Deepr v2.50.3 - fail-closed completions, terminal jobs, and authenticated docs
Deepr 2.50.3 closes remaining fail-closed holes found after v2.50.2: empty queue-sync completions, incomplete provider snapshots left PROCESSING, dashboard poller paging, terminal queue overwrites, and unauthenticated REST docs.
Fixed
- Shared provider completion fails empty extractable content instead of saving a blank
report.mdas COMPLETED. - CLI job get/list/status and
deepr queue syncclose incomplete, expired, cancelled, and failed provider snapshots. - The dashboard poller pages every PROCESSING job, matching the worker.
- SQLite
update_statusrefuses to rewrite COMPLETED, FAILED, or CANCELLED rows. Failed and cancelled rows recordcompleted_at. - REST
/api/docs,/apispec_1.json, and/flasgger_staticrequire the API token whenDEEPR_API_TOKENis set. - MCP expert names reject reserved Windows device names at the validator.
- Dashboard auth cookies set
Secureon HTTPS. The REST debug server cannot enable the Werkzeug debugger off-loopback.
Verification
- Python 3.12, 3.13, and 3.14 CI passed on PR #152 and the merged
maincommitdafd5786. - Lint, security (Gitleaks, pip-audit), CodeQL, frontend, agent-plugin, and core-install jobs passed.
- GitHub and the local checkout contain only the clean
mainbranch. - No paid model or provider API calls were made during bug hunting, testing, or release verification.
Full detail is in docs/CHANGELOG.md.
Artifact SHA-256:
deepr_research-2.50.3-py3-none-any.whl:145c4a781fa28fababd5192923c5a7bc6d4ea31f3b95ccc311f703a2a1dc8a80deepr_research-2.50.3.tar.gz:8db8f8df83d4c366ac592d5f20d9fd5709ae8c4dfb3ff9d80de8a1fc6dc52901