Deepr 2.50.7 strengthens MCP state integrity and asynchronous task lifecycle behavior. It preserves canonical research state across restarts and schema upgrades, prevents stale observations from regressing settled jobs, and makes cancellation stop the underlying work.
Fixed
- Preserve active tasks, temporal findings, hypothesis history, plan state, and belief state through SQLite restarts and legacy schema migrations.
- Replace destructive parent and child persistence writes with foreign-key-safe upserts, serialize shared SQLite access, and validate related job identities before mutation.
- Keep partial saves from clearing omitted state and clear stale active tasks when restart recovery fails.
- Make terminal job phases and accumulated costs monotonic, reject invalid or non-finite numeric values, and prevent stale provider polls from resurrecting settled jobs.
- Validate asynchronous task batches before dispatch, including task IDs, coroutine payloads, dependency references, and dependency cycles.
- Cancel and await actual task runners, and isolate concurrent batches that reuse the same task ID.
- Restrict wildcard subscriptions to canonical campaign and expert resource paths with safe identifiers.
Changed
- Refresh the README, roadmap, changelog, supported surface, threat model, package metadata, lockfile, Agent Skill, Agent Plugin, and compatibility fixtures for 2.50.7.
- Add focused regression coverage for legacy persistence, partial updates, restart recovery, terminal-state races, invalid task graphs, real cancellation, concurrent same-ID batches, and malformed subscription paths.
Verification
- Pull request #156 passed the complete required check set before merge.
- Main CI passed on the exact release commit with Python 3.12, 3.13, and 3.14.
- CodeQL passed for Actions, JavaScript/TypeScript, and Python on the same commit.
- 11,700 tests passed and 20 were skipped in the local full unit run, with 85.10% branch coverage against the 80% gate.
- Strict mypy passed across 158 source files. Ruff lint and format checks, security and complexity ratchets, documentation consistency, packaging tests, and frontend checks passed.
- The final wheel and source distribution passed packaged-frontend inspection and Twine metadata validation.
- Two independent Agent Plugin builds were byte-for-byte identical, and the exact-main Agent Plugin CI job passed clean installation and contained read-only MCP smoke tests.
- No paid provider calls were made.
Artifact SHA-256
deepr_research-2.50.7-py3-none-any.whl:92aa9b210fb35d7c3fb468e55c8bea5ff4f1a1f4835d6e2dae4ec4e9fde84ae1deepr_research-2.50.7.tar.gz:6f08ecea86a62dc6ee4682bf32da74b4f7b9942d82f6c62b64c21687e4618ca2deepr-agent-plugin-2.50.7.tar.gz:67cc22fcda8177d10a31f3681b4f17c77a88213731fd7dd436e2be00681244e9