Commit graph

704 commits

Author SHA1 Message Date
Aran Yogesh
b6ea229a46
feat: give agent ability to read cross-posted Slack message links [closes OPE-37] (#1200)
* feat: give agent ability to read cross-posted Slack message links [close OPE-37]

* refactor: clean up Slack link resolution code

* linting

* refactor: address PR review feedback for Slack link resolution

* linting

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-29 17:42:27 -07:00
Aran Yogesh
920a8a7624
feat: open PRs under user's name and add OpenSWE label (#1215)
* feat: open PRs under user's name and add OpenSWE label

* feat: use user token for PR authorship, add OpenSWE label, and consolidate fallback logic

* linting

* fix: address review nits for PR authorship and labeling

Fix docstring casing, add debug logging for 422 existing-PR search
fallback, tighten test type annotations, and add missing HTTPError
fallback test.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-29 17:34:00 -07:00
Johannes du Plessis
448be4a466
feat(open-swe): Default to GPT-5.5 medium reasoning (#1224)
* feat: default to GPT-5.5 medium reasoning

Use OpenAI GPT-5.5 with medium reasoning as the default model and document the completion-token budget semantics for reasoning models.

* fix: use Responses API reasoning config

Pass GPT-5.5 reasoning settings through LangChain's Responses API parameter instead of the Chat Completions-only reasoning_effort field.

* feat: raise GPT-5.5 output budget

Set the default GPT-5.5 output token budget to the model maximum so long-running coding tasks have more room for reasoning and final responses.

* feat: align recursion limit with Deep Agents

Use Deep Agents' default recursion limit so longer coding runs have room to complete without Open SWE imposing a lower cap.

* chore: remove minimal effort level

* chore: reduce max tokens to 64_000

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-28 15:03:21 -07:00
Brace Sproul
59bfc65bb7
fix: Remove obsolete automatic repository selection notifications (#1221)
* Remove obsolete automatic repository selection notifications.

Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>

* Add coverage to ensure repository resolution does not post Slack replies.

Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-04-25 12:27:20 -07:00
Aran Yogesh
fc3e492083
fix: use thread-level LangSmith URLs instead of run-level URLs to fix broken trace links (#1217)
* fix: use thread-level LangSmith URLs instead of run-level URLs to fix broken trace links

* linting
2026-04-23 13:46:28 -07:00
Aran Yogesh
a3a40a1bec
Revert "fix: Auto assign PRs to creator (#1211)" (#1214)
This reverts commit e9b94ac8ba.
2026-04-22 13:46:44 -07:00
Aran Yogesh
92a6c256f4
fix: update LangSmith trace URL format to use peek query params (#1213) 2026-04-22 13:10:43 -07:00
Brace Sproul
e9b94ac8ba
fix: Auto assign PRs to creator (#1211)
* fix: Auto assign PRs to creator

* cr
2026-04-21 14:13:55 -07:00
Ramon Nogueira
5925a90a95
feat: migrate LangSmith sandbox creation to snapshot API (#1201)
* feat: migrate LangSmith sandbox creation to snapshot API

Replaces the template-based sandbox flow (DEFAULT_SANDBOX_TEMPLATE_NAME /
DEFAULT_SANDBOX_TEMPLATE_IMAGE) with the new snapshot-based flow.

- New required env var DEFAULT_SANDBOX_SNAPSHOT_ID (UUID of a pre-built
  LangSmith snapshot; build out-of-band via UI or SandboxClient.create_snapshot)
- Optional DEFAULT_SANDBOX_SNAPSHOT_FS_CAPACITY_BYTES overrides the root FS
  size at boot (default 32 GiB)
- Startup-time validation via a FastAPI lifespan hook: the server refuses
  to boot with a clear ValueError if SANDBOX_TYPE=langsmith and
  DEFAULT_SANDBOX_SNAPSHOT_ID is unset, so failures surface in boot logs
  rather than on the first thread
- Reconnect-to-existing-sandbox path unchanged
- Docs (INSTALLATION.md, CUSTOMIZATION.md) updated to describe the new
  snapshot workflow

