NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #688 by repository stars
Last release 3 days ago
05 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 months old
927 releases · first in 2025
One column per month.
security(deps): bump pytest to >=9.0.3 (CVE-2025-71176) by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/488
⚠️ This is a staging/pre-release version for testing. Not recommended for production use.
# Staging binary (use --staging flag)
curl -fsSL https://agentfield.ai/install.sh | bash -s -- --staging
# Python SDK (prerelease - requires --pre flag)
pip install --pre agentfield
# TypeScript SDK
npm install @agentfield/sdk@next
VERSION=v0.1.139-rc.1 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64af call rejecting valid input for optional reasoner params by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/610_current_status issue where status stuck on `S… by @DebanKsahu in https://github.com/Agent-Field/agentfield/pull/673af install by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/738Note truncated.
TestOutputPath and TestSchemaPath asserted hardcoded Unix path separators (/tmp/...), so they failed on Windows where filepath.Join produces backslash separators. Assert against filepath.Join with the existing filename constants so the expected value is computed the same way the production code computes it.
Go SDK CI runs only on ubuntu-latest, so these failures surfaced only in local Windows development. The change is a no-op on Linux (Join yields the identical string) and a fix on Windows. (10aa43c)
`bash curl -fsSL https://agentfield.ai/install.sh | bash `
curl -fsSL https://agentfield.ai/install.sh | bash
VERSION=v0.1.138 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64Full Changelog: https://github.com/Agent-Field/agentfield/compare/v0.1.137...v0.1.138
security(deps): bump pytest to >=9.0.3 (CVE-2025-71176) by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/488
⚠️ This is a staging/pre-release version for testing. Not recommended for production use.
# Staging binary (use --staging flag)
curl -fsSL https://agentfield.ai/install.sh | bash -s -- --staging
# Python SDK (prerelease - requires --pre flag)
pip install --pre agentfield
# TypeScript SDK
npm install @agentfield/sdk@next
VERSION=v0.1.138-rc.16 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64af call rejecting valid input for optional reasoner params by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/610_current_status issue where status stuck on `S… by @DebanKsahu in https://github.com/Agent-Field/agentfield/pull/673af install by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/738Note truncated.
Bumps the npm_and_yarn group with 1 update in the /sdk/typescript directory: @ai-sdk/provider-utils.
Updates @ai-sdk/provider-utils from 4.0.23 to 4.0.50
updated-dependencies:
Signed-off-by: dependabot[bot] support@github.com
Dependabot's refresh also rewrote desktop/package-lock.json, but that lockfile contains no @ai-sdk packages at all -- its only change was an unrelated browserslist 4.28.8 -> 4.28.9 dev-dependency drift. Revert it so the PR carries only the security fix.
sdk/typescript/package-lock.json is kept as dependabot generated it. Every
@ai-sdk/* adapter and ai pins @ai-sdk/provider-utils to an exact version --
no caret, no tilde -- in every one of their published releases, so the package
cannot be moved on its own: npm update @ai-sdk/provider-utils --package-lock-only against the base lockfile is a verified no-op. Regenerating
from the base with a scoped npm update of only the direct AI dependencies
reproduces this same resolution, and every package that moves is a forced
consequence of that exact-pin chain (see the PR discussion for the per-package
breakdown).
Co-Authored-By: Claude Opus 5 noreply@anthropic.com
Signed-off-by: dependabot[bot] support@github.com Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Abir Abbas abirabbas1998@gmail.com Co-authored-by: Claude Opus 5 noreply@anthropic.com (d2fad28)
security(deps): bump pytest to >=9.0.3 (CVE-2025-71176) by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/488
⚠️ This is a staging/pre-release version for testing. Not recommended for production use.
# Staging binary (use --staging flag)
curl -fsSL https://agentfield.ai/install.sh | bash -s -- --staging
# Python SDK (prerelease - requires --pre flag)
pip install --pre agentfield
# TypeScript SDK
npm install @agentfield/sdk@next
VERSION=v0.1.138-rc.15 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64af call rejecting valid input for optional reasoner params by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/610_current_status issue where status stuck on `S… by @DebanKsahu in https://github.com/Agent-Field/agentfield/pull/673af install by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/738Note truncated.
fix(storage): honor execution activity in workflow reaper
fix(storage): guard stale workflow update against activity race
fix(storage): re-check staleness in the execution reaper update
MarkStaleWorkflowExecutions now repeats its candidate predicates in the conditional UPDATE, but MarkStaleExecutions still only re-checked status. A heartbeat that lands between its candidate selection and that UPDATE therefore still flips a live execution row to timeout — the same false timeout the workflow reaper just stopped producing, through a narrower window (its candidate query reads the clock the heartbeat writes, so the race is the millisecond gap between the two statements rather than the whole run).
Give it the same treatment: the conditional UPDATE re-evaluates the activity clock against the sweep cutoff and the non-terminal-child guard, and the body moves behind the same post-selection seam the workflow reaper uses so the interleaving is testable without sleeps.
Tests: a real execution-note write landing in that window leaves the row running with its note intact; a seam that writes nothing still reaps the silent row with the existing "no activity" message.
