mirror of
https://github.com/langchain-ai/langchain.git
synced 2026-10-05 09:25:14 +03:00
2e9616bf0d0467f50a9cff2a2c8f80fa4a09fbc6
16876
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
0a86934ab5 |
fix(core): clear usage metadata callback on exceptions in context manager (#39616)
Co-authored-by: Solaris-star <820622658@qq.com> |
||
|
|
2d47a5f398 | chore(partners): bump langgraph floor in openai and huggingface lockfiles (#39617) | ||
|
|
4545c74216 |
chore(model-profiles): refresh model profile data (#39609)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **4 added · 0 removed · 2 changed** across 1 provider(s). ### openrouter **➕ 4 added** - `bytedance-seed/seed-2.0-code` — 262,144 ctx, 131,072 out, text+image+video in, reasoning, tools - `liquid/lfm-2.5-2.6b:free` — 128,000 ctx, 32,768 out, reasoning, tools - `nvidia/nemotron-3.5-lightning` — 262,144 ctx, 262,144 out, reasoning - `nvidia/nemotron-3.5-lightning:free` — 1,000,000 ctx, 65,536 out, reasoning, tools **✏️ 2 changed** - `z-ai/glm-5.2`: max output tokens 262,144 → 131,072 - `~deepseek/deepseek-v4-flash-latest`: max output tokens 131,072 → 262,144 Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
b6eccc5f97 | fix(core): handle falsy LLM and chat model caches (#39283) | ||
|
|
5a28e17fbb | chore(core): add httpx as an explicit dep (#39612) | ||
|
|
0727992d4a |
fix(anthropic): correct model profile data for Fable 5, Sonnet 5, Opus 4.1 (#39604)
Fixed `ChatAnthropic` model profiles: `claude-fable-5` and `claude-sonnet-5` now correctly report structured output support, `claude-fable-5` reports its reasoning effort levels and default, and the retired `claude-opus-4-1` entry was removed. --- Users calling `model.profile` on `ChatAnthropic` get wrong capability data for three models: - `claude-fable-5` reported `structured_output: false` and no reasoning-effort metadata, even though Fable 5 supports structured outputs and all five effort levels (`low` through `max`, defaulting to `high`). - `claude-sonnet-5` reported `structured_output: false` despite supporting structured outputs. - `claude-opus-4-1` lingered as a sparse augmentation-only entry (six fields, no token limits or modalities) after models.dev dropped it — Anthropic retired the model on 2026-08-05, so the entry is removed rather than backfilled. Corrections verified against Anthropic's [structured outputs compatibility list](https://platform.claude.com/docs/en/build-with-claude/structured-outputs), [effort docs](https://platform.claude.com/docs/en/build-with-claude/effort), and [deprecation schedule](https://platform.claude.com/docs/en/about-claude/model-deprecations). `_profiles.py` regenerated with `langchain-profiles refresh --provider anthropic`. |
||
|
|
7cdf9658f0 |
fix(core): preserve non-str/non-dict items in DictPromptTemplate list values (#39588)
|
||
|
|
2c3b11c6c4 |
chore: bump setuptools in Hugging Face lockfile (#39603)
## Summary - bumps `setuptools` from 81.0.0 to 84.0.0 in `libs/partners/huggingface/uv.lock` - resolves Dependabot alert #3955 / GHSA-h35f-9h28-mq5c / CVE-2026-59890 (first patched version: 83.0.0) - keeps the change scoped to the affected lockfile entry ## Validation - [x] `uv sync --project libs/partners/huggingface --frozen --no-install-project --no-dev` - [x] verified resolved `setuptools==84.0.0` is outside the vulnerable range - [x] `git diff --check` ## Notes `uv lock --locked` reports that the lockfile needs unrelated workspace metadata updates (`langchain`, `langchain-core`, and `langgraph`). Those unrelated refreshes were intentionally excluded to keep this security patch narrow. Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> |
||
|
|
61c5678835 | fix(core): raise ValueError when explicit tool_outputs length mismatches tool_calls in tool_example_to_messages (#39142) | ||
|
|
e34cd76346 | fix(core): guard malformed Anthropic content blocks (#38670) | ||
|
|
119bf69a1e | release(anthropic): 1.5.5 (#39597) langchain-anthropic==1.5.5 | ||
|
|
f4bc5031db | release(langchain): 1.3.15 (#39595) langchain==1.3.15 | ||
|
|
5ff19c613a | release(core): 1.5.4 (#39592) langchain-core==1.5.4 | ||
|
|
1925966dc6 |
feat(langchain): expose trace_policy on AgentMiddleware (#38910)
|
||
|
|
ce8e8bd8b1 |
chore(model-profiles): refresh model profile data (#39579)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **3 added · 1 removed · 8 changed** across 1 provider(s). ### openrouter **➕ 3 added** - `meta/muse-glimmer-30b` — 131,072 ctx, 131,072 out, text+image in, reasoning, tools - `sakana/sakana-namazu` — 262,144 ctx, 65,536 out, text+image+pdf in, reasoning, tools - `upstage/solar-pro4` — 524,288 ctx, 131,072 out, reasoning, tools **➖ 1 removed** - `openai/gpt-5.3-chat` **✏️ 8 changed** - `deepseek/deepseek-v4-pro`: max output tokens 384,000 → 393,216 - `inclusionai/ling-3.0-tiny:free`: added open weights - `moonshotai/kimi-k3`: added video input - `openai/gpt-5.2-chat`: max output tokens 16,384 → 32,000 - `qwen/qwen3-coder-30b-a3b-instruct`: max output tokens 32,768 → 262,144 - `qwen/qwen3-next-80b-a3b-thinking`: max output tokens 32,768 → 262,144 - `qwen/qwen3.5-397b-a17b`: max output tokens 65,536 → 262,144 - `~moonshotai/kimi-latest`: added video input Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
a2a9b1bde4 |
fix(anthropic): report reasoning tokens in usage metadata (#39590)
Co-authored-by: Philemon Schöpf <philemon.schoepf@otera.ai> |
||
|
|
39b4e0f9a8 | chore(langchain): fix type errors in tests (#39589) | ||
|
|
f78df6d977 |
chore(model-profiles): refresh model profile data (#39430)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **0 added · 0 removed · 5 changed** across 1 provider(s). ### openrouter **✏️ 5 changed** - `google/gemma-4-26b-a4b-it`: max output tokens 16,384 → 262,144 - `nvidia/nemotron-3-nano-30b-a3b`: max output tokens 262,144 → 228,000 - `qwen/qwen3-14b`: max output tokens 8,192 → 16,384 - `qwen/qwen3-next-80b-a3b-thinking`: max output tokens 262,144 → 32,768 - `z-ai/glm-5.2`: max output tokens 131,072 → 262,144 Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
