Skip to content

v0.184.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 03:20
· 298 commits to main since this release
27e2d5d

Upgrade notes

  • Code pane: if an earlier version moved the Code rail item to the bottom dock when you clicked a diagram link, drag it back to your preferred dock once. It now stays where you put it (#3640).
  • Remote terminal views through a fleet hub need terminal-plugin ≥0.9.2 on the remote (#3648).
  • Zed: the folder approval card needs the protoagent-acp shim from this release. An older client's plain "approve" registers nothing and the agent says why (#3642).

Onboarding a repo (Engineer archetype)

  • repo-onboard now shows you the project, not just a card (#3641). It finds the repo's ecosystem(s) from its root files (npm/pnpm/yarn/bun and JS monorepos, Python, Rust, Go, Ruby, JVM, .NET, PHP, Elixir, Deno). It shows the README verbatim as a markdown artifact and opens the main manifest's scripts and dependencies in the code pane. It then draws a linked architecture overview: a 5–12-box Mermaid flowchart where every box links to its code. It ends with the repo card and a choice: a guided tour of one of the key flows it spotted, a sequence diagram of one, or straight to the bug. Onboarding still makes no edits. Engineer plugin 0.2.0.
  • Artifact plugin 0.20.1: diagram links fail loudly instead of silently (#3641). A link key that can't match the diagram type (a participant: key on a flowchart) is now reported as matching nothing. Before, it was reported as linked but couldn't be clicked. An update_artifact with a partial links map now says which links it removed and asks for the complete map.

Folders outside the onboarding root

  • An agent can ask to register a folder outside onboarding.root, and you approve it in chat (#3642). register_local_project used to refuse flat. It now shows an approval card for that one folder: Allow read-only / Allow read-write / Deny. It works in the console, the fleet deck and Zed. A stock install with no onboarding root gets the same card, so an agent can be pointed at a checkout you already have.
    • The server writes the card from the folder's resolved path (with its git origin). Your choice of access wins over what the agent asked for, and the root still bounds everything else.
    • The card can't be skipped: /bypass, "Approve & don't ask again" and Zed's "Allow for this session" don't apply to it, because approving it widens the agent's reach beyond this turn.
    • Refused outright, with no card: the filesystem root, your home directory, ~/Library and similar app-data folders, credential directories (.ssh, .aws, .gnupg and others), protoAgent's own data directories and system directories.
    • onboarding.approve_outside_root (default true); set it to false to restore the flat refusal.

Fleet: pairing with remote members (ADR 0113)

This release lands the server and CLI side of agent pairing. The console's pairing dialog comes in a later release.

  • A fleet hub can pair with a remote protoAgent by code (#3645, #3646, #3649; PRs #3655, #3659, #3656). On the remote, protoagent pair (or POST /api/pairing/start {"kind": "agent"}) mints a typeable 10-character code (XXXXX-XXXXX, valid 5 minutes) and prints a ready-to-paste protoagent fleet pair <url> <code> line for each address a hub can reach it on. It works headless (docker or server installs) and in the desktop app's CLI. A loopback-bound instance says it can't be paired and names the fix: a reachable bind with a token. On the hub, protoagent fleet pair <url> <code> [--name N] (or POST /api/fleet/remotes/pair) redeems it and stores a per-hub token as that member's credential. It adds the member, or re-tokens the one already at that URL. The hub never sees the remote's shared bearer, and the remote can revoke the hub on its own. Codes forgive case, dashes, spaces and look-alike characters (O/0, I/L/1). A code or token crosses plain http:// only to loopback or a tailnet address; anything else needs --insecure-http / allow_insecure.
  • Remote members show whether their token works (#3646, #3659). A remote now reports auth: ok | rejected | open | unknown | none from an authenticated check every 30 s, so a revoked or wrong token shows as rejected instead of "running". Changing a remote's URL to a different scheme, host or port clears its stored token unless you pass a new one in the same edit, so one host's credential is never sent to another.
  • Delegates to a remote member route through the hub (#3647, #3657). The roster advertises a remote's A2A endpoint as the hub's local proxy, so "Add as delegate" on a remote needs no token. A 401 through the proxy now tells you to pair the remote.
  • Terminal and agent-browser live views work on remote members again (#3648, #3658). WebSockets to remotes were refused (#1607) because the hub used to lend them its credentials. They now go through the hub, which never attaches a credential on its own. An operator token presented to the hub is swapped for the remote's stored one. Any other credential, or a browser from a foreign origin, is refused. A remote with no stored token is still refused.

