1844 Commits
Author SHA1 Message Date
dependabot[bot] 57236d55d9 chore(deps): bump notebook from 7.5.6 to 7.5.7 in /libs/core (#40992)
Bumps [notebook](https://github.com/jupyter/notebook) from 7.5.6 to
7.5.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jupyter/notebook/releases">notebook's
releases</a>.</em></p>
<blockquote>
<h2>v7.5.7</h2>
<h2>7.5.7</h2>
<p>(<a
href="https://github.com/jupyter/notebook/compare/@jupyter-notebook/application-extension@7.5.6...af55f111d335315edd9e5eab472c9c1bbbb17b27">Full
Changelog</a>)</p>
<h3>Maintenance and upkeep improvements</h3>
<ul>
<li>Pin Node to 22.x in UI tests <a
href="https://redirect.github.com/jupyter/notebook/pull/7940">#7940</a>
(<a href="https://github.com/jtpio"><code>@​jtpio</code></a>)</li>
<li>Update to JupyterLab v4.5.8 <a
href="https://redirect.github.com/jupyter/notebook/pull/7939">#7939</a>
(<a href="https://github.com/jtpio"><code>@​jtpio</code></a>)</li>
</ul>
<h3>Contributors to this release</h3>
<p>The following people contributed discussions, new ideas, code and
documentation contributions, and review.
See <a
href="https://github-activity.readthedocs.io/en/latest/use/#how-does-this-tool-define-contributions-in-the-reports">our
definition of contributors</a>.</p>
<p>(<a
href="https://github.com/jupyter/notebook/graphs/contributors?from=2026-04-30&amp;to=2026-06-04&amp;type=c">GitHub
contributors page for this release</a>)</p>
<p><a href="https://github.com/jtpio"><code>@​jtpio</code></a> (<a
href="https://github.com/search?q=repo%3Ajupyter%2Fnotebook+involves%3Ajtpio+updated%3A2026-04-30..2026-06-04&amp;type=Issues">activity</a>)</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jupyter/notebook/blob/@jupyter-notebook/tree@7.5.7/CHANGELOG.md">notebook's
changelog</a>.</em></p>
<blockquote>
<h2>7.5.7</h2>
<p>(<a
href="https://github.com/jupyter/notebook/compare/@jupyter-notebook/application-extension@7.5.6...af55f111d335315edd9e5eab472c9c1bbbb17b27">Full
Changelog</a>)</p>
<h3>Maintenance and upkeep improvements</h3>
<ul>
<li>Pin Node to 22.x in UI tests <a
href="https://redirect.github.com/jupyter/notebook/pull/7940">#7940</a>
(<a href="https://github.com/jtpio"><code>@​jtpio</code></a>)</li>
<li>Update to JupyterLab v4.5.8 <a
href="https://redirect.github.com/jupyter/notebook/pull/7939">#7939</a>
(<a href="https://github.com/jtpio"><code>@​jtpio</code></a>)</li>
</ul>
<h3>Contributors to this release</h3>
<p>The following people contributed discussions, new ideas, code and
documentation contributions, and review.
See <a
href="https://github-activity.readthedocs.io/en/latest/use/#how-does-this-tool-define-contributions-in-the-reports">our
definition of contributors</a>.</p>
<p>(<a
href="https://github.com/jupyter/notebook/graphs/contributors?from=2026-04-30&amp;to=2026-06-04&amp;type=c">GitHub
contributors page for this release</a>)</p>
<p><a href="https://github.com/jtpio"><code>@​jtpio</code></a> (<a
href="https://github.com/search?q=repo%3Ajupyter%2Fnotebook+involves%3Ajtpio+updated%3A2026-04-30..2026-06-04&amp;type=Issues">activity</a>)</p>
<!-- raw HTML omitted -->
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jupyter/notebook/commit/a25fa5eda09ef85984ddafe4a5def427bf34912b"><code>a25fa5e</code></a>
Publish 7.5.7</li>
<li><a
href="https://github.com/jupyter/notebook/commit/af55f111d335315edd9e5eab472c9c1bbbb17b27"><code>af55f11</code></a>
Update to JupyterLab v4.5.8 (<a
href="https://redirect.github.com/jupyter/notebook/issues/7939">#7939</a>)</li>
<li><a
href="https://github.com/jupyter/notebook/commit/1f7059106ebdd038ecd30512295e2d1f77b7d698"><code>1f70591</code></a>
Pin Node to 22.x in UI tests to avoid Playwright install hang (<a
href="https://redirect.github.com/jupyter/notebook/issues/7940">#7940</a>)</li>
<li>See full diff in <a
href="https://github.com/jupyter/notebook/compare/@jupyter-notebook/tree@7.5.6...@jupyter-notebook/tree@7.5.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=notebook&package-manager=uv&previous-version=7.5.6&new-version=7.5.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-02 12:35:20 -07:00
dependabot[bot] 0904175ce5 chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/core (#40972)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 08:33:39 +00:00
dependabot[bot] 79aa9cf2d3 chore(deps): bump tornado from 6.5.8 to 6.5.9 in /libs/core (#40970)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.8 to
6.5.9.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.6.0
releases/v6.5.10
releases/v6.5.9
releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/75ef8b1cfa0e658aceb17c5a810ad1c74dc69bc7"><code>75ef8b1</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3719">#3719</a>
from bdarnell/fixes-659</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/3590cb4566d363331c294cfa63c5035ae2c32c87"><code>3590cb4</code></a>
test: Hardcode SimpleAsyncHTTPClient in HTTP1xxLimitTestCase</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/9fc5d6d9fff435066836d165d0f1f6ebb067fb9e"><code>9fc5d6d</code></a>
test: Make tracemalloc optional in httpclient_test</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/555a2ee9a20275d6dfde879977fce58d02e7898a"><code>555a2ee</code></a>
iostream: Treat connection resets as a clean close in
read_until_close</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/3ba622f2ecb75226a8e64d4ee96b7045fc4c8a64"><code>3ba622f</code></a>
Release notes and version bump for 6.5.9</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/41eea68aba54e8ecaafc1b777dc5c104d289a290"><code>41eea68</code></a>
test: Fix some test issues only found by our custom tox config</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/ab1a778defaccd0dde9c1c419578e3a1777a9eeb"><code>ab1a778</code></a>
Merge remote-tracking branch
'bdarnell/claude/asynchttpclient-streaming-memor...</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"><code>437ab5f</code></a>
web: Do not follow symlinks out of the static directory</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/03945136ea9746eccf61caf88edae39642e59c93"><code>0394513</code></a>
httputil: Apply the argument count limit to query strings</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b798f8322a15ba8b6ef725d698d1037024139714"><code>b798f83</code></a>
http1connection: Return after reading the response that follows a
1xx</li>
<li>Additional commits viewable in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.8...v6.5.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.8&new-version=6.5.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 08:15:22 +00:00
ccurme 08064f4859 release(core): 1.6.6 (#40906) 2026-09-29 09:25:34 -04:00
ce9066138d fix(anthropic): support Claude Sonnet 5.5 compatibility (#40882)
Co-authored-by: Hunter Lovell <hntrl@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: ccurme <ccurme@users.noreply.github.com>
Co-authored-by: Chester Curme <chester.curme@gmail.com>
2026-09-29 09:05:37 -04:00
40fe8d6e02 docs(core): fix docstring examples that don't run as copied (#40815)
Co-authored-by: ccurme <ccurme@users.noreply.github.com>
Co-authored-by: Aman Gupta <168967382+aman99dex@users.noreply.github.com>
2026-09-25 14:18:56 -04:00
ccurme c5ab14d42a release(core): 1.6.5 (#40816) 2026-09-24 14:03:30 -04:00
19cadaa1a1 fix(core): abbreviate long tool IDs in XML buffer strings (#40792)
Co-authored-by: ccurme <ccurme@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-23 15:36:26 -04:00
ccurme 99d0d06621 release(core): 1.6.4 (#40718) 2026-09-21 11:42:11 -04:00
ccurmeandopen-swe[bot] 3290757339 chore(core): deprecate chat message history (#40711)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-21 10:28:24 -04:00
dependabot[bot] 1a046a5319 chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (#40634)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.0 to 4.14.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.14.2</h2>
<ul>
<li>Changed <code>ByteReceiveStream.receive()</code> implementations to
raise a <code>ValueError</code> when <code>max_bytes</code> is not a
positive integer (<a
href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated
outside of an event loop. The adapter setter checked for infinity by
identity (<code>value is math.inf</code>), so only the exact
<code>math.inf</code> singleton was accepted, while every backend setter
(using <code>math.isinf()</code>) accepts any positive infinity (<a
href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>;
PR by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker
function writes enough data to <code>sys.stderr</code> to fill the