56daacc8df | release(openai): 1.4.3 (#39485) langchain-openai==1.4.3 | ||
|
|
24e8d2b596 |
chore(model-profiles): refresh model profile data (#39344)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **0 added · 0 removed · 8 changed** across 1 provider(s). ### openrouter **✏️ 8 changed** - `deepseek/deepseek-v4-flash`: max output tokens 131,072 → 393,216 - `deepseek/deepseek-v4-flash-0731`: max output tokens 65,536 → 384,000 - `mancer/weaver`: max output tokens 2,000 → 6,000 - `qwen/qwen3-next-80b-a3b-thinking`: max output tokens 32,768 → 262,144 - `thinkingmachines/inkling`: max output tokens 1,048,576 → 262,144 - `thinkingmachines/inkling-small`: added structured output - `undi95/remm-slerp-l2-13b`: max output tokens 2,048 → 6,144 - `~deepseek/deepseek-v4-flash-latest`: max output tokens 65,536 → 131,072 Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
9b4ef2ab34 | fix(openai): filter invalid tool calls from content (#39366) | ||
|
|
9f738f5297 |
fix(core): compat with pydantic 2.14 (#39328)
Co-authored-by: PRINCE KUMAR MAURYA <218506877+alwaysprince05@users.noreply.github.com> |
||
|
|
d048fbe170 |
chore: bump h2 from 4.3.0 to 4.4.1 in /libs/langchain (#39325)
Bumps [h2](https://github.com/python-hyper/h2) from 4.3.0 to 4.4.1. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst">h2's changelog</a>.</em></p> <blockquote> <h2>4.4.1 (2026-08-03)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Performance improvement: remove consumed frames in-place from data buffer.</li> <li>Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.</li> </ul> <h2>4.4.0 (2026-07-23)</h2> <p><strong>API Changes (Backward Incompatible)</strong></p> <ul> <li>Support for Python 3.9 has been removed.</li> <li>Support for PyPy 3.9 has been removed.</li> <li><code>Stream.end_stream()</code> now raises <code>NoSuchStreamError</code> or <code>StreamClosedError</code> exceptions, instead of a generic <code>KeyError</code>.</li> <li>Duplicate <code>content-length</code> headers with different values now raise <code>ProtocolError</code>. Previously, the first <code>content-length</code> header was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.</li> <li>Parse <code>content-length</code> headers according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.</li> <li><strong>backfill from v4.3.0</strong> Convert emitted events into Python <code>dataclass</code>, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work.</li> </ul> <p><strong>API Changes (Backward Compatible)</strong></p> <ul> <li>Support for Python 3.14 has been added.</li> <li><code>H2Connection.receive_data</code> now accepts any byte-like object that implements the buffer protocol, such as <code>bytes</code>, <code>bytearray</code>, and <code>memoryview</code>. Existing <code>bytes</code> callers are unaffected.</li> <li>Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires <code>:method=CONNECT</code> and <code>:authority</code>, and forbids <code>:scheme</code>/<code>:path</code>. Extended CONNECT (e.g., WebSocket) requires <code>:scheme</code>, <code>:path</code>, <code>:authority</code> plus <code>:protocol</code>. (PR <a href="https://redirect.github.com/python-hyper/h2/issues/1309">#1309</a>)</li> <li>Fix incorrect substring matching of secure header in <code>cookie</code> and <code>:method</code>.</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li>Fix to allow sending 0 bytes on a stream even if the flow control window is negative.</li> <li>Reject non-zero <code>SETTINGS_ENABLE_PUSH</code> values received from servers.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08"><code>bc239af</code></a> v4.4.1</li> <li><a href="https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452"><code>92b925e</code></a> add test for duplicate host headers</li> <li><a href="https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6"><code>292a408</code></a> reject duplicate Host headers in request headers</li> <li><a href="https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde"><code>04d3b87</code></a> update changelog</li> <li><a href="https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a"><code>439b970</code></a> prepare for next release cycle</li> <li><a href="https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a"><code>9a7ff74</code></a> performance: remove consumed frames in place from data buffer (<a href="https://redirect.github.com/python-hyper/h2/issues/1321">#1321</a>)</li> <li><a href="https://github.com/python-hyper/h2/commit/6cce763997eca5b826f3e435a611b7a7fc73f633"><code>6cce763</code></a> v4.4.0</li> <li><a href="https://github.com/python-hyper/h2/commit/dfafda3b0cd96455b45d1785ef1ebc6968bba5cf"><code>dfafda3</code></a> Bump pytest from 8.4.2 to 9.0.3 (<a href="https://redirect.github.com/python-hyper/h2/issues/1320">#1320</a>)</li> <li><a href="https://github.com/python-hyper/h2/commit/b45207cedf9fabe2c77bb3c1c10f403a610599a0"><code>b45207c</code></a> dependencies and packaging++</li> <li><a href="https://github.com/python-hyper/h2/commit/c40145f69c5473850849fe96301ac0416b1afea6"><code>c40145f</code></a> parse <code>content-length</code> headers according to RFC9110 grammar for numbers (1*DI...</li> <li>Additional commits viewable in <a href="https://github.com/python-hyper/h2/compare/v4.3.0...v4.4.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
a0a434c185 |
chore: bump h2 from 4.3.0 to 4.4.1 in /libs/langchain_v1 (#39324)