* fix: format create_sandbox_snapshot.py to pass ruff

---------

Co-authored-by: aran-yogesh <yogesh.mahendran@langchain.dev>
2026-04-21 12:17:19 -07:00
Aran Yogesh
f1907521f3
feat: enforce AGENTS.md reading with strict ALL CAPS prompting (#1209)
* feat: enforce AGENTS.md reading with strict ALL CAPS prompting

* linting
2026-04-17 13:43:42 -07:00
Aran Yogesh
301d124c3d
fix: remove deprecated temperature parameter (#1207)
for Opus 4.7 compatibility
2026-04-17 10:45:01 -07:00
dependabot[bot]
213473dc08
chore(deps): bump the minor-and-patch group with 11 updates (#1198)
Bumps the minor-and-patch group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [deepagents](https://github.com/langchain-ai/deepagents) | `0.5.0a4` | `0.5.3` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.128.3` | `0.135.3` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.44.0` |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.3.4` | `0.3.13` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.7.31` | `0.7.32` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.10` | `1.1.13` |
| [langchain-daytona](https://github.com/langchain-ai/deepagents) | `0.0.3` | `0.0.5` |
| [langchain-modal](https://github.com/langchain-ai/deepagents) | `0.0.2` | `0.0.3` |
| [langchain-runloop](https://github.com/langchain-ai/deepagents) | `0.0.3` | `0.0.4` |
| [exa-py](https://github.com/exa-labs/exa-py) | `2.10.1` | `2.12.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.0` | `0.15.10` |


Updates `deepagents` from 0.5.0a4 to 0.5.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/deepagents==0.5.0a4...deepagents==0.5.3)

Updates `fastapi` from 0.128.3 to 0.135.3
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.128.3...0.135.3)

Updates `uvicorn` from 0.40.0 to 0.44.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.40.0...0.44.0)

Updates `langgraph-sdk` from 0.3.4 to 0.3.13
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/0.3.4...0.3.13)

Updates `langsmith` from 0.7.31 to 0.7.32
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.31...v0.7.32)

Updates `langchain-openai` from 1.1.10 to 1.1.13
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.1.10...langchain-openai==1.1.13)

Updates `langchain-daytona` from 0.0.3 to 0.0.5
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-daytona==0.0.3...langchain-daytona==0.0.5)

Updates `langchain-modal` from 0.0.2 to 0.0.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-modal==0.0.2...langchain-modal==0.0.3)

Updates `langchain-runloop` from 0.0.3 to 0.0.4
- [Release notes](https://github.com/langchain-ai/deepagents/releases)
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-runloop==0.0.3...langchain-runloop==0.0.4)

Updates `exa-py` from 2.10.1 to 2.12.0
- [Commits](https://github.com/exa-labs/exa-py/commits)

Updates `ruff` from 0.15.0 to 0.15.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.15.0...0.15.10)

---
updated-dependencies:
- dependency-name: deepagents
  dependency-version: 0.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: fastapi
  dependency-version: 0.135.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: uvicorn
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langgraph-sdk
  dependency-version: 0.3.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langsmith
  dependency-version: 0.7.32
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.1.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-daytona
  dependency-version: 0.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-modal
  dependency-version: 0.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-runloop
  dependency-version: 0.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: exa-py
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ruff
  dependency-version: 0.15.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 07:09:02 +00:00
dependabot[bot]
c0c5125912
chore(deps): bump python in the minor-and-patch group (#1195)
Bumps the minor-and-patch group with 1 update: python.


Updates `python` from 3.12.12-slim-trixie to 3.14.0-slim-trixie

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14.0-slim-trixie
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:56 -07:00
dependabot[bot]
aee6f20627
chore(deps): update langgraph-cli[inmem] requirement (#1199)
Updates the requirements on [langgraph-cli[inmem]](https://github.com/langchain-ai/langgraph) to permit the latest version.
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/cli==0.4.12...cli==0.4.21)

