Commit graph

678 commits

Author SHA1 Message Date
Brace Sproul
3405d145ac
feat: add edit_pull_request tool for editing PR titles/descriptions (#1063)
* feat: add edit_pull_request tool for editing PR titles and descriptions

* fix: patch auth flow in open PR middleware tests

* fix: support app token for editing PRs

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 18:12:41 -07:00
dependabot[bot]
3d3d8403fe
chore(deps): bump astral-sh/setup-uv in the minor-and-patch group (#1232)
Bumps the minor-and-patch group with 1 update: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv).


Updates `astral-sh/setup-uv` from 8.0.0 to 8.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](cec208311d...08807647e7)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 18:00:53 -07:00
fuyua9
226e6c8263
fix(daytona): make sandbox snapshot configurable (#1220) 2026-05-01 22:51:34 +00:00
open-swe[bot]
b829cef97a
feat: add release note section to PR body template (#1202)
* feat: add release note section to PR body template

The langchainplus repo PR template includes a ## Release Note section,
but the agent hardcoded PR body template only had ## Description and
## Test Plan. This caused the release note section to be dropped from
agent-created PRs.

* docs: align PR body argument docs

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 15:32:30 -07:00
dependabot[bot]
4af9eb885c
chore(deps): bump python-dotenv from 1.2.1 to 1.2.2 (#1212)
* chore(deps): bump python-dotenv from 1.2.1 to 1.2.2

Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-version: 1.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* added deps to pr scopes

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 22:27:21 +00:00
ericness
b1431c2802
Update OAuth provider ID in installation instructions (#1222)
When setting up the OAuth Provider in LangSmith using `github-oauth-provider` results in the error:

> Error: Provider ID 'github-oauth-provider' is reserved for Fleet public OAuth. Choose another name.
2026-05-01 22:23:07 +00:00
ericness
c3e1390cf2
Update GitHub OAuth installation instructions (#1223)
Added Authorization and Token URLs for GitHub OAuth setup.
2026-05-01 22:22:07 +00:00
langsmith-forge[bot]
bd97678a5e
fix: prevent futile retry loop when commit_and_open_pr fails (#1210)
* fix: prevent futile retry loop when commit_and_open_pr fails with git/API errors

- Root cause: when git checkout or GitHub PR API fails, the tool returned a generic {"success": false} error with no signal that retrying is futile, causing the agent to loop 9-13+ times until hitting the 1000-step recursion limit
- Change: (1) git_checkout_branch now returns (bool, str) so the actual git error output is surfaced in the tool response; (2) checkout and PR creation failures now include "fatal": true and an explicit "Do not retry" message; (3) prompt.py COMMIT_PR_SECTION adds an explicit instruction to stop on fatal errors
- Verified: 109 unit tests pass, no regressions

* fix: skip PR safety net on fatal commit failures

* style(open_pr): ruff-format fatal retry skip condition

---------

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 22:05:22 +00:00
langsmith-forge[bot]
48965a82a6
fix: coerce malformed integer strings in read_file offset/limit params (#1216)
- Root cause: LLM occasionally generates strings like '1, 80' or '170, "limit": 60'
  for integer fields, causing a Pydantic ValidationError and wasting an LLM turn
- Change: add SanitizeToolInputsMiddleware in agent/middleware/sanitize_tool_inputs.py
  that extracts the leading integer from any string value in offset/limit before
  the call reaches Pydantic validation; registered before ToolErrorMiddleware in server.py
- Verified: 14 unit tests covering all three production trace patterns pass

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 14:29:48 -07:00
langsmith-forge[bot]
e5bc27a0ad
fix: notify users via Slack when agent hits model call step limit (#1204)
* fix: notify users via Slack when agent hits model call step limit

- Root cause: GraphRecursionError at 1000 steps bypassed all @after_agent
  middleware including open_pr_if_needed, leaving users with no notification
- Change: Added ModelCallLimitMiddleware(run_limit=60) to intercept gracefully
  before the hard recursion limit, and added notify_step_limit_reached
  @after_agent middleware to post a Slack thread reply when the limit fires
- Verified: 107 existing tests pass, no regressions

* fix: harden step-limit Slack notification

Ensure the step-limit notification runs after the PR safety net and cover the new middleware behavior with focused unit tests.

