v2.1.0 Release #5832
WillemJiang
announced in
Announcements
v2.1.0 Release
#5832
Replies: 1 comment
|
When will The DeerFlow Harness release that described on https://deerflow.tech/en/docs/harness, and on which version? |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
DeerFlow 2.1.0
DeerFlow 2.1 builds on the 2.0 super-agent harness with a focus on trust,
scale, and operability: verifiable agent execution, durable batch delegation,
pluggable memory backends, four new sandbox providers, an out-of-tree extension
system, and enterprise-grade authentication and authorization — wrapped in a
much richer workspace with projects, conversation branching, and referenced
conversations.
This release closes the 2.1.0 milestone
with 772 merged PRs since the 2.0.0 release.
X-Trace-Idheader, andlogging.enhance.enablednow controls log outputonly. Client-supplied
deerflow_trace_idvalues in run metadata areoverwritten so header, logs, and the persisted run cannot disagree — send
the
X-Trace-Idrequest header to pin a correlation id. ([feature(gateway): issue request trace ids unconditionally #5119])/mnt/skillsis reserved for managed enabled-only skill projections.DEER_FLOW_HOST_SKILLS_PATH/SKILLS_HOST_PATHare no longer used, andE2B operator mounts targeting that path are skipped with a warning.
([fix(sandbox): enforce disabled skills in filesystem views #4178])
sandbox.replicasis enforced for E2B as a capacity limit; the defaultwaitpolicy can now fail the agent turn instead of growing past the cap.([fix(sandbox): enforce E2B replica capacity limits #4391])
SKILL.mddirectory is a runtime package boundary — nestedSKILL.mdfiles are supporting data, no longer registered as independent skills.
([fix(skills): apply allowed-tools only to active skills #4098])
memory.manager_class): DeerMem-private settingsmove into
memory.backend_config(auto-migrated with a warning),/memory/configchanged shape,storage_pathis now a root directory(legacy file-style values are dropped with a warning), custom storage classes
move to a new path and take
configin__init__, and a backend withoutsearch()fails fast intoolmode. ([feat(memory): pluggable memory abstraction with self-contained DeerMem backend #4122], [feat(memory): add memory tool sets #4023], [[feat] memory: pluggable MemoryManager interface for backend onboarding #4324])database.checkpoint_delta_snapshot_frequencymoved todatabase.checkpoint_delta.snapshot_frequencyand its default changed from1000to10— set it explicitly to keep the old cadence. ([feat(checkpoint): make delta snapshot_frequency configurable #4516])127.0.0.1in both compose files, matching the documented local-trustdeployment model; set
BIND_HOSTto expose the stack on other interfaces.([fix(docker): bind the published entry port to loopback by default #4618])
✨ Highlights
runtime-stamped receipt and a bounded receipt ledger reaches the model
context; subagent reports must cite tool receipts with verifiable deliverable
handles that the lead agent cross-checks; and
acceptance_criteriaondelegations are checked deterministically parent-side (file existence,
recorded test-command exit status), with anything undecidable reported
UNVERIFIED. ([feat(harness): deterministic tool receipts with model-visible ledger (RFC #4651, layer 1) #4659], [feat(harness): subagent receipt citation verification #5076], [feat(harness): subagent report contract and delegation acceptance criteria #5090], [feat(harness): deterministic acceptance checklist for subagent delegations (RFC #4651, layer 2) #5109], [feat(runtime): record terminal artifact delivery receipts (slice 1 of #4272) #4365])
redundant re-delegation and a total cap bounds fan-out ([feat(subagents): system-maintained delegation ledger to stop redundant re-delegation #3877], [feat(agent): Add subagent total delegation cap #4115]);
one process-wide capacity controller governs concurrency, and the opt-in
batch_tasktool runs large collections of independent items as durable,resumable SQL-backed batches with leases, retries, pause/resume/cancel, and
a chat progress panel ([feat(subagents): add unified capacity and durable batch execution #4998], [feat(subagents): add acceptance checks to durable batch items #5289]);
task(context_mode="snapshot")carries a dispatch-time copy of the parent conversation ([feat(subagents): add opt-in parent context snapshots #5367]); and
subagent step history is persisted and displayed in the thread. ([feat(subagents): persist and display subagent step history (#3779) #3845])
intervalschedules joinonceandcron([feat(scheduler): add interval schedule type #5291]); upcoming cron occurrences can be previewed before saving
([feat(scheduled-tasks): preview upcoming cron occurrences #5381]); run history filters server-side by status and pages backwards in
the UI ([feat(scheduled-tasks): filter run history by occurrence status #5384], [feat(scheduled-tasks): browse paginated run history #5363]); tasks can pin
lead_agentor a custom agent([[feat] Let scheduled tasks choose a custom agent #5286], [feat(scheduler): let scheduled tasks pin a custom agent #5288]); busy occurrences queue durably across restarts
([fix(scheduler): enqueue busy scheduled task runs #4918]); and multi-instance recovery no longer interrupts live runs.
