Commit graph

644 commits

Author SHA1 Message Date
Aran Yogesh
301d124c3d
fix: remove deprecated temperature parameter (#1207)
for Opus 4.7 compatibility
2026-04-17 10:45:01 -07:00
dependabot[bot]
213473dc08
chore(deps): bump the minor-and-patch group with 11 updates (#1198)
Bumps the minor-and-patch group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [deepagents](https://github.com/langchain-ai/deepagents) | `0.5.0a4` | `0.5.3` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.128.3` | `0.135.3` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.44.0` |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.3.4` | `0.3.13` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.7.31` | `0.7.32` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.10` | `1.1.13` |
| [langchain-daytona](https://github.com/langchain-ai/deepagents) | `0.0.3` | `0.0.5` |
| [langchain-modal](https://github.com/langchain-ai/deepagents) | `0.0.2` | `0.0.3` |
| [langchain-runloop](https://github.com/langchain-ai/deepagents) | `0.0.3` | `0.0.4` |
| [exa-py](https://github.com/exa-labs/exa-py) | `2.10.1` | `2.12.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.0` | `0.15.10` |


Updates `deepagents` from 0.5.0a4 to 0.5.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/deepagents==0.5.0a4...deepagents==0.5.3)

Updates `fastapi` from 0.128.3 to 0.135.3
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.128.3...0.135.3)

Updates `uvicorn` from 0.40.0 to 0.44.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.40.0...0.44.0)

Updates `langgraph-sdk` from 0.3.4 to 0.3.13
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/0.3.4...0.3.13)

Updates `langsmith` from 0.7.31 to 0.7.32
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.31...v0.7.32)

Updates `langchain-openai` from 1.1.10 to 1.1.13
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.1.10...langchain-openai==1.1.13)

Updates `langchain-daytona` from 0.0.3 to 0.0.5
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-daytona==0.0.3...langchain-daytona==0.0.5)

Updates `langchain-modal` from 0.0.2 to 0.0.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-modal==0.0.2...langchain-modal==0.0.3)

Updates `langchain-runloop` from 0.0.3 to 0.0.4
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-runloop==0.0.3...langchain-runloop==0.0.4)

Updates `exa-py` from 2.10.1 to 2.12.0
- [Commits](https://github.com/exa-labs/exa-py/commits)

Updates `ruff` from 0.15.0 to 0.15.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.15.0...0.15.10)

---
updated-dependencies:
- dependency-name: deepagents
  dependency-version: 0.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: fastapi
  dependency-version: 0.135.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: uvicorn
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langgraph-sdk
  dependency-version: 0.3.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langsmith
  dependency-version: 0.7.32
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.1.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-daytona
  dependency-version: 0.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-modal
  dependency-version: 0.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-runloop
  dependency-version: 0.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: exa-py
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ruff
  dependency-version: 0.15.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 07:09:02 +00:00
dependabot[bot]
c0c5125912
chore(deps): bump python in the minor-and-patch group (#1195)
Bumps the minor-and-patch group with 1 update: python.


Updates `python` from 3.12.12-slim-trixie to 3.14.0-slim-trixie

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14.0-slim-trixie
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:56 -07:00
dependabot[bot]
aee6f20627
chore(deps): update langgraph-cli[inmem] requirement (#1199)
Updates the requirements on [langgraph-cli[inmem]](https://github.com/langchain-ai/langgraph) to permit the latest version.
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/cli==0.4.12...cli==0.4.21)

---
updated-dependencies:
- dependency-name: langgraph-cli[inmem]
  dependency-version: 0.4.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:19 -07:00
dependabot[bot]
d2042bfefd
chore(deps): bump astral-sh/setup-uv from 4.2.0 to 8.0.0 (#1196)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 4.2.0 to 8.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](38f3f10444...cec208311d)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:45:46 -07:00
dependabot[bot]
8ae4179378
chore(deps): bump amannn/action-semantic-pull-request from 5 to 6 (#1197)
Bumps [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) from 5 to 6.
- [Release notes](https://github.com/amannn/action-semantic-pull-request/releases)
- [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md)
- [Commits](e32d7e603d...48f256284b)

---
updated-dependencies:
- dependency-name: amannn/action-semantic-pull-request
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:41:08 -07:00
dependabot[bot]
9219912068
chore(deps): bump actions/checkout from 4 to 6 (#1194)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:37:03 -07:00
John Kennedy
a94fb8b94c
ci: SHA-pin third-party actions in workflow files (#1193)
Pin astral-sh/setup-uv and amannn/action-semantic-pull-request to
full commit SHAs to prevent supply chain attacks via tag hijacking.
2026-04-15 23:36:07 -07:00
John Kennedy
da11bcdf60
chore: add dependabot.yml with uv, docker, and github-actions coverage (#1192)
Adds a compliant dependabot configuration covering all detected
ecosystems with monthly schedule and grouped update-type splits.
2026-04-15 23:35:42 -07:00
dependabot[bot]
32eecbcee2
chore(deps): bump the uv group across 1 directory with 3 updates (#1191)
Bumps the uv group with 3 updates in the / directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk), [pytest](https://github.com/pytest-dev/pytest) and [python-multipart](https://github.com/Kludex/python-multipart).