(undrained) pipe buffer. The worker process now redirects
<code>sys.stderr</code> to <code>os.devnull</code> as well, matching the
documented behavior</li>
<li>Fixed <code>TLSStream.wrap()</code> matching an internationalized
(unicode) host name against the peer certificate using IDNA 2003 (via
the standard library) instead of IDNA 2008, which could cause the host
name to be matched against the wrong certificate (<a
href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li>
<li>Fixed <code>anyio.open_process()</code> (and
<code>run_process()</code>) ignoring the <code>extra_groups</code>
argument, as it mistakenly passed the value of the <code>group</code>
argument instead (<a
href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li>
<li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on
the <code>trio</code> backend when there are no tokens available (<a
href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li>
<li>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens (<code>borrowed_tokens</code> exceeding
<code>total_tokens</code> and <code>available_tokens</code> going
negative) when a non-blocking acquire was made in the window between a
token being released and the notified waiter resuming. The freed token
is now reserved for the woken waiter right away, so the non-blocking
acquire correctly raises <code>WouldBlock</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>;
PR by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>)</li>
<li>Fixed unnecessary CPU spin when delivering cancellation from
<code>CancelScope</code> on asyncio under certain conditions, including
improper cancel scope nesting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li>
</ul>
<h2>4.14.1</h2>
<ul>
<li>Fixed teardown of higher-scoped async fixtures failing on asyncio
with <code>RuntimeError: Attempted to exit cancel scope in a different
task than it was entered in</code> when an async test raise an outcome
exception (e.g., <code>pytest.skip()</code>,
<code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a
href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of
<code>0</code> when the limiter was instantiated outside of an event
loop, contradicting the documented behavior of allowing 0 total tokens
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>;
PR by <a
href="https://github.com/nyxst4ck"><code>@​nyxst4ck</code></a>)</li>
</ul>
<h2>4.14.0</h2>
<ul>
<li>
<p>Added support for Python 3.15</p>
</li>
<li>
<p>Added an asynchronous implementation of the <code>itertools</code>
module (<a
href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>;
PR by <a href="https://github.com/11kkw"><code>@​11kkw</code></a>)</p>
</li>
<li>
<p>Added the <code>local_port</code> parameter to
<code>connect_tcp()</code> to allow binding to a specific local port
before connecting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>;
PR by <a
href="https://github.com/nullwiz"><code>@​nullwiz</code></a>)</p>
</li>
<li>
<p>Added support for custom capacity limiters in async path and file I/O
functions and classes</p>
</li>
<li>
<p>Added the <code>create_task()</code> task group method for easier
asyncio migration (returns a <code>TaskHandle</code>) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p>
</li>
<li>
<p>Changed <code>TaskGroup.start_soon()</code> to return a
<code>TaskHandle</code></p>
</li>
<li>
<p>Added an option for <code>TaskGroup.start()</code> to return a
<code>TaskHandle</code> (which then contains the start value in the
<code>start_value</code> property)</p>
</li>
<li>
<p>Added the <code>cancel()</code> convenience method to
<code>TaskGroup</code> as a shortcut for cancelling the task group's
cancel scope</p>
</li>
<li>
<p>Improved the error message when a known backend is not installed to
suggest the install command (<a
href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Improved <code>anyio.Path</code> to preserve subclass types by
returning <code>Self</code> in methods that return path objects (<a
href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Changed the parameter type annotation in
<code>anyio.Path.write_bytes()</code> to accept any
<code>ReadableBuffer</code>, thus allowing it to accept
<code>bytearray</code> and <code>memoryview</code> to match
<code>pathlib.Path.write_bytes()</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>;
PR by <a href="https://github.com/SAY-5"><code>@​SAY-5</code></a>)</p>
</li>
<li>
<p>Changed several type annotations to only accept callables returning
coroutine-like objects instead of arbitrary awaitables:</p>
<ul>
<li><code>TaskGroup.start_soon()</code></li>
<li><code>TaskGroup.start()</code></li>
<li><code>anyio.from_thread.run()</code></li>
</ul>
<p>This reverts an earlier change from v3.7.0 which was made in error.
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p>
</li>
<li>
<p>Changed <code>anyio.run</code> to support callables returning
arbitrary awaitables at runtime on all backends. Previously, this only
worked on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed several classes (and their subclasses) to have
<code>__slots__</code> (with <code>__weakref__</code>):</p>
<ul>
<li><code>anyio.CancelScope</code></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a>
Fixed 100% CPU spin on cancel scope misuse (<a
href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a>
Fix CapacityLimiter over-granting tokens on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a>
Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less
flaky</li>
<li><a
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a>
Relaxed timeouts to fix test flakiness</li>
<li><a
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a>
Fix test flakiness caused by slow callback duration logging</li>
<li><a
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a>
Fixed CapacityLimiter raising trio.WouldBlock instead of
anyio.WouldBlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a>
Pin setup-uv to a commit sha across downstream jobs (<a
href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a>
Fixed stderr writes in a worker subprocess causing a deadlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a>
Fix flaky test_tcp_listener_same_port using a hardcoded port (<a
href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.12.0...4.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.12.0&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 14:04:35 -04:00
dependabot[bot] f9ea7202e1 chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (#40574)
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.8.4
to 2.9.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facelessuser/soupsieve/releases">soupsieve's
releases</a>.</em></p>
<blockquote>
<h2>2.9</h2>
<ul>
<li><strong>NEW</strong>: Drop Python 3.9 support.</li>
<li><strong>NEW</strong>: Lazy compile selector patterns to improve
initial import speed.</li>
<li><strong>FIX</strong>: Correct
<code>:nth-child</code>/<code>:nth-of-type</code> (and
<code>-last-</code> variants) for <code>An+B</code> values whose
sequence steps onto
index 0 or onto the last child (e.g. <code>:nth-child(2n-2)</code>,
<code>:nth-child(n-1)</code>, <code>:nth-child(n+5)</code>), which
previously
matched the wrong elements or nothing at all (<a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>).</li>
<li><strong>FIX</strong>: More efficient CSS ID matching (<a
href="https://github.com/kaimandalic"><code>@​kaimandalic</code></a>).</li>
<li><strong>FIX</strong>: Fix inefficient trimming of comments and white
space (<a
href="https://github.com/kaimandalic"><code>@​kaimandalic</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004"><code>8763f91</code></a>
Format changelog message</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda"><code>cf198fc</code></a>
Fix inefficient trimming of comments and white space</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef"><code>ce44e49</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19"><code>751c57b</code></a>
Fix :nth-child/:nth-of-type matching for An+B index boundaries (<a
href="https://redirect.github.com/facelessuser/soupsieve/issues/297">#297</a>)</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b"><code>08e9ede</code></a>
Drop Python 3.9</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81"><code>d6e6830</code></a>
Rework selector mapping</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3"><code>d2d1581</code></a>
Utilize property for accessing lazy regular expression pattern</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d"><code>b8701de</code></a>