([fix(scheduler): support safe multi-instance scheduler recovery #4713])
([feat(memory): add OpenViking HTTP backend #4509], [feat(memory): add mem0 HTTP memory backend #4528], [feat(memory): add Honcho backend (user-model memory provider) #4730]); a built-in FTS5/BM25 retrieval adapter
([feat(memory): built-in FTS5/BM25 retrieval adapter #4360]); LLM-assisted consolidation and staleness pruning ([feat(memory): add memory consolidation to synthesize fragmented facts #3996],
[feat(memory): add staleness review to prune silently-outdated facts #3860], [feat(memory): LLM-assigned per-fact expected_valid_days and staleFactsToExtend #4143]); incremental per-agent fact storage ([feat(memory): add incremental agent-scoped Markdown fact storage #4279]); a hybrid
eviction policy ([feat(memory): add hybrid fact eviction policy #4789]); guaranteed correction-fact injection ([feat(memory): add guaranteed injection for correction facts with graceful fallback #3592]);
and opt-in write-side fact dedup. ([feat(memory): add deterministic near-duplicate fact gate #5254])
pool), Tenki, and OpenSandbox providers ([feat(sandbox): add E2B sandbox provider #3883], [feat(sandbox): add BoxLite micro-VM sandbox provider (scaffold) #3940], [feat(sandbox): warm pool for boxlite #3951], [feat(sandbox): add Tenki cloud sandbox provider #4382],
[feat(sandbox): add OpenSandbox provider #4877]); opt-in
isolated/ domain-allowlistnetwork egress for localDocker sandboxes, with denied domains approvable through the Human Input
card ([feat(sandbox): add controlled egress with approvals #5152]); and hardened local containers — bridge-gateway port binds,
default seccomp, dropped capabilities. ([fix(sandbox): harden local Docker sandbox containers and port binding #4986])
lifecycle and system-model observers, Gateway services, and HTTP routers,
managed with
deerflow extensions install/upgrade/enable/disable/remove([feat(extensions): add middleware plugin foundation #4636], [feat(extensions): observe task lifecycle and system model calls #4684], [feat(extensions): add gateway contribution points and packaged extension management #4780], [feat(extensions): add in-place upgrade that keeps private config #5347]); a 0.2 extension API lets extensions
observe what the agent did ([feat(extensions): let an out-of-tree extension observe what the agent did #4863]); and a new
RunEvidenceReadercontractdrives durable, cursor-based changed-run discovery. ([feat(extensions): expose incremental run evidence reader #5405])
([feat(auth): add generic OIDC/SSO authentication with Keycloak support #3506]); personal access tokens with scoped route policies ([feat(auth): add personal access tokens for programmatic API access #5041]); a
built-in RBAC provider with tool, model, and sandbox authorization enforced
at both assembly and runtime ([feat(authz): add built-in RBAC provider and provider factory #4260], [feat(authz): enforce tool authorization at assembly and runtime #4370], [feat(authz): enforce model authorization at Gateway routes and runtime (#4063 Phase 3) #4540], [feat(authz): enforce sandbox:execute authorization at sandbox acquisition (#4063 Phase 3) #4911], [feat(authz): derive Gateway route permissions from AuthorizationProvider #4439]);
