v2.9.14">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraphjs/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
c088c7659c |
feat(supervisor): widen agents type to accept createAgent graphs (#2317)
## Summary - Add a broader `CompiledStateGraph<any, any, string, any, any>` to the `agents` union in `CreateSupervisorParams` - Graphs produced by `createAgent` from `langchain` (via `.graph`) are now accepted alongside existing `createReactAgent` graphs and `RemoteGraph` - The original `AnnotationRootT`-parameterized `CompiledStateGraph` type is preserved for backward compatibility ## Motivation The new `createAgent` API in the `langchain` package returns a `ReactAgent` whose `.graph` property is a `CompiledStateGraph` with a different state schema (`BuiltInState`) than the `MessagesAnnotation`-based state from `createReactAgent`. Since `createReactAgent` is deprecated in favor of `createAgent`, `createSupervisor` needs to accept both graph types. At runtime this already works — `makeCallAgent` types its `agent` parameter as `any` and only accesses `.name`, `.invoke()`, and optionally `.description`. The type constraint on the `agents` parameter was simply too narrow for the new API. ## Changes ### `@langchain/langgraph-supervisor` (`libs/langgraph-supervisor`) - Updated `CreateSupervisorParams.agents` type to include `CompiledStateGraph<any, any, string, any, any>` in the union alongside the existing strictly-typed `CompiledStateGraph` and `RemoteGraph` ## Test plan - [x] `pnpm build` passes for `@langchain/langgraph-supervisor` - [x] Consuming project using `createAgent` + `createSupervisor` compiles without errors - [x] Existing supervisor tests still pass --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
ebeb1452d2 |
fix(langgraph-checkpoint-redis): fix deleteThread using wrong key pattern for writes (#2208)
## Summary Fixes #2207 - Fix `deleteThread()` using incorrect `writes:` prefix instead of `checkpoint_write:` for write key deletion - Add missing cleanup of `write_keys_zset:` entries, matching the correct implementation in `ShallowRedisSaver` The bug was found by comparing `RedisSaver.deleteThread()` with `ShallowRedisSaver.deleteThread()` in `shallow.ts`, which correctly uses `checkpoint_write:` prefix and also cleans up zset keys. ## AI Disclosure This bug was identified through code review with AI assistance. The fix aligns the standard `RedisSaver` implementation with the existing correct `ShallowRedisSaver` implementation. --------- Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
3529e3831a |
fix(sdk): align AssembledToolCall typing with pre-v1 expectations (#2421)
## Summary - Split tool-call handles by consumer: - **Client SDK** (`ThreadStream.toolCalls`, subgraph/subagent projections): `ClientAssembledToolCall` with a promise-only `output` (resolves on success, rejects on error). Still exported as `AssembledToolCall` from `@langchain/langgraph-sdk/client` for script usage. - **Framework SDKs** (`stream.toolCalls`, `useToolCalls`, `injectToolCalls`): `AssembledToolCall` with plain reactive fields — `output: T | null`, `status`, and `error` — updated in place as events arrive so React/Vue/Svelte/Angular can render from snapshots without `await`, effects, or Suspense around promises. - Add generic `AssembledToolCall<TName, TInput, TOutput>` plus `id`/`args` aliases; point `InferToolCalls` at assembled streaming handles and add `AssembledToolCallFromTool` (exported as `ToolCallFromTool` from `@langchain/react`, `@langchain/vue`, `@langchain/svelte`, and `@langchain/angular`). - Rework `ToolCallAssembler` around a mutable internal handle and `toClientAssembledToolCall()` for client projections; framework stores the reactive handle directly. - Remove redundant `InferAssembledToolCalls` and deprecated `StateOf`; wire typed `toolCalls` / selector generics across all four framework packages. - Expand and align `createAgent`, `createDeepAgent`, and `langgraph` type tests across React, Vue, Svelte, and Angular; update examples, protocol-v2 integration tests, and Vue migration docs. |
||
|
|
4a7d9a7c5d |
chore: version packages (#2416)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph@1.3.2 ### Patch Changes - [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415) [`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - Move `@langchain/core` from a runtime dependency back to a required peer dependency so installing the SDK alone no longer pulls in `@langchain/core` (and `js-tiktoken`, etc.). Consumers that use streaming or message coercion must install `@langchain/core` explicitly or via `@langchain/langgraph`. - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/langgraph-sdk@1.9.4 ### Patch Changes - [#2415](https://github.com/langchain-ai/langgraphjs/pull/2415) [`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4) Thanks [@christian-bromann](https://github.com/christian-bromann)! - Move `@langchain/core` from a runtime dependency back to a required peer dependency so installing the SDK alone no longer pulls in `@langchain/core` (and `js-tiktoken`, etc.). Consumers that use streaming or message coercion must install `@langchain/core` explicitly or via `@langchain/langgraph`. ## @langchain/angular@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/react@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/svelte@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @langchain/vue@1.0.4 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 ## @example/ai-elements@0.1.19 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/assistant-ui-claude@0.1.19 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/ui-angular@0.0.29 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 - @langchain/langgraph@1.3.2 - @langchain/angular@1.0.4 ## @examples/ui-multimodal@0.0.5 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## @examples/ui-react@0.0.5 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph-sdk@1.9.4 - @langchain/langgraph@1.3.2 - @langchain/react@1.0.4 ## langgraph@1.0.34 ### Patch Changes - Updated dependencies \[[`9d3c9dd`](https://github.com/langchain-ai/langgraphjs/commit/9d3c9dd3182059f9eca9fd9b14d8f7466b4338c4)]: - @langchain/langgraph@1.3.2 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
9d3c9dd318 |
fix(core): move @langchain/core back into being a peer dep (#2415)
`@langchain/langgraph-sdk@1.9.0` promoted `@langchain/core` from a dev dependency to a **runtime dependency**, which caused install-size metrics for `@langchain/langgraph` to jump from ~6 MB to ~40 MB for consumers who did not already have core installed (or who use `--legacy-peer-deps`). That happened because core pulls in heavy transitive deps such as `js-tiktoken` (~21 MB) and `zod` (~6 MB), even though `@langchain/langgraph` already lists core as a peer. This PR moves `@langchain/core` back to a **required peer dependency** on the SDK, matching `@langchain/langgraph` and the pre-1.9.0 SDK layout. Runtime behavior is unchanged for typical LangGraph apps that already install core; SDK-only installs no longer force core into the tree. Also switches `LangChainTracer` in `types.ts` to a type-only import so the tracer subpath is not pulled as a value import. |
