Aran Yogesh
2039fe6660
feat: stop auto-cloning and let agent manage repo setup [closes OPE-21] ( #1159 )
...
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* removing logger.info
* formatting and linting
* fix: resolve lint errors in server.py (imports, unused vars, undefined names)
* feat: use opaque proxy headers for GitHub auth in sandbox
* linting formatting and test changes
* linting
* Delete .claude directory
* Delete tests/evals directory
* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests
* fix: restore authorship, branch_name support, and installation token for PR creation
* linitng
* fix: move installation token fetch before commit, clean up dead proxy validation code
* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]
* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]
* fix: address review feedback — restore agents_md, add git user config, lint fixes
* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config
* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config
* linting
* linting
* feat: add installation token auth to list_repos GitHub API call
* agents.md update
* linting
* fix: address PR review feedback — shell precedence bug in prompt, remove dead code
* linting
* Apply suggestion from @bracesproul
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Apply suggestion from @bracesproul
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* fix: address PR review feedback — restore {working_dir} in prompt, remove clone code block
* fix:Extract check_or_recreate_sandbox utility from inline sandbox health check
* fix: address PR review feedback — async list_repos, restore template name, fix prompt colon
* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
* linting
* yogesh/ope-21-stop-auto-cloning
* Update agent/tools/list_repos.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Update agent/prompt.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* feat: address PR review — list_repos uses GitHub API only, PR trigger includes org/repo
* linting
* feat: address PR review feedback — list_repos pagination, simpler return, sandbox health check
* feat: support listing repos for personal user accounts via is_organization flag
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-10 17:04:55 -07:00
Aran Yogesh
91f63de361
fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures ( #1178 )
...
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures
* function name change
2026-04-09 14:59:49 -07:00
Aran Yogesh
67c782c295
fix: block open-swe from approving PRs ( #1177 )
...
* fix: block open-swe from approving PRs
* linting
* fix: add case-insensitive APPROVE guard and unit tests
2026-04-09 11:45:08 -07:00
Aran Yogesh
4d4f5fbfc7
fix: proxy config restored the branch yogesh/GitHub auth proxy ( #1173 )
...
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* removing logger.info
* formatting and linting
* fix: resolve lint errors in server.py (imports, unused vars, undefined names)
* feat: use opaque proxy headers for GitHub auth in sandbox
* linting formatting and test changes
* linting
* Delete .claude directory
* Delete tests/evals directory
* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests
* fix: restore authorship, branch_name support, and installation token for PR creation
* linitng
* fix: move installation token fetch before commit, clean up dead proxy validation code
* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config
* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config
* linting
* linting
* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-08 15:02:52 -07:00
Aran Yogesh
9e5088b75a
Revert "feat: add minimal diff rules and scope planning to agent prompt ( #1171 )" ( #1174 )
...
This reverts commit 71b573625c .
2026-04-08 15:00:43 -07:00
Aran Yogesh
71b573625c
feat: add minimal diff rules and scope planning to agent prompt ( #1171 )
2026-04-08 14:56:34 -07:00
Aran Yogesh
9aba4d0545
Revert "feat: authenticate git operations via sandbox proxy instead of creden…" ( #1170 )
...
This reverts commit 6305e13dc6 .
2026-04-07 18:45:33 -07:00
Brace Sproul
c5ba4e2e93
Revert "fix: add retry with delay for sandbox proxy config to avoid 500 when …" ( #1169 )
...
This reverts commit e25b158218 .
2026-04-07 18:37:15 -07:00
Aran Yogesh
e25b158218
fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready ( #1168 )
...
* fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready
* fix: add retry with exponential backoff and connection error handling for proxy config
2026-04-07 17:57:21 -07:00
Aran Yogesh
6305e13dc6
feat: authenticate git operations via sandbox proxy instead of credential files [closes: OPE-20] ( #1070 )
...
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* removing logger.info
* formatting and linting
* fix: resolve lint errors in server.py (imports, unused vars, undefined names)
* feat: use opaque proxy headers for GitHub auth in sandbox
* linting formatting and test changes
* linting
* Delete .claude directory
* Delete tests/evals directory
* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests
* fix: restore authorship, branch_name support, and installation token for PR creation
* linitng
* fix: move installation token fetch before commit, clean up dead proxy validation code
* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config
* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config
* linting
* linting
* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-07 16:41:48 -07:00
open-swe[bot]
24a6343352
chore: upgrade deepagents to v0.5.0a4 ( #1161 )
...
