v1.1.2
Security
openbox_api_keyis no longer written to workflow history. Credentials are now captured on the governance activity instance instead of flowing throughsend_governance_eventinputs. Rotate your key after upgrade if your namespace was shared - old histories still contain it.
New
- W3C trace propagation through Temporal headers is on by default.
traceparentflows from caller → workflow → activity, so upstream spans finally stitch to workflow spans in your tracing backend. Opt out with
enable_trace_propagation=False.
Fixes
WorkflowFailedreporting can no longer shadow the real workflow exception when governance isfail_closedand the API is down.- Governance error routing now matches
ApplicationError.typeinstead of substring-matchingstr(e)- no more false halts when a user error message contains a governance keyword. - Race fix on the lazy
httpxclient inhook_governance- eliminates connection-pool leaks under concurrent activities. Replayerin plugin integration tests now receives the plugin, validating interceptor replay-safety.print()in plugin/worker init replaced with module loggers.temporalio >= 1.23.0version-pin comments corrected.
Compat
No breaking public-API changes. New parameter enable_trace_propagation (default True) on OpenBoxPlugin and create_openbox_worker().
Full changelog: https://github.com/OpenBox-AI/openbox-temporal-sdk-python/blob/main/CHANGELOG.md