Build patterns and regexes lazily in css_parser (<a
href="https://redirect.github.com/facelessuser/soupsieve/issues/296">#296</a>)</li>
<li>See full diff in <a
href="https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=soupsieve&package-manager=uv&previous-version=2.8.4&new-version=2.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-17 14:17:02 -07:00
ccurme 348c9dc572 release(core): 1.6.3 (#40407) 2026-09-11 13:27:47 -04:00
Jacob Lee e0e1557bd6 feat(core): Allow model name and provider tracing metadata override based on gateway response (#40406)
With custom configs, the actual model name and provider the gateway
actually runs are different from what are requested. This reconciles
clientside tracing.
2026-09-11 10:13:02 -07:00
Bob Ok 16a58955e4 test(core): cover the deprecated .text() access path (#40243) 2026-09-06 09:32:58 -04:00
Manohar PaturiandManoharPaturi eef3eaeac8 docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (#40211)
Co-authored-by: ManoharPaturi <186662190+ManoharPaturi@users.noreply.github.com>
2026-09-05 22:44:11 -04:00
ccurme 8215039dea release(core): 1.6.2 (#40209) 2026-09-04 15:54:48 -04:00
ccurme 3f212e7a88 feat(openai): support async tools (#40208) 2026-09-04 15:49:14 -04:00
dependabot[bot] e90201b7af chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (#40150)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/releases">mistune's
releases</a>.</em></p>
<blockquote>
<h2>v3.3.3</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Set prev token in render_list_item and add block_text to
ignore_blocks  -  by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a> in <a
href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a>
<a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw
HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li>
<li>Improve nested bracket link input  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML
omitted -->(fe02f)<!-- raw HTML omitted --></a></li>
<li>Escape literal emphasis markers in MarkdownRenderer  -  by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a> <a
href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML
omitted -->(b0429)<!-- raw HTML omitted --></a></li>
<li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML
omitted -->(4009f)<!-- raw HTML omitted --></a></li>
<li>Add max_emphasis_depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML
omitted -->(0938f)<!-- raw HTML omitted --></a></li>
<li>Add image max depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML
omitted -->(cca5e)<!-- raw HTML omitted --></a></li>
<li><strong>inline</strong>: Use original run length in emphasis
multiple-of-3 rule  -  by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a> and
<strong>Claude Opus 4.8 (1M context)</strong> <a
href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML
omitted -->(2d26b)<!-- raw HTML omitted --></a></li>
</ul>
<h3>   🏎 Performance</h3>
<ul>
<li>Improve link label parsing performance  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML
omitted -->(e001d)<!-- raw HTML omitted --></a></li>
<li>Improve performance for math and formatting plugins  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML
omitted -->(c2228)<!-- raw HTML omitted --></a></li>
<li>Improve for footnotes, ruby and spoiler  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML
omitted -->(ae7e9)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View
changes on GitHub</a></h5>
<h2>v3.3.2</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Try to support python 3.8  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML
omitted -->(c9f1a)<!-- raw HTML omitted --></a></li>
<li>Resolve mypy issues for python 3.8 and 3.9+  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML
omitted -->(29b70)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View
changes on GitHub</a></h5>
<h2>v3.3.1</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li><strong>abbr</strong>: Update process_text method in abrr, adding
parse_emphasis parameter  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML
omitted -->(ae850)<!-- raw HTML omitted --></a></li>
<li><strong>directive</strong>: Use correct file path for include
directive  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML
omitted -->(18c21)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's
changelog</a>.</em></p>
<blockquote>
<h2>Version 3.3.3</h2>
<p><strong>Released on Jul 9, 2026</strong></p>
<ul>
<li>Limit deeply nested emphasis and image parsing to avoid
<code>RecursionError</code>.</li>
<li>Fix repeated link suffix and unclosed formatting marker performance
issues.</li>
<li>Fix unclosed inline spoiler performance issues.</li>
<li>Avoid recursive parsing for adjacent ruby tokens.</li>
<li>Speed up footnote reference indexing.</li>
</ul>
<h2>Version 3.3.2</h2>
<p><strong>Released on Jun 23, 2026</strong></p>
<ul>
<li>Fix Python 3.8 import compatibility in the inline parser.</li>
<li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li>
</ul>
<h2>Version 3.3.1</h2>
<p><strong>Released on Jun 22, 2026</strong></p>
<ul>
<li>Fix <code>abbr</code> plugin compatibility with escaped inline
text.</li>
<li>Normalize included Markdown line endings before parsing
directives.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a>
chore: release 3.3.3</li>
<li><a
href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a>
perf: improve for footnotes, ruby and spoiler</li>
<li><a
href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a>
perf: improve performance for math and formatting plugins</li>
<li><a
href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a>
perf: improve link label parsing performance</li>
<li><a
href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a>
fix: add image max depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a>
fix: add max_emphasis_depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a>
tests: update dealine time for pypy</li>
<li><a
href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a>
fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li>
<li><a
href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a>
Merge pull request <a
href="https://redirect.github.com/lepture/mistune/issues/462">#462</a>
from Sanjays2402/fix/markdown-renderer-escape-emphasis</li>
<li><a
href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a>
fix: escape literal emphasis markers in MarkdownRenderer</li>
<li>Additional commits viewable in <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=mistune&package-manager=uv&previous-version=3.3.0&new-version=3.3.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 10:16:08 -07:00
dependabot[bot] 4662366268 chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (#40113)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to
6.5.8.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2
releases/v4.0.1
releases/v4.0.0
releases/v3.2.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a>
from bdarnell/security-6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a>
docs: add additional credit to release notes</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a>
Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a>
release notes and version bump for 6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a>
auth: Formally deprecated OpenIDMixin</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a>
web: Also check for semicolons in deprecated mixed-case cookie args</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a>
httputil: Enforce a new limit on the number of arguments in a
request</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a>
httputil: Apply multipart max_parts limit earlier</li>
<li>See full diff in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.7&new-version=6.5.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:05:43 -07:00
ccurmeandHotragn Pettugani e92c8a08bf fix(core): avoid mutation in google-genai standard content (#40023)
Co-authored-by: Hotragn Pettugani <103170876+Hotragn@users.noreply.github.com>
2026-08-29 22:44:25 -04:00
ccurmeandZhewen Tan 36f0d10348 fix(core): avoid mutation in bedrock converse standard content (#40022)
Co-authored-by: Zhewen Tan <127607634+tandede@users.noreply.github.com>
2026-08-29 22:16:32 -04:00
ccurme 8fa38dc143 revert: release(core): 1.6.2 (#39971) 2026-08-27 14:39:23 -04:00
ccurme 122030d79e release(core): 1.6.2 (#39967) 2026-08-27 14:31:42 -04:00
ccurme 38e211359f fix(core): shore up indexing in genai v1 streaming content (#39964) 2026-08-27 12:37:49 -04:00
Emil F 13b1b2feae fix(core): make StructuredTool JSON-serializable (#39631)
## Problem

