Brace Sproul
e9b94ac8ba
fix: Auto assign PRs to creator ( #1211 )
...
* fix: Auto assign PRs to creator
* cr
2026-04-21 14:13:55 -07:00
Ramon Nogueira
5925a90a95
feat: migrate LangSmith sandbox creation to snapshot API ( #1201 )
...
* feat: migrate LangSmith sandbox creation to snapshot API
Replaces the template-based sandbox flow (DEFAULT_SANDBOX_TEMPLATE_NAME /
DEFAULT_SANDBOX_TEMPLATE_IMAGE) with the new snapshot-based flow.
- New required env var DEFAULT_SANDBOX_SNAPSHOT_ID (UUID of a pre-built
LangSmith snapshot; build out-of-band via UI or SandboxClient.create_snapshot)
- Optional DEFAULT_SANDBOX_SNAPSHOT_FS_CAPACITY_BYTES overrides the root FS
size at boot (default 32 GiB)
- Startup-time validation via a FastAPI lifespan hook: the server refuses
to boot with a clear ValueError if SANDBOX_TYPE=langsmith and
DEFAULT_SANDBOX_SNAPSHOT_ID is unset, so failures surface in boot logs
rather than on the first thread
- Reconnect-to-existing-sandbox path unchanged
- Docs (INSTALLATION.md, CUSTOMIZATION.md) updated to describe the new
snapshot workflow
* fix: format create_sandbox_snapshot.py to pass ruff
---------
Co-authored-by: aran-yogesh <yogesh.mahendran@langchain.dev>
2026-04-21 12:17:19 -07:00
Aran Yogesh
f1907521f3
feat: enforce AGENTS.md reading with strict ALL CAPS prompting ( #1209 )
...
* feat: enforce AGENTS.md reading with strict ALL CAPS prompting
* linting
2026-04-17 13:43:42 -07:00
Aran Yogesh
301d124c3d
fix: remove deprecated temperature parameter ( #1207 )
...
for Opus 4.7 compatibility
2026-04-17 10:45:01 -07:00
dependabot[bot]
213473dc08
chore(deps): bump the minor-and-patch group with 11 updates ( #1198 )
...
Bumps the minor-and-patch group with 11 updates:
| Package | From | To |
| --- | --- | --- |
| [deepagents](https://github.com/langchain-ai/deepagents ) | `0.5.0a4` | `0.5.3` |
| [fastapi](https://github.com/fastapi/fastapi ) | `0.128.3` | `0.135.3` |
| [uvicorn](https://github.com/Kludex/uvicorn ) | `0.40.0` | `0.44.0` |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph ) | `0.3.4` | `0.3.13` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk ) | `0.7.31` | `0.7.32` |
| [langchain-openai](https://github.com/langchain-ai/langchain ) | `1.1.10` | `1.1.13` |
| [langchain-daytona](https://github.com/langchain-ai/deepagents ) | `0.0.3` | `0.0.5` |
| [langchain-modal](https://github.com/langchain-ai/deepagents ) | `0.0.2` | `0.0.3` |
| [langchain-runloop](https://github.com/langchain-ai/deepagents ) | `0.0.3` | `0.0.4` |
| [exa-py](https://github.com/exa-labs/exa-py ) | `2.10.1` | `2.12.0` |
| [ruff](https://github.com/astral-sh/ruff ) | `0.15.0` | `0.15.10` |
Updates `deepagents` from 0.5.0a4 to 0.5.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases )
- [Commits](https://github.com/langchain-ai/deepagents/compare/deepagents==0.5.0a4...deepagents==0.5.3 )
Updates `fastapi` from 0.128.3 to 0.135.3
- [Release notes](https://github.com/fastapi/fastapi/releases )
- [Commits](https://github.com/fastapi/fastapi/compare/0.128.3...0.135.3 )
Updates `uvicorn` from 0.40.0 to 0.44.0
- [Release notes](https://github.com/Kludex/uvicorn/releases )
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md )
- [Commits](https://github.com/Kludex/uvicorn/compare/0.40.0...0.44.0 )
Updates `langgraph-sdk` from 0.3.4 to 0.3.13
- [Release notes](https://github.com/langchain-ai/langgraph/releases )
- [Commits](https://github.com/langchain-ai/langgraph/compare/0.3.4...0.3.13 )
Updates `langsmith` from 0.7.31 to 0.7.32
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.31...v0.7.32 )
Updates `langchain-openai` from 1.1.10 to 1.1.13
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.1.10...langchain-openai==1.1.13 )
Updates `langchain-daytona` from 0.0.3 to 0.0.5
- [Release notes](https://github.com/langchain-ai/deepagents/releases )
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-daytona==0.0.3...langchain-daytona==0.0.5 )
Updates `langchain-modal` from 0.0.2 to 0.0.3
- [Release notes](https://github.com/langchain-ai/deepagents/releases )