Replace custom LangSmithBackend with built-in LangSmithSandbox from
deepagents. Update deprecated protocol method names in docs.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Sydney Runkle <54324534+sydney-runkle@users.noreply.github.com>
2026-04-06 10:24:50 -07:00
John Kennedy
d3506598fe
fix: upgrade deps to patch Pygments ReDoS and PyJWT crit header vulns ( #1164 )
...
- Bump deepagents >=0.4.3 → >=0.4.12
- Bump PyJWT >=2.8.0 → >=2.12.0 (fixes CVE-2026-32597, GHSA-752w-5fwx-jx9f)
- Pin Pygments >=2.20.0 in dev deps (fixes CVE-2026-4539, GHSA-5239-wwwm-4pmq)
- Regenerate uv.lock (also pulls langchain 1.2.15, langgraph 1.1.6)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 20:42:51 -07:00
dependabot[bot]
924c096782
chore(deps): bump aiohttp in the uv group across 1 directory ( #1158 )
...
---
updated-dependencies:
- dependency-name: aiohttp
dependency-version: 3.13.4
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:19:49 -07:00
mlo20030
4a4bb37d45
adding myself as user ( #1162 )
2026-04-03 15:52:04 -07:00
Brace Sproul
fd8e6d98ee
fix: Shell injection and ssrf issues ( #1155 )
...
* fix: Shell injection and ssrf issues
* cr
2026-04-01 12:37:35 -07:00
dependabot[bot]
4856cc31d4
chore(deps): bump the uv group across 1 directory with 3 updates ( #1152 )
...
Bumps the uv group with 3 updates in the / directory: [cryptography](https://github.com/pyca/cryptography ), [langchain-core](https://github.com/langchain-ai/langchain ) and [requests](https://github.com/psf/requests ).
Updates `cryptography` from 46.0.5 to 46.0.6
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6 )
Updates `langchain-core` from 1.2.15 to 1.2.22
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.15...langchain-core==1.2.22 )
Updates `requests` from 2.32.5 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases )
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md )
- [Commits](https://github.com/psf/requests/compare/v2.32.5...v2.33.0 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.6
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.2.22
dependency-type: indirect
dependency-group: uv
- dependency-name: requests
dependency-version: 2.33.0
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 23:33:28 -07:00
dependabot[bot]
1bc4afc05d
chore(deps): bump cbor2 in the uv group across 1 directory ( #1120 )
...
Bumps the uv group with 1 update in the / directory: [cbor2](https://github.com/agronholm/cbor2 ).
Updates `cbor2` from 5.8.0 to 5.9.0
- [Release notes](https://github.com/agronholm/cbor2/releases )
- [Commits](https://github.com/agronholm/cbor2/compare/5.8.0...5.9.0 )
---
updated-dependencies:
- dependency-name: cbor2
dependency-version: 5.9.0
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 01:58:27 -07:00
Aran Yogesh
86307affe4
fix: use GitHub App installation token for PR creation instead of user token ( #1149 )
...
* fix: use GitHub App installation token for PR creation instead of user token
* fix: move installation token fetch after no-changes check to avoid unnecessary API call
2026-03-30 12:47:57 -07:00
Aran Yogesh
7d1004ad66
fix: add Exa web search tool [closes: OPE-29] ( #1133 )
...
* fix: add Exa web search tool
* chore: update uv.lock for exa-py dependency
* linting
* chore: remove web_search from system prompt
* chore: drop search_type and category params from web_search
2026-03-25 16:24:31 -07:00
Brace Sproul
87968ab813
fix: Add scripts for getting usage, fix dual committing ( #1131 )
2026-03-25 13:39:33 -07:00
Brace Sproul
0d8647c2cd
fix: Revert dummy readme change ( #1132 )
2026-03-25 13:35:11 -07:00
Brace Sproul
4cfe2fd8a5
chore: dummy readme change to test committing workflow ( #1130 )
...
* chore: dummy readme change to test committing workflow
Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>
* cr
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 13:34:08 -07:00
Brace Sproul
e1de58c584
fix: convert @Name(USER_ID) mentions to Slack's <@USER_ID> format in thread replies ( #1126 )
...
The agent sees users formatted as @Name(USER_ID) in conversation context and
reproduces that pattern in replies, but Slack requires <@USER_ID> for real
mentions. This adds automatic conversion and updates prompt instructions.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:51:11 -07:00
Brace Sproul
3fea3c8709
feat: read LLM model ID from LLM_MODEL_ID env var, defaulting to anthropic:claude-opus-4-6 ( #1128 )
...
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:32:44 -07:00
Brace Sproul
267b2fd011
feat: add github pr review tools [closes OPE-24] ( #1104 )
...