||
|
|
1b5ce0fca0 |
chore: version packages (#2405)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-checkpoint-mongodb@1.3.1 ### Patch Changes - [#2397](https://github.com/langchain-ai/langgraphjs/pull/2397) [`284226c`](https://github.com/langchain-ai/langgraphjs/commit/284226c7ca164b3c81fe2d9e32b10f1fc6b99a3c) Thanks [@hntrl](https://github.com/hntrl)! - fix(checkpoint-mongodb): validate configurable checkpoint identifiers before queries Add runtime validation for `thread_id`, `checkpoint_ns`, and `checkpoint_id` in `MongoDBSaver` methods that read and write checkpoints. This prevents object-based operator payloads from being passed into MongoDB query filters and ensures invalid configurable values fail fast with explicit errors. ## @langchain/langgraph-api@1.2.2 ### Patch Changes - [#2396](https://github.com/langchain-ai/langgraphjs/pull/2396) [`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph-cli): accept hyphenated prerelease tags in `api_version` values. - Updated dependencies \[]: - @langchain/langgraph-ui@1.2.2 ## @langchain/langgraph-cli@1.2.2 ### Patch Changes - [#2389](https://github.com/langchain-ai/langgraphjs/pull/2389) [`40bcdab`](https://github.com/langchain-ai/langgraphjs/commit/40bcdab38fa495028d8eba68062e48079dbe9208) Thanks [@jdrogers940](https://github.com/jdrogers940)! - Adding support for pre-release versions in api_version. - [#2396](https://github.com/langchain-ai/langgraphjs/pull/2396) [`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph-cli): accept hyphenated prerelease tags in `api_version` values. - Updated dependencies \[[`9b20df0`](https://github.com/langchain-ai/langgraphjs/commit/9b20df081a82b79efca3dfd2c128243889b11eb8)]: - @langchain/langgraph-api@1.2.2 ## @langchain/langgraph@1.3.1 ### Patch Changes - [#2339](https://github.com/langchain-ai/langgraphjs/pull/2339) [`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f) Thanks [@vigneshpatel14](https://github.com/vigneshpatel14)! - fix(langgraph): surface structuredResponse parse failures in createReactAgent - [#2406](https://github.com/langchain-ai/langgraphjs/pull/2406) [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(langgraph-core): keep tool results out of v3 message streams - [#2376](https://github.com/langchain-ai/langgraphjs/pull/2376) [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph): prefer configurable assistant and graph IDs for runtime server info Update runtime `serverInfo` construction to read `assistant_id` and `graph_id` from `config.configurable` first, with fallback to `config.metadata` for compatibility. Also expands `execution_info` tests to cover configurable sourcing, precedence, and metadata fallback behavior. - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/langgraph-sdk@1.9.3 ### Patch Changes - [#2387](https://github.com/langchain-ai/langgraphjs/pull/2387) [`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Coalesce `RootMessageProjection` store writes through a single `setTimeout(0)` flush so long `messages`-channel replays (on refresh, mid-run join, or rapid subagent streaming) no longer drain as a per-event microtask chain that trips React's `Maximum update depth exceeded` guard. Replaces the previous `MessageChannel`-based batching, which deferred initial-submit events past the first render and left the UI looking frozen until refresh. - [#2372](https://github.com/langchain-ai/langgraphjs/pull/2372) [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7) Thanks [@ahmed-z0](https://github.com/ahmed-z0)! - Fix subagent message routing to prefer the stream event namespace over checkpoint metadata when filtering subagent messages. - [#2384](https://github.com/langchain-ai/langgraphjs/pull/2384) [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - batch RootMessageProjection store writes through a macrotask - [#2388](https://github.com/langchain-ai/langgraphjs/pull/2388) [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c) Thanks [@hntrl](https://github.com/hntrl)! - fix(sdk): retry connection failures before throwing ConnectionError - [#2381](https://github.com/langchain-ai/langgraphjs/pull/2381) [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - fix(sdk): forward config + metadata on respondInput for resume submits - [#2379](https://github.com/langchain-ai/langgraphjs/pull/2379) [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - filter SSE-replayed input.requested events through a hydrated interrupt allowlist - [#2390](https://github.com/langchain-ai/langgraphjs/pull/2390) [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Bind deepagents subagent discovery to the execution namespace via taskInput so `useMessages(stream, subagent)` resolves the streaming scope instead of the trigger tool-call namespace. ## @langchain/angular@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/react@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/svelte@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/vue@1.0.3 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 ## @langchain/langgraph-cua@1.0.2 ## @langchain/langgraph-supervisor@1.0.2 ## @langchain/langgraph-swarm@1.0.2 ## @langchain/langgraph-ui@1.2.2 ## @example/ai-elements@0.1.18 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## @examples/assistant-ui-claude@0.1.18 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## @examples/ui-angular@0.0.28 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 - @langchain/langgraph@1.3.1 - @langchain/angular@1.0.3 ## @examples/ui-multimodal@0.0.4 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## @examples/ui-react@0.0.4 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`01dd046`](https://github.com/langchain-ai/langgraphjs/commit/01dd0462ed300dee5a9a51f229e6c401315f070c), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3 - @langchain/langgraph@1.3.1 - @langchain/react@1.0.3 ## langgraph@1.0.33 ### Patch Changes - Updated dependencies \[[`2b88da4`](https://github.com/langchain-ai/langgraphjs/commit/2b88da497b2c6f8fbf8f4d901578a198824eb32f), [`e54ae90`](https://github.com/langchain-ai/langgraphjs/commit/e54ae901e119ccf81653b90d5a0db2485027a5a9), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1 ## docs@null # docs ## null ## null --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
284226c7ca |
fix(langgraph-checkpoint-mongodb): validate configurable checkpoint IDs (#2397)