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-modal==0.0.2...langchain-modal==0.0.3 )
Updates `langchain-runloop` from 0.0.3 to 0.0.4
- [Release notes](https://github.com/langchain-ai/deepagents/releases )
- [Commits](https://github.com/langchain-ai/deepagents/compare/langchain-runloop==0.0.3...langchain-runloop==0.0.4 )
Updates `exa-py` from 2.10.1 to 2.12.0
- [Commits](https://github.com/exa-labs/exa-py/commits )
Updates `ruff` from 0.15.0 to 0.15.10
- [Release notes](https://github.com/astral-sh/ruff/releases )
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md )
- [Commits](https://github.com/astral-sh/ruff/compare/0.15.0...0.15.10 )
---
updated-dependencies:
- dependency-name: deepagents
dependency-version: 0.5.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: fastapi
dependency-version: 0.135.3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: uvicorn
dependency-version: 0.44.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: langgraph-sdk
dependency-version: 0.3.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: langsmith
dependency-version: 0.7.32
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: langchain-openai
dependency-version: 1.1.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: langchain-daytona
dependency-version: 0.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: langchain-modal
dependency-version: 0.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: langchain-runloop
dependency-version: 0.0.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
- dependency-name: exa-py
dependency-version: 2.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: ruff
dependency-version: 0.15.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 07:09:02 +00:00
dependabot[bot]
c0c5125912
chore(deps): bump python in the minor-and-patch group ( #1195 )
...
Bumps the minor-and-patch group with 1 update: python.
Updates `python` from 3.12.12-slim-trixie to 3.14.0-slim-trixie
---
updated-dependencies:
- dependency-name: python
dependency-version: 3.14.0-slim-trixie
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:56 -07:00
dependabot[bot]
aee6f20627
chore(deps): update langgraph-cli[inmem] requirement ( #1199 )
...
Updates the requirements on [langgraph-cli[inmem]](https://github.com/langchain-ai/langgraph ) to permit the latest version.
- [Release notes](https://github.com/langchain-ai/langgraph/releases )
- [Commits](https://github.com/langchain-ai/langgraph/compare/cli==0.4.12...cli==0.4.21 )
---
updated-dependencies:
- dependency-name: langgraph-cli[inmem]
dependency-version: 0.4.21
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:46:19 -07:00
dependabot[bot]
d2042bfefd
chore(deps): bump astral-sh/setup-uv from 4.2.0 to 8.0.0 ( #1196 )
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 4.2.0 to 8.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](38f3f10444...cec208311d )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 8.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:45:46 -07:00
dependabot[bot]
8ae4179378
chore(deps): bump amannn/action-semantic-pull-request from 5 to 6 ( #1197 )
...
Bumps [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request ) from 5 to 6.
- [Release notes](https://github.com/amannn/action-semantic-pull-request/releases )
- [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md )
- [Commits](e32d7e603d...48f256284b )
---
updated-dependencies:
- dependency-name: amannn/action-semantic-pull-request
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:41:08 -07:00
dependabot[bot]
9219912068
chore(deps): bump actions/checkout from 4 to 6 ( #1194 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:37:03 -07:00
John Kennedy
a94fb8b94c
ci: SHA-pin third-party actions in workflow files ( #1193 )
...
Pin astral-sh/setup-uv and amannn/action-semantic-pull-request to
full commit SHAs to prevent supply chain attacks via tag hijacking.
2026-04-15 23:36:07 -07:00
John Kennedy
da11bcdf60
chore: add dependabot.yml with uv, docker, and github-actions coverage ( #1192 )
...