local self-registration can be closed to SSO-only provisioning ([fix(auth): let deployments close local self-registration #4311]);
and account preferences survive a cleared browser. ([feat(settings): persist account preferences across browsers #5397])
Gateway restarts and reports progress in the chat UI ([feat(mcp): add durable task runtime foundation #4665], [feat(mcp): add ordinary durable task driver #4690],
[feat(mcp): complete durable task notifications and chat UI #4833]); shared servers can inject per-user credentials or map
request-scoped secrets to headers ([feat(mcp): per-user credential injection for shared MCP servers #4868], [feat(mcp): map request-scoped secrets to MCP HTTP/SSE headers #5010]); servers are managed
from Settings ([feat(mcp): manage servers from Settings #5022]); and a hung stdio server can no longer stall the
Gateway or agent assembly. ([fix(mcp): bring-up has no timeout and externalized tool outputs are counted as undelivered artifacts #4657], [fix(runtime): keep agent construction off event loop #5217])
agent and subagents ([feat(middleware): add TokenBudgetMiddleware for per-run token budget e… #3412]); goal continuations with a tracked, capped
count ([feat(runtime): implement goal continuations #3858]); dual-mode checkpoint storage cuts long-run thread storage
from O(N²) to near-linear ([feat(checkpoint): dual-mode checkpoint storage with LangGraph DeltaChannel #4292], [feat(checkpoint): checkpoint history cache #4638]); durable context survives
summarization ([feat(context): record effective memory identity per run #3556], [feat: preserve durable context across summarization #3887], [feat: emit structured runtime metadata (follow-up#3887) #3906]); opt-in task notes and
compacted-history recall ([feat: add opt-in task notes and compacted history recall #5382]); a run can read referenced earlier
conversations, grantable from the SDK and the composer ([[feat] add opt-in conversation reads for Gateway runs #5399], [feat(gateway): accept conversation references in run context and report the capability #5463],
[feat(frontend): reference conversations from the composer #5465]); structured clarification form fields ([feat(clarification): structured form fields for human-input cards (#4400 Phase 1) #4406]); and configurable
recursion limits for Gateway and scheduled runs. ([fix(gateway): make recursion limit configurable #5390], [feat(scheduler): make scheduled-run recursion_limit configurable #4848])
an optional request-admission limiter paces calls per provider ([feat(models): pace shared RPM budgets before dispatch #5432]);
per-user model favorites ([feat(models): add user model favorites #5441]); a Z.AI GLM-5.3-Flash profile and MiniMax
Code ACP support ([feat(models): add GLM-5.3-Flash thinking workaround #5074], [feat: integrate MiniMax Code as a native ACP agent #4846]); opt-in
knowledge_searchover RAGFlowor LightRAG ([feat(knowledge): add read-only RAGFlow retrieval #4955], [feat(knowledge): add read-only LightRAG retrieval, fixes #5208 #5209]); Playwright-backed agentic browser control
([feat(browser): add agentic browser control #4187]); and new search providers — Serply, Tencent Cloud WSA, Sofya,
GroundRoute, Crawl4AI, fastCRW, and Parallel — with native recency filters.