## Summary Fixes #2351 This change hardens `@langchain/langgraph-checkpoint-mongodb` against object-based configurable input in checkpoint identifiers. It adds runtime validation for `thread_id`, `checkpoint_ns`, and `checkpoint_id` before any MongoDB query/write path uses these values, so operator-like payloads are rejected early with explicit errors. ## Changes ### `@langchain/langgraph-checkpoint-mongodb` - Added a shared `getStringConfigValue` runtime validator in [`libs/checkpoint-mongodb/src/checkpoint.ts`](libs/checkpoint-mongodb/src/checkpoint.ts). - Applied validation to `getTuple`, `list`, `put`, `putWrites`, and `deleteThread`. - Preserved existing behavior where `getTuple` returns `undefined` when `thread_id` is missing, while now rejecting non-string values. - Added regression tests in [`libs/checkpoint-mongodb/src/tests/checkpoints.test.ts`](libs/checkpoint-mongodb/src/tests/checkpoints.test.ts) for object/operator payloads across the affected methods. - Added a patch changeset for `@langchain/langgraph-checkpoint-mongodb`. Co-authored-by: Itay <9601971+etairl@users.noreply.github.com> |
||
|
|
e54ae901e1 |
fix(core): keep tool results out of v3 message streams (#2406)
## Summary - Prevent v3 `run.messages` from surfacing `ToolMessage` outputs as assistant text. - Skip tool-role message lifecycles in the messages transformer while preserving tool messages in state snapshots. - Add regression coverage for tool-result message leakage. fixes https://github.com/langchain-ai/deepagentsjs/issues/534 |
||
|
|
01dd0462ed |
fix(sdk): retry connection failures before throwing ConnectionError (#2388)
## Summary This change updates SDK retry behavior so connection-related failures are retried instead of immediately aborting inside `onFailedAttempt`. When retries are exhausted, the final surfaced error is still coalesced to a `ConnectionError` with the existing LangGraph-specific guidance. A focused unit test was added to lock in this behavior. ## Changes ### @langchain/langgraph-sdk - Updated `AsyncCaller` connection-error handling to only throw `ConnectionError` on the final failed attempt (`retriesLeft === 0`), while allowing retries on earlier attempts. - Added a regression test covering retry count plus final `ConnectionError` coalescing for connection-refused/fetch-failed style errors. - Added a patch changeset for `@langchain/langgraph-sdk` documenting the retry/coalescing fix. |
||
|
|
2b88da497b |
fix(langgraph): surface structuredResponse parse failures in createReactAgent (#2339)
Closes Issue #2338 ## Problem When `createReactAgent` is called with `responseFormat`, the `generate_structured_response` node calls `model.withStructuredOutput(schema).invoke(...)`. Some parsers return `null`/`undefined` (instead of throwing) when the LLM produces JSON that is syntactically valid but does not satisfy the schema (e.g. a missing required field). The result was unconditionally assigned to the `structuredResponse` channel, so the agent silently resolved with `structuredResponse: undefined` — no error, no warning, no log. ## Fix Detect the `null`/`undefined` case in `generate_structured_response` and throw a descriptive error stating that the structured-output parser returned null/undefined and the model output did not satisfy the schema. This converts the silent failure into an explicit, debuggable error. The error does not include the raw model completion. The existing call shape (`withStructuredOutput(schema, options).invoke(...)`) returns only the parsed value. Switching to `{ includeRaw: true }` would surface the completion but (a) overrides any caller-supplied `includeRaw` in the existing options object and (b) relies on every chat-model implementation honoring `includeRaw` consistently, so it's left as a possible follow-up. ## Test Added `Throws when structured output parser returns null` in `libs/langgraph-core/src/tests/prebuilt.test.ts`. It spies on `withStructuredOutput` to return `null` (simulating the silent failure) and asserts the agent rejects with the new error message. The test runs inside the existing `describe.each([["v1"], ["v2"]])` block, so both agent versions are covered. --------- Co-authored-by: Voddam Vignesh <vignesh.voddam@gep.com> Co-authored-by: Christian Bromann <git@bromann.dev> |
||
|
|
22c4541b53 |
chore: version packages (rc) (#2385)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. ⚠️⚠️⚠️⚠️⚠️⚠️ `main` is currently in **pre mode** so this branch has prereleases rather than normal releases. If you want to exit prereleases, run `changeset pre exit` on `main`. ⚠️⚠️⚠️⚠️⚠️⚠️ # Releases ## @langchain/langgraph-api@1.2.2-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 - @langchain/langgraph@1.3.1-rc.0 - @langchain/langgraph-ui@1.2.2-rc.0 ## @langchain/langgraph-cli@1.2.2-rc.0 ### Patch Changes - [#2389](https://github.com/langchain-ai/langgraphjs/pull/2389) [`40bcdab`](https://github.com/langchain-ai/langgraphjs/commit/40bcdab38fa495028d8eba68062e48079dbe9208) Thanks [@jdrogers940](https://github.com/jdrogers940)! - Adding support for pre-release versions in api_version. - Updated dependencies \[]: - @langchain/langgraph-api@1.2.2-rc.0 ## @langchain/langgraph@1.3.1-rc.0 ### Patch Changes - [#2376](https://github.com/langchain-ai/langgraphjs/pull/2376) [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280) Thanks [@hntrl](https://github.com/hntrl)! - fix(langgraph): prefer configurable assistant and graph IDs for runtime server info Update runtime `serverInfo` construction to read `assistant_id` and `graph_id` from `config.configurable` first, with fallback to `config.metadata` for compatibility. Also expands `execution_info` tests to cover configurable sourcing, precedence, and metadata fallback behavior. - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 ## @langchain/langgraph-cua@1.0.2-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 ## @langchain/langgraph-supervisor@1.0.2-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 ## @langchain/langgraph-swarm@1.0.2-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 ## @langchain/langgraph-sdk@1.9.3-rc.0 ### Patch Changes - [#2387](https://github.com/langchain-ai/langgraphjs/pull/2387) [`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Coalesce `RootMessageProjection` store writes through a single `setTimeout(0)` flush so long `messages`-channel replays (on refresh, mid-run join, or rapid subagent streaming) no longer drain as a per-event microtask chain that trips React's `Maximum update depth exceeded` guard. Replaces the previous `MessageChannel`-based batching, which deferred initial-submit events past the first render and left the UI looking frozen until refresh. - [#2372](https://github.com/langchain-ai/langgraphjs/pull/2372) [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7) Thanks [@ahmed-z0](https://github.com/ahmed-z0)! - Fix subagent message routing to prefer the stream event namespace over checkpoint metadata when filtering subagent messages. - [#2384](https://github.com/langchain-ai/langgraphjs/pull/2384) [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - batch