Updates `langsmith` from 0.7.25 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.25...v0.7.31)

Updates `pytest` from 9.0.2 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.0.3)

Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases)
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26)

---
updated-dependencies:
- dependency-name: langsmith
  dependency-version: 0.7.31
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: pytest
  dependency-version: 9.0.3
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: python-multipart
  dependency-version: 0.0.26
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:31:23 -07:00
dependabot[bot]
db29b6cad1
chore(deps): bump the uv group across 1 directory with 2 updates (#1176)
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [langchain-core](https://github.com/langchain-ai/langchain).


Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7)

Updates `langchain-core` from 1.2.22 to 1.2.28
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.22...langchain-core==1.2.28)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: langchain-core
  dependency-version: 1.2.28
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 22:40:37 -07:00
Aran Yogesh
6049405aed
feat: add configurable default prompt file for org-level agent instructions [close OPE-36] (#1187)
* feat: add configurable default prompt file for org-level agent instructions

* linting

* Update CUSTOMIZATION.md

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: address PR review feedback on default prompt

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-15 15:18:14 -07:00
Aran Yogesh
2039fe6660
feat: stop auto-cloning and let agent manage repo setup [closes OPE-21] (#1159)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]

* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]

* fix: address review feedback — restore agents_md, add git user config, lint fixes

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* feat: add installation token auth to list_repos GitHub API call

* agents.md update

* linting

* fix: address PR review feedback — shell precedence bug in prompt, remove dead code

* linting

* Apply suggestion from @bracesproul

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Apply suggestion from @bracesproul

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: address PR review feedback — restore {working_dir} in prompt, remove clone code block

* fix:Extract check_or_recreate_sandbox utility from inline sandbox health check

* fix: address PR review feedback — async list_repos, restore template name, fix prompt colon

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox

* linting

* yogesh/ope-21-stop-auto-cloning

* Update agent/tools/list_repos.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Update agent/prompt.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* feat: address PR review — list_repos uses GitHub API only, PR trigger includes org/repo

* linting

* feat: address PR review feedback — list_repos pagination, simpler return, sandbox health check

* feat: support listing repos for personal user accounts via is_organization flag

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-10 17:04:55 -07:00
Aran Yogesh
91f63de361
fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures (#1178)
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures

* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures

* function name change
2026-04-09 14:59:49 -07:00
Aran Yogesh
67c782c295
fix: block open-swe from approving PRs (#1177)
* fix: block open-swe from approving PRs

* linting

* fix: add case-insensitive APPROVE guard and unit tests
2026-04-09 11:45:08 -07:00
Aran Yogesh
4d4f5fbfc7
fix: proxy config restored the branch yogesh/GitHub auth proxy (#1173)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-08 15:02:52 -07:00
Aran Yogesh
9e5088b75a
Revert "feat: add minimal diff rules and scope planning to agent prompt (#1171)" (#1174)
This reverts commit 71b573625c.
2026-04-08 15:00:43 -07:00
Aran Yogesh
71b573625c
feat: add minimal diff rules and scope planning to agent prompt (#1171) 2026-04-08 14:56:34 -07:00
Aran Yogesh
9aba4d0545
Revert "feat: authenticate git operations via sandbox proxy instead of creden…" (#1170)
This reverts commit 6305e13dc6.
2026-04-07 18:45:33 -07:00
Brace Sproul
c5ba4e2e93
Revert "fix: add retry with delay for sandbox proxy config to avoid 500 when …" (#1169)
This reverts commit e25b158218.
2026-04-07 18:37:15 -07:00
Aran Yogesh
e25b158218
fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready (#1168)
* fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready

* fix: add retry with exponential backoff and connection error handling for proxy config
2026-04-07 17:57:21 -07:00
Aran Yogesh
6305e13dc6
feat: authenticate git operations via sandbox proxy instead of credential files [closes: OPE-20] (#1070)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-07 16:41:48 -07:00
open-swe[bot]
24a6343352
chore: upgrade deepagents to v0.5.0a4 (#1161)
Replace custom LangSmithBackend with built-in LangSmithSandbox from
deepagents. Update deprecated protocol method names in docs.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Sydney Runkle <54324534+sydney-runkle@users.noreply.github.com>
2026-04-06 10:24:50 -07:00
John Kennedy
d3506598fe
fix: upgrade deps to patch Pygments ReDoS and PyJWT crit header vulns (#1164)
- Bump deepagents >=0.4.3 → >=0.4.12
- Bump PyJWT >=2.8.0 → >=2.12.0 (fixes CVE-2026-32597, GHSA-752w-5fwx-jx9f)
- Pin Pygments >=2.20.0 in dev deps (fixes CVE-2026-4539, GHSA-5239-wwwm-4pmq)
- Regenerate uv.lock (also pulls langchain 1.2.15, langgraph 1.1.6)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 20:42:51 -07:00
dependabot[bot]
924c096782
chore(deps): bump aiohttp in the uv group across 1 directory (#1158)
---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.13.4
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:19:49 -07:00
mlo20030
4a4bb37d45
adding myself as user (#1162) 2026-04-03 15:52:04 -07:00
Brace Sproul
fd8e6d98ee
fix: Shell injection and ssrf issues (#1155)
* fix: Shell injection and ssrf issues

* cr
2026-04-01 12:37:35 -07:00
dependabot[bot]
4856cc31d4
chore(deps): bump the uv group across 1 directory with 3 updates (#1152)
Bumps the uv group with 3 updates in the / directory: [cryptography](https://github.com/pyca/cryptography), [langchain-core](https://github.com/langchain-ai/langchain) and [requests](https://github.com/psf/requests).


Updates `cryptography` from 46.0.5 to 46.0.6
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6)

Updates `langchain-core` from 1.2.15 to 1.2.22
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.15...langchain-core==1.2.22)

Updates `requests` from 2.32.5 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.6
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: langchain-core
  dependency-version: 1.2.22
  dependency-type: indirect
  dependency-group: uv
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 23:33:28 -07:00
dependabot[bot]
1bc4afc05d
chore(deps): bump cbor2 in the uv group across 1 directory (#1120)
Bumps the uv group with 1 update in the / directory: [cbor2](https://github.com/agronholm/cbor2).


Updates `cbor2` from 5.8.0 to 5.9.0
- [Release notes](https://github.com/agronholm/cbor2/releases)
- [Commits](https://github.com/agronholm/cbor2/compare/5.8.0...5.9.0)

---
updated-dependencies:
- dependency-name: cbor2
  dependency-version: 5.9.0
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 01:58:27 -07:00
Aran Yogesh
86307affe4
fix: use GitHub App installation token for PR creation instead of user token (#1149)
* fix: use GitHub App installation token for PR creation instead of user token

* fix: move installation token fetch after no-changes check to avoid unnecessary API call
2026-03-30 12:47:57 -07:00
Aran Yogesh
7d1004ad66
fix: add Exa web search tool [closes: OPE-29] (#1133)
* fix: add Exa web search tool

* chore: update uv.lock for exa-py dependency

* linting

* chore: remove web_search from system prompt

* chore: drop search_type and category params from web_search
2026-03-25 16:24:31 -07:00
Brace Sproul
87968ab813
fix: Add scripts for getting usage, fix dual committing (#1131) 2026-03-25 13:39:33 -07:00
Brace Sproul
0d8647c2cd
fix: Revert dummy readme change (#1132) 2026-03-25 13:35:11 -07:00
Brace Sproul
4cfe2fd8a5
chore: dummy readme change to test committing workflow (#1130)
* chore: dummy readme change to test committing workflow

Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>

* cr

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 13:34:08 -07:00
Brace Sproul
e1de58c584
fix: convert @Name(USER_ID) mentions to Slack's <@USER_ID> format in thread replies (#1126)
The agent sees users formatted as @Name(USER_ID) in conversation context and
reproduces that pattern in replies, but Slack requires <@USER_ID> for real
mentions. This adds automatic conversion and updates prompt instructions.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:51:11 -07:00
Brace Sproul
3fea3c8709
feat: read LLM model ID from LLM_MODEL_ID env var, defaulting to anthropic:claude-opus-4-6 (#1128)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:32:44 -07:00
Brace Sproul
267b2fd011
feat: add github pr review tools [closes OPE-24] (#1104)
* Add GitHub PR review tools (list, get, create, update, dismiss, submit, list comments) and bind them to the agent

* format n lint

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Aran Yogesh <yogesh.mahendran@langchain.dev>
2026-03-23 21:37:54 +00:00
Brace Sproul
91348aeb7c
feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105)
Adds 6 new agent tools backed by Linear's GraphQL API, with a shared
_graphql_request helper to reduce boilerplate. Refactors existing
comment_on_linear_issue to use the same helper.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-23 14:32:44 -07:00
Aran Yogesh
f79e824d8e
feat: add Slack image support with url_private auth and content-type validation [closes: OPE-23] (#1073)
* feat: add Slack image support with url_private auth and content-type validation