Co-Authored-By: Claude Opus 5 noreply@anthropic.com
Co-authored-by: Abir Abbas abirabbas1998@gmail.com Co-authored-by: Claude Opus 5 noreply@anthropic.com (78215f1)
Two defects let execution_completed count things that were not executions.
Duplicate lifecycle events were forwarded verbatim. A terminal status callback re-delivered after a lost 200 used to re-run every side effect, publishing a second completed event for an execution that had already been reported (#951 closed that path in the handler; the SDKs retry a callback up to five times, so one execution could report several). The telemetry client had no defense of its own: it minted a stable telemetry_event_id and left deduplication entirely to the ingest side. It now remembers the terminal outcomes it has reported and drops a repeat, so a republished event cannot inflate a count regardless of what ingest does with the event ID. Only stable identities are eligible — the random ones belong to transitions allowed to recur, such as timeout -> running -> timeout, and collapsing those would lose real events. The set is bounded at 8192 keys with oldest-first eviction; a duplicate arrives within seconds, so eviction can only drop keys long past the window where they could suppress anything.
usage_context rode only on control_plane_started. A CI job starts the control plane on a fresh volume, so it mints a new install ID and its executions look exactly like a real first-time user's — and with the context on the startup event alone, nothing downstream could separate them after ingestion. Disabling telemetry for the functional-test compose stacks was a fix for one known producer; this makes every producer distinguishable at the source. It is now stamped on every event, so execution_completed can be filtered to dev_or_local/server and CI traffic excluded.
Schema version goes to 3 so the ingest side can tell a build that stamps usage_context everywhere from one that does not, and know when the filter is trustworthy.
Co-authored-by: Santosh kumar santoshkumarradha@users.noreply.github.com
The relay validates telemetry_schema_version strictly: it accepts only 1 or 2 (app/api/oss/telemetry/route.ts in Agent-Field/website2.0) and returns 400 invalid_telemetry_event for anything else, before ingest. A producer declaring 3 would therefore have every payload dropped whole rather than degraded, silently zeroing out control-plane telemetry.
Nothing in this branch changes the v2 wire shape -- usage_context is additive and already allowlisted by the relay's shared property schema, and the duplicate suppression is producer-side and invisible to ingest -- so the bump bought nothing. Keep it at 2 until a relay that accepts a newer version is deployed.
The test asserted the emitted version against the constant, which compares the constant to itself; it now pins the literal 2 so a future bump has to be a visible test change.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
observe() recorded the outcome before enqueue() ran, and enqueue drops the event when the 256-deep send queue is full (one worker, one network POST at a time). The outcome was then marked reported without ever being sent, and the republish that would have delivered it was suppressed for good -- turning a transient backpressure drop into permanent loss of that execution's terminal event, precisely when volume is highest. Before this branch that retry got through.
enqueue now reports whether the event actually made it onto the queue, and handleExecutionEvent releases the dedupe key when it did not. observe stays ahead of the enqueue because it is an atomic test-and-set: that is what bounds concurrent republishes to at most one report.
telemetryReportedSet keeps the key's ring slot in the membership map so forget can clear both, otherwise a released key would leave a stale ring entry that later evicts a freshly re-observed key ahead of its time.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
detectUsageContext bucketed the process as ci on the mere presence of
CI, GITHUB_ACTIONS, GITLAB_CI, BUILDKITE, CIRCLECI or JENKINS_URL.
CI=false is a common way to say "not CI" / "turn CI behaviour off", so
a user who exports it had every event labelled ci. Now that
usage_context rides on every event rather than just control_plane_started,
that mislabels all of their traffic and filters real usage out of the
product numbers.
Only a truthy value counts: empty, 0, false, no and off (trimmed, case-insensitive) are not CI.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Suppressing a republished terminal outcome keeps the counts right, but at Debug it also makes the producer bug that caused the republish invisible: the metric stops moving and nothing says why. Warn keeps that signal alive for an operator without changing behaviour.
The line stays low-cardinality and carries only the telemetry event name -- never the execution ID or the dedupe key, which are exactly what eventIdentity exists to keep inside the process.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Co-authored-by: Cursor Agent cursoragent@cursor.com Co-authored-by: Santosh kumar santoshkumarradha@users.noreply.github.com Co-authored-by: Abir Abbas abirabbas1998@gmail.com Co-authored-by: Claude Fable 5.1 noreply@anthropic.com (366c7ff)
security(deps): bump pytest to >=9.0.3 (CVE-2025-71176) by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/488
⚠️ This is a staging/pre-release version for testing. Not recommended for production use.
# Staging binary (use --staging flag)
curl -fsSL https://agentfield.ai/install.sh | bash -s -- --staging
# Python SDK (prerelease - requires --pre flag)
pip install --pre agentfield
# TypeScript SDK
npm install @agentfield/sdk@next
VERSION=v0.1.138-rc.14 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64af call rejecting valid input for optional reasoner params by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/610_current_status issue where status stuck on `S… by @DebanKsahu in https://github.com/Agent-Field/agentfield/pull/673af install by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/738Note truncated.