RootMessageProjection store writes through a macrotask - [#2381](https://github.com/langchain-ai/langgraphjs/pull/2381) [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - fix(sdk): forward config + metadata on respondInput for resume submits - [#2379](https://github.com/langchain-ai/langgraphjs/pull/2379) [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - filter SSE-replayed input.requested events through a hydrated interrupt allowlist - [#2390](https://github.com/langchain-ai/langgraphjs/pull/2390) [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3) Thanks [@nick-hollon-lc](https://github.com/nick-hollon-lc)! - Bind deepagents subagent discovery to the execution namespace via taskInput so `useMessages(stream, subagent)` resolves the streaming scope instead of the trigger tool-call namespace. ## @langchain/angular@1.0.3-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 ## @langchain/react@1.0.3-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 ## @langchain/svelte@1.0.3-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 ## @langchain/vue@1.0.3-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 ## @langchain/langgraph-ui@1.2.2-rc.0 ## @example/ai-elements@0.1.18-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 - @langchain/react@1.0.3-rc.0 ## @examples/assistant-ui-claude@0.1.18-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 - @langchain/react@1.0.3-rc.0 ## @examples/ui-angular@0.0.28-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 - @langchain/langgraph@1.3.1-rc.0 - @langchain/angular@1.0.3-rc.0 ## @examples/ui-multimodal@0.0.4-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 - @langchain/react@1.0.3-rc.0 ## @examples/ui-react@0.0.4-rc.0 ### Patch Changes - Updated dependencies \[[`44746b1`](https://github.com/langchain-ai/langgraphjs/commit/44746b1a3b5b49737542b120b9e45d6f94181113), [`4cc6491`](https://github.com/langchain-ai/langgraphjs/commit/4cc6491844f21ed0fc737eaef8498133daa877f7), [`ae8af2d`](https://github.com/langchain-ai/langgraphjs/commit/ae8af2d75aef9a7bbd930d221d1ce03e7fbb90ad), [`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280), [`2ad1aa4`](https://github.com/langchain-ai/langgraphjs/commit/2ad1aa48c6a3f45340b4833e6de555fdc7348d15), [`75e651b`](https://github.com/langchain-ai/langgraphjs/commit/75e651b9cff1a1e39ad6513b8a5e9b565b9ad7fe), [`f1d651a`](https://github.com/langchain-ai/langgraphjs/commit/f1d651ae14ca178f4a915ac853ba9b439cd55ba3)]: - @langchain/langgraph-sdk@1.9.3-rc.0 - @langchain/langgraph@1.3.1-rc.0 - @langchain/react@1.0.3-rc.0 ## langgraph@1.0.33-rc.0 ### Patch Changes - Updated dependencies \[[`4fd1e9f`](https://github.com/langchain-ai/langgraphjs/commit/4fd1e9f5720361a86a386a286ad8fcc824643280)]: - @langchain/langgraph@1.3.1-rc.0 --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Hunter Lovell <hunter@hntrl.io> |
||
|
|
67831afa7f |
chore(deps-dev): bump svelte from 5.55.5 to 5.55.7 (#2394)
Bumps [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte) from 5.55.5 to 5.55.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sveltejs/svelte/releases">svelte's releases</a>.</em></p> <blockquote> <h2>svelte@5.55.7</h2> <h3>Patch Changes</h3> <ul> <li> <p>fix: prevent XSS on <code>hydratable</code> from user contents (<a href="https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"><code>a16ebc67bbcf8f708360195687e1b2719463e1a4</code></a>)</p> </li> <li> <p>chore: bump devalue (<a href="https://redirect.github.com/sveltejs/svelte/pull/18219">#18219</a>)</p> </li> <li> <p>fix: disallow empty attribute names during SSR (<a href="https://github.com/sveltejs/svelte/commit/547853e2406a2147ad7fb5ffeba95b01bd9642da"><code>547853e2406a2147ad7fb5ffeba95b01bd9642da</code></a>)</p> </li> <li> <p>fix: harden regex (<a href="https://github.com/sveltejs/svelte/commit/d2375e2ebcab5c88feb5652f1a9d621b8f06b259"><code>d2375e2ebcab5c88feb5652f1a9d621b8f06b259</code></a>)</p> </li> <li> <p>fix: move Svelte runtime properties to symbols (<a href="https://github.com/sveltejs/svelte/commit/e1cbbd96441e82c9eb8a23a2903c0d06d3cda991"><code>e1cbbd96441e82c9eb8a23a2903c0d06d3cda991</code></a>)</p> </li> </ul> <h2>svelte@5.55.6</h2> <h3>Patch Changes</h3> <ul> <li> <p>fix: leave stale promises to wait for a later resolution, instead of rejecting (<a href="https://redirect.github.com/sveltejs/svelte/pull/18180">#18180</a>)</p> </li> <li> <p>fix: keep dependencies of <code>$state.eager/pending</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18218">#18218</a>)</p> </li> <li> <p>fix: reapply context after transforming error during SSR (<a href="https://redirect.github.com/sveltejs/svelte/pull/18099">#18099</a>)</p> </li> <li> <p>fix: don't rebase just-created batches (<a href="https://redirect.github.com/sveltejs/svelte/pull/18117">#18117</a>)</p> </li> <li> <p>chore: allow <code>null</code> for <code>pending</code> in typings (<a href="https://redirect.github.com/sveltejs/svelte/pull/18201">#18201</a>)</p> </li> <li> <p>fix: flush eager effects in production (<a href="https://redirect.github.com/sveltejs/svelte/pull/18107">#18107</a>)</p> </li> <li> <p>fix: rethrow error of failed iterable after calling <code>return()</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18169">#18169</a>)</p> </li> <li> <p>fix: account for proxified instance when updating <code>bind:this</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18147">#18147</a>)</p> </li> <li> <p>fix: ensure scheduled batch is flushed if not obsolete (<a href="https://redirect.github.com/sveltejs/svelte/pull/18131">#18131</a>)</p> </li> <li> <p>fix: resolve stale deriveds with latest value (<a href="https://redirect.github.com/sveltejs/svelte/pull/18167">#18167</a>)</p> </li> <li> <p>chore: remove unnecessary <code>increment_pending</code> calls (<a href="https://redirect.github.com/sveltejs/svelte/pull/18183">#18183</a>)</p> </li> <li> <p>fix: correctly compile component member expressions for SSR (<a href="https://redirect.github.com/sveltejs/svelte/pull/18192">#18192</a>)</p> </li> <li> <p>fix: reset <code>source.updated</code> stack traces after <code>flush</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18196">#18196</a>)</p> </li> <li> <p>fix: replacing async 'blocking' strategy with 'merging' (<a href="https://redirect.github.com/sveltejs/svelte/pull/18205">#18205</a>)</p> </li> <li> <p>fix: allow <code>@debug</code> tags to reference awaited variables (<a href="https://redirect.github.com/sveltejs/svelte/pull/18138">#18138</a>)</p> </li> <li> <p>fix: re-run fallback props if dependencies update (<a href="https://redirect.github.com/sveltejs/svelte/pull/18146">#18146</a>)</p> </li> <li> <p>fix: abort running obsolete async branches (<a href="https://redirect.github.com/sveltejs/svelte/pull/18118">#18118</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md">svelte's changelog</a>.