---------

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 14:24:25 -07:00
langsmith-forge[bot]
0464126c83
fix: warn against using http_request for GitHub PR creation (#1203)
* fix: warn against using http_request for GitHub PR creation

- Root cause: http_request tool description and system prompt lacked explicit guidance not to use it for GitHub PR operations, causing the agent to fall back to it and receive 401 Unauthorized responses
- Change: added clear warnings to both the http_request docstring and the TOOL_USAGE_SECTION in prompt.py directing agents to use commit_and_open_pr instead
- Verified: docstring and prompt changes are minimal and scoped

* fix: clarify http_request PR guidance

---------

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 14:14:44 -07:00
langsmith-forge[bot]
1a206c94d0
fix: prevent scope creep — clarify lockfile handling and task scope guidance (#1185)
* fix: prevent scope creep — clarify lockfile handling and task scope guidance

- Root cause: CODING_STANDARDS_SECTION ambiguously said 'package manager files' (interpreted to include lockfiles like uv.lock, package-lock.json) and TASK_EXECUTION_SECTION scope guidance was too generic to prevent cross-language or cross-service modifications
- Change: clarify that only manifest files (pyproject.toml, package.json) need updating and auto-generated lockfiles must NOT be committed; add concrete examples to scope guidance (no JS when Python-only, no other services when one is targeted)
- Verified: 3 production traces showing users complaining about scope creep

* fix: clarify prompt lockfile guidance

---------

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 14:09:22 -07:00
langsmith-forge[bot]
8095f93364
fix: update existing PR title and body when create returns 422 (#1163)
- Root cause: create_github_pr found an existing PR on 422 but never
  PATCHed it, so callers like commit_and_open_pr could not update the
  PR body (e.g. adding "Closes AB-1159") on subsequent invocations.
- Change: after _find_existing_pr succeeds, call new _update_github_pr
  helper which PATCHes /repos/{owner}/{repo}/pulls/{number} with the
  requested title and body before returning pr_existing=True.
- Verified: self-evident API call addition; proof in production traces.

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-05-01 14:02:39 -07:00
Johannes du Plessis
c6ea869df8
chore: bump all dependencies to latest stable versions (#1230)
Bump floors in pyproject.toml and refresh uv.lock. Notable changes:
- deepagents 0.5.3 -> 0.5.6
- langchain 1.2.15 -> 1.2.17, langchain-core -> 1.3.2
- langchain-anthropic 1.4.0 -> 1.4.2, anthropic -> 0.97.0
- langchain-openai 1.1.13 -> 1.2.1 (unpinned from ==)
- langgraph 1.1.6 -> 1.1.10, langgraph-api -> 0.8.5
- langsmith 0.7.32 -> 0.8.0
- fastapi 0.135.3 -> 0.136.1, starlette -> 1.0.0
- uvicorn 0.44.0 -> 0.46.0, pydantic -> 2.13.3

cryptography stays at <47 due to langgraph-api upper bound.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-05-01 13:43:34 -07:00
langsmith-forge[bot]
15a7268d30
fix: return actionable error when push fails with workflows scope error (#1153)
* fix: return actionable error when git push fails due to workflows scope

- Root cause: push failure with "workflows scope" error returned a generic
  "Git push failed: ..." message, causing the agent to retry 10+ times
- Change: detect "workflows" + "scope" in push output and return a clear
  message instructing the agent to remove .github/workflows/ file changes
- Verified: unit tests cover both the workflow-scope path and the
  non-workflow path to prevent regressions

* fix: detect github workflow permission push failures

* style: ruff-format checkout line in commit_and_open_pr

---------

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 13:09:54 -07:00
langsmith-forge[bot]
b25222f1f9
fix: recover existing PR after httpx.HTTPError in create_github_pr (#1148)
- Root cause: httpx.HTTPError handler returned (None, None, False) without
  checking if the PR was already created on GitHub before the network error
- Change: added _find_existing_pr fallback in except block in agent/utils/github.py
- Verified: 5 production traces showed false failures where PR existed (pr_existing=True on retry)

Co-authored-by: LangSmith Forge <forge-agent@langsmith.ai>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 13:00:23 -07:00
langsmith-forge-dev[bot]
c61d8b0376
fix: stop agent retrying commit_and_open_pr on 403 permission denied (#1123)
* fix: stop agent retrying commit_and_open_pr on 403 permission denied

Detect 403/permission-denied push failures in commit_and_open_pr and
return a PERMANENT_FAILURE message so the LLM stops retrying. Also add
prompt-level guidance to the COMMIT_PR_SECTION reinforcing this. Add
unit tests covering both the 403 and non-403 push failure paths.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: stop safety net retrying permanent push failures

Skip the after-agent PR fallback when commit_and_open_pr reports a permanent GitHub push authorization failure, while preserving fallback behavior for recoverable failures.

