Skip to content

v1.4.9

Latest

Choose a tag to compare

@github-actions github-actions released this 09 Oct 22:48
· 15 commits to main since this release

Release Notes v1.4.9

Released: 2026-10-09

A model-refresh and supply-chain release. Sibyl now defaults to Claude Haiku 5.5, every registered model moves to its current generation with verified pricing, pydantic-ai jumps to 2.54 to clear GHSA-6fqq-452j-qhrp, and the Homebrew formula finally ships the CLI's dependency tree instead of a broken half-install.

Highlights

Claude Haiku 5.5 as the default extraction model

SIBYL_LLM_MODEL defaults to claude-haiku-5-5 (was claude-haiku-4-5) across .env.example, charts/sibyl/values.yaml, both compose files, and the deployment docs. Synthesis moves to claude-sonnet-5-5, crawling to gemini-3-5-flash-lite. Same per-token input price as Haiku 4.5 at $0.10/MTok in, $0.50/MTok out, with a 128K output ceiling.

Every registered model brought current

registry.py adds claude-haiku-5-5, claude-sonnet-5-5, gemini-3-8-flash, gemini-3-5-flash-lite, gpt-6.1-sol and gpt-6-luna, all verified on 2026-10-08. Use-case tags (extraction, synthesis, bulk-crawling, budget, openai-parity) move to the new generation, gemini-3-1-flash-lite points at the GA snapshot instead of the preview, and gemini-3-1-flash-lite and gpt-5.4-nano carry deprecated_after dates.

Correct cost accounting for models genai-prices does not price yet

New sibyl_core/ai/prices.py prepends Sibyl's own ModelInfo entries onto the bundled genai-prices 0.1.10 snapshot. It encodes Haiku 5.5's 5x long-prompt tier past 100K tokens, Sonnet 5.5's 0.05x cache-read rate, GPT-6.1 Sol's 272K tier, and a 10% markup on Bedrock geography profiles (us, eu, apac, au, jp, us-gov). supplement_price() returns None for anything it does not cover, so bundled pricing stays authoritative everywhere else.

pydantic-ai 2.54 closes GHSA-6fqq-452j-qhrp

pydantic-ai-slim moves from >=2.42.0,<2.52 to >=2.54.0,<2.55 (CVE-2026-107286: a concurrency-limited model can retain its slot when a streamed request ends early). Sibyl never used ConcurrencyLimitedModel, but the Trivy image gate blocked every build and release until the pin moved.

Homebrew installs a working CLI again

brew install sibyl previously staged Sibyl's own packages with --no-deps and nothing they import. The formula now embeds third-party pins exported from the release-tag uv.lock, each with sha256 hashes checked under --require-hashes.

Model routing and profiles

  • Profile corrections for models pydantic-ai does not know. anthropic_profile() in providers.py layers Sibyl's fixes over the upstream profile. ANTHROPIC_PROFILE_PATCHES covers claude-haiku-5-5, which matched no upstream rule and would otherwise send temperature (a 400 on that model), skip effort and adaptive thinking, and refuse native structured output.
  • Output mode stays where Sibyl put it. forced_tool_choice_disables_thinking=False stops pydantic-ai 2.52+ from silently unforcing the output tool or switching to native output on think-by-default models, so a tool-mode request is budgeted, receipted and retried in the mode Sibyl recorded.
  • Output ceiling pinned at 4,096 tokens. ANTHROPIC_DEFAULT_MAX_TOKENS restores the 2.42 behaviour; from 2.52 pydantic-ai sends the model's entire output limit (128K on Opus 5.5). Surfaces that need more set max_tokens explicitly, as memory does.
  • Structured output routing. BEDROCK_JSON_SCHEMA_OUTPUT_MODELS gains claude-haiku-5-5 and claude-sonnet-5-5, both confirmed answering native output_config.format with schema-valid output in us-west-2. ANTHROPIC_MODELS_WITHOUT_FORCED_TOOLS now holds claude-opus-5-5 and claude-sonnet-5-5 alongside claude-fable-5-1 and claude-mythos-5-1, so Opus 5.5 rejects a forced tool too: on Bedrock it stays on tool output with tool_choice degraded to auto, while Opus 5 keeps the forced tool. The Bedrock override key is corrected from anthropic_supports_forced_tool_choice to supports_forced_tool_choice.
  • Tool output is named. clients.py and validation.py fall back to ToolOutput(...) instead of a bare output type, so budgets, receipts and retries all agree on the mode in use.
  • Memory defaults. claude-sonnet-5-5 joins MemoryModelDefaults at 32,768 output tokens and a 1.6M-character input window. Haiku 5.5 is deliberately excluded: its window costs 5x past 100K prompt tokens and it answers unthinking in the tool mode memory uses.
  • Cheapest probe models now resolve to claude-haiku-5-5 (Anthropic and Bedrock), gemini-3-5-flash-lite, and gpt-6-luna.