Adds a compliant dependabot configuration covering all detected
ecosystems with monthly schedule and grouped update-type splits.
2026-04-15 23:35:42 -07:00
dependabot[bot]
32eecbcee2
chore(deps): bump the uv group across 1 directory with 3 updates ( #1191 )
...
Bumps the uv group with 3 updates in the / directory: [langsmith](https://github.com/langchain-ai/langsmith-sdk ), [pytest](https://github.com/pytest-dev/pytest ) and [python-multipart](https://github.com/Kludex/python-multipart ).
Updates `langsmith` from 0.7.25 to 0.7.31
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases )
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.25...v0.7.31 )
Updates `pytest` from 9.0.2 to 9.0.3
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.0.3 )
Updates `python-multipart` from 0.0.22 to 0.0.26
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.26 )
---
updated-dependencies:
- dependency-name: langsmith
dependency-version: 0.7.31
dependency-type: direct:production
dependency-group: uv
- dependency-name: pytest
dependency-version: 9.0.3
dependency-type: direct:production
dependency-group: uv
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:31:23 -07:00
dependabot[bot]
db29b6cad1
chore(deps): bump the uv group across 1 directory with 2 updates ( #1176 )
...
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography ) and [langchain-core](https://github.com/langchain-ai/langchain ).
Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7 )
Updates `langchain-core` from 1.2.22 to 1.2.28
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.22...langchain-core==1.2.28 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.7
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.2.28
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 22:40:37 -07:00
Aran Yogesh
6049405aed
feat: add configurable default prompt file for org-level agent instructions [close OPE-36] ( #1187 )
...
* feat: add configurable default prompt file for org-level agent instructions
* linting
* Update CUSTOMIZATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* fix: address PR review feedback on default prompt
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-15 15:18:14 -07:00
Aran Yogesh
2039fe6660
feat: stop auto-cloning and let agent manage repo setup [closes OPE-21] ( #1159 )
...
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* removing logger.info
* formatting and linting
* fix: resolve lint errors in server.py (imports, unused vars, undefined names)
* feat: use opaque proxy headers for GitHub auth in sandbox
* linting formatting and test changes
* linting
* Delete .claude directory
* Delete tests/evals directory
* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests
* fix: restore authorship, branch_name support, and installation token for PR creation
* linitng
* fix: move installation token fetch before commit, clean up dead proxy validation code
* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]
* feat: stop auto-cloning and let agent manage repo setup [closes OPE-21]
* fix: address review feedback — restore agents_md, add git user config, lint fixes
* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config
* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config
* linting
* linting
* feat: add installation token auth to list_repos GitHub API call
* agents.md update
* linting
* fix: address PR review feedback — shell precedence bug in prompt, remove dead code
* linting
* Apply suggestion from @bracesproul
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Apply suggestion from @bracesproul
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* fix: address PR review feedback — restore {working_dir} in prompt, remove clone code block
* fix:Extract check_or_recreate_sandbox utility from inline sandbox health check
* fix: address PR review feedback — async list_repos, restore template name, fix prompt colon
* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
* linting
* yogesh/ope-21-stop-auto-cloning
* Update agent/tools/list_repos.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Update agent/prompt.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* feat: address PR review — list_repos uses GitHub API only, PR trigger includes org/repo
* linting
* feat: address PR review feedback — list_repos pagination, simpler return, sandbox health check
* feat: support listing repos for personal user accounts via is_organization flag
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-04-10 17:04:55 -07:00
Aran Yogesh
91f63de361
fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures ( #1178 )
...
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures
* fix: refresh GitHub proxy token on sandbox reuse to prevent git auth failures
* function name change
2026-04-09 14:59:49 -07:00
Aran Yogesh
67c782c295
fix: block open-swe from approving PRs ( #1177 )
...
* fix: block open-swe from approving PRs
* linting
* fix: add case-insensitive APPROVE guard and unit tests
2026-04-09 11:45:08 -07:00
Aran Yogesh
4d4f5fbfc7
fix: proxy config restored the branch yogesh/GitHub auth proxy ( #1173 )
...