`StructuredTool` cannot be dumped to JSON:

```python
@tool
def write_file(file_path: str, content: str) -> str:
    """Write content to the given path."""
    return "ok"

write_file.model_dump(mode="json")
# PydanticSerializationError: Unable to serialize unknown type:
#   <class 'pydantic._internal._model_construction.ModelMetaclass'>
```

`args_schema` holds a Pydantic model class, and `func` / `coroutine`
hold callables. None of them have a JSON form. Python-mode
`model_dump()` works; only the JSON modes raise.

This also costs tracing performance. The [LangSmith
SDK](https://github.com/langchain-ai/langsmith-sdk/blob/main/python/langsmith/_internal/_serde.py)
catches the error, dumps again in Python mode, and then sends every
class and function left in the result through its own `default` hook.

## Change

A `PlainSerializer(..., when_used="json-unless-none")` on the three
fields.

- `args_schema` dumps as its own JSON schema: `model_json_schema()` for
a Pydantic v2 class, `schema()` for a v1 one. A dict schema passes
through unchanged. A schema holding an arbitrary type has no JSON schema
at all, so it falls back to its repr instead of raising.
- `func` and `coroutine` dump as strings.
- Python-mode dumps are unchanged — still the live schema class and
callables.
- `exclude` / `include` / `exclude_none` keep working.
- Attached with `Annotated`, not `@field_serializer`. A field has only
one serializer slot, so `@field_serializer` would break any subclass
that declares its own serializer for the same field.
- Schema generation is cached per class. Pydantic does not memoize it,
and tracing would pay for it on every run.