Bumps [h2](https://github.com/python-hyper/h2) from 4.3.0 to 4.4.1. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst">h2's changelog</a>.</em></p> <blockquote> <h2>4.4.1 (2026-08-03)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Performance improvement: remove consumed frames in-place from data buffer.</li> <li>Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.</li> </ul> <h2>4.4.0 (2026-07-23)</h2> <p><strong>API Changes (Backward Incompatible)</strong></p> <ul> <li>Support for Python 3.9 has been removed.</li> <li>Support for PyPy 3.9 has been removed.</li> <li><code>Stream.end_stream()</code> now raises <code>NoSuchStreamError</code> or <code>StreamClosedError</code> exceptions, instead of a generic <code>KeyError</code>.</li> <li>Duplicate <code>content-length</code> headers with different values now raise <code>ProtocolError</code>. Previously, the first <code>content-length</code> header was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.</li> <li>Parse <code>content-length</code> headers according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.</li> <li><strong>backfill from v4.3.0</strong> Convert emitted events into Python <code>dataclass</code>, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work.</li> </ul> <p><strong>API Changes (Backward Compatible)</strong></p> <ul> <li>Support for Python 3.14 has been added.</li> <li><code>H2Connection.receive_data</code> now accepts any byte-like object that implements the buffer protocol, such as <code>bytes</code>, <code>bytearray</code>, and <code>memoryview</code>. Existing <code>bytes</code> callers are unaffected.</li> <li>Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires <code>:method=CONNECT</code> and <code>:authority</code>, and forbids <code>:scheme</code>/<code>:path</code>. Extended CONNECT (e.g., WebSocket) requires <code>:scheme</code>, <code>:path</code>, <code>:authority</code> plus <code>:protocol</code>. (PR <a href="https://redirect.github.com/python-hyper/h2/issues/1309">#1309</a>)</li> <li>Fix incorrect substring matching of secure header in <code>cookie</code> and <code>:method</code>.</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li>Fix to allow sending 0 bytes on a stream even if the flow control window is negative.</li> <li>Reject non-zero <code>SETTINGS_ENABLE_PUSH</code> values received from servers.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08"><code>bc239af</code></a> v4.4.1</li> <li><a href="https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452"><code>92b925e</code></a> add test for duplicate host headers</li> <li><a href="https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6"><code>292a408</code></a> reject duplicate Host headers in request headers</li> <li><a href="https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde"><code>04d3b87</code></a> update changelog</li> <li><a href="https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a"><code>439b970</code></a> prepare for next release cycle</li> <li><a href="https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a"><code>9a7ff74</code></a> performance: remove consumed frames in place from data buffer (<a href="https://redirect.github.com/python-hyper/h2/issues/1321">#1321</a>)</li> <li><a href="https://github.com/python-hyper/h2/commit/6cce763997eca5b826f3e435a611b7a7fc73f633"><code>6cce763</code></a> v4.4.0</li> <li><a href="https://github.com/python-hyper/h2/commit/dfafda3b0cd96455b45d1785ef1ebc6968bba5cf"><code>dfafda3</code></a> Bump pytest from 8.4.2 to 9.0.3 (<a href="https://redirect.github.com/python-hyper/h2/issues/1320">#1320</a>)</li> <li><a href="https://github.com/python-hyper/h2/commit/b45207cedf9fabe2c77bb3c1c10f403a610599a0"><code>b45207c</code></a> dependencies and packaging++</li> <li><a href="https://github.com/python-hyper/h2/commit/c40145f69c5473850849fe96301ac0416b1afea6"><code>c40145f</code></a> parse <code>content-length</code> headers according to RFC9110 grammar for numbers (1*DI...</li> <li>Additional commits viewable in <a href="https://github.com/python-hyper/h2/compare/v4.3.0...v4.4.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c318abed44 | fix(text-splitters): raise TypeError for non-dict, non-convertible input to RecursiveJsonSplitter (#39238) | ||
|
|
1499aa9900 |
fix(core): stop StructuredPrompt from mutating caller kwargs (#39174)
Co-authored-by: Jony <13896935+zyz619963502zyz@users.noreply.github.com> |
||
|
|
0424e03dc7 |
fix(core): preserve flat tool args schema for RootModel runnables (#39307)
Closes #38713 Fixes `Runnable.as_tool()` advertising `TypedDict` inputs under a synthetic `root` key. When a runnable's `input_schema` is a `RootModel` (e.g. compiled `StateGraph`s), the tool schema is now built from the runnable's type hints instead, keeping the advertised schema consistent with the flat input the runnable actually expects. --------- Co-authored-by: shusnapx <ashu.kumarexam@gmail.com> |
||
|
|
bc16168d71 |
fix(langchain): preserve history on SummarizationMiddleware summary failure (#39268)
Closes #38867 Fixes `SummarizationMiddleware` replacing conversation history with error text when summary generation fails. Summary calls now retry transient failures up to 3 times via `Runnable.with_retry`. If all attempts fail, the underlying exception propagates and the original history remains untouched. `_create_summary`/`_acreate_summary` no longer convert exceptions into fabricated summaries. No new parameters or exception types are introduced. ### Release note `SummarizationMiddleware` now retries failed summary calls and propagates the underlying error if retries are exhausted, instead of replacing conversation history with error text. Thanks @harshxth for raising this! --------- Signed-off-by: Nishitha M <32355027+imnishitha@users.noreply.github.com> |
||
|
|
44ae55a186 |
chore(model-profiles): refresh model profile data (#39318)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **1 added · 1 removed · 6 changed** across 1 provider(s). ### openrouter **➕ 1 added** - `inclusionai/ling-3.0-tiny:free` — 262,144 ctx, 32,768 out, reasoning, tools **➖ 1 removed** - `inclusionai/ling-3.0-flash:free` **✏️ 6 changed** - `anthropic/claude-opus-4.1`: removed structured output - `google/gemini-3-flash-preview`: max output tokens 65,535 → 65,536 - `inclusionai/ling-3.0-flash`: max input tokens 131,072 → 262,144; max output tokens 16,384 → 32,768 - `qwen/qwen3-coder-next`: last updated `2026-02-04` → `2026-02-03`; release date `2026-02-04` → `2026-02-03` - `qwen/qwen3.5-122b-a10b`: max output tokens 65,536 → 81,920 - `z-ai/glm-5.2`: max output tokens 262,144 → 131,072 Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