---------

Co-authored-by: Claude Agent <agent@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 19:37:53 +00:00
langsmith-forge-dev[bot]
4060933ce4
feat: add github CI check run tools for shepherding CI (#1121)
* feat: add github CI check run tools for shepherding CI

Add get_pr_check_runs and rerun_failed_check_runs tools that authenticate
using the GitHub App installation token so the agent can query and retry
CI status on private repos without relying on GH_TOKEN or unauthenticated
http_request calls.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: handle paginated GitHub CI results

* refactor(github_ci): address review feedback

- Rename rerun_failed_check_runs -> rerun_failed_workflow_runs and clarify
  in docstrings that the tool only retries GitHub Actions workflow runs
  (not third-party CI checks surfaced by get_pr_check_runs).
- Skip action_required workflow runs when rerunning; those need manual
  approval, not a rerun.
- Run rerun-failed-jobs requests concurrently via asyncio.gather instead
  of sequentially.
- Fix latent pagination bug in _fetch_paginated_items where caller-supplied
  params could overwrite per_page/page and break the end-of-pagination
  check; reserved keys now always win and the threshold uses a PER_PAGE
  constant.
- Set an explicit 30s httpx timeout so a hung GitHub call cannot stall
  the agent loop.
- Restore alphabetical ordering of tools in agent/tools/__init__.py.
- Add tests for: a 500 surfaced on a later pagination page, and
  action_required runs being filtered out of rerun candidates.

---------

Co-authored-by: Claude Agent <agent@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 12:19:04 -07:00
langsmith-forge-dev[bot]
28027d5295
fix: skip notification step when no source channel context is present (#1119)
When the agent is triggered by automated deployment monitoring (no Slack
thread, no Linear ticket, no GitHub issue), the prompt now explicitly
instructs it to skip the notification step rather than attempting
slack_thread_reply and failing.

Co-authored-by: Claude Agent <agent@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-01 11:41:18 -07:00
Johannes du Plessis
3683614601
chore: adding AGENTS and CLAUDE md files (#1228)
* chore: adding AGENTS and CLAUDE md files

* chore: de-clauding
2026-05-01 03:06:58 +00:00
Johannes du Plessis
6ef70823be
fix(open_pr): reuse config for GitHub token; defer installation token lookup (#1227)
Calling get_github_token() without arguments always invoked LangGraph get_config internally,
which broke tests that only patch agent.middleware.open_pr.get_config and failed outside
runnable context.

Extend get_github_token with an optional runnable config mapping; the middleware passes
the config dict already resolved from get_config(). Request GitHub App installation tokens
only after detecting sandbox/repo changes worth publishing.

Fixes failing Agent unit tests in tests/test_open_pr_middleware.py.
2026-04-30 17:48:15 -07:00
langsmith-forge-dev[bot]
b5ed2a6b8b
fix: safety net middleware never fires due to key-existence check (#1051)
* fix: safety net middleware always skipped due to key-existence check

The open_pr_if_needed after-agent middleware checked `if 'success' in pr_payload`
which evaluates True for BOTH success and failure responses from commit_and_open_pr
(all responses include the 'success' key). This meant the safety net never fired.

Fix: use `pr_payload.get('success')` to check the VALUE instead of key existence.

Evidence: 6+ production traces in last 24h where commit_and_open_pr returned
success=False but the safety net silently skipped (non-fast-forward push failures,
missing GitHub token, workflow permission errors, API 500 errors).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* update

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Palash Shah <palash@langchain.dev>
2026-04-30 17:22:11 -07:00
langsmith-forge-dev[bot]
d63780a77f
fix: add get_pr_review_comments tool to fetch PR review comments with auth (#1043)
* feat: add get_pr_review_comments tool for authenticated GitHub API access

The agent was asking users to paste PR review comments because it had no
tool to fetch them with auth. This adds get_pr_review_comments, which uses
the GitHub App installation token to fetch all three comment types (thread
comments, inline review comments, review submissions) from private repos.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* u