([feat(community): add Serply web search tool #5023], [feat(search): add Tencent Cloud WSA provider #5057], [feat(search): add native recency filters #5099], [feat(community): add Sofya web search provider #5239], [feat(community): add GroundRoute web search + fetch engine #3675], [feat(community): add Crawl4AI web_fetch provider #3821], [feat: add fastCRW provider #3585], [feat(community): add Browserless web_capture screenshot tool #3881],
[feat(community): add Brave image search community tool #3866], [feat(mcp): add optional Parallel Search server #5028])
document shelf, and two-way file promotion ([feat(projects): project workspaces with scoped chats and thread membership #5265], [feat(projects): Projects MVP Phase 2 — instructions, document shelf, promotion, trash #5443]); assistant
turns branch into side conversations with distinguishing titles ([feat: add branching support for assistant turns #3950],
[feat(frontend): add side conversations for quoted follow-ups #3934], [feat(threads): distinguish branched conversations #4983]); the latest answer regenerates and user turns edit and
rerun in place ([feat: support regenerating latest answer #3637], [feat(chat): edit and rerun latest user turn #4377]); chats archive, restore, and pin
([feat(chats): add archive and restore #5236], [feat(frontend): pin recent chats #4442]); a conversation outline navigates long chats ([feat(frontend): add conversation outline navigation for long chats #5025]);
CSV/TSV artifacts preview as tables ([feat(artifacts): preview CSV and TSV files as bounded tables #5284]); text artifacts stream over
byte ranges and a run's files download as one zip ([feat(frontend): render markdown artifacts in the "open in new window" view #5056], [feat(artifacts): download run files as zip #5117]);
MCP servers, integrations, and skills move into a dedicated Capability
Center ([feat(frontend): move capability management out of Settings #5468]); and Custom Agents get display names, a deployment-level
subagent catalog, and stateless
memory_enabled: falsemode. ([feat(agents): support Unicode display names for custom agents #5324],[feat: add managed subagents and delegation scopes #4887], [feat(agents): allow custom agents to disable memory #5167])
/agent list//agent useIM commands switch a conversation to the owner'sCustom Agents ([feat(channels): select custom agents per conversation #5168]); Postgres-backed webhook dedup lets several pods
serve the same channel ([feat(channels): share inbound webhook dedupe across pods via Postgres #4210]); and DingTalk gains file/image
attachments. ([feat(dingtalk): support inbound file and image attachments #4423])
🚀 Performance
DeltaChannelcuts threadstorage from O(N²) to near-linear for long research/coding runs. ([feat(checkpoint): dual-mode checkpoint storage with LangGraph DeltaChannel #4292])
messages-tuple+updates+custominstead of fullvaluessnapshots — retransmitted history was ~75% of SSE payload. ([perf(frontend): avoid redundant chat state snapshots #5159])MemoryRunStorebythread_idandMemoryRunEventStoreevents byrun_idto eliminate O(n) scans. ([perf(runtime): index MemoryRunStore by thread_id to avoid O(n) scans #3562], [perf(runtime): index MemoryRunEventStore events by run_id to avoid O(n) scans #3686])read_filereads only the requested line range from the sandbox instead offetching the whole file first. ([fix(sandbox): push read_file ranges into sandbox reads #3824])
view_imageinjects content viawrap_model_call, so up to 20 MB of base64no longer sits in two checkpoints per viewed image. ([perf(middleware): stop checkpointing view_image base64 payloads #5014])
([perf(sandbox): cache LocalSandbox path-rewrite regexes per instance (#3647) #3648], [perf(sandbox): cache local-path masking patterns instead of recompiling per search match (#3712) #3713])
message content on every chunk, cache settled copy-data derivation, and
enforce route JS/CSS budgets. ([perf(frontend): coalesce streaming renders to a frame budget instead of per chunk #4425], [perf(frontend): stop re-deriving message content on every stream chunk #4441], [perf(frontend): cache settled copy-data derivation across streaming chunks #5095])
🔒 Security
(binaries, nested archives, and NUL bytes no longer escape scanning),
archive extraction is capped by member count as well as size, and installer,
export guard, and scanner share one code-file/executable-magic definition.