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* removing logger.info
* formatting and linting
* fix: resolve lint errors in server.py (imports, unused vars, undefined names)
* feat: use opaque proxy headers for GitHub auth in sandbox
* linting formatting and test changes
* linting
* Delete .claude directory
* Delete tests/evals directory
* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests
* fix: restore authorship, branch_name support, and installation token for PR creation
* linitng
* fix: move installation token fetch before commit, clean up dead proxy validation code
* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config
* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config
* linting
* linting
* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-08 15:02:52 -07:00
Aran Yogesh
9e5088b75a
Revert "feat: add minimal diff rules and scope planning to agent prompt ( #1171 )" ( #1174 )
...
This reverts commit 71b573625c .
2026-04-08 15:00:43 -07:00
Aran Yogesh
71b573625c
feat: add minimal diff rules and scope planning to agent prompt ( #1171 )
2026-04-08 14:56:34 -07:00
Aran Yogesh
9aba4d0545
Revert "feat: authenticate git operations via sandbox proxy instead of creden…" ( #1170 )
...
This reverts commit 6305e13dc6 .
2026-04-07 18:45:33 -07:00
Brace Sproul
c5ba4e2e93
Revert "fix: add retry with delay for sandbox proxy config to avoid 500 when …" ( #1169 )
...
This reverts commit e25b158218 .
2026-04-07 18:37:15 -07:00
Aran Yogesh
e25b158218
fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready ( #1168 )
...
* fix: add retry with delay for sandbox proxy config to avoid 500 when proxy isn't ready
* fix: add retry with exponential backoff and connection error handling for proxy config
2026-04-07 17:57:21 -07:00
Aran Yogesh
6305e13dc6
feat: authenticate git operations via sandbox proxy instead of credential files [closes: OPE-20] ( #1070 )
...
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* feat: authenticate git operations via sandbox proxy instead of credential files
* removing logger.info
* formatting and linting
* fix: resolve lint errors in server.py (imports, unused vars, undefined names)
* feat: use opaque proxy headers for GitHub auth in sandbox
* linting formatting and test changes
* linting
* Delete .claude directory
* Delete tests/evals directory
* fix: address PR review — guard missing tokens, quote shell paths, add proxy auth tests
* fix: restore authorship, branch_name support, and installation token for PR creation
* linitng
* fix: move installation token fetch before commit, clean up dead proxy validation code
* fix: drop github_token arg from sandbox creation, use generic create_sandbox factory with langsmith-only proxy config
* fix: use _get_langsmith_api_key() for prod key fallback, warn when API key missing for proxy config
* linting
* linting
* fix: resolve merge conflicts with main, adopt deepagents v0.5.0a4 LangSmithSandbox
2026-04-07 16:41:48 -07:00
open-swe[bot]
24a6343352
chore: upgrade deepagents to v0.5.0a4 ( #1161 )
...
Replace custom LangSmithBackend with built-in LangSmithSandbox from
deepagents. Update deprecated protocol method names in docs.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Sydney Runkle <54324534+sydney-runkle@users.noreply.github.com>
2026-04-06 10:24:50 -07:00
John Kennedy
d3506598fe
fix: upgrade deps to patch Pygments ReDoS and PyJWT crit header vulns ( #1164 )
...
- Bump deepagents >=0.4.3 → >=0.4.12
- Bump PyJWT >=2.8.0 → >=2.12.0 (fixes CVE-2026-32597, GHSA-752w-5fwx-jx9f)
- Pin Pygments >=2.20.0 in dev deps (fixes CVE-2026-4539, GHSA-5239-wwwm-4pmq)
- Regenerate uv.lock (also pulls langchain 1.2.15, langgraph 1.1.6)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 20:42:51 -07:00
dependabot[bot]
924c096782
chore(deps): bump aiohttp in the uv group across 1 directory ( #1158 )
...
---
updated-dependencies:
- dependency-name: aiohttp
dependency-version: 3.13.4
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:19:49 -07:00
mlo20030
4a4bb37d45
adding myself as user ( #1162 )
2026-04-03 15:52:04 -07:00
Brace Sproul
fd8e6d98ee
fix: Shell injection and ssrf issues ( #1155 )
...
* fix: Shell injection and ssrf issues
* cr
2026-04-01 12:37:35 -07:00
dependabot[bot]
4856cc31d4
chore(deps): bump the uv group across 1 directory with 3 updates ( #1152 )
...