## Result

The dump is JSON-native, and the schema it carries has the same shape a
dict `args_schema` already has, so it validates back into a working
tool.

Measured on the 8 filesystem tools of a deepagents agent, dumped through
the LangSmith serializer:

| | master | this PR |
|---|---|---|
| time per dump | 0.119 ms | **0.025 ms** |
| payload | 7,706 B | 12,213 B |
| objects reaching the SDK's `default` hook | 32 | 8 |

The payload grows because `args_schema` now carries the real schema
instead of `"<class ...>"`. Only the tool itself still enters the
`default` hook; the class and functions inside it no longer do. Without
the per-class cache the same dump takes 1.10 ms, so the cache is what
makes this a win rather than a regression.

## Why not on `BaseTool`

`args_schema` is declared there as well, so `Tool` and custom subclasses
hit the same error. But an `Annotated` serializer only applies where the
field is declared, and `StructuredTool` redeclares `args_schema` — it
would not inherit one from `BaseTool`.

## Tests

In `libs/core/tests/unit_tests/test_tools.py`: JSON round trip, Python
mode unchanged, dump options respected, dict `args_schema` preserved,
Pydantic v1 schema class, arbitrary-type fallback, and a subclass
declaring its own serializers for the same fields.
2026-08-27 17:50:53 +02:00
69505d861b chore(deps): bump minor and patch dependencies (#39869)
Bumps the minor-and-patch group with 15 updates in the /libs/core
directory:

| Package | From | To |
| --- | --- | --- |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.8.18`
| `0.11.1` |
| [typing-extensions](https://github.com/python/typing_extensions) |
`4.15.0` | `4.16.0` |
| [packaging](https://github.com/pypa/packaging) | `26.0` | `26.3` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.4`
|
| [uuid-utils](https://github.com/aminalaee/uuid-utils) | `0.16.0` |
`0.17.0` |
| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) |
`0.0.17` | `0.0.18` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.5` | `0.16.4` |
| [mypy](https://github.com/python/mypy) | `2.1.0` | `2.3.1` |
| [types-requests](https://github.com/python/typeshed) |
`2.32.4.20260107` | `2.33.0.20260712` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` |
| [syrupy](https://github.com/syrupy-project/syrupy) | `5.1.0` | `5.5.3`
|
| [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) |
`1.3.0` | `1.4.0` |
| [responses](https://github.com/getsentry/responses) | `0.26.0` |
`0.26.2` |
| [pytest-socket](https://github.com/miketheman/pytest-socket) | `0.7.0`
| `0.8.1` |
| [blockbuster](https://github.com/cbornet/blockbuster) | `1.5.26` |
`1.5.27` |

Bumps the minor-and-patch group with 37 updates in the /libs/langchain
directory:

| Package | From | To |
| --- | --- | --- |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.8.18`
| `0.11.1` |
| [packaging](https://github.com/pypa/packaging) | `26.0` | `26.3` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.4`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.15.5` | `0.16.4` |
| [mypy](https://github.com/python/mypy) | `2.1.0` | `2.3.1` |
| [types-requests](https://github.com/python/typeshed) |
`2.32.4.20260107` | `2.33.0.20260712` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` |
| [syrupy](https://github.com/syrupy-project/syrupy) | `5.1.0` | `5.5.3`
|
| [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) |
`1.3.0` | `1.4.0` |
| [responses](https://github.com/getsentry/responses) | `0.26.0` |
`0.26.2` |
| [pytest-socket](https://github.com/miketheman/pytest-socket) | `0.7.0`
| `0.8.1` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.48` |
`2.0.52` |
| [requests](https://github.com/psf/requests) | `2.33.0` | `2.34.2` |
|
[langchain-community](https://github.com/langchain-ai/langchain-community)
| `0.4.1` | `0.4.2` |
| [langchain-anthropic](https://github.com/langchain-ai/langchain) |
`1.4.6` | `1.6.1` |
| [langchain-azure-ai](https://github.com/langchain-ai/langchain-azure)
| `1.2.3` | `1.2.8` |
| [langchain-cohere](https://github.com/langchain-ai/langchain-cohere) |
`0.5.1` | `0.6.0` |
|
[langchain-google-vertexai](https://github.com/langchain-ai/langchain-google)
| `3.2.3` | `3.2.4` |
|
[langchain-google-genai](https://github.com/langchain-ai/langchain-google)
| `4.2.1` | `4.3.5` |
| [langchain-fireworks](https://github.com/langchain-ai/langchain) |
`1.1.0` | `1.6.0` |
| [langchain-ollama](https://github.com/langchain-ai/langchain) |
`1.0.1` | `1.1.0` |
|
[langchain-together](https://github.com/langchain-ai/langchain-together)
| `0.0.2.post1` | `0.4.0` |
| [langchain-mistralai](https://github.com/langchain-ai/langchain) |
`1.1.1` | `1.1.6` |
| [langchain-huggingface](https://github.com/langchain-ai/langchain) |
`1.2.1` | `1.2.2` |
| [langchain-groq](https://github.com/langchain-ai/langchain) | `1.1.2`
| `1.1.3` |
| [langchain-aws](https://github.com/langchain-ai/langchain-aws) |
`1.3.1` | `1.7.3` |
| [langchain-deepseek](https://github.com/langchain-ai/langchain) |
`1.0.1` | `1.1.0` |
| [langchain-xai](https://github.com/langchain-ai/langchain) | `1.2.2` |
`1.3.0` |
| [langchain-perplexity](https://github.com/langchain-ai/langchain) |
`1.1.0` | `1.4.0` |
| [pytest-cov](https://github.com/pytest-dev/pytest-cov) | `7.0.0` |
`7.1.0` |
| [vcrpy](https://github.com/kevin1024/vcrpy) | `8.2.1` | `8.3.0` |
| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.1.2` | `2.3.0`
|
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2`
| `1.2.3` |
| [mypy-protobuf](https://github.com/nipunn1313/mypy-protobuf) | `5.0.0`
| `5.1.0` |
| [types-pytz](https://github.com/python/typeshed) | `2026.1.1.20260408`
| `2026.3.1.20260727` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.135.1` | `0.141.1`
|
| [playwright](https://github.com/microsoft/playwright-python) |
`1.58.0` | `1.62.0` |