---
updated-dependencies:
- dependency-name: langgraph-cli[inmem]
  dependency-version: 0.4.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:19 -07:00
dependabot[bot]
d2042bfefd
chore(deps): bump astral-sh/setup-uv from 4.2.0 to 8.0.0 (#1196)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 4.2.0 to 8.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](38f3f10444...cec208311d)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:45:46 -07:00
dependabot[bot]
8ae4179378
chore(deps): bump amannn/action-semantic-pull-request from 5 to 6 (#1197)
Bumps [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) from 5 to 6.
- [Release notes](https://github.com/amannn/action-semantic-pull-request/releases)
- [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md)
- [Commits](e32d7e603d...48f256284b)

---
updated-dependencies:
- dependency-name: amannn/action-semantic-pull-request
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:41:08 -07:00
dependabot[bot]
9219912068
chore(deps): bump actions/checkout from 4 to 6 (#1194)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:37:03 -07:00
John Kennedy
a94fb8b94c
ci: SHA-pin third-party actions in workflow files (#1193)
Pin astral-sh/setup-uv and amannn/action-semantic-pull-request to
full commit SHAs to prevent supply chain attacks via tag hijacking.
2026-04-15 23:36:07 -07:00
John Kennedy
da11bcdf60
chore: add dependabot.yml with uv, docker, and github-actions coverage (#1192)
Adds a compliant dependabot configuration covering all detected
ecosystems with monthly schedule and grouped update-type splits.
2026-04-15 23:35:42 -07:00
dependabot[bot]
32eecbcee2
chore(deps): bump the uv group across 1 directory with 3 updates (#1191)
Bumps the uv group with 3 updates in the / directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk), [pytest](https://github.com/pytest-dev/pytest) and [python-multipart](https://github.com/Kludex/python-multipart).


Updates `langsmith` from 0.7.25 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.25...v0.7.31)

Updates `pytest` from 9.0.2 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.0.3)

Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases)
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26)

---
updated-dependencies:
- dependency-name: langsmith
  dependency-version: 0.7.31
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: pytest
  dependency-version: 9.0.3
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: python-multipart
  dependency-version: 0.0.26
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:31:23 -07:00
dependabot[bot]
db29b6cad1
chore(deps): bump the uv group across 1 directory with 2 updates (#1176)
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [langchain-core](https://github.com/langchain-ai/langchain).


Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7)

Updates `langchain-core` from 1.2.22 to 1.2.28
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.22...langchain-core==1.2.28)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: langchain-core
  dependency-version: 1.2.28
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 22:40:37 -07:00
Aran Yogesh
6049405aed
feat: add configurable default prompt file for org-level agent instructions [close OPE-36] (#1187)
* feat: add configurable default prompt file for org-level agent instructions

* linting

* Update CUSTOMIZATION.md

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: address PR review feedback on default prompt

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-15 15:18:14 -07:00
Aran Yogesh
2039fe6660
feat: stop auto-cloning and let agent manage repo setup [closes OPE-21] (#1159)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]

* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]

* fix: address review feedback — restore agents_md, add git user config, lint fixes

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* feat: add installation token auth to list_repos GitHub API call

* agents.md update

* linting

* fix: address PR review feedback — shell precedence bug in prompt, remove dead code

* linting

* Apply suggestion from @bracesproul

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Apply suggestion from @bracesproul

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: address PR review feedback — restore {working_dir} in prompt, remove clone code block

* fix:Extract check_or_recreate_sandbox utility from inline sandbox health check

* fix: address PR review feedback — async list_repos, restore template name, fix prompt colon

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox

* linting

* yogesh/ope-21-stop-auto-cloning

* Update agent/tools/list_repos.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* Update agent/prompt.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* feat: address PR review — list_repos uses GitHub API only, PR trigger includes org/repo

* linting

* feat: address PR review feedback — list_repos pagination, simpler return, sandbox health check

* feat: support listing repos for personal user accounts via is_organization flag

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-10 17:04:55 -07:00
Aran Yogesh
91f63de361
fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures (#1178)
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures

* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures

* function name change
2026-04-09 14:59:49 -07:00
Aran Yogesh
67c782c295
fix: block open-swe from approving PRs (#1177)
* fix: block open-swe from approving PRs