* u

---------

Co-authored-by: Forge Agent <agent@forge.ai>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Palash Shah <palash@langchain.dev>
Co-authored-by: Palash Shah <35114859+Palashio@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-30 17:01:13 -07:00
Johannes du Plessis
016eef6875
fix: lower default LangSmith sandbox size to fit "large" tier (#1226)
Previous defaults (4 vCPU / 15 GiB) exceed the maximum sandbox size
the LangSmith API accepts, causing a 400 on every sandbox creation:

  sandbox size 4 vCPU / 15360 MiB exceeds the maximum supported size;
  must fit within one of: small (1 vCPU / 1792 MiB),
  medium (1 vCPU / 3840 MiB), or large (2 vCPU / 7936 MiB)

Default to the "large" cap (2 vCPU / 7936 MiB) so deployments without
DEFAULT_SANDBOX_VCPUS / DEFAULT_SANDBOX_MEM_BYTES env overrides boot
into a working state.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-30 13:24:15 -07:00
Aran Yogesh
b6ea229a46
feat: give agent ability to read cross-posted Slack message links [closes OPE-37] (#1200)
* feat: give agent ability to read cross-posted Slack message links [close OPE-37]

* refactor: clean up Slack link resolution code

* linting

* refactor: address PR review feedback for Slack link resolution

* linting

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-29 17:42:27 -07:00
Aran Yogesh
920a8a7624
feat: open PRs under user's name and add OpenSWE label (#1215)
* feat: open PRs under user's name and add OpenSWE label

* feat: use user token for PR authorship, add OpenSWE label, and consolidate fallback logic

* linting

* fix: address review nits for PR authorship and labeling

Fix docstring casing, add debug logging for 422 existing-PR search
fallback, tighten test type annotations, and add missing HTTPError
fallback test.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-29 17:34:00 -07:00
Johannes du Plessis
448be4a466
feat(open-swe): Default to GPT-5.5 medium reasoning (#1224)
* feat: default to GPT-5.5 medium reasoning

Use OpenAI GPT-5.5 with medium reasoning as the default model and document the completion-token budget semantics for reasoning models.

* fix: use Responses API reasoning config

Pass GPT-5.5 reasoning settings through LangChain's Responses API parameter instead of the Chat Completions-only reasoning_effort field.

* feat: raise GPT-5.5 output budget

Set the default GPT-5.5 output token budget to the model maximum so long-running coding tasks have more room for reasoning and final responses.

* feat: align recursion limit with Deep Agents

Use Deep Agents' default recursion limit so longer coding runs have room to complete without Open SWE imposing a lower cap.

* chore: remove minimal effort level

* chore: reduce max tokens to 64_000

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-28 15:03:21 -07:00
Brace Sproul
59bfc65bb7
fix: Remove obsolete automatic repository selection notifications (#1221)
* Remove obsolete automatic repository selection notifications.

Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>

* Add coverage to ensure repository resolution does not post Slack replies.

Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-25 12:27:20 -07:00
Aran Yogesh
fc3e492083
fix: use thread-level LangSmith URLs instead of run-level URLs to fix broken trace links (#1217)
* fix: use thread-level LangSmith URLs instead of run-level URLs to fix broken trace links

* linting
2026-04-23 13:46:28 -07:00
Aran Yogesh
a3a40a1bec
Revert "fix: Auto assign PRs to creator (#1211)" (#1214)
This reverts commit e9b94ac8ba.
2026-04-22 13:46:44 -07:00
Aran Yogesh
92a6c256f4
fix: update LangSmith trace URL format to use peek query params (#1213) 2026-04-22 13:10:43 -07:00
Brace Sproul
e9b94ac8ba
fix: Auto assign PRs to creator (#1211)
* fix: Auto assign PRs to creator

* cr
2026-04-21 14:13:55 -07:00
Ramon Nogueira
5925a90a95
feat: migrate LangSmith sandbox creation to snapshot API (#1201)
* feat: migrate LangSmith sandbox creation to snapshot API

Replaces the template-based sandbox flow (DEFAULT_SANDBOX_TEMPLATE_NAME /
DEFAULT_SANDBOX_TEMPLATE_IMAGE) with the new snapshot-based flow.