Bumps the uv group with 3 updates in the / directory: [cryptography](https://github.com/pyca/cryptography ), [langchain-core](https://github.com/langchain-ai/langchain ) and [requests](https://github.com/psf/requests ).
Updates `cryptography` from 46.0.5 to 46.0.6
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6 )
Updates `langchain-core` from 1.2.15 to 1.2.22
- [Release notes](https://github.com/langchain-ai/langchain/releases )
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-core==1.2.15...langchain-core==1.2.22 )
Updates `requests` from 2.32.5 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases )
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md )
- [Commits](https://github.com/psf/requests/compare/v2.32.5...v2.33.0 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.6
dependency-type: direct:production
dependency-group: uv
- dependency-name: langchain-core
dependency-version: 1.2.22
dependency-type: indirect
dependency-group: uv
- dependency-name: requests
dependency-version: 2.33.0
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 23:33:28 -07:00
dependabot[bot]
1bc4afc05d
chore(deps): bump cbor2 in the uv group across 1 directory ( #1120 )
...
Bumps the uv group with 1 update in the / directory: [cbor2](https://github.com/agronholm/cbor2 ).
Updates `cbor2` from 5.8.0 to 5.9.0
- [Release notes](https://github.com/agronholm/cbor2/releases )
- [Commits](https://github.com/agronholm/cbor2/compare/5.8.0...5.9.0 )
---
updated-dependencies:
- dependency-name: cbor2
dependency-version: 5.9.0
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 01:58:27 -07:00
Aran Yogesh
86307affe4
fix: use GitHub App installation token for PR creation instead of user token ( #1149 )
...
* fix: use GitHub App installation token for PR creation instead of user token
* fix: move installation token fetch after no-changes check to avoid unnecessary API call
2026-03-30 12:47:57 -07:00
Aran Yogesh
7d1004ad66
fix: add Exa web search tool [closes: OPE-29] ( #1133 )
...
* fix: add Exa web search tool
* chore: update uv.lock for exa-py dependency
* linting
* chore: remove web_search from system prompt
* chore: drop search_type and category params from web_search
2026-03-25 16:24:31 -07:00
Brace Sproul
87968ab813
fix: Add scripts for getting usage, fix dual committing ( #1131 )
2026-03-25 13:39:33 -07:00
Brace Sproul
0d8647c2cd
fix: Revert dummy readme change ( #1132 )
2026-03-25 13:35:11 -07:00
Brace Sproul
4cfe2fd8a5
chore: dummy readme change to test committing workflow ( #1130 )
...
* chore: dummy readme change to test committing workflow
Co-authored-by: Brace Sproul <46789226+bracesproul@users.noreply.github.com>
* cr
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 13:34:08 -07:00
Brace Sproul
e1de58c584
fix: convert @Name(USER_ID) mentions to Slack's <@USER_ID> format in thread replies ( #1126 )
...
The agent sees users formatted as @Name(USER_ID) in conversation context and
reproduces that pattern in replies, but Slack requires <@USER_ID> for real
mentions. This adds automatic conversion and updates prompt instructions.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:51:11 -07:00
Brace Sproul
3fea3c8709
feat: read LLM model ID from LLM_MODEL_ID env var, defaulting to anthropic:claude-opus-4-6 ( #1128 )
...
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-25 11:32:44 -07:00
Brace Sproul
267b2fd011
feat: add github pr review tools [closes OPE-24] ( #1104 )
...
* Add GitHub PR review tools (list, get, create, update, dismiss, submit, list comments) and bind them to the agent
* format n lint
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Aran Yogesh <yogesh.mahendran@langchain.dev>
2026-03-23 21:37:54 +00:00
Brace Sproul
91348aeb7c
feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments ( #1105 )
...
Adds 6 new agent tools backed by Linear's GraphQL API, with a shared
_graphql_request helper to reduce boilerplate. Refactors existing
comment_on_linear_issue to use the same helper.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-23 14:32:44 -07:00
Aran Yogesh
f79e824d8e
feat: add Slack image support with url_private auth and content-type validation [closes: OPE-23] ( #1073 )
...