</em></p> <blockquote> <h2>5.55.7</h2> <h3>Patch Changes</h3> <ul> <li> <p>fix: prevent XSS on <code>hydratable</code> from user contents (<a href="https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"><code>a16ebc67bbcf8f708360195687e1b2719463e1a4</code></a>)</p> </li> <li> <p>chore: bump devalue (<a href="https://redirect.github.com/sveltejs/svelte/pull/18219">#18219</a>)</p> </li> <li> <p>fix: disallow empty attribute names during SSR (<a href="https://github.com/sveltejs/svelte/commit/547853e2406a2147ad7fb5ffeba95b01bd9642da"><code>547853e2406a2147ad7fb5ffeba95b01bd9642da</code></a>)</p> </li> <li> <p>fix: harden regex (<a href="https://github.com/sveltejs/svelte/commit/d2375e2ebcab5c88feb5652f1a9d621b8f06b259"><code>d2375e2ebcab5c88feb5652f1a9d621b8f06b259</code></a>)</p> </li> <li> <p>fix: move Svelte runtime properties to symbols (<a href="https://github.com/sveltejs/svelte/commit/e1cbbd96441e82c9eb8a23a2903c0d06d3cda991"><code>e1cbbd96441e82c9eb8a23a2903c0d06d3cda991</code></a>)</p> </li> </ul> <h2>5.55.6</h2> <h3>Patch Changes</h3> <ul> <li> <p>fix: leave stale promises to wait for a later resolution, instead of rejecting (<a href="https://redirect.github.com/sveltejs/svelte/pull/18180">#18180</a>)</p> </li> <li> <p>fix: keep dependencies of <code>$state.eager/pending</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18218">#18218</a>)</p> </li> <li> <p>fix: reapply context after transforming error during SSR (<a href="https://redirect.github.com/sveltejs/svelte/pull/18099">#18099</a>)</p> </li> <li> <p>fix: don't rebase just-created batches (<a href="https://redirect.github.com/sveltejs/svelte/pull/18117">#18117</a>)</p> </li> <li> <p>chore: allow <code>null</code> for <code>pending</code> in typings (<a href="https://redirect.github.com/sveltejs/svelte/pull/18201">#18201</a>)</p> </li> <li> <p>fix: flush eager effects in production (<a href="https://redirect.github.com/sveltejs/svelte/pull/18107">#18107</a>)</p> </li> <li> <p>fix: rethrow error of failed iterable after calling <code>return()</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18169">#18169</a>)</p> </li> <li> <p>fix: account for proxified instance when updating <code>bind:this</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18147">#18147</a>)</p> </li> <li> <p>fix: ensure scheduled batch is flushed if not obsolete (<a href="https://redirect.github.com/sveltejs/svelte/pull/18131">#18131</a>)</p> </li> <li> <p>fix: resolve stale deriveds with latest value (<a href="https://redirect.github.com/sveltejs/svelte/pull/18167">#18167</a>)</p> </li> <li> <p>chore: remove unnecessary <code>increment_pending</code> calls (<a href="https://redirect.github.com/sveltejs/svelte/pull/18183">#18183</a>)</p> </li> <li> <p>fix: correctly compile component member expressions for SSR (<a href="https://redirect.github.com/sveltejs/svelte/pull/18192">#18192</a>)</p> </li> <li> <p>fix: reset <code>source.updated</code> stack traces after <code>flush</code> (<a href="https://redirect.github.com/sveltejs/svelte/pull/18196">#18196</a>)</p> </li> <li> <p>fix: replacing async 'blocking' strategy with 'merging' (<a href="https://redirect.github.com/sveltejs/svelte/pull/18205">#18205</a>)</p> </li> <li> <p>fix: allow <code>@debug</code> tags to reference awaited variables (<a href="https://redirect.github.com/sveltejs/svelte/pull/18138">#18138</a>)</p> </li> <li> <p>fix: re-run fallback props if dependencies update (<a href="https://redirect.github.com/sveltejs/svelte/pull/18146">#18146</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sveltejs/svelte/commit/4d8f99a2709e3c02e48d8bc6c77458f4ba49d0e3"><code>4d8f99a</code></a> Version Packages (<a href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18220">#18220</a>)</li> <li><a href="https://github.com/sveltejs/svelte/commit/05523088173e10af0753877af6936088de924833"><code>0552308</code></a> chore: bump devalue (<a href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18219">#18219</a>)</li> <li><a href="https://github.com/sveltejs/svelte/commit/e1cbbd96441e82c9eb8a23a2903c0d06d3cda991"><code>e1cbbd9</code></a> Merge commit from fork</li> <li><a href="https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"><code>a16ebc6</code></a> Merge commit from fork</li> <li><a href="https://github.com/sveltejs/svelte/commit/d2375e2ebcab5c88feb5652f1a9d621b8f06b259"><code>d2375e2</code></a> Merge commit from fork</li> <li><a href="https://github.com/sveltejs/svelte/commit/547853e2406a2147ad7fb5ffeba95b01bd9642da"><code>547853e</code></a> Merge commit from fork</li> <li><a href="https://github.com/sveltejs/svelte/commit/55f9c85c09d625c3dd80c71ce7542f57386fafb4"><code>55f9c85</code></a> Version Packages (<a href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18158">#18158</a>)</li> <li><a href="https://github.com/sveltejs/svelte/commit/a10e8e47a5946623a60a1e36b9023c23926eae87"><code>a10e8e4</code></a> fix: keep dependencies of <code>$state.eager</code>/<code>pending</code> (alternative approach) (<a href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/1">#1</a>...</li> <li><a href="https://github.com/sveltejs/svelte/commit/ef4b97dfabfd7a23b27933e18f7393587c343d66"><code>ef4b97d</code></a> fix: duplicated "of" in events.js comment (<a href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18217">#18217</a>)</li> <li><a href="https://github.com/sveltejs/svelte/commit/5122936edb3c14e9a602e579727479b49cbd3239"><code>5122936</code></a> fix: treat batches as a linked list (<a href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18205">#18205</a>)</li> <li>Additional commits viewable in <a href="https://github.com/sveltejs/svelte/commits/svelte@5.55.7/packages/svelte">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraphjs/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9b20df081a | fix(langgraph-cli): allow hyphenated prerelease api_version (#2396) | ||
|
|
f1d651ae14 |
fix(sdk): bind subagent namespace to execution scope via taskInput (#2390)
## Summary
When the SDK consumes a deepagents run over protocol-v2, the parent's
`task` tool call registers a subagent under `tools:<tool_call_id>` (e.g.
`tools:toolu_*`), but the subagent's pregel execution emits its
`values`/`messages`/`lifecycle` events at a **sibling** namespace
`tools:<pregel-uuid>` — not nested, no shared segment.
`SubagentDiscovery` tracked the trigger namespace, so
`useMessages(stream, subagent)` filtered the wrong scope and consumers
saw empty subagent cards while content streamed server-side.
The wire carries no first-class link between the two namespaces — the
lifecycle event's `trigger_call_id` is the Pregel UUID, not the
Anthropic `tool_call_id`.
## Approach
The server seeds the subagent's first state with
`HumanMessage(content=description)`, so an exact-equality match against
`taskInput` is deterministic. Adds:
- `#toolCallIdByTaskInput: Map<string, string[]>` — FIFO queue keyed by
taskInput, populated when a `task` tool call is registered.