Bumps the minor-and-patch group with 27 updates in the
/libs/langchain_v1 directory:

| Package | From | To |
| --- | --- | --- |
| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.4`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.15.5` | `0.16.4` |
| [mypy](https://github.com/python/mypy) | `2.1.0` | `2.3.1` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` |
| [syrupy](https://github.com/syrupy-project/syrupy) | `5.1.0` | `5.5.3`
|
| [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) |
`1.3.0` | `1.4.0` |
| [pytest-socket](https://github.com/miketheman/pytest-socket) | `0.7.0`
| `0.8.1` |
| [blockbuster](https://github.com/cbornet/blockbuster) | `1.5.26` |
`1.5.27` |
|
[langchain-community](https://github.com/langchain-ai/langchain-community)
| `0.4.1` | `0.4.2` |
| [langchain-azure-ai](https://github.com/langchain-ai/langchain-azure)
| `1.0.62` | `1.2.8` |
|
[langchain-google-vertexai](https://github.com/langchain-ai/langchain-google)
| `3.2.3` | `3.2.4` |
|
[langchain-google-genai](https://github.com/langchain-ai/langchain-google)
| `4.2.1` | `4.3.5` |
| [langchain-fireworks](https://github.com/langchain-ai/langchain) |
`1.1.0` | `1.6.0` |
| [langchain-ollama](https://github.com/langchain-ai/langchain) |
`1.0.1` | `1.1.0` |
|
[langchain-together](https://github.com/langchain-ai/langchain-together)
| `0.0.2.post1` | `0.4.0` |
| [langchain-mistralai](https://github.com/langchain-ai/langchain) |
`1.1.1` | `1.1.6` |
| [langchain-huggingface](https://github.com/langchain-ai/langchain) |
`1.2.1` | `1.2.2` |
| [langchain-groq](https://github.com/langchain-ai/langchain) | `1.1.2`
| `1.1.3` |
| [langchain-aws](https://github.com/langchain-ai/langchain-aws) |
`1.3.1` | `1.7.3` |
| [langchain-deepseek](https://github.com/langchain-ai/langchain) |
`1.0.1` | `1.1.0` |
| [langchain-xai](https://github.com/langchain-ai/langchain) | `1.2.2` |
`1.3.0` |
| [langchain-perplexity](https://github.com/langchain-ai/langchain) |
`1.1.0` | `1.4.0` |
| [pytest-cov](https://github.com/pytest-dev/pytest-cov) | `7.0.0` |
`7.1.0` |
| [vcrpy](https://github.com/kevin1024/vcrpy) | `8.2.1` | `8.3.0` |
| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.1.2` | `2.3.0`
|
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2`
| `1.2.3` |
| [langchain-baseten](https://github.com/basetenlabs/langchain-baseten)
| `0.2.0` | `0.2.3` |
Updates `langsmith` from 0.8.18 to 0.11.1

Made by [Open
SWE](https://openswe.vercel.app/agents/9fbadc55-1050-53d9-b978-f64592c56110)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-24 22:31:12 +00:00
Eugene Yurtsev 339eaa6f86 release(core): 1.6.1 (#39832)
Release 1.6.1
2026-08-21 18:38:03 +00:00
Eugene Yurtsev ed0ad742e9 feat(core): propagate gateway information on error path (#39829)
This PR plumbs through gateway metadata information for exceptions

<img width="2380" height="956" alt="image"
src="https://github.com/user-attachments/assets/c3b3644e-3022-421c-b447-6ab6603021e4"
/>
2026-08-21 14:33:30 -04:00
ccurme 85602c3676 release(core): 1.6.0 (#39760) 2026-08-19 11:51:29 -04:00
Mason Daugherty 5c3538e83a fix(core): resolve postponed annotations in StructuredTool._injected_args_keys (#39602)
Closes #39568

Related: #33999

> [!WARNING]
> This PR expands the surface area for arbitrary code execution during
tool setup. Detecting injected arguments now requires calling
`typing.get_type_hints`, which *evaluates* string annotations (e.g.
those created by `from __future__ import annotations` or quoted forward
references) as Python expressions. As with existing type-hint resolution
paths, wrapped tool callables must be trusted application code — never
point `StructuredTool` at a callable whose module or annotations come
from an untrusted source.

Tools with a custom `args_schema` could drop injected arguments such as
`ToolRuntime` when the wrapped function's module uses postponed
annotations. The injected value was removed during input validation, so
an otherwise valid tool call failed at invocation.

---

`StructuredTool` now resolves annotations with
`typing.get_type_hints(..., include_extras=True)` before identifying
injected parameters. If an unrelated forward reference prevents
resolving the complete signature, each string annotation is resolved
independently so resolvable injected arguments are still preserved.
Callable wrappers resolve annotations from the source of their effective
signature, honoring `__wrapped__` and `__signature__`, while other
callable objects use their `__call__` method. `functools.partial`
callables retain their effective signature so already-bound injected
arguments remain excluded.