- New required env var DEFAULT_SANDBOX_SNAPSHOT_ID (UUID of a pre-built
  LangSmith snapshot; build out-of-band via UI or SandboxClient.create_snapshot)
- Optional DEFAULT_SANDBOX_SNAPSHOT_FS_CAPACITY_BYTES overrides the root FS
  size at boot (default 32 GiB)
- Startup-time validation via a FastAPI lifespan hook: the server refuses
  to boot with a clear ValueError if SANDBOX_TYPE=langsmith and
  DEFAULT_SANDBOX_SNAPSHOT_ID is unset, so failures surface in boot logs
  rather than on the first thread
- Reconnect-to-existing-sandbox path unchanged
- Docs (INSTALLATION.md, CUSTOMIZATION.md) updated to describe the new
  snapshot workflow

* fix: format create_sandbox_snapshot.py to pass ruff

---------

Co-authored-by: aran-yogesh <yogesh.mahendran@langchain.dev>
2026-04-21 12:17:19 -07:00
Aran Yogesh
f1907521f3
feat: enforce AGENTS.md reading with strict ALL CAPS prompting (#1209)
* feat: enforce AGENTS.md reading with strict ALL CAPS prompting

* linting
2026-04-17 13:43:42 -07:00
Aran Yogesh
301d124c3d
fix: remove deprecated temperature parameter (#1207)
for Opus 4.7 compatibility
2026-04-17 10:45:01 -07:00
dependabot[bot]
213473dc08
chore(deps): bump the minor-and-patch group with 11 updates (#1198)
Bumps the minor-and-patch group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [deepagents](https://github.com/langchain-ai/deepagents) | `0.5.0a4` | `0.5.3` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.128.3` | `0.135.3` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.44.0` |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.3.4` | `0.3.13` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.7.31` | `0.7.32` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.10` | `1.1.13` |
| [langchain-daytona](https://github.com/langchain-ai/deepagents) | `0.0.3` | `0.0.5` |
| [langchain-modal](https://github.com/langchain-ai/deepagents) | `0.0.2` | `0.0.3` |
| [langchain-runloop](https://github.com/langchain-ai/deepagents) | `0.0.3` | `0.0.4` |
| [exa-py](https://github.com/exa-labs/exa-py) | `2.10.1` | `2.12.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.0` | `0.15.10` |


Updates `deepagents` from 0.5.0a4 to 0.5.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/deepagents==0.5.0a4...deepagents==0.5.3)

Updates `fastapi` from 0.128.3 to 0.135.3
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.128.3...0.135.3)

Updates `uvicorn` from 0.40.0 to 0.44.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.40.0...0.44.0)

Updates `langgraph-sdk` from 0.3.4 to 0.3.13
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/0.3.4...0.3.13)

Updates `langsmith` from 0.7.31 to 0.7.32
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.31...v0.7.32)

Updates `langchain-openai` from 1.1.10 to 1.1.13
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.1.10...langchain-openai==1.1.13)

Updates `langchain-daytona` from 0.0.3 to 0.0.5
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-daytona==0.0.3...langchain-daytona==0.0.5)

Updates `langchain-modal` from 0.0.2 to 0.0.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-modal==0.0.2...langchain-modal==0.0.3)

Updates `langchain-runloop` from 0.0.3 to 0.0.4
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-runloop==0.0.3...langchain-runloop==0.0.4)

Updates `exa-py` from 2.10.1 to 2.12.0
- [Commits](https://github.com/exa-labs/exa-py/commits)

Updates `ruff` from 0.15.0 to 0.15.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.15.0...0.15.10)

---
updated-dependencies:
- dependency-name: deepagents
  dependency-version: 0.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: fastapi
  dependency-version: 0.135.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: uvicorn
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langgraph-sdk
  dependency-version: 0.3.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langsmith
  dependency-version: 0.7.32
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.1.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-daytona
  dependency-version: 0.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-modal
  dependency-version: 0.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-runloop
  dependency-version: 0.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: exa-py
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ruff
  dependency-version: 0.15.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 07:09:02 +00:00
dependabot[bot]
c0c5125912
chore(deps): bump python in the minor-and-patch group (#1195)
Bumps the minor-and-patch group with 1 update: python.