* Add GitHub PR review tools (list, get, create, update, dismiss, submit, list comments) and bind them to the agent
* format n lint
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Aran Yogesh <yogesh.mahendran@langchain.dev>
2026-03-23 21:37:54 +00:00
Brace Sproul
91348aeb7c
feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments ( #1105 )
...
Adds 6 new agent tools backed by Linear's GraphQL API, with a shared
_graphql_request helper to reduce boilerplate. Refactors existing
comment_on_linear_issue to use the same helper.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-23 14:32:44 -07:00
Aran Yogesh
f79e824d8e
feat: add Slack image support with url_private auth and content-type validation [closes: OPE-23] ( #1073 )
...
* feat: add Slack image support with url_private auth and content-type validation
* fix: simplify Slack image fetch by removing manual redirect logic
* fix: use urlparse hostname check to resolve CodeQL URL sanitization warning
* Update agent/utils/multimodal.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* fix: simplify host matching conditions in multimodal image fetching
* reverting changes
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-20 14:34:14 -07:00
Brace Sproul
46d7ed9d43
feat: extract repo parsing into shared util, add linear comment repo override ( #1103 )
...
* feat: extract repo parsing into shared util and add linear comment repo override
Moves the repo extraction regex logic (repo:, repo , GitHub URL) into
agent/utils/repo.py so it can be reused. Updates the Linear webhook
handler to check the comment body for a custom repo first, falling back
to the team/project mapping when none is specified.
* chore: document repo extraction util and default org configuration
* feat: add generic DEFAULT_REPO_OWNER/DEFAULT_REPO_NAME env vars replacing Slack-only defaults
* chore: remove deprecated SLACK_REPO_OWNER/NAME env vars from docs
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 13:34:00 -07:00
Aran Yogesh
6fc82d9edd
feat: default org to langchain-ai when repo name specified without org ( #1099 )
...
* feat: default org to langchain-ai when repo: is used without org prefix
* chore: use SLACK_REPO_OWNER for repo shorthand default org and document in CUSTOMIZATION.md
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 12:05:30 -07:00
Aran Yogesh
150ff6f0c8
fix: allow open-swe to be triggered on any GitHuh branch ( #1100 )
...
* fix: allow open-swe to be triggered on any GitHuh branch
* formmatting
2026-03-20 10:53:33 -07:00
Aran Yogesh
ea27978d51
fix: queue Slack follow-up messages instead of interrupting active runs ( #1050 )
...
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-19 13:59:25 -07:00
Brace Sproul
352f787989
fix: log all exceptions ( #1089 )
2026-03-19 10:26:26 -07:00
dependabot[bot]
075e163746
chore(deps): bump pyasn1 in the uv group across 1 directory ( #1078 )
...
Bumps the uv group with 1 update in the / directory: [pyasn1](https://github.com/pyasn1/pyasn1 ).
Updates `pyasn1` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/pyasn1/pyasn1/releases )
- [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst )
- [Commits](https://github.com/pyasn1/pyasn1/compare/v0.6.2...v0.6.3 )
---
updated-dependencies:
- dependency-name: pyasn1
dependency-version: 0.6.3
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-18 21:40:10 -07:00
dependabot[bot]
64b41b4f8b
chore(deps): bump the uv group across 1 directory with 2 updates ( #1031 )
...
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography ) and [langgraph](https://github.com/langchain-ai/langgraph ).
Updates `cryptography` from 46.0.4 to 46.0.5
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.4...46.0.5 )
Updates `langgraph` from 1.0.8 to 1.0.10rc1
- [Release notes](https://github.com/langchain-ai/langgraph/releases )
- [Commits](https://github.com/langchain-ai/langgraph/compare/1.0.8...1.0.10rc1 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.5
dependency-type: direct:production
dependency-group: uv
- dependency-name: langgraph
dependency-version: 1.0.10rc1
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-19 04:36:43 +00:00
Aran Yogesh
b64d871913
feat: send LangSmith trace URL on run trigger from Slack and Linear ( #1057 )
...
* feat: send LangSmith trace URL on run trigger from Slack and Linear
* fix: check LANGSMITH_PROJECT before LANGSMITH_PROJECT_PROD for project name lookup
* fix: pass LangSmith API key explicitly to Client and remove global variable
* Update agent/utils/langsmith.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* refactor: move trace notification helpers out of webapp and use env vars for LangSmith URL base
* docs: add LangSmith tenant and project ID env vars to installation guide
* fix: remove unused comment_on_linear_issue import from webapp
* nit: remove lru_cache, make get_langsmith_trace_url sync, and move langsmith import to top level
* Update INSTALLATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Update INSTALLATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Update INSTALLATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-18 12:17:45 -07:00
Brace Sproul
d7d9bc5179
fix: better custom backend support ( #1071 )
...