b6bce1a943 |
chore: bump h2 from 4.3.0 to 4.4.1 in /libs/partners/qdrant (#39323)
Bumps [h2](https://github.com/python-hyper/h2) from 4.3.0 to 4.4.1. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst">h2's changelog</a>.</em></p> <blockquote> <h2>4.4.1 (2026-08-03)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Performance improvement: remove consumed frames in-place from data buffer.</li> <li>Reject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.</li> </ul> <h2>4.4.0 (2026-07-23)</h2> <p><strong>API Changes (Backward Incompatible)</strong></p> <ul> <li>Support for Python 3.9 has been removed.</li> <li>Support for PyPy 3.9 has been removed.</li> <li><code>Stream.end_stream()</code> now raises <code>NoSuchStreamError</code> or <code>StreamClosedError</code> exceptions, instead of a generic <code>KeyError</code>.</li> <li>Duplicate <code>content-length</code> headers with different values now raise <code>ProtocolError</code>. Previously, the first <code>content-length</code> header was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.</li> <li>Parse <code>content-length</code> headers according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.</li> <li><strong>backfill from v4.3.0</strong> Convert emitted events into Python <code>dataclass</code>, which introduces new constructors with required arguments. Instantiating these events without arguments, as previously commonly used API pattern, will no longer work.</li> </ul> <p><strong>API Changes (Backward Compatible)</strong></p> <ul> <li>Support for Python 3.14 has been added.</li> <li><code>H2Connection.receive_data</code> now accepts any byte-like object that implements the buffer protocol, such as <code>bytes</code>, <code>bytearray</code>, and <code>memoryview</code>. Existing <code>bytes</code> callers are unaffected.</li> <li>Align CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4. Ordinary CONNECT now requires <code>:method=CONNECT</code> and <code>:authority</code>, and forbids <code>:scheme</code>/<code>:path</code>. Extended CONNECT (e.g., WebSocket) requires <code>:scheme</code>, <code>:path</code>, <code>:authority</code> plus <code>:protocol</code>. (PR <a href="https://redirect.github.com/python-hyper/h2/issues/1309">#1309</a>)</li> <li>Fix incorrect substring matching of secure header in <code>cookie</code> and <code>:method</code>.</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li>Fix to allow sending 0 bytes on a stream even if the flow control window is negative.</li> <li>Reject non-zero <code>SETTINGS_ENABLE_PUSH</code> values received from servers.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08"><code>bc239af</code></a> v4.4.1</li> <li><a href="https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452"><code>92b925e</code></a> add test for duplicate host headers</li> <li><a href="https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6"><code>292a408</code></a> reject duplicate Host headers in request headers</li> <li><a href="https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde"><code>04d3b87</code></a> update changelog</li> <li><a href="https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a"><code>439b970</code></a> prepare for next release cycle</li> <li><a href="https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a"><code>9a7ff74</code></a> performance: remove consumed frames in place from data buffer (<a href="https://redirect.github.com/python-hyper/h2/issues/1321">#1321</a>)</li> <li><a href="https://github.com/python-hyper/h2/commit/6cce763997eca5b826f3e435a611b7a7fc73f633"><code>6cce763</code></a> v4.4.0</li> <li><a href="https://github.com/python-hyper/h2/commit/dfafda3b0cd96455b45d1785ef1ebc6968bba5cf"><code>dfafda3</code></a> Bump pytest from 8.4.2 to 9.0.3 (<a href="https://redirect.github.com/python-hyper/h2/issues/1320">#1320</a>)</li> <li><a href="https://github.com/python-hyper/h2/commit/b45207cedf9fabe2c77bb3c1c10f403a610599a0"><code>b45207c</code></a> dependencies and packaging++</li> <li><a href="https://github.com/python-hyper/h2/commit/c40145f69c5473850849fe96301ac0416b1afea6"><code>c40145f</code></a> parse <code>content-length</code> headers according to RFC9110 grammar for numbers (1*DI...</li> <li>Additional commits viewable in <a href="https://github.com/python-hyper/h2/compare/v4.3.0...v4.4.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
536ce56f4e |
fix(anthropic): fix KeyError on rename in Claude file-tool middleware (#39293)
Closes #35852, #38465 The `file_tool` dispatcher builds the operation arguments using `"path"` as the source path for all commands, including `rename`. However, `_handle_rename` was the only handler reading `args["old_path"]` instead of `args["path"]`, resulting in a `KeyError` on every rename across all Claude file/memory tool middleware classes. The fix makes `_handle_rename` read the source path from `args["path"]`, matching the dispatcher's behavior and keeping rename consistent with every other file operation. Claude adapts to the advertised tool schema: it initially emits the documented [Memory Tool rename payload ](https://platform.claude.com/docs/en/agents-and-tools/tool-use/memory-tool#rename)(`old_path/new_path`), but after receiving a validation error because path is required by this tool, it retries with both path and old_path. Since the dispatcher already normalizes the source path under path, the simplest and most consistent fix is for `_handle_rename `to read `args["path"]`, matching every other handler and the dispatcher itself. Otherwise making `path` as an optional arg in the tool would be a breaking change. Co-authored-by: LincolnBurrows2017 <lincolnburrows2017@gmail.com> |
||
|
|
d616af71dd | fix(exa): handle missing optional result metadata (#39171) | ||
|
|
2f4aa5a79c | feat(openrouter): preserve provider in response metadata (#39301) | ||
|
|
367df8e3d9 | chore(openai): update guidance for responses API for OpenAI-compatible providers (#39327) | ||
|
|
a4fb5f1a7a |
fix(langchain): handle import error in LLMToolEmulator by model (#39290)