<details>
<summary><b>Before/after:</b> injected arg dropped under <code>from
__future__ import annotations</code></summary>

With postponed annotations, every annotation is stored as a plain
string. Previously `_injected_args_keys` read the raw `signature()`
annotations, so `runtime` was never recognized as injected and was
stripped during `args_schema` validation:

```python
from __future__ import annotations  # all annotations become strings

from pydantic import BaseModel
from langchain_core.tools import tool, ToolRuntime

class InputSchema(BaseModel):
    query: str

@tool(args_schema=InputSchema)
def my_tool(query: str, runtime: ToolRuntime) -> str:
    """Echo the query."""
    return query
```

| | Behavior |
|---|---|
| **Before** | `runtime` not detected as injected → removed during
validation → tool call fails at invocation |
| **After** | `runtime` detected via `get_type_hints` → survives
validation and is injected at invocation; hidden from the model-facing
schema |

</details>

<details>
<summary><b>Before/after:</b> one unresolvable annotation disabling
injection for the whole signature</summary>

`get_type_hints` resolves *all* annotations at once and raises on the
first failure. A single unresolvable forward reference — even on an
unrelated parameter — previously meant *no* hints were available, so the
resolvable injected arg was dropped too:

```python
@tool(args_schema=InputSchema)
def my_tool(
    query: "SomeTypeThatDoesNotExist",  # unresolvable forward reference
    runtime: "ToolRuntime",             # resolvable injected arg
) -> str:
    """Echo the query."""
    return query
```

| | Behavior |
|---|---|
| **Before** | `get_type_hints` raises on `query` → all hints discarded
→ `runtime` not detected as injected |
| **After** | each annotation is retried independently → `query` falls
back to its raw string (not injected), `runtime` still resolves and is
injected |

</details>

<details>
<summary><b>Before/after:</b> callable objects and wrappers</summary>

For non-function callables, the annotations now come from the source of
the *effective* signature: `__call__` for callable objects, and the
wrapped function for wrappers (`__wrapped__` / `__signature__`):

```python
class MyCallableTool:
    def __call__(self, query: str, runtime: ToolRuntime) -> str:
        return query

tool = StructuredTool.from_function(
    func=MyCallableTool(),
    name="my_tool",
    description="Echo the query.",
    args_schema=InputSchema,
)
```

| | Behavior |
|---|---|
| **Before** | annotations read from the wrong callable (or left as
unresolved strings) → `runtime` dropped |
| **After** | annotations resolved from `__call__` / the unwrapped
function → `runtime` injected correctly |

</details>

<details>
<summary><b>Unchanged:</b> <code>functools.partial</code> with an
already-bound injected arg</summary>

A `partial` that already binds an injected argument keeps its effective
signature — the bound parameter is absent, so nothing is re-injected
over it:

```python
from functools import partial

def fn(x: int, runtime: ToolRuntime, y: int) -> int:
    return x + y

tool = StructuredTool.from_function(
    func=partial(fn, 1, bound_runtime),
    name="fn",
    description="Add two numbers.",
    args_schema=InputSchema,
)
```

**Before & after:** `runtime` is already bound by the `partial` →
excluded from the signature → the bound value is used as-is

</details>

Co-authored-by: Soban Shankar
<165470467+Soban-2004@users.noreply.github.com>
2026-08-19 11:38:30 -04:00
ccurme 9984a87fa5 feat(core): add standard model exception types (#39538) 2026-08-19 11:21:32 -04:00
gaoanze888 ded2a1fb3c fix(core): allow deserializing RunnablePick (#39753) 2026-08-19 10:45:58 -04:00
04ae7447d7 fix(core): make convert_to_openai_function handle callables and non-dict mappings (#39750)
Co-authored-by: gaoanze <gaoanze@meituan.com>
Co-authored-by: Chester Curme <chester.curme@gmail.com>
2026-08-19 10:39:18 -04:00
c8b2d767bf fix(core): make subprocess and temporary file tests portable on Windows (#39664)
Co-authored-by: Pu Jingnan <149932541+Puuuuup@users.noreply.github.com>
Co-authored-by: Chester Curme <chester.curme@gmail.com>
2026-08-18 17:34:30 -04:00
Hunter Lovell b5e8e2e85e fix(core): fail fast when tool schemas can't resolve forward refs during serialization (#39570)
fixes #39099

We currently allow forward refs in pydantic v2 schemas upon creation:

```python
class Container(BaseModel):
    rows: list["Row"] = [] # "Row" is declared below, after the tool is decorated

@tool
def my_tool(container: Container):
    """A tool whose schema depends on a forward reference that is not resolvable yet."""
    return "ok"

class Row(BaseModel):
    name: str
```

When it comes time to introspect the tool schema (notably in
`count_tokens_approximately` and `convert_to_openai_tool`), we rely on
[signature
introspection](https://github.com/langchain-ai/langchain/blob/943dd700ef7c33e3f1f21d3e280c9c249b88259c/libs/core/langchain_core/tools/base.py#L1654-L1661)
to extract the tool's input schema. If that contains invalid forward
references, there's no schema fields to extract which results in an
empty dict:

<details>

<summary>Invalid forward reference MRE</summary>

```python
from __future__ import annotations

import inspect

from pydantic import BaseModel, Field
from pydantic.errors import PydanticUndefinedAnnotation

from langchain_core.tools.base import get_all_basemodel_annotations
from langchain_core.utils.pydantic import _create_subset_model, model_json_schema


class Container(BaseModel):
    """A model with a nested forward reference that can never resolve."""

    rows: list["UndefinedRow"] = Field(default_factory=list)


def main() -> None:
    """Print the field-selection inputs and their zero-field subset result."""
    selected_annotations = get_all_basemodel_annotations(Container)
    subset_schema = _create_subset_model(
        "ContainerSubset",
        Container,
        list(selected_annotations),
        fn_description=Container.__doc__,
    )

    print(f"Pydantic complete: {Container.__pydantic_complete__}")
    print(f"Pydantic fields: {list(Container.model_fields)}")
    print(f"inspect.signature: {inspect.signature(Container)}")
    print(f"Fields selected by get_all_basemodel_annotations: {selected_annotations}")
    print(f"Subset properties: {model_json_schema(subset_schema)['properties']}")


if __name__ == "__main__":
    main()
```

```output
Pydantic complete: False
Pydantic fields: ['rows']
inspect.signature: (**data: 'Any') -> 'None'
Fields selected by get_all_basemodel_annotations: {}
Subset properties: {}
```