* linting

* fix: add case-insensitive APPROVE guard and unit tests
2026-04-09 11:45:08 -07:00
Aran Yogesh
4d4f5fbfc7
fix: proxy config restored the branch yogesh/GitHub auth proxy (#1173)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-08 15:02:52 -07:00
Aran Yogesh
9e5088b75a
Revert "feat: add minimal diff rules and scope planning to agent prompt (#1171)" (#1174)
This reverts commit 71b573625c.
2026-04-08 15:00:43 -07:00
Aran Yogesh
71b573625c
feat: add minimal diff rules and scope planning to agent prompt (#1171) 2026-04-08 14:56:34 -07:00
Aran Yogesh
9aba4d0545
Revert "feat: authenticate git operations via sandbox proxy instead of creden…" (#1170)
This reverts commit 6305e13dc6.
2026-04-07 18:45:33 -07:00
Brace Sproul
c5ba4e2e93
Revert "fix: add retry with delay for sandbox proxy config to avoid 500 when …" (#1169)
This reverts commit e25b158218.
2026-04-07 18:37:15 -07:00
Aran Yogesh
e25b158218
fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready (#1168)
* fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready

* fix: add retry with exponential backoff and connection error handling for proxy config
2026-04-07 17:57:21 -07:00
Aran Yogesh
6305e13dc6
feat: authenticate git operations via sandbox proxy instead of credential files [closes: OPE-20] (#1070)
* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* feat: authenticate git operations via sandbox proxy instead of credential files

* removing logger.info

* formatting and linting

* fix: resolve lint errors in server.py (imports, unused vars, undefined names)

* feat: use opaque proxy headers for GitHub auth in sandbox

* linting formatting and test changes

* linting

* Delete .claude directory

* Delete tests/evals directory

* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests

* fix: restore authorship, branch_name support, and installation token for PR creation

* linitng

* fix: move installation token fetch before commit, clean up dead proxy validation code

* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config

* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config

* linting

* linting

* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-07 16:41:48 -07:00
open-swe[bot]
24a6343352
chore: upgrade deepagents to v0.5.0a4 (#1161)
Replace custom LangSmithBackend with built-in LangSmithSandbox from
deepagents. Update deprecated protocol method names in docs.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Sydney Runkle <54324534+sydney-runkle@users.noreply.github.com>
2026-04-06 10:24:50 -07:00
John Kennedy
d3506598fe
fix: upgrade deps to patch Pygments ReDoS and PyJWT crit header vulns (#1164)
- Bump deepagents >=0.4.3 → >=0.4.12
- Bump PyJWT >=2.8.0 → >=2.12.0 (fixes CVE-2026-32597, GHSA-752w-5fwx-jx9f)
- Pin Pygments >=2.20.0 in dev deps (fixes CVE-2026-4539, GHSA-5239-wwwm-4pmq)
- Regenerate uv.lock (also pulls langchain 1.2.15, langgraph 1.1.6)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 20:42:51 -07:00
dependabot[bot]
924c096782
chore(deps): bump aiohttp in the uv group across 1 directory (#1158)
---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.13.4
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:19:49 -07:00
mlo20030
4a4bb37d45
adding myself as user (#1162) 2026-04-03 15:52:04 -07:00
Brace Sproul
fd8e6d98ee
fix: Shell injection and ssrf issues (#1155)
* fix: Shell injection and ssrf issues

* cr
2026-04-01 12:37:35 -07:00
dependabot[bot]
4856cc31d4
chore(deps): bump the uv group across 1 directory with 3 updates (#1152)
Bumps the uv group with 3 updates in the / directory: [cryptography](https://github.com/pyca/cryptography), [langchain-core](https://github.com/langchain-ai/langchain) and [requests](https://github.com/psf/requests).


Updates `cryptography` from 46.0.5 to 46.0.6
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6)

Updates `langchain-core` from 1.2.15 to 1.2.22
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.15...langchain-core==1.2.22)

Updates `requests` from 2.32.5 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.6
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: langchain-core
  dependency-version: 1.2.22
  dependency-type: indirect
  dependency-group: uv
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 23:33:28 -07:00
dependabot[bot]
1bc4afc05d
chore(deps): bump cbor2 in the uv group across 1 directory (#1120)
Bumps the uv group with 1 update in the / directory: [cbor2](https://github.com/agronholm/cbor2).