- `#bindNamespaceByTaskInput` — on the first `values` event at a
`tools:<id>` namespace, look up the first HumanMessage text, shift the
matching `tool_call_id`, and seed `#taskIdByObservedNamespace`.
`#recordObservedWorkNamespace` promotes the namespace as before.
The queue handles parallel dispatches that share a description. Pregel
preserves dispatch order across executions, so FIFO pop attributes them
correctly.
## Known cliff edges (all silent — card stays empty)
- Wrapper middleware mutates the seeded HumanMessage before it reaches
the subagent.
- The HumanMessage uses multimodal content blocks instead of a string.
- A custom \`CompiledSubAgent\` state doesn't include a HumanMessage.
The upstream fix that eliminates the whole class is for langgraph's
\`_TasksLifecycleBase\` (or deepagents) to enrich the subagent's
lifecycle payload with \`cause: { tool_call_id }\`. That would replace
this bridge with a flat lookup.
|
||
|
|
44746b1a3b |
fix(sdk): coalesce RootMessageProjection writes via setTimeout(0) (#2387)
## Summary Reworks `RootMessageProjection` batching to fix two regressions at once. The freeze that #2384 originally addressed: on refresh, mid-run join, or a rapidly-streaming subagent, many `messages`-channel events drain through the controller's `for await` pump as a microtask chain. Per-event `store.setState` calls fire `useSyncExternalStore` notifications per event, and after ~50 React's `nestedUpdateCount` guard trips with "Maximum update depth exceeded", permanently freezing the UI on the first few messages. The new regression #2384 introduced: its `MessageChannel`-based scheduler deferred the first event of every streaming burst past React's initial render. Initial submit looked frozen — no user message, no AI response — until refresh. This change keeps the coalescing (so the freeze stays fixed) but swaps the scheduler to `setTimeout(0)` with a `#flushScheduled` idempotency guard: - `handleMessage` / `applyValues` compute new `messages` / `values` synchronously and stage them in `#pendingMessages` / `#pendingValues`. `#indexById` and `#valuesMessageIds` mutate synchronously so subsequent same-tick calls see up-to-date positions. - One `setTimeout(0)` flush per tick commits the staged values to the store in a single `setState`. Bursts collapse to one notification; streaming events separated by network latency each flush on their own boundary. - `reset()` drops pending writes so thread swaps can't bleed staged state. No test-only flush flag on the projection — the existing tests gained `await drainFlush()` between mutations and assertions. ### New regression coverage A `scheduling` describe block guards both contracts: - streamed event commits within one macrotask (would fail on a deferral-chain scheduler — initial-submit freeze) - values snapshot commits within one macrotask (would fail on hydrate freeze) - 200-delta synchronous burst → fewer than 10 store notifications (would fail on per-event `setState` — long-replay freeze) - 50 sequential `applyValues` calls → fewer than 10 store notifications (would fail on hydrate per-event freeze) Both coalesce tests fail on a sync projection; both single-event tests fail on a multi-macrotask deferral chain. ## Release Note None |
||
|
|
40bcdab38f |
fix: support pre-release versions in api_version (#2389)
<!-- Thank you for contributing to LangGraph.js! Your PR will appear in our next release under the title you set above. Please make sure it highlights your valuable contribution. To help streamline the review process, please make sure you read our contribution guidelines: https://github.com/langchain-ai/langgraphjs/blob/main/CONTRIBUTING.md Replace this block with a description of the change, the issue it fixes (if applicable), and relevant context. Finally, we'd love to show appreciation for your contribution - if you'd like us to shout you out on Twitter, please also include your handle below! --> <!-- Remove if not applicable --> Fixing api_version in langgraph.json to support PEP compatible versions (e.g. `0.9.0rc1`). Today we support JS compatible versions (e.g. `0.9.0-rc1` but langgraph-api is a python package so the versioning doesn't make sense and runs into issues with the image names. |
||
|
|
75e651b9cf |
fix(sdk): filter SSE-replayed input.requested events through a hydrated interrupt allowlist (#2379)
SSE replay of past \`input.requested\` events was re-adding historically requested (and since-resolved) interrupts to the UI on every page navigation back to the thread. The protocol has no \`input.responded\` event, so the SDK has no signal to distinguish replay from live for an idle thread — it would add anything replayed to \`rootStore.interrupts\`. Adds \`StreamController.#hydratedActiveInterruptIds\`: a \`Set\` populated during \`hydrate()\` from \`client.threads.getState()\`'s \`tasks[].interrupts\`. Used as a strict allowlist when processing replayed \`input.requested\` events. \`null\` outside the hydrate window so genuinely-new live interrupts on an active run aren't filtered; cleared at the start of \`submit()\` for the same reason. Also drops the unused \`subagents\` constructor param from \`RootMessageProjection\` — it was only ever read to forward events to a discovery instance that the controller already feeds directly, so the param had no behavioral effect. Included here because the matching call-site change lives in \`controller.ts\`. ## Release Note None --------- Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com> |
||
|
|
2ad1aa48c6 |
fix(sdk): subscription plumbing — dedicated SSE streams, run.start ordering, WS pre-register (#2381)
Three subscription-lifecycle correctness fixes; all share
\`client/stream/index.ts\` and are thematically the same surface.
### 1. \`subscribeDedicated\` + dedicated SSE event stream for narrow
projections
Selector hook consumers (\`useMessages\`, \`useToolCalls\`) scoped to a
subagent namespace would otherwise widen the shared content pump's
\`(channels, namespaces)\` union and pull every channel for every active
namespace onto the wire just to satisfy a single narrow consumer. SSE
transports get a fresh \`openEventStream\`; WS falls back to the shared
command stream (no union-widening cost on WS since all events flow on
one connection).
### 2. \`run.start\` lifecycle ordering
The lifecycle watcher and the values projection both open subscriptions
on \`/threads/{id}/stream/events\`; if either lands before \`run.start\`
commits the thread server-side, the server emits a
\`404: Thread not found\` protocol error and the client waits forever
for terminal events. Reorder so \`run.start\` awaits first, then
watchers attach. Also adds \`config\` + \`metadata\` to \`respondInput\`
signature so resume submits can carry per-run configuration overrides
(the v2 server already forwards both).
### 3. Pre-register subscription under a placeholder id before sending
\`subscription.subscribe\`
The WebSocket server replays buffered events through
\`install_subscription_with_replay\` before returning the success
response that carries the \`subscription_id\` — without
pre-registration,
those replayed events arrive at \`#handleIncoming\` while no matching
subscription is registered and never reach the iterator. UI symptom:
\`useMessages\` renders empty after click-to-expand on WebSocket.