* feat: add Slack image support with url_private auth and content-type validation
* fix: simplify Slack image fetch by removing manual redirect logic
* fix: use urlparse hostname check to resolve CodeQL URL sanitization warning
* Update agent/utils/multimodal.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* fix: simplify host matching conditions in multimodal image fetching
* reverting changes
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-20 14:34:14 -07:00
Brace Sproul
46d7ed9d43
feat: extract repo parsing into shared util, add linear comment repo override ( #1103 )
...
* feat: extract repo parsing into shared util and add linear comment repo override
Moves the repo extraction regex logic (repo:, repo , GitHub URL) into
agent/utils/repo.py so it can be reused. Updates the Linear webhook
handler to check the comment body for a custom repo first, falling back
to the team/project mapping when none is specified.
* chore: document repo extraction util and default org configuration
* feat: add generic DEFAULT_REPO_OWNER/DEFAULT_REPO_NAME env vars replacing Slack-only defaults
* chore: remove deprecated SLACK_REPO_OWNER/NAME env vars from docs
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 13:34:00 -07:00
Aran Yogesh
6fc82d9edd
feat: default org to langchain-ai when repo name specified without org ( #1099 )
...
* feat: default org to langchain-ai when repo: is used without org prefix
* chore: use SLACK_REPO_OWNER for repo shorthand default org and document in CUSTOMIZATION.md
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-03-20 12:05:30 -07:00
Aran Yogesh
150ff6f0c8
fix: allow open-swe to be triggered on any GitHuh branch ( #1100 )
...
* fix: allow open-swe to be triggered on any GitHuh branch
* formmatting
2026-03-20 10:53:33 -07:00
Aran Yogesh
ea27978d51
fix: queue Slack follow-up messages instead of interrupting active runs ( #1050 )
...
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-19 13:59:25 -07:00
Brace Sproul
352f787989
fix: log all exceptions ( #1089 )
2026-03-19 10:26:26 -07:00
dependabot[bot]
075e163746
chore(deps): bump pyasn1 in the uv group across 1 directory ( #1078 )
...
Bumps the uv group with 1 update in the / directory: [pyasn1](https://github.com/pyasn1/pyasn1 ).
Updates `pyasn1` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/pyasn1/pyasn1/releases )
- [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst )
- [Commits](https://github.com/pyasn1/pyasn1/compare/v0.6.2...v0.6.3 )
---
updated-dependencies:
- dependency-name: pyasn1
dependency-version: 0.6.3
dependency-type: indirect
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-18 21:40:10 -07:00
dependabot[bot]
64b41b4f8b
chore(deps): bump the uv group across 1 directory with 2 updates ( #1031 )
...
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography ) and [langgraph](https://github.com/langchain-ai/langgraph ).
Updates `cryptography` from 46.0.4 to 46.0.5
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/46.0.4...46.0.5 )
Updates `langgraph` from 1.0.8 to 1.0.10rc1
- [Release notes](https://github.com/langchain-ai/langgraph/releases )
- [Commits](https://github.com/langchain-ai/langgraph/compare/1.0.8...1.0.10rc1 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 46.0.5
dependency-type: direct:production
dependency-group: uv
- dependency-name: langgraph
dependency-version: 1.0.10rc1
dependency-type: direct:production
dependency-group: uv
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-19 04:36:43 +00:00
Aran Yogesh
b64d871913
feat: send LangSmith trace URL on run trigger from Slack and Linear ( #1057 )
...
* feat: send LangSmith trace URL on run trigger from Slack and Linear
* fix: check LANGSMITH_PROJECT before LANGSMITH_PROJECT_PROD for project name lookup
* fix: pass LangSmith API key explicitly to Client and remove global variable
* Update agent/utils/langsmith.py
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* refactor: move trace notification helpers out of webapp and use env vars for LangSmith URL base
* docs: add LangSmith tenant and project ID env vars to installation guide
* fix: remove unused comment_on_linear_issue import from webapp
* nit: remove lru_cache, make get_langsmith_trace_url sync, and move langsmith import to top level
* Update INSTALLATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Update INSTALLATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
* Update INSTALLATION.md
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
---------
Co-authored-by: Brace Sproul <braceasproul@gmail.com>
2026-03-18 12:17:45 -07:00