Updates `cbor2` from 5.8.0 to 5.9.0
- [Release notes](https://github.com/agronholm/cbor2/releases)
- [Commits](https://github.com/agronholm/cbor2/compare/5.8.0...5.9.0)

---
updated-dependencies:
- dependency-name: cbor2
  dependency-version: 5.9.0
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 01:58:27 -07:00
Aran Yogesh
86307affe4
fix: use GitHub App installation token for PR creation instead of user token (#1149)
* fix: use GitHub App installation token for PR creation instead of user token

* fix: move installation token fetch after no-changes check to avoid unnecessary API call
2026-03-30 12:47:57 -07:00
Aran Yogesh
7d1004ad66
fix: add Exa web search tool [closes: OPE-29] (#1133)
* fix: add Exa web search tool

* chore: update uv.lock for exa-py dependency

* linting

* chore: remove web_search from system prompt

* chore: drop search_type and category params from web_search
2026-03-25 16:24:31 -07:00
Brace Sproul
87968ab813
fix: Add scripts for getting usage, fix dual committing (#1131) 2026-03-25 13:39:33 -07:00
Brace Sproul
0d8647c2cd
fix: Revert dummy readme change (#1132) 2026-03-25 13:35:11 -07:00
Brace Sproul
4cfe2fd8a5
chore: dummy readme change to test committing workflow (#1130)
* chore: dummy readme change to test committing workflow

Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>

* cr

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 13:34:08 -07:00
Brace Sproul
e1de58c584
fix: convert @Name(USER_ID) mentions to Slack's <@USER_ID> format in thread replies (#1126)
The agent sees users formatted as @Name(USER_ID) in conversation context and
reproduces that pattern in replies, but Slack requires <@USER_ID> for real
mentions. This adds automatic conversion and updates prompt instructions.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:51:11 -07:00
Brace Sproul
3fea3c8709
feat: read LLM model ID from LLM_MODEL_ID env var, defaulting to anthropic:claude-opus-4-6 (#1128)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:32:44 -07:00
Brace Sproul
267b2fd011
feat: add github pr review tools [closes OPE-24] (#1104)
* Add GitHub PR review tools (list, get, create, update, dismiss, submit, list comments) and bind them to the agent

* format n lint

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Aran Yogesh <yogesh.mahendran@langchain.dev>
2026-03-23 21:37:54 +00:00
Brace Sproul
91348aeb7c
feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105)
Adds 6 new agent tools backed by Linear's GraphQL API, with a shared
_graphql_request helper to reduce boilerplate. Refactors existing
comment_on_linear_issue to use the same helper.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-23 14:32:44 -07:00
Aran Yogesh
f79e824d8e
feat: add Slack image support with url_private auth and content-type validation [closes: OPE-23] (#1073)
* feat: add Slack image support with url_private auth and content-type validation

* fix: simplify Slack image fetch by removing manual redirect logic

* fix: use urlparse hostname check to resolve CodeQL URL sanitization warning

* Update agent/utils/multimodal.py

Co-authored-by: Brace Sproul <braceasproul@gmail.com>

* fix: simplify host matching conditions in multimodal image fetching

* reverting changes

---------

Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-20 14:34:14 -07:00
Brace Sproul
46d7ed9d43
feat: extract repo parsing into shared util, add linear comment repo override (#1103)
* feat: extract repo parsing into shared util and add linear comment repo override

Moves the repo extraction regex logic (repo:, repo , GitHub URL) into
agent/utils/repo.py so it can be reused. Updates the Linear webhook
handler to check the comment body for a custom repo first, falling back
to the team/project mapping when none is specified.

* chore: document repo extraction util and default org configuration

* feat: add generic DEFAULT_REPO_OWNER/DEFAULT_REPO_NAME env vars replacing Slack-only defaults

* chore: remove deprecated SLACK_REPO_OWNER/NAME env vars from docs

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 13:34:00 -07:00