## Release Note
None
---------
Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
|
||
|
|
4cc6491844 |
fix(sdk): route subagent messages by stream event namespace (#2372)
## Summary
Fix `StreamManager` subagent message routing so `messages|...` stream
events prefer the SSE event namespace when it identifies a subagent,
falling back to `metadata.langgraph_checkpoint_ns` /
`metadata.checkpoint_ns` only when there is no subagent event namespace.
This prevents subagent message chunks from being buffered under the
wrong namespace when the event name and message metadata disagree.
## Motivation
When streaming DeepAgent subgraphs from a deployed LangGraph server, the
stream can contain events shaped like:
```text
event: messages|tools:<stream-task-id>
data: [{...}, { checkpoint_ns: "tools:<metadata-task-id>" }]
```
`updates|tools:<stream-task-id>` and `values|tools:<stream-task-id>`
establish the visible subagent using the event namespace, but the
`messages` handler currently derives the subagent id from metadata. If
the metadata namespace differs, the subagent's internal AI/tool messages
are queued under a namespace that never maps to the visible subagent, so
`getSubagentsByMessage(...)` returns the subagent without its tool-call
history.
The stream event namespace is already parsed and passed to other
subagent event handlers, so message events should use it when available.
## Tests
```bash
pnpm --filter @langchain/langgraph-sdk test -- src/ui/manager.test.ts
```
Result: 37 files passed, 512 tests passed, no type errors.
|
||
|
|
ae8af2d75a |
fix(sdk): batch RootMessageProjection store writes through a macrotask (#2384)
Mirrors the \`MessageChannel\`-batching pattern that the namespace-scoped messages projection (\`projections/messages.ts\`) already uses, applied to the root namespace. When a long thread replays through the \`messages\` channel — on refresh, on resume of an in-flight run, or on a rapidly-streaming subagent — dozens of \`messages\`-channel events can land within a single SSE parse. They drain through the \`for await\` pump as a long microtask chain, and calling \`store.setState\` per event fires \`useSyncExternalStore\` notifications per event. After ~50 React's \`nestedUpdateCount\` guard trips with "Maximum update depth exceeded" and the UI freezes, permanently stuck at the first few messages. \`handleMessage\` and \`applyValues\` now compute their new \`messages\`/\`values\` synchronously (and keep mutating \`#indexById\` and \`#valuesMessageIds\` in line so subsequent calls in the same tick see up-to-date positions) but stage the result in \`#pendingMessages\`/\`#pendingValues\`. A single \`MessageChannel\`-backed \`#flushPending\` copies the staged values onto the store in one \`setState\` call per tick. Adds a test-only \`flushImmediately\` constructor flag so tests that assert against the store immediately after each call don't need to await a tick. Production wiring leaves it false. ## Release Note None --------- Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com> |
||
|
|
4fd1e9f572 |
fix(langgraph): source serverInfo ids from configurable first (#2376)
## Summary Runtime now prefers `assistant_id` and `graph_id` from `config.configurable`, which aligns with server-provided config, while preserving metadata fallback for compatibility. ## Changes ### `@langchain/langgraph` - Updated `libs/langgraph-core/src/pregel/index.ts` `_buildServerInfo` to resolve `assistant_id` and `graph_id` from `config.configurable` first, then fall back to `config.metadata`. - Kept `langgraph_auth_user` sourcing unchanged from `config.configurable`. - Expanded `libs/langgraph-core/src/tests/execution_info.test.ts` to cover: - configurable-based ID sourcing, - configurable-over-metadata precedence, - metadata fallback behavior, - existing auth-user serverInfo behavior with configurable IDs. |
||
|
|
aa6deb60c7 |
chore(deps): bump hono from 4.12.14 to 4.12.18 (#2374)
Bumps [hono](https://github.com/honojs/hono) from 4.12.14 to 4.12.18. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/honojs/hono/releases">hono's releases</a>.</em></p> <blockquote> <h2>v4.12.18</h2> <h2>Security fixes</h2> <p>This release includes fixes for the following security issues:</p> <h3>Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage</h3> <p>Affects: Cache Middleware. Fixes missing cache-skip handling for <code>Vary: Authorization</code> and <code>Vary: Cookie</code>, where a response cached for one authenticated user could be served to other users. GHSA-p77w-8qqv-26rm</p> <h3>CSS Declaration Injection via Style Object Values in JSX SSR</h3> <p>Affects: hono/jsx. Fixes a missing CSS-context escape for <code>style</code> object values and property names, where untrusted input could inject additional CSS declarations. The impact is limited to CSS and does not allow JavaScript execution. GHSA-qp7p-654g-cw7p</p> <h3>Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()</h3> <p>Affects: <code>hono/utils/jwt</code>. Fixes improper validation of <code>exp</code>, <code>nbf</code>, and <code>iat</code> claims, where falsy, non-finite, or non-numeric values could silently bypass time-based checks instead of being rejected per RFC 7519. GHSA-hm8q-7f3q-5f36</p> <hr /> <p>Users who use the JWT helper, hono/jsx, or the Cache middleware are strongly encouraged to upgrade to this version.</p> <h2>v4.12.17</h2> <h2>What's Changed</h2> <ul> <li>fix(jsx): normalize SVG attributes on the <!-- raw HTML omitted --> root element by <a href="https://github.com/kfly8"><code>@kfly8</code></a> in <a href="https://redirect.github.com/honojs/hono/pull/4893">honojs/hono#4893</a></li> <li>fix(ssg): add <code>atom+xml</code> and <code>rss+xml</code> to <code>defaultExtensionMap</code> by <a href="https://github.com/yuintei"><code>@yuintei</code></a> in <a href="https://redirect.github.com/honojs/hono/pull/4899">honojs/hono#4899</a></li> <li>fix(cors): make origin optional in CORSOptions by <a href="https://github.com/truffle-dev"><code>@truffle-dev</code></a> in <a href="https://redirect.github.com/honojs/hono/pull/4905">honojs/hono#4905</a></li> <li>fix(types): propagate middleware response types to app.on overloads by <a href="https://github.com/T4ko0522"><code>@T4ko0522</code></a> in <a href="https://redirect.github.com/honojs/hono/pull/4906">honojs/hono#4906</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/kfly8"><code>@kfly8</code></a> made their first contribution in <a href="https://redirect.github.com/honojs/hono/pull/4893">honojs/hono#4893</a></li> <li><a href="https://github.com/truffle-dev"><code>@truffle-dev</code></a> made their first contribution in <a href="https://redirect.github.com/honojs/hono/pull/4905">honojs/hono#4905</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/honojs/hono/compare/v4.12.16...v4.12.17">https://github.com/honojs/hono/compare/v4.12.16...v4.12.17</a></p> <h2>v4.12.16</h2> <h2>Security