</details>

<details>

<summary>Valid forward reference MRE</summary>

```python
from __future__ import annotations

import inspect

from pydantic import BaseModel, Field
from pydantic.errors import PydanticUndefinedAnnotation

from langchain_core.tools.base import get_all_basemodel_annotations
from langchain_core.utils.pydantic import _create_subset_model, model_json_schema


class Container(BaseModel):
    """A model with a nested forward reference that can never resolve."""

    rows: list["UndefinedRow"] = Field(default_factory=list)

class UndefinedRow(BaseModel):
    name: str = Field()


def main() -> None:
    """Print the field-selection inputs and their zero-field subset result."""
    Container.model_rebuild()
    selected_annotations = get_all_basemodel_annotations(Container)
    subset_schema = _create_subset_model(
        "ContainerSubset",
        Container,
        list(selected_annotations),
        fn_description=Container.__doc__,
    )

    print(f"Pydantic complete: {Container.__pydantic_complete__}")
    print(f"Pydantic fields: {list(Container.model_fields)}")
    print(f"inspect.signature: {inspect.signature(Container)}")
    print(f"Fields selected by get_all_basemodel_annotations: {selected_annotations}")
    print(f"Subset properties: {model_json_schema(subset_schema)['properties']}")


if __name__ == "__main__":
    main()

```

```output
Pydantic complete: True
Pydantic fields: ['rows']
inspect.signature: (*, rows: list[__main__.UndefinedRow] = <factory>) -> None
Fields selected by get_all_basemodel_annotations: {'rows': list[__main__.UndefinedRow]}
Subset properties: {'rows': {'items': {'$ref': '#/$defs/UndefinedRow'}, 'title': 'Rows', 'type': 'array'}}
```
</details>

---

The fix is to
* at introspection time, resolve forward references using
`.model_rebuild()` that raises a pydantic exception if forward
references cant be resolved
* i'm also widening a pydantic utility to use a type guard instead of
having to use bool + cast

I'm intentionally not rebuilding pydantic v1 schemas in the same way
since
* forward references are specified by explicitly passing names into
`update_forward_refs`
* pydantic v1 is old news
2026-08-18 14:08:52 -07:00
Mason Daughertyandopen-swe[bot] 72fb0090bd test(core): avoid version-dependent runnable snapshots (#39705)
Runnable snapshots currently embed the exact `langchain-core` version,
forcing unrelated snapshot rewrites during every release. Normalize only
the current `VERSION` to a stable placeholder before comparison, so
missing or stale version metadata still fails.

Made by [Open
SWE](https://openswe.vercel.app/agents/bfd72574-359e-544e-dbf5-78f8bae3636a)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-18 16:16:21 -04:00
65e5e3cfa3 fix(core): require all nested properties for strict tool schemas (#39306)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Chester Curme <chester.curme@gmail.com>
Co-authored-by: dkundu56 <188023074+dkundu56@users.noreply.github.com>
Co-authored-by: Andrea Rossi <6909990+AndRossi@users.noreply.github.com>
2026-08-18 17:08:57 +00:00
94509faaed fix(core): remove stale sync-stream xfail [closes #39720] (#39723)
Co-authored-by: PAVAN KUMAR S <239303217+pufuki@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-18 12:57:41 -04:00
jtoman cccfbb1c5b perf(core): Lazily import transformers (#38037) 2026-08-18 10:12:05 -04:00
Lingjin 9c21d84bcb fix(core): accept non-dict Mapping values in mustache templates (#39680) 2026-08-17 20:29:33 -04:00
ccurme 4f355f38de docs(core): clarify Runnable pipe coercion [closes #39075] (#39707) 2026-08-18 00:25:17 +00:00
James Yang 300eb71549 fix(core): finalize chain-group runs on BaseException (#39699) 2026-08-17 19:52:46 -04:00
Eugene Yurtsev 4033a4eb7f chore(core): release 1.5.6 (#39704)
Release 1.5.6
2026-08-17 21:00:09 +00:00
5650448a03 feat(core): incorporate gateway metadata to traces (#39703)
This PR sends gateway metadata information (if present in the client
response) as metadata for the llm invocation.

Requires changes corresponding changes in the ChatModel implementations
(e.g., ChatOpenAI) so gateway metadata is picked up from the gateway
response headers.

---------

Signed-off-by: Eugene Yurtsev <eugene@langchain.dev>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: eyurtsev <3205522+eyurtsev@users.noreply.github.com>
2026-08-17 20:18:26 +00:00
ccurme 555702e1c6 release(core): 1.5.5 (#39655) 2026-08-14 14:13:15 -04:00
pxmps f9ee55d94c fix(core): make abatch_iterate consistent with batch_iterate for None and zero size (#39367) 2026-08-13 17:27:44 -04:00
Hunter Lovell cde529347a fix(core): respect pydantic aliases when validating tool inputs (#39572) 2026-08-13 09:19:50 -04:00
Nishitha Mandopen-swe[bot] a648460cfd fix(core): issues in merging chunks (#39535)
Closes #38064, #35259, #38850

`merge_dicts`, `merge_lists`, and `AddableDict` all guessed at merge
semantics for streaming chunks in ways that silently corrupted data
instead of failing loudly:

- `merge_dicts` fell into the `int` branch for differing `bool` values
(since `bool` subclasses `int`) and summed them, turning `True + False`
into `1`. It now raises `TypeError`, consistent with other unmergeable
types.
- `merge_lists` used `"index" in e_left` on untyped list elements; when
an element was a plain `str` containing the literal substring `"index"`,
it then subscripted the string and raised an unrelated `TypeError`. It
now checks `isinstance(e_left, dict)` first.
- `AddableDict.__add__`/`__radd__` silently discarded the left-hand
value on any `TypeError` from `chunk[key] + other[key]`. They now
re-raise a `TypeError` naming the key and both types.

### Release note

`merge_dicts` now raises `TypeError` for differing boolean values at the
same key instead of silently summing them to an `int`; `AddableDict`
addition now raises `TypeError` on type-incompatible keys instead of
silently dropping data; `merge_lists` no longer misidentifies non-dict
elements as index-keyed.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-12 17:40:35 -04:00
Hunter Lovell 13b2f8d727 fix(core): handle v1 base model validation in async path (#39576) 2026-08-12 15:49:24 -04:00