* fix: simplify Slack image fetch by removing manual redirect logic

* fix: use urlparse hostname check to resolve CodeQL URL sanitization warning

* Update agent/utils/multimodal.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: simplify host matching conditions in multimodal image fetching

* reverting changes

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-20 14:34:14 -07:00
Brace Sproul
46d7ed9d43
feat: extract repo parsing into shared util, add linear comment repo override (#1103)
* feat: extract repo parsing into shared util and add linear comment repo override

Moves the repo extraction regex logic (repo:, repo , GitHub URL) into
agent/utils/repo.py so it can be reused. Updates the Linear webhook
handler to check the comment body for a custom repo first, falling back
to the team/project mapping when none is specified.

* chore: document repo extraction util and default org configuration

* feat: add generic DEFAULT_REPO_OWNER/DEFAULT_REPO_NAME env vars replacing Slack-only defaults

* chore: remove deprecated SLACK_REPO_OWNER/NAME env vars from docs

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 13:34:00 -07:00
Aran Yogesh
6fc82d9edd
feat: default org to langchain-ai when repo name specified without org (#1099)
* feat: default org to langchain-ai when repo: is used without org prefix

* chore: use SLACK_REPO_OWNER for repo shorthand default org and document in CUSTOMIZATION.md

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 12:05:30 -07:00
Aran Yogesh
150ff6f0c8
fix: allow open-swe to be triggered on any GitHuh branch (#1100)
* fix: allow open-swe to be triggered on any GitHuh branch

* formmatting
2026-03-20 10:53:33 -07:00
Aran Yogesh
ea27978d51
fix: queue Slack follow-up messages instead of interrupting active runs (#1050)
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-19 13:59:25 -07:00
Brace Sproul
352f787989
fix: log all exceptions (#1089) 2026-03-19 10:26:26 -07:00
dependabot[bot]
075e163746
chore(deps): bump pyasn1 in the uv group across 1 directory (#1078)
Bumps the uv group with 1 update in the / directory: [pyasn1](https://github.com/pyasn1/pyasn1).


Updates `pyasn1` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/pyasn1/pyasn1/releases)
- [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst)
- [Commits](https://github.com/pyasn1/pyasn1/compare/v0.6.2...v0.6.3)

---
updated-dependencies:
- dependency-name: pyasn1
  dependency-version: 0.6.3
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-18 21:40:10 -07:00
dependabot[bot]
64b41b4f8b
chore(deps): bump the uv group across 1 directory with 2 updates (#1031)
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [langgraph](https://github.com/langchain-ai/langgraph).


Updates `cryptography` from 46.0.4 to 46.0.5
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.4...46.0.5)

Updates `langgraph` from 1.0.8 to 1.0.10rc1
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/1.0.8...1.0.10rc1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.5
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: langgraph
  dependency-version: 1.0.10rc1
  dependency-type: direct:production
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-19 04:36:43 +00:00
Aran Yogesh
b64d871913
feat: send LangSmith trace URL on run trigger from Slack and Linear (#1057)
* feat: send LangSmith trace URL on run trigger from Slack and Linear

* fix: check LANGSMITH_PROJECT before LANGSMITH_PROJECT_PROD for project name lookup

* fix: pass LangSmith API key explicitly to Client and remove global variable

* Update agent/utils/langsmith.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* refactor: move trace notification helpers out of webapp and use env vars for LangSmith URL base

* docs: add LangSmith tenant and project ID env vars to installation guide

* fix: remove unused comment_on_linear_issue import from webapp

* nit: remove lru_cache, make get_langsmith_trace_url sync, and move langsmith import to top level

* Update INSTALLATION.md

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Update INSTALLATION.md

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Update INSTALLATION.md

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-18 12:17:45 -07:00
Brace Sproul
d7d9bc5179
fix: better custom backend support (#1071)
* fix: better custom backend support

* cr
2026-03-17 11:55:36 -07:00
Mason Daugherty
d524e3ba92
chore: add badges and tagline to readme header (#1069)
* Add badges, tagline, and ecosystem links to README header

* Match README header syntax exactly to langchain-ai/langchain repo style

* Apply suggestion from @mdrxy

Co-authored-by: Mason Daugherty <github@mdrxy.com>

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-17 18:25:48 +00:00
Palash Shah
3e64399d13
feat: inject LANGSMITH_AGENT_VERSION metadata into all run creation calls (#1066)
Reads LANGCHAIN_REVISION_ID env var (set by LSD from LANGSMITH_LANGGRAPH_GIT_REF_SHA)
and injects it as LANGSMITH_AGENT_VERSION metadata on every runs.create() call.
This enables the agent_deployments sync job to track which agent version produced each trace.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-17 10:49:32 -07:00