([fix(skills): close SkillScan bypasses in the skill review gate #5431], [fix(skills): cap archive entry count in safe_extract_skill_archive #4241])
bypasses closed; untrusted content in model prompts (memory facts,
SOUL.md, subagent descriptions, skill metadata) HTML-escaped; MindIEtool-response framing escaped; and
web_captureand MCP-sourced toolresults sanitized through the same trust boundary as the built-in web tools.
([fix(security): add input sanitization middleware for prompt-injection defense (#3630) #3662], [fix(gateway): close two input-sanitization bypasses #5375], [fix(security): html-escape fact content in memory prompt sections #4028], [fix(security): escape MindIE tool-response content against </tool_response> breakout #4253], [fix(security): sanitize MCP-sourced tool results through the same trust boundary #4839])
Docker bridge gateway, run Docker's default seccomp profile, drop all
capabilities, and get
no-new-privileges;SSH_AUTH_SOCKis scrubbed fromthe sandbox environment; and projected skill files are copies, not
hardlinks, so a sandboxed write cannot mutate the canonical source.
([fix(sandbox): harden local Docker sandbox containers and port binding #4986], [fix(sandbox): scrub SSH_AUTH_SOCK from the sandbox subprocess env #5145], [fix(skills): copy projected skill files instead of hardlinking #4825], [fix(skills): fail closed on drifted projection namespace on all platforms #4830])
skill environment; MCP stdio launcher arguments and env vars are constrained
at the config API; credentials that cannot travel as HTTP header values are
rejected at the config boundary; and skill toggles no longer persist
resolved
$VARsecrets intoextensions_config.json. ([fix(sandbox): scrub MYSQL_PWD and REDISCLI_AUTH from the inherited skill env #4018], [fix(mcp): constrain stdio launcher args and env at the config API #4617],[fix(mcp): reject credentials that cannot travel as HTTP header values #5066], [fix(skills): stop persisting resolved secrets when toggling skills #5357])
percent-encoded dot segments or symlinks, and XML artifacts (any
+xmltype included) are served as download attachments so active content cannot
call the API with the viewer's session. ([fix(gateway): confine artifact PUT to /mnt/user-data/outputs after path resolution #5321], [fix(gateway): serve XML artifacts as attachments to block same-origin script #5353])
open; run-create is enforced on stateless stream/wait endpoints; a revoked
sandbox:executegrant is re-checked before sandbox reuse; custom-Agentskill allowlists are enforced at the sandbox filesystem level; and
cancel/rollback actions on GET stream joins are rejected with 405.
([fix(guardrails): empty allowlist must deny all tools instead of failing open #4067], [fix(gateway): enforce run-create authorization on stateless endpoints #5030], [fix(authz): recheck policy before sandbox reuse #5006], [fix: enforce custom agent skill allowlists in sandboxes #5077], [fix(runs): reject cancel actions on GET stream joins #5092])
web_fetchproviders; Lark CLIcredential trees enforce private ACLs on Windows; and streamdown
sanitization is restored in custom rehype chains. ([fix(web_fetch): add SSRF guard for self-hosted providers #3942], [fix(lark): enforce private ACLs on Windows credential tree #5141], [fix(frontend): restore sanitization in custom streamdown rehype chains #4987])
🐛 Notable fixes
owner; cross-worker idempotent reuse no longer permanently blocks the
thread; keyed retries resolve the request user consistently; the shutdown
run drain survives repeated cancellation; and a repair migration heals
databases that silently skipped the run-change clock schema. ([fix(runtime): cancel runs across live gateway workers #4500],
[fix(runtime): stop idempotent reuse from blocking the thread on a peer worker #5393], [fix(runtime): resolve omitted run owners before idempotent reuse #5401], [fix(gateway): keep run drain alive across repeated cancellation #5487], [fix(persistence): repair run-change clock schema skipped by the 0023 insertion #5517])