fixes</h2> <p>This release includes fixes for the following security issues:</p> <h3>Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection</h3> <p>Affects: hono/jsx. Fixes missing validation of JSX tag names when using <code>jsx()</code> or <code>createElement()</code>, which could allow HTML injection if untrusted input is used as the tag name. GHSA-69xw-7hcm-h432</p> <h3>bodyLimit() can be bypassed for chunked / unknown-length requests</h3> <p>Affects: Body Limit Middleware. Fixes late enforcement for request bodies without a reliable Content-Length (e.g. chunked requests), where oversized requests could reach handlers and return successful responses before being rejected. GHSA-9vqf-7f2p-gf9v</p> <h2>v4.12.15</h2> <h2>What's Changed</h2> <ul> <li>fix(jwt): support single-line PEM keys by <a href="https://github.com/hiendv"><code>@hiendv</code></a> in <a href="https://redirect.github.com/honojs/hono/pull/4889">honojs/hono#4889</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/honojs/hono/commit/f10dee89ced5956b73c1cdc416d6bc0fd54d63b7"><code>f10dee8</code></a> 4.12.18</li> <li><a href="https://github.com/honojs/hono/commit/a5bd9ebead279ed9d0239ecbd854f629edfc0e57"><code>a5bd9eb</code></a> Merge commit from fork</li> <li><a href="https://github.com/honojs/hono/commit/58d3d3ad5656e007ed99da1b73865975952de5e9"><code>58d3d3a</code></a> Merge commit from fork</li> <li><a href="https://github.com/honojs/hono/commit/568c2ecc1dd556894fad4dfa4a7ba499db6dba9c"><code>568c2ec</code></a> Merge commit from fork</li> <li><a href="https://github.com/honojs/hono/commit/ff2b3d31df1be35f7d597a95dd3369402b6e87f2"><code>ff2b3d3</code></a> 4.12.17</li> <li><a href="https://github.com/honojs/hono/commit/52aaaf9714b06303ce5caa655b1d80675be687e9"><code>52aaaf9</code></a> fix(types): propagate middleware response types to app.on overloads (<a href="https://redirect.github.com/honojs/hono/issues/4906">#4906</a>)</li> <li><a href="https://github.com/honojs/hono/commit/76d5589e9b0569f4e74ec37e8dd6979455f70dfa"><code>76d5589</code></a> fix(cors): make origin optional in CORSOptions (<a href="https://redirect.github.com/honojs/hono/issues/4905">#4905</a>)</li> <li><a href="https://github.com/honojs/hono/commit/8f027e5574e91e3c7f263a728656e3888559e51a"><code>8f027e5</code></a> fix(ssg): add <code>atom+xml</code> and <code>rss+xml</code> to <code>defaultExtensionMap</code> (<a href="https://redirect.github.com/honojs/hono/issues/4899">#4899</a>)</li> <li><a href="https://github.com/honojs/hono/commit/bfba97ca7ea3d4541a3419f1749e5a1a3e8f1727"><code>bfba97c</code></a> fix(jsx): normalize SVG attributes on the <svg> root element (<a href="https://redirect.github.com/honojs/hono/issues/4893">#4893</a>)</li> <li><a href="https://github.com/honojs/hono/commit/90d4182aabd328e2ec6af3f25ec62ddc574ad8cb"><code>90d4182</code></a> 4.12.16</li> <li>Additional commits viewable in <a href="https://github.com/honojs/hono/compare/v4.12.14...v4.12.18">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraphjs/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
f5b22a6f19 |
chore: version packages (#2373)
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @langchain/langgraph-sdk@1.9.2 ### Patch Changes - [#2370](https://github.com/langchain-ai/langgraphjs/pull/2370) [`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2) Thanks [@open-swe](https://github.com/apps/open-swe)! - feat(sdk): support metadata filter for crons search/count - [#2377](https://github.com/langchain-ai/langgraphjs/pull/2377) [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905) Thanks [@christian-bromann](https://github.com/christian-bromann)! - fix(sdk): preserve AI content blocks during message projection ## @langchain/angular@1.0.2 ### Patch Changes - Updated dependencies \[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2), [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]: - @langchain/langgraph-sdk@1.9.2 ## @langchain/react@1.0.2 ### Patch Changes - Updated dependencies \[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2), [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]: - @langchain/langgraph-sdk@1.9.2 ## @langchain/svelte@1.0.2 ### Patch Changes - Updated dependencies \[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2), [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]: - @langchain/langgraph-sdk@1.9.2 ## @langchain/vue@1.0.2 ### Patch Changes - Updated dependencies \[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2), [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]: - @langchain/langgraph-sdk@1.9.2 ## @example/ai-elements@0.1.17 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.2 ## @examples/assistant-ui-claude@0.1.17 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.2 ## @examples/ui-angular@0.0.27 ### Patch Changes - Updated dependencies \[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2), [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]: - @langchain/langgraph-sdk@1.9.2 - @langchain/angular@1.0.2 ## @examples/ui-multimodal@0.0.3 ### Patch Changes - Updated dependencies \[]: - @langchain/react@1.0.2 ## @examples/ui-react@0.0.3 ### Patch Changes - Updated dependencies \[[`4c6875c`](https://github.com/langchain-ai/langgraphjs/commit/4c6875c1e3dd32857d526925865c389e4e9c10c2), [`a5089cd`](https://github.com/langchain-ai/langgraphjs/commit/a5089cda1d9db1e4b50c17cdd12a770a67279905)]: - @langchain/langgraph-sdk@1.9.2 - @langchain/react@1.0.2 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
a5089cda1d |
fix(sdk): preserve AI content blocks during message projection (#2377)
While testing out more streaming examples, discovered some minor bugs around reasoning. This patch: - Preserve structured AI message content blocks when converting assembled stream messages, so reasoning blocks are not collapsed into plain text. - Update message reconciliation to prefer finalized `values.messages` tool-call args when they contain meaningful data missing from the streamed message. - Add coverage for mixed reasoning/text content blocks using the reasoning token stream fixture. |
||
|
|
4c6875c1e3 |
feat(sdk): support metadata filter for crons search/count (#2370)
## Description Mirror the langgraph-api change in https://github.com/langchain-ai/langgraph-api/pull/3400 by accepting an optional `metadata` filter on `crons.search` and `crons.count` in the JS SDK. Matches the existing pattern used for assistants/threads search. ## Release Note JS SDK: `crons.search` and `crons.count` now accept an optional `metadata` filter that is forwarded to the server. ## Test Plan - [ ] New unit tests in `libs/sdk/src/client/crons/index.test.ts` verify metadata is forwarded for both `search` and `count`, and omitted when not provided. --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
5e9f3cb532 | docs(react): add missing v1 migration guide |