Packaging and CI

  • Formula scope narrowed to the CLI. sibyld is dropped from the Homebrew formula and its symlink removed; it ships as a container image, and its tree (scipy, playwright, crawl4ai) is not something Homebrew should build on a laptop.
  • Hash-pinned dependency export. cli_requirements() runs uv export --frozen --no-dev --no-emit-workspace --package sibyl-dev, and validate_requirements() refuses anything unpinned, unhashed, empty, or naming a Sibyl package. Install uses --require-hashes --no-deps --only-binary=:all: --ignore-installed; an Intel macOS guard fails early with a uv tool install sibyl-dev pointer since cryptography has no Intel wheel. The formula's test block now runs pip check.
  • The formula is installed before it ships. New tools/release/verify_homebrew_formula.sh taps the generated formula into a throwaway local tap, installs it, runs brew test, and executes sibyl --version. publish.yml runs this before the tap commit (job timeout raised 10 → 25 minutes), and a new homebrew-formula.yml workflow runs the same check on PRs touching uv.lock, the CLI or core pyproject.toml, or the formula tooling.
  • Docker Hub pulls survive outages. New .github/actions/start-surrealdb/dockerhub-login.sh retries login five times with 10s/20s/30s/40s/50s backoff, then warns and continues anonymously rather than failing the job. Buildx in publish.yml and image-cve-gate.yml boots from mirror.gcr.io/moby/buildkit:buildx-stable-1 and mirrors docker.io through mirror.gcr.io, with the start-surrealdb action pre-pulling and retagging through the mirror. Release and nightly workflows pass DOCKERHUB_USERNAME/DOCKERHUB_TOKEN; PR builds stay anonymous.

Tests

  • tests/ai/test_model_profiles.py is new: it checks the Haiku 5.5 profile corrections against upstream, confirms already-profiled models keep their upstream values apart from forced_tool_choice_disables_thinking, verifies the 4,096-token ceiling, and asserts GPT-6 Luna and GPT-6.1 Sol resolve as reasoning models. Its wire-level test captures the outgoing Anthropic request for Opus 5, Opus 5.5 and Haiku 5.5, asserting tool_choice.type == "any" for Opus 5 and Haiku 5.5 and "auto" for Opus 5.5, with no output_config.format in any of the three.
  • tests/ai/test_prices.py covers the Haiku 5.5 and GPT-6.1 Sol tier thresholds (including cache reads counting toward the long-prompt tier), Sonnet 5.5 cache-read rates, the Bedrock geography markup, and that the supplemented snapshot does not mutate bundled genai-prices data.
  • tools/tests/test_release_workflow.py asserts the formula embeds hashed pins, keeps the pip flags and Intel guard, no longer references sibyld, and that both publish and PR workflows verify the formula before it ships.

Upgrade Notes

  • Images and charts move to 1.4.9: ghcr.io/hyperb1iss/sibyl-api:1.4.9, ghcr.io/hyperb1iss/sibyl-web:1.4.9, with charts/sibyl, charts/surrealdb, both compose files and infra/ansible/roles/sibyl/defaults/main.yml updated.
  • If you pin SIBYL_LLM_MODEL explicitly, nothing changes. To pick up the new default, drop the override or set claude-haiku-5-5. Haiku 5.5 charges 5x past 100K prompt tokens, so check any surface that routinely sends large prompts.
  • Memory consolidation on claude-sonnet-5-5 runs through native structured output and thinks before answering; its 1.6M-character input budget is set in .env.example under the consolidation max-input setting.
  • Anyone embedding sibyl-core directly should note the pydantic-ai-slim floor is now 2.54.
  • brew install sibyl installs the CLI only. For the daemon, use the container image; on Intel macOS, use uv tool install sibyl-dev.
  • CI forks running the release or nightly workflows should set the DOCKERHUB_USERNAME variable and DOCKERHUB_TOKEN secret. Without them, pulls fall back to anonymous through mirror.gcr.io and still work.

Install

Local server

curl -fsSL https://raw.githubusercontent.com/hyperb1iss/sibyl/main/install.sh | sh -s -- --version 1.4.9

Remote CLI

curl -fsSL https://raw.githubusercontent.com/hyperb1iss/sibyl/main/install.sh | sh -s -- --remote --version 1.4.9
sibyl init --remote https://sibyl.example.com
sibyl auth login

Homebrew

brew install hyperb1iss/tap/sibyl
sibyl up

Arch Linux (AUR)

paru -S sibyl
sibyl up

Headless server

curl -fsSL https://raw.githubusercontent.com/hyperb1iss/sibyl/main/install.sh | sh -s -- --version 1.4.9 --no-open

Kubernetes (Helm)

helm repo add sibyl https://raw.githubusercontent.com/hyperb1iss/sibyl/gh-pages
helm repo update sibyl
helm upgrade --install sibyl sibyl/sibyl --version 1.4.9

Artifacts

This release includes Python wheels and sdists, the generated
Homebrew formula, the generated AUR PKGBUILD, Helm charts, Docker
SBOMs, aggregate dual-registry cosign receipts, and a SHA256 checksum
manifest.