read_fileby exact line range, sopaging through a file no longer trips the hard stop;
max_turnsnow grantsthe turns it names (it was passed as LangGraph super-steps, ~7–8 per turn);
token budgets hold across goal continuations; guards that remove tool calls
no longer break every later Claude/Responses turn; and retried model calls
re-deliver queued warnings. ([fix(agents): key read_file loop detection on its exact line window #5486], [fix(subagents): scale max_turns into the graph's super-step budget #5485], [fix(agents): keep the token budget across goal continuations of a run #5410], [fix(agents): remove provider tool-call blocks when guards strip calls #5447], [fix(agents): keep queued guard warnings when a model call is retried #5433])
a delegated subagent's error no longer fails the parent run; repeatedly
cancelled subagents no longer leak their execution slot; and Windows
acceptance checks fail closed on out-of-scope commands. ([fix(subagents): keep the subagent system prompt through context compaction #5454], [fix(worker): don't fail the parent run on a subagent error carried by task_running #5407],
[fix(subagents): preserve capacity release across repeated cancellation #5477], [fix(subagents): make acceptance checks portable #5162])
list_dir/glob/grepreport failuresinstead of inventing "empty directory" or "no matches";
read_filetruncation is reported in lines with the exact resume point; host-path
masking handles
$PATH-style joins and forward-slash Windows spellings;concurrent subagents work past the AIO shell-session ceiling; and CJK tool
output is no longer garbled in PowerShell. ([fix(sandbox): stop list_dir from reporting failures as empty #5264], [fix(sandbox): reject incomplete remote list_dir results #5422], [fix(sandbox): stop remote grep/glob from reporting failures as no matches #5380],
[fix(sandbox): cut read_file output at a line boundary and name the next start_line #5474], [fix(sandbox): mask every host path in a colon-joined list #5418], [fix(sandbox): reverse-resolve forward-slash spellings of Windows host paths #5373], [fix(sandbox): prevent AIO subagent session eviction #5178], [fix(sandbox): force UTF-8 console for PowerShell so CJK output is not garbled #5440])
summarization, and subagent models stop losing their credential; models with
supports_reasoning_effortno longer fail to build; Codex invalid toolcalls are paired with their results; and
api_baseis honored on everyBaseChatOpenAIsubclass. ([fix(models): reuse the Claude Code OAuth token read from a file descriptor #5411], [fix(models): stop reasoning_effort from reaching the constructor twice #5403], [fix(models): pair Codex invalid tool calls with their tool results #5509], [fix(models): scope the OpenAI-compat rules to BaseChatOpenAI, not a class-path allowlist #4146])dropping the reply; one undecodable WeChat message no longer drops its
batch; a dead Discord client no longer hangs outbound sends and freezes the
channel pool; Telegram
rich_messagesrenders only when the text actuallycontains rich constructs; and WeChat/WeCom inbound media is streamed,
size-bounded, and host-allowlisted. ([fix(channels): cap WeCom outbound content at the 20480-byte protocol limit #5148], [fix(channels): isolate per-message failures in WeChat poll loop #4231], [fix(channels): bound Discord outbound cross-loop awaits and restart dead clients, fixes #5226 #5227], [fix(channels): send Telegram messages as rich only when content has rich constructs #5470],
[fix(channels): stream-cap and validate WeChat/WeCom inbound media downloads, fixes #5223 #5225])
into
extensions_config.json; restore$VARreferences and rotate anycredential exposed this way. ([fix(skills): stop persisting resolved secrets when toggling skills #5357])
max_concurrent_runsbudget is enforced onSQLite (not just Postgres) and for manual triggers; and a dispatch race
that could launch two runs for one task is closed. ([fix(scheduler): serialize the SQLite launch-budget claim #5469], [fix: enforce global concurrent-run budget for manual triggers #4769],