Security

  • The hub proxy no longer hands hub credentials to remote fleet members (#3647, #3657). A remote now gets its own stored token only for an operator caller the hub has authenticated; otherwise it gets no credential at all. This closes four paths: a tokenless remote was sent the hub's fleet service token (proxy and telemetry rollup); a "member-public" path let the caller's own hub token through; a federation-tier caller was lent the remote's operator token; and the hub-signed ?token= on event streams was forwarded to the remote.
  • WebSocket upgrades to remotes never carry a hub credential (#3648). See the live-views item above.

Fixed

  • A code link opens the code pane on the dock you keep it on (#3640). Clicking a code-linked diagram in the Artifact panel used to move the Code rail item to another dock (usually the bottom), rewriting your layout. Now the pane opens wherever Code lives, even if that swaps the diagram out (its rail icon brings it back). A Code pane you've never placed still opens away from chat.
  • mDNS announces only an address you can reach (#3649, #3656). An agent bound to loopback no longer announces its LAN address, which put an unreachable entry in every sibling's Discover list. An agent bound to a specific address announces that address rather than the default route's.
  • search_files no longer crashes on an unreadable folder (#3663). Unreadable folders and files are skipped, the readable hits come back, and the result ends with one (skipped N unreadable paths) line.
  • The setup wizard no longer crashes on a partial config (#3654). A config missing its identity or model section (for example from a fleet member on an older core) now falls back to the wizard's defaults.
  • Workflow step traces say which run, step and inputs they belong to (#3565, #3661). Each step's Langfuse span, and the tool calls and generations under it, now carry run_id, workflow, step_id, subagent, the parent session and the run's scalar inputs (redacted, capped at 200 characters). Traces are tagged workflow:, run: and step:. A run started from chat stays in that chat's trace. In an incognito turn the ids are kept but no inputs or outputs are sent, which also fixes a nested run span that sent both. Plugins get the same seam as sdk.trace_attributes and sdk.trace_run(inputs=, tags=).
  • Traces name their agent, and the delegation ledger records what a delegation cost (#3565, #3669). Every agent used to export to Langfuse as service.name = unknown_service, so a fleet sharing one Langfuse project couldn't be split by agent. Each instance's traces now carry its identity name (config identity.name, then AGENT_NAME); OTEL_SERVICE_NAME / OTEL_RESOURCE_ATTRIBUTES still win. delegations.cost_usd in ledger.db was empty on every row. Subagent delegations (including workflow steps) now record the sum of their priced model calls, and background jobs record their turn's cost. It stays empty when no call reported usage (unknown, not free). The parent turn already counts this spend, so don't add it to turns.cost_usd.
  • Re-attaching to a turn that just started no longer fails with "Task not found" (#3575, #3660). The a2a-sdk in the refreshed dependencies checks the task store before a new turn's first write lands. The fleet deck attaching to a turn the server just started, and the eval client's resubscribe(), now retry that one error briefly (under a second at worst). The eval client reports a refusal as an error event instead of an empty stream.

Dependencies

  • Dependencies refreshed to what a fresh install resolves today (#3575, #3660). uv.lock had fallen behind what a fresh install gets. The lock now matches a fresh resolve, and the full suite passes on it. Notable versions: openai 3.19, anthropic 1.8, langsmith 0.14, langchain-openai 1.6.6, langchain-core 1.6.5, langgraph 1.2.12, protobuf 7, SQLAlchemy 2.1 and OpenTelemetry 1.45. The PROTOAGENT_GATEWAY_RESPONSES_API=1 escape hatch still works.
  • A fresh pip install -r requirements.txt no longer installs an older langchain/langgraph than the release ships (#3666). websockets 17 is out, but langgraph-sdk 0.4.x caps it below 17, so an unconstrained resolve quietly walked langgraph back to 1.2.2 and langchain to 1.3.2 to get the newer websockets. pyproject.toml now requires langchain>=1.4.2 and langgraph>=1.2.12, the versions uv.lock already ships. No locked package version changed.

Docs

  • ADR 0113: agent pairing for remote fleet members (#3653). The design record for the pairing work above.
  • Roadmap: "The trajectory" (#2806) is now Planned, and the Ollama & Hugging Face listings move to In progress (#3665). The listings are waiting on upstream review.