Closes #34274 - Removed the redundant double-check (`not self.emulate_all and tools is not None`) when building `tools_to_emulate`. - The middleware now: raises an actionable `ImportError` when `langchain-anthropic` isn't installed and emits a `DeprecationWarning` either way, so callers have a real migration window before model becomes required in a future release. ### Release notes `model` will be made required param in the future relase --------- Co-authored-by: keenborder786 <21110290@lums.edu.pk> |
||
|
|
c9b301a8b7 |
chore(openai): update docstring for include_response_headers (#39326)
|
||
|
|
8ba2d26622 | release(openai): 1.4.2 (#39322) langchain-openai==1.4.2 | ||
|
|
016e7cb976 |
fix(openai): handle ContextWindowExceededError (#39300)
|
||
|
|
f48fa9478d |
chore(model-profiles): refresh model profile data (#39299)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **5 added · 1 removed · 7 changed** across 3 provider(s). <details> <summary>anthropic</summary> **➖ 1 removed** - `claude-opus-4-1-20250805` **✏️ 1 changed** - `claude-opus-4-1`: removed attachments; audio input no → unset; audio output no → unset; removed image input; image output no → unset; last updated `2025-08-05` → unset; max input tokens 200,000 → unset; max output tokens 32,000 → unset; display name `Claude Opus 4.1 (latest)` → unset; open weights no → unset; removed reasoning; release date `2025-08-05` → unset; status `deprecated` → unset; removed temperature control; removed text input; removed text output; removed tool calling; video input no → unset; video output no → unset </details> <details> <summary>huggingface</summary> **➕ 3 added** - `Qwen/Qwen3-235B-A22B-Instruct-2507` — 262,144 ctx, 16,384 out, tools - `deepseek-ai/DeepSeek-V3` — 64,000 ctx, 8,192 out, tools - `deepseek-ai/DeepSeek-V3.1` — 131,072 ctx, 8,192 out, reasoning, tools </details> <details> <summary>openrouter</summary> **➕ 2 added** - `inclusionai/ling-3.0-flash` — 131,072 ctx, 16,384 out, reasoning, tools - `meta/muse-spark-1.2` — 1,048,576 ctx, 1,048,576 out, text+image+audio+video+pdf in, reasoning, tools **✏️ 6 changed** - `deepseek/deepseek-v4-flash`: max output tokens 393,216 → 131,072 - `inclusionai/ling-3.0-flash:free`: added open weights - `qwen/qwen3-235b-a22b-2507`: max output tokens 32,768 → 16,384 - `qwen/qwen3.6-27b`: max output tokens 131,072 → 262,144 - `upstage/solar-pro-3`: max input tokens 128,000 → 131,072; max output tokens 128,000 → 131,072 - `z-ai/glm-5.1`: max output tokens 128,000 → 131,072 </details> --------- Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> Co-authored-by: Mason Daugherty <mason@langchain.dev> Co-authored-by: Mason Daugherty <github@mdrxy.com> |
||
|
|
ea52f5b409 |
refactor(langchain): update doc strings (#39305)
Update doc strings |
||
|
|
167c537886 |
feat(langchain): add state_schema param to wrap_tool_call (#39292)
Closes #36409 `wrap_tool_call` was the only middleware decorator lacking a `state_schema` parameter (`before_model`, `after_model`, `wrap_model_call`, `before_agent`, and `after_agent` all have it). Added it for consistency. Co-authored-by: @acookie <14118569+acoo4ie@user.noreply.gitee.com> |
||
|
|
0cd7003c11 |
fix(langchain): re-export PIIMatch from middleware package (#39291)
Closes #38718 `PIIMatch` was already in `pii.py`'s `__all__`, but not re-exported from the package `__init__`, forcing custom PII detector authors to import it from the private `_redaction` module. --------- Co-authored-by: @abhi-0203 <abhi-0203@users.noreply.github.com> |
||
|
|
b7e5dda39e |
fix(langchain): restrict narrowed ToolStrategy in bound tools (#39259)
Fixes #36568 Previously, narrowing a union `ToolStrategy` via `request.override()` validated the narrowed schema but still bound all originally declared structured-output tools, allowing the model to choose a schema outside the subset. `_get_bound_model` now binds only the tools in the effective `response_format`, so middleware overrides correctly restrict the available structured-output schemas. Co-authored-by: r266-tech <r2668940489@gmail.com> Co-authored-by: Jung Seunghoon <175179350+seuthootDev@users.noreply.github.com> |
||
|
|
3579fe93ee |
fix(anthropic): clearer error when no credentials are configured (#39285)
`ChatAnthropic` now raises a clear, actionable `TypeError` when a call
is made without any Anthropic credentials configured. The message points
users to `ANTHROPIC_API_KEY`, the `api_key=` parameter,
`default_headers`, and the LangSmith gateway, replacing the anthropic
SDK's internal "Could not resolve authentication method" error. The
original error remains available via exception chaining.
---
Users who construct `ChatAnthropic` without credentials currently get a
confusing failure on their first call. The model builds fine with no API
key — `anthropic_api_key` defaults to an empty `SecretStr`, and the raw
anthropic SDK accepts it at construction — so the error only surfaces on
the first `invoke()`/`stream()`, deep inside the anthropic SDK's header
validation:
```
TypeError: "Could not resolve authentication method. Expected one of api_key,
auth_token, or credentials to be set. Or for one of the `X-Api-Key` or
`Authorization` headers to be explicitly omitted"
```
That message never mentions `ANTHROPIC_API_KEY`, `api_key=`, or the
LangSmith gateway — the things a LangChain user actually needs to fix —
and the traceback points into the anthropic SDK rather than at the
missing configuration.
This PR catches that specific `TypeError` at the call site in
`ChatAnthropic._create`/`_acreate` (covering both the beta and non-beta
`messages.create` paths) and re-raises it, chained `from e`, with
LangChain-specific guidance:
```
Anthropic authentication failed: no API key or authorization credentials
were provided. Set the ANTHROPIC_API_KEY environment variable, pass
api_key=... to ChatAnthropic, or provide credentials via
default_headers={"Authorization": ...}. If you are routing through the
LangSmith gateway, set LANGSMITH_GATEWAY and LANGSMITH_GATEWAY_API_KEY.