* fix: better custom backend support
* cr
2026-03-17 11:55:36 -07:00
Mason Daugherty
d524e3ba92
chore: add badges and tagline to readme header ( #1069 )
...
* Add badges, tagline, and ecosystem links to README header
* Match README header syntax exactly to langchain-ai/langchain repo style
* Apply suggestion from @mdrxy
Co-authored-by: Mason Daugherty <github@mdrxy.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-17 18:25:48 +00:00
Palash Shah
3e64399d13
feat: inject LANGSMITH_AGENT_VERSION metadata into all run creation calls ( #1066 )
...
Reads LANGCHAIN_REVISION_ID env var (set by LSD from LANGSMITH_LANGGRAPH_GIT_REF_SHA)
and injects it as LANGSMITH_AGENT_VERSION metadata on every runs.create() call.
This enables the agent_deployments sync job to track which agent version produced each trace.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-17 10:49:32 -07:00
Brace Sproul
633d80bf0e
fix: Add back logo to readme ( #1068 )
2026-03-17 10:41:41 -07:00
Brace Sproul
82e2bcc94b
chore: Update announcement blog post link in README ( #1067 )
2026-03-17 10:38:51 -07:00
Brace Sproul
226ddde8a6
chore: Update debug log to error log ( #1064 )
2026-03-16 16:22:00 -07:00
Aran Yogesh
c2af14383b
fix: skip full test suite in sandbox, run only task-related tests ( #1058 )
2026-03-16 12:05:43 -07:00
Brace Sproul
3e73447920
fix: better docs, github auth ( #1055 )
...
* fix: Update github auth methods
* cr
2026-03-11 22:57:56 -08:00
agent-forge-app[bot]
ebfa8eb388
fix: extend Slack repo detection to support space syntax and GitHub URLs ( #1046 )
...
`get_slack_repo_config` previously only matched `repo:owner/name` (colon).
Messages using `repo owner/name` (space) or containing a GitHub URL like
`https://github.com/langchain-ai/langgraph-api ` fell back to the default
repo. This extends the detection with both patterns — additive, no existing
behavior changed.
Co-authored-by: Forge Agent <forge-agent@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-10 13:33:05 -07:00
agent-forge-app[bot]
d98cd9ddc1
fix: skip no_op injection when PR is committed and user is notified ( #1047 )
...
* fix: skip no_op injection when PR is committed and user is notified
- Root cause: ensure_no_empty_msg Branch 1 (empty AI message) lacked the
same completion checks as Branch 2 (text-only AI message), causing a
spurious no_op injection after commit_and_open_pr + user notification
- Change: add check_if_model_already_called_commit_and_open_pr AND
check_if_model_messaged_user guard to Branch 1 of ensure_no_empty_msg
- Verified: 7/100 production traces no longer get an extra LLM call
* updated
* pass tests
---------
Co-authored-by: Auto Fix Bot <auto-fix@langchain.ai>
Co-authored-by: Palash Shah <palash@langchain.dev>
Co-authored-by: Palash Shah <35114859+Palashio@users.noreply.github.com>
2026-03-10 12:56:44 -07:00
Aran Yogesh
2f38484451
email-update ( #1048 )
2026-03-10 11:28:34 -07:00
Brace Sproul
6f04cea26c
chore: Add langsmith deployments data plane linear project ( #1044 )
...
* chore: Add langsmith deployments data plane linear project
* cr
2026-03-09 18:36:00 -07:00
Aran Yogesh
b735afb445
feat: add GitHub PR comment trigger and reply support [closes OPE-1] ( #1014 )
...
* feat: add GitHub PR comment trigger and reply support
* refactor: improve readability of GitHub integration
* linting
* fix: resolve github token from thread metadata and improve PR trigger flow
* fix: fall back to OAuth for GitHub webhook when no token in thread metadata
* give me commit message github integeration working without a breaking
* auth.py refactor
* fix: validate cached GitHub token before use to handle expiry
* liniting
* ci unitest formatting
* feat: post PR comments as GitHub App bot instead of user OAuth token
* resolved comments
* slack resolveed comments
* Refactor docstring and comments in get_slack_repo_config
Removed unnecessary comments and cleaned up docstring formatting.
* cr
* cr
* cr
* cr
---------
Co-authored-by: bracesproul <braceasproul@gmail.com>
2026-03-09 17:14:13 -07:00
Brace Sproul
9763835873
fix: Slack tests ( #1032 )
2026-03-09 12:10:41 -07:00
Harrison Chase
da5c0f36f6
cr
2026-03-07 13:24:22 -08:00