Updates `python` from 3.12.12-slim-trixie to 3.14.0-slim-trixie

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14.0-slim-trixie
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:56 -07:00
dependabot[bot]
aee6f20627
chore(deps): update langgraph-cli[inmem] requirement (#1199)
Updates the requirements on [langgraph-cli[inmem]](https://github.com/langchain-ai/langgraph) to permit the latest version.
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/cli==0.4.12...cli==0.4.21)

---
updated-dependencies:
- dependency-name: langgraph-cli[inmem]
  dependency-version: 0.4.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:19 -07:00
dependabot[bot]
d2042bfefd
chore(deps): bump astral-sh/setup-uv from 4.2.0 to 8.0.0 (#1196)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 4.2.0 to 8.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](38f3f10444...cec208311d)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:45:46 -07:00
dependabot[bot]
8ae4179378
chore(deps): bump amannn/action-semantic-pull-request from 5 to 6 (#1197)
Bumps [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) from 5 to 6.
- [Release notes](https://github.com/amannn/action-semantic-pull-request/releases)
- [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md)
- [Commits](e32d7e603d...48f256284b)

---
updated-dependencies:
- dependency-name: amannn/action-semantic-pull-request
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:41:08 -07:00
dependabot[bot]
9219912068
chore(deps): bump actions/checkout from 4 to 6 (#1194)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:37:03 -07:00
John Kennedy
a94fb8b94c
ci: SHA-pin third-party actions in workflow files (#1193)
Pin astral-sh/setup-uv and amannn/action-semantic-pull-request to
full commit SHAs to prevent supply chain attacks via tag hijacking.
2026-04-15 23:36:07 -07:00
John Kennedy
da11bcdf60
chore: add dependabot.yml with uv, docker, and github-actions coverage (#1192)
Adds a compliant dependabot configuration covering all detected
ecosystems with monthly schedule and grouped update-type splits.
2026-04-15 23:35:42 -07:00
dependabot[bot]
32eecbcee2
chore(deps): bump the uv group across 1 directory with 3 updates (#1191)
Bumps the uv group with 3 updates in the / directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk), [pytest](https://github.com/pytest-dev/pytest) and [python-multipart](https://github.com/Kludex/python-multipart).


Updates `langsmith` from 0.7.25 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.25...v0.7.31)

Updates `pytest` from 9.0.2 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.0.3)

Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases)
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26)

---
updated-dependencies:
- dependency-name: langsmith
  dependency-version: 0.7.31
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: pytest
  dependency-version: 9.0.3
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: python-multipart
  dependency-version: 0.0.26
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:31:23 -07:00
dependabot[bot]
db29b6cad1
chore(deps): bump the uv group across 1 directory with 2 updates (#1176)
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [langchain-core](https://github.com/langchain-ai/langchain).


Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7)

Updates `langchain-core` from 1.2.22 to 1.2.28
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.22...langchain-core==1.2.28)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: langchain-core
  dependency-version: 1.2.28
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 22:40:37 -07:00
Aran Yogesh
6049405aed
feat: add configurable default prompt file for org-level agent instructions [close OPE-36] (#1187)
* feat: add configurable default prompt file for org-level agent instructions

* linting

* Update CUSTOMIZATION.md

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: address PR review feedback on default prompt

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-15 15:18:14 -07:00
Aran Yogesh
2039fe6660
feat: stop auto-cloning and let agent manage repo setup [closes OPE-21] (#1159)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]

* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]

* fix: address review feedback — restore agents_md, add git user config, lint fixes

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* feat: add installation token auth to list_repos GitHub API call

* agents.md update

* linting

* fix: address PR review feedback — shell precedence bug in prompt, remove dead code

* linting

* Apply suggestion from @bracesproul

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Apply suggestion from @bracesproul

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: address PR review feedback — restore {working_dir} in prompt, remove clone code block

* fix:Extract check_or_recreate_sandbox utility from inline sandbox health check

* fix: address PR review feedback — async list_repos, restore template name, fix prompt colon

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox

* linting

* yogesh/ope-21-stop-auto-cloning

* Update agent/tools/list_repos.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Update agent/prompt.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* feat: address PR review — list_repos uses GitHub API only, PR trigger includes org/repo

* linting

* feat: address PR review feedback — list_repos pagination, simpler return, sandbox health check

* feat: support listing repos for personal user accounts via is_organization flag

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-10 17:04:55 -07:00
Aran Yogesh
91f63de361
fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures (#1178)
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures

* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures

* function name change
2026-04-09 14:59:49 -07:00
Aran Yogesh
67c782c295
fix: block open-swe from approving PRs (#1177)
* fix: block open-swe from approving PRs

* linting

* fix: add case-insensitive APPROVE guard and unit tests
2026-04-09 11:45:08 -07:00
Aran Yogesh
4d4f5fbfc7
fix: proxy config restored the branch yogesh/GitHub auth proxy (#1173)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-08 15:02:52 -07:00