Argument coercion only handled a bare model or a 2-arg Optional[model]. Complex hints fell through as raw dicts:
It also silently swallowed validation errors due to a Pydantic v2 ValidationError constructor mismatch, returning the raw dict instead of surfacing the failure.
Fix:
Adds tests for each reported case plus non-model pass-through and validation-error propagation.
Addresses review feedback on PR #1035. The rewrite wrapped validation failures as ValueError, but the reasoner/skill call sites in agent.py and decorators.py intercept pydantic.ValidationError specifically to route bad payloads through their safe-validation path (_HandlerInputError, avoiding stack-trace exposure in 422s). Wrapping as ValueError let a bad payload miss that handler and fall back to the raw dict.
Let the ValidationError from TypeAdapter propagate unchanged so the existing callers keep intercepting it. Tests now assert ValidationError explicitly.
Two follow-ups to the complex-hint coercion in this PR, both found by driving a real Agent through its ASGI request path:
def reasoner(m: MyModel = None) and def reasoner(items: list[MyModel] = None) (implicit Optional, no Optional[...] wrapper) used to work:
apply_defaults() fills None and the old code never validated a
non-dict. Under TypeAdapter(hint).validate_python(None) they started
raising ValidationError, so every call to such a reasoner became an
error response. Return top-level None unchanged, before any adapter
work; None elements inside a container are still validated by the
adapter, and a null for a required parameter is still rejected by
Agent._validate_handler_input before conversion runs.
A fresh TypeAdapter was built on every call. Measured on python 3.11 /
pydantic 2.13.5 with a list[Model] | None parameter: 84 us per
conversion, of which 55 us is adapter construction; with the adapter
cached the validation itself is 1.2 us. Cache it in a 512-entry
lru_cache, with an uncached fallback for unhashable hints so a hint can
never silently lose its coercion just because it is not hashable.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Now that convert_function_args lets pydantic's ValidationError escape, the three call sites that were written to handle it are actually reached — and two of them were broken:
agent.py built a _HandlerInputError "to prevent stack trace exposure in
422 responses" but nothing caught it, so an invalid payload for one of the
newly covered shapes escaped the endpoint and starlette answered
500 "Internal Server Error". Verified over the real ASGI path: a reasoner
typed M1 | M2 | None given {"item": {"x": "bad"}}, a reasoner typed
list[M1] given [{"a": "bad"}], and the equivalent skill call all
returned 500. They now return 422 {"detail": "..."}, the same shape the
input validator already returns, with no pydantic text or payload echoed
back. The skill conversion moved above the execution-context setup so the
early return cannot leak the context; the reasoner path catches
_HandlerInputError around both synchronous awaits, leaving the 202
fire-and-forget path, cancellation (499) and cost-tracker handling alone.
decorators.py re-raised ValidationError(msg, model=...), the exact
pydantic-v2 constructor misuse that was removed from pydantic_utils.py in
this PR: it raises TypeError: ValidationError.__new__() got an unexpected keyword argument 'model'. It was dead code before (the error never
escaped conversion); it is live now, so a bad payload on the in-process
reasoner-calls-reasoner path failed with that TypeError instead of the
validation error. Propagate the original ValidationError unchanged.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Co-authored-by: Abir Abbas abirabbas1998@gmail.com Co-authored-by: Claude Fable 5.1 noreply@anthropic.com (faf5f78)
security(deps): bump pytest to >=9.0.3 (CVE-2025-71176) by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/488
⚠️ This is a staging/pre-release version for testing. Not recommended for production use.
# Staging binary (use --staging flag)
curl -fsSL https://agentfield.ai/install.sh | bash -s -- --staging
# Python SDK (prerelease - requires --pre flag)
pip install --pre agentfield
# TypeScript SDK
npm install @agentfield/sdk@next
VERSION=v0.1.138-rc.13 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64af call rejecting valid input for optional reasoner params by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/610_current_status issue where status stuck on `S… by @DebanKsahu in https://github.com/Agent-Field/agentfield/pull/673af install by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/738Note truncated.
security(deps): bump pytest to >=9.0.3 (CVE-2025-71176) by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/488
⚠️ This is a staging/pre-release version for testing. Not recommended for production use.
# Staging binary (use --staging flag)
curl -fsSL https://agentfield.ai/install.sh | bash -s -- --staging
# Python SDK (prerelease - requires --pre flag)
pip install --pre agentfield
# TypeScript SDK
npm install @agentfield/sdk@next
VERSION=v0.1.138-rc.12 curl -fsSL https://agentfield.ai/install.sh | bash
Download the binary for your platform below, make it executable, and move it to your PATH.
agentfield-darwin-amd64agentfield-darwin-arm64agentfield-linux-amd64agentfield-linux-arm64af call rejecting valid input for optional reasoner params by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/610_current_status issue where status stuck on `S… by @DebanKsahu in https://github.com/Agent-Field/agentfield/pull/673af install by @AbirAbbas in https://github.com/Agent-Field/agentfield/pull/738Note truncated.
Your coding agent can read these notes before it upgrades. Set up the MCP server →