Skip to content

LightAgent v0.11.0

Latest

Choose a tag to compare

@wxai-space wxai-space released this 30 Sep 18:16
8318a5d

Dynamic DAG Multi-Agent And Unified Security Context

Highlights

  • Added the opt-in LightDAG runtime for persistent dynamic task graphs, runtime decomposition, bounded concurrent workers, and parent-task integration.
  • Added transactional SQLite graph mutations, cycle checks, task attempts, durable events, budget reservations, leases, fencing, and restart recovery.
  • Added application-owned verification gates and immutable content-addressed artifacts. Model output alone cannot mark a task complete or publish a trusted artifact.
  • Added narrowing-only SecurityContext, capability gates, and identity-, argument-, resource-, expiry-, and policy-bound approval tokens.
  • Fixed async-generator tool consumption in both streaming and non-streaming agent runs, and documented MCP Streamable HTTP configuration.
  • Hardened Python executor parsing with narrow JSON exception boundaries, bounded nested code extraction, cycle handling, and cross-version regression tests.
  • Added an optional dependency-free-at-import Memcode memory adapter example with aligned agent identity, namespaced users, provenance checks, and offline policy/hook round-trip tests.

Compatibility And Scope

  • Existing agent.run(...), streaming entry points, and fixed-workflow LightFlow usage remain available. LightDAG is opt-in.
  • Async-generator tools are buffered into a final result; this is not live per-chunk