```
Matching is done on the message substring, so unrelated `TypeError`s
propagate unchanged. There is deliberately no construction-time
validation or warning: key-less setups are legitimate (LangSmith gateway
routing, `default_headers` with an explicit `Authorization` header, or a
user-supplied `http_client` that injects auth), so the error still
surfaces only at call time, exactly as before — just with an actionable
message.
|
||
|
|
89cc9c5cbb |
feat(langchain): filter internal middleware model calls from messages projection (#39252)
Closes #34139 #34382 `SummarizationMiddleware`, `LLMToolEmulator`, and `LLMToolSelectorMiddleware` make internal model calls for bookkeeping, but these were indistinguishable from the agent's main model call in the event stream. This PR tags internal calls in config metadata and adds an `InternalCallTransformer` that filters them from `run.messages` and the raw event log. Note: If a user wants to stream the internal LLM calls, needs to build a custom transformer around it --------- Co-authored-by: Devbyteai <abud6673@gmail.com> |
||
|
|
3e871a148d |
fix(langchain): sanitize evaluation Git remote tags (#39254)
Evaluation runs currently copy Git remote URLs into every run tag unchanged, which can fan out credentials embedded in HTTPS or SSH remotes. This change strips URL userinfo while preserving repository host/path identity for HTTPS, SSH, Git, and scp-style remotes. Malformed, ambiguous, query-bearing, and control-character-bearing values fail closed and are omitted. Other Git correlation tags remain unchanged. Sync and async evaluation flows are covered. ## Release note LangChain evaluation runs now remove credentials from Git remote URL tags while preserving credential-free repository identity. This contribution was implemented with AI-agent assistance. |
||
|
|
759c5e348a |
chore: bump langsmith from 0.10.6 to 0.10.16 in /libs/partners/chroma (#39280)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from 0.10.6 to 0.10.16. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's releases</a>.</em></p> <blockquote> <h2>v0.10.16</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.8.9 by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3316">langchain-ai/langsmith-sdk#3316</a></li> <li>fix(python): mask metadata after the runtime env merge and via the anonymizer by <a href="https://github.com/vladislav-nechakhin"><code>@vladislav-nechakhin</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li> <li>fix(js): mask metadata after the runtime env merge and via the anonymizer by <a href="https://github.com/vladislav-nechakhin"><code>@vladislav-nechakhin</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3314">langchain-ai/langsmith-sdk#3314</a></li> <li>chore(deps-dev): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3325">langchain-ai/langsmith-sdk#3325</a></li> <li>chore(deps-dev): bump types-pyyaml from 6.0.12.20260518 to 6.0.12.20260724 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3324">langchain-ai/langsmith-sdk#3324</a></li> <li>chore(deps): bump the actions-major group with 2 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3321">langchain-ai/langsmith-sdk#3321</a></li> <li>chore(deps): bump the actions-minor-and-patch group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3320">langchain-ai/langsmith-sdk#3320</a></li> <li>chore(deps): bump the npm_and_yarn group across 3 directories with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3330">langchain-ai/langsmith-sdk#3330</a></li> <li>fix(js,py): stamp ls_agent_type on wrap_openai LLM runs by <a href="https://github.com/ybathula707"><code>@ybathula707</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3317">langchain-ai/langsmith-sdk#3317</a></li> <li>chore(deps): bump aiohttp from 3.14.1 to 3.14.3 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3329">langchain-ai/langsmith-sdk#3329</a></li> <li>chore(deps-dev): bump the py-major group in /python with 2 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3323">langchain-ai/langsmith-sdk#3323</a></li> <li>chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3331">langchain-ai/langsmith-sdk#3331</a></li> <li>fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk integration by <a href="https://github.com/ybathula707"><code>@ybathula707</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3318">langchain-ai/langsmith-sdk#3318</a></li> <li>fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper by <a href="https://github.com/ybathula707"><code>@ybathula707</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3319">langchain-ai/langsmith-sdk#3319</a></li> <li>chore(deps): bump the py-minor-and-patch group across 1 directory with 25 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3322">langchain-ai/langsmith-sdk#3322</a></li> <li>fix(profiles): resolve the OAuth token endpoint from deployment metadata by <a href="https://github.com/langchain-infra"><code>@langchain-infra</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3333">langchain-ai/langsmith-sdk#3333</a></li> <li>fix: avoid resetting compression threads by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3332">langchain-ai/langsmith-sdk#3332</a></li> <li>docs(sandbox): fix invalid sizing example in JS sandbox README by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3335">langchain-ai/langsmith-sdk#3335</a></li> <li>test(claude-agent-sdk): run subagent in foreground so trace nests correctly by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3339">langchain-ai/langsmith-sdk#3339</a></li> <li>release(py): 0.10.16 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3337">langchain-ai/langsmith-sdk#3337</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/vladislav-nechakhin"><code>@vladislav-nechakhin</code></a> made their first contribution in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16</a></p> <h2>v0.10.15</h2> <h2>What's Changed</h2> <ul> <li>fix(python): apply the caller-supplied session's config to v2 endpoints by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3304">langchain-ai/langsmith-sdk#3304</a></li> <li>chore: Use a common function for backend detection by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3307">langchain-ai/langsmith-sdk#3307</a></li> <li>fix: prioritize API key over OAuth profile auth [closes LSDK-414] by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3295">langchain-ai/langsmith-sdk#3295</a></li> <li>fix(js): apply caller-supplied headers to the v2 endpoints by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3305">langchain-ai/langsmith-sdk#3305</a></li> <li>chore: deprecate legacy SmithDB-migration SDK methods by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3299">langchain-ai/langsmith-sdk#3299</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3310">langchain-ai/langsmith-sdk#3310</a></li> <li>fix: stop supported APIs from emitting nested deprecation warnings by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3308">langchain-ai/langsmith-sdk#3308</a></li> <li>chore: deprecate the run-sharing SDK methods by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3312">langchain-ai/langsmith-sdk#3312</a></li> <li>release(py): 0.10.15 by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3315">langchain-ai/langsmith-sdk#3315</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15</a></p> <h2>v0.10.14</h2> <h2>What's Changed</h2> <ul> <li>fix(sandbox): count an acknowledged reattachment as progress by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3301">langchain-ai/langsmith-sdk#3301</a></li> <li>feat(python): trace raw Gemini Live sessions by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3291">langchain-ai/langsmith-sdk#3291</a></li> <li>release(py): 0.10.14 by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3302">langchain-ai/langsmith-sdk#3302</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/3f9fe09d8e0698d65aa8bb63ac3316dfcb2ca947"><code>3f9fe09</code></a> release(py): 0.10.16 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3337">#3337</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/8c5d807dca1f25673bc95492ed9a04f3a6850a2c"><code>8c5d807</code></a> test(claude-agent-sdk): run subagent in foreground so trace nests correctly (...