[fix(scheduler): close dispatch race that can launch two runs for one task #4105])
each other's connection; the session pool holds its capacity limit under
concurrent initialization; and durable task polling preserves pooled
sessions across protocol timeouts. ([fix(mcp): isolate pooled sessions by owning event loop #5396], [fix(mcp): enforce session pool capacity during promotion #4962], [fix(mcp): preserve pooled stdio sessions after task timeouts #5027])
human-input cards keep the turn that requested them; the user's input is
restored after an incremental stream reconnect; sidebar chat deletion asks
for confirmation first; and the client emits a streamed tool call once, with
its complete arguments. ([fix(frontend): preserve trusted message positions through content merge #5293], [fix(frontend): keep human input cards with their turn #4892], [fix(frontend): restore user input after stream reconnect #5428], [fix(frontend): confirm sidebar chat deletion #5406], [fix(client): emit streamed tool calls once with complete args #5408])
📦 Deploy & ops
breaking changes);
make upwaits for a real Gateway health probe beforedeclaring the stack ready; startup tolerates a missing
.env; and WindowsGit Bash preflight and socket handling work. ([fix(docker): bind the published entry port to loopback by default #4618], [fix(docker): set DEER_FLOW_ROOT for log commands #4658], [fix(docker): wait for gateway readiness #4806],
[fix(docker): allow aio DooD socket preflight on Windows Git Bash (#5370) #5371], [fix(deploy): prevent Git Bash path conversion of default docker socket on Windows (#5400) #5402])
ClusterIPinstead ofNodePort, so sandboxes are reachable only inside the cluster ([fix(helm): default sandbox Services to ClusterIP (#3929) #4190]);ClusterIP Services and scoped per-skill PVC mounts ([feat(provisioner): support ClusterIP services and scoped skills PVC mounts #4016], [feat(provisioner): make sandbox container port configurable #3928]); and
an optional Lark credential broker sidecar keeps app secrets out of the
sandbox filesystem. ([feat(lark): sidecar credential broker for sandbox lark-cli (Pattern B) #4501])
GET /health/readyruns a bounded databaseprobe and returns 503 while the database is unreachable;
/healthstayspure liveness. ([feat(gateway): add /health/ready readiness probe backed by the database #5166])
slow
/compactno longer returns 504 for work that was applied), and longchat prompts pass
/api/langgraph/without a raw 500. ([fix(nginx): allow model-bound /api/threads requests past 60 seconds #5505], [fix(nginx): allow long chat prompts through /api/langgraph/ without a raw 500 #4277])postgres_schemaand created automatically ([feat(persistence): support custom postgres schema #3442]);recursion_limitandscheduler.recursion_limitare deployment-configurable ([fix(gateway): make recursion limit configurable #5390], [feat(scheduler): make scheduled-run recursion_limit configurable #4848]);and
make devpreserves theollamauv extra across restarts. ([fix(scripts): detect the ollama extra from configured models #5318])revision, keeping rollback possible ([fix(persistence): preserve rollback across the incarnation migration #5219]); legacy threads get run-event
seed backfill ([feat(gateway): seed checkpoint history #4590]); and Postgres connections survive idle timeouts via
pool_recycle. ([fix: harden Postgres async engine with pool_recycle and command_timeout to stop stale-connection 504s #4230])parallel shards with isolated Postgres/Redis ([feat(ci): split backend unit tests into parallel shards #5137]); and the renamed
tenkipackage replaces the PyPI-removedtenki-sandbox. ([fix(deps): depend on renamed tenki package instead of tenki-sandbox #5087])🙌 Thanks
Huge thanks to the 178 contributors who landed 772 merged PRs in the 2.1.0
milestone, and to everyone who filed issues, tested builds, and shared
feedback. DeerFlow 2.1 wouldn't exist without you.
In alphabetical order:
See the full author and PR list on the
milestone page.
This discussion was created from the release v2.1.0 Release.
All reactions