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/b34c68e3a87897f082da436d7f0ccd7d82fd5c9f"><code>b34c68e</code></a> docs(sandbox): fix invalid sizing example in JS sandbox README (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3335">#3335</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/446c78c7481b2d890db78636101aabe1a51acf90"><code>446c78c</code></a> fix: avoid resetting compression threads (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3332">#3332</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/cc9291a6852f13bdd732f466d61056e5b8a4d0c5"><code>cc9291a</code></a> fix(profiles): resolve the OAuth token endpoint from deployment metadata (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3333">#3333</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/1e70bf5c526a518916bd477f1c4e785a73a9f7d8"><code>1e70bf5</code></a> chore(deps): bump the py-minor-and-patch group across 1 directory with 25 upd...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/9b047e3ca79bd9b7dd633c2f0d750154713fbe8b"><code>9b047e3</code></a> fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3319">#3319</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/0a6256d636c1b824650e543c529ed46140322b32"><code>0a6256d</code></a> fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk integra...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/312a9f545764f0456f5d9e803aaa1e7c4bb8d164"><code>312a9f5</code></a> chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3331">#3331</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/2a81489e723df8f65593811171cca2d12d4f49df"><code>2a81489</code></a> chore(deps-dev): bump the py-major group in /python with 2 updates (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3323">#3323</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.6...v0.10.16">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1fb3b1a599 |
chore: bump langsmith from 0.10.6 to 0.10.16 in /libs/partners/fireworks (#39279)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from 0.10.6 to 0.10.16. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's releases</a>.</em></p> <blockquote> <h2>v0.10.16</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.8.9 by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3316">langchain-ai/langsmith-sdk#3316</a></li> <li>fix(python): mask metadata after the runtime env merge and via the anonymizer by <a href="https://github.com/vladislav-nechakhin"><code>@vladislav-nechakhin</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li> <li>fix(js): mask metadata after the runtime env merge and via the anonymizer by <a href="https://github.com/vladislav-nechakhin"><code>@vladislav-nechakhin</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3314">langchain-ai/langsmith-sdk#3314</a></li> <li>chore(deps-dev): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3325">langchain-ai/langsmith-sdk#3325</a></li> <li>chore(deps-dev): bump types-pyyaml from 6.0.12.20260518 to 6.0.12.20260724 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3324">langchain-ai/langsmith-sdk#3324</a></li> <li>chore(deps): bump the actions-major group with 2 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3321">langchain-ai/langsmith-sdk#3321</a></li> <li>chore(deps): bump the actions-minor-and-patch group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3320">langchain-ai/langsmith-sdk#3320</a></li> <li>chore(deps): bump the npm_and_yarn group across 3 directories with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3330">langchain-ai/langsmith-sdk#3330</a></li> <li>fix(js,py): stamp ls_agent_type on wrap_openai LLM runs by <a href="https://github.com/ybathula707"><code>@ybathula707</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3317">langchain-ai/langsmith-sdk#3317</a></li> <li>chore(deps): bump aiohttp from 3.14.1 to 3.14.3 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3329">langchain-ai/langsmith-sdk#3329</a></li> <li>chore(deps-dev): bump the py-major group in /python with 2 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3323">langchain-ai/langsmith-sdk#3323</a></li> <li>chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3331">langchain-ai/langsmith-sdk#3331</a></li> <li>fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk integration by <a href="https://github.com/ybathula707"><code>@ybathula707</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3318">langchain-ai/langsmith-sdk#3318</a></li> <li>fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper by <a href="https://github.com/ybathula707"><code>@ybathula707</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3319">langchain-ai/langsmith-sdk#3319</a></li> <li>chore(deps): bump the py-minor-and-patch group across 1 directory with 25 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3322">langchain-ai/langsmith-sdk#3322</a></li> <li>fix(profiles): resolve the OAuth token endpoint from deployment metadata by <a href="https://github.com/langchain-infra"><code>@langchain-infra</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3333">langchain-ai/langsmith-sdk#3333</a></li> <li>fix: avoid resetting compression threads by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3332">langchain-ai/langsmith-sdk#3332</a></li> <li>docs(sandbox): fix invalid sizing example in JS sandbox README by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3335">langchain-ai/langsmith-sdk#3335</a></li> <li>test(claude-agent-sdk): run subagent in foreground so trace nests correctly by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3339">langchain-ai/langsmith-sdk#3339</a></li> <li>release(py): 0.10.16 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3337">langchain-ai/langsmith-sdk#3337</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/vladislav-nechakhin"><code>@vladislav-nechakhin</code></a> made their first contribution in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16</a></p> <h2>v0.10.15</h2> <h2>What's Changed</h2> <ul> <li>fix(python): apply the caller-supplied session's config to v2 endpoints by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3304">langchain-ai/langsmith-sdk#3304</a></li> <li>chore: Use a common function for backend detection by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3307">langchain-ai/langsmith-sdk#3307</a></li> <li>fix: prioritize API key over OAuth profile auth [closes LSDK-414] by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3295">langchain-ai/langsmith-sdk#3295</a></li> <li>fix(js): apply caller-supplied headers to the v2 endpoints by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3305">langchain-ai/langsmith-sdk#3305</a></li> <li>chore: deprecate legacy SmithDB-migration SDK methods by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3299">langchain-ai/langsmith-sdk#3299</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3310">langchain-ai/langsmith-sdk#3310</a></li> <li>fix: stop supported APIs from emitting nested deprecation warnings by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3308">langchain-ai/langsmith-sdk#3308</a></li> <li>chore: deprecate the run-sharing SDK methods by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3312">langchain-ai/langsmith-sdk#3312</a></li> <li>release(py): 0.10.15 by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3315">langchain-ai/langsmith-sdk#3315</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15</a></p> <h2>v0.10.14</h2> <h2>What's Changed</h2> <ul> <li>fix(sandbox): count an acknowledged reattachment as progress by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3301">langchain-ai/langsmith-sdk#3301</a></li> <li>feat(python): trace raw Gemini Live sessions by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3291">langchain-ai/langsmith-sdk#3291</a></li> <li>release(py): 0.10.14 by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3302">langchain-ai/langsmith-sdk#3302</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/3f9fe09d8e0698d65aa8bb63ac3316dfcb2ca947"><code>3f9fe09</code></a> release(py): 0.10.16 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3337">#3337</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/8c5d807dca1f25673bc95492ed9a04f3a6850a2c"><code>8c5d807</code></a> test(claude-agent-sdk): run subagent in foreground so trace nests correctly (...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/b34c68e3a87897f082da436d7f0ccd7d82fd5c9f"><code>b34c68e</code></a> docs(sandbox): fix invalid sizing example in JS sandbox README (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3335">#3335</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/446c78c7481b2d890db78636101aabe1a51acf90"><code>446c78c</code></a> fix: avoid resetting compression threads (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3332">#3332</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/cc9291a6852f13bdd732f466d61056e5b8a4d0c5"><code>cc9291a</code></a> fix(profiles): resolve the OAuth token endpoint from deployment metadata (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3333">#3333</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/1e70bf5c526a518916bd477f1c4e785a73a9f7d8"><code>1e70bf5</code></a> chore(deps): bump the py-minor-and-patch group across 1 directory with 25 upd...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/9b047e3ca79bd9b7dd633c2f0d750154713fbe8b"><code>9b047e3</code></a> fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3319">#3319</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/0a6256d636c1b824650e543c529ed46140322b32"><code>0a6256d</code></a> fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk integra...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/312a9f545764f0456f5d9e803aaa1e7c4bb8d164"><code>312a9f5</code></a> chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3331">#3331</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/2a81489e723df8f65593811171cca2d12d4f49df"><code>2a81489</code></a> chore(deps-dev): bump the py-major group in /python with 2 updates (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3323">#3323</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.6...v0.10.16">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
8a78a812ec |
chore: bump cryptography from 48.0.1 to 50.0.0 in /libs/langchain (#39243)
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1 to 50.0.0. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's changelog</a>.</em></p> <blockquote> <p>50.0.0 - 2026-07-31</p> <pre><code> * **SECURITY ISSUE**: :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der` and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in :rfc:`3218`. Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247** * Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm. * Added ``xof()`` class methods to :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing algorithm instances configured for use with :class:`~cryptography.hazmat.primitives.hashes.XOFHash`. * The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now considered stable and are subject to our API stability policy. * Added the :doc:`/cobblestone` recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP chunked-encryption specification <https://c2sp.org/chunked-encryption>`_ for streaming authenticated encryption of large messages. * Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them. * Added support for using :class:`~cryptography.x509.Name` as a field type in the :doc:`/hazmat/asn1/index` module. * Loading a public key or an EC private key now rejects DER where the ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero number of unused bits, instead of silently ignoring it. * Parsing a CRL entry's ``InvalidityDate`` extension now rejects a ``GeneralizedTime`` that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field. * :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request or response whose ``version`` field is not ``v1``, the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs. * :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported when building against AWS-LC. * HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC. * Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported when building against AWS-LC. </tr></table> </code></pre> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc"><code>dcb7050</code></a> Prepare for 50.0.0 release (<a href="https://redirect.github.com/pyca/cryptography/issues/15372">#15372</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"><code>53fccd9</code></a> Don't leak how PKCS#7 encryptedKey decryption failed (<a href="https://redirect.github.com/pyca/cryptography/issues/15369">#15369</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8"><code>d472f97</code></a> Add <code>from __future__ import annotations</code> to all src/ Python files (<a href="https://redirect.github.com/pyca/cryptography/issues/15371">#15371</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a"><code>908773d</code></a> Bump downstream dependencies in CI (<a href="https://redirect.github.com/pyca/cryptography/issues/15368">#15368</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812"><code>2cc07cc</code></a> Bump BoringSSL, OpenSSL, AWS-LC in CI (<a href="https://redirect.github.com/pyca/cryptography/issues/15367">#15367</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66"><code>c94ede9</code></a> chore(deps): bump ruff from 0.16.0 to 0.16.1 (<a href="https://redirect.github.com/pyca/cryptography/issues/15366">#15366</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35"><code>67a8308</code></a> chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (<a href="https://redirect.github.com/pyca/cryptography/issues/15365">#15365</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596"><code>95018ff</code></a> Release the GIL in one-shot AEAD encrypt/decrypt (<a href="https://redirect.github.com/pyca/cryptography/issues/15361">#15361</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02"><code>6954733</code></a> Release the GIL during DH and DSA parameter generation (<a href="https://redirect.github.com/pyca/cryptography/issues/15364">#15364</a>)</li> <li><a href="https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6"><code>6893b94</code></a> Import _serialization instead of serialization in x509/extensions (<a href="https://redirect.github.com/pyca/cryptography/issues/15363">#15363</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pyca/cryptography/compare/48.0.1...50.0.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ff3425ae48 |
chore: bump aiohttp from 3.14.1 to 3.14.3 in /libs/langchain_v1 (#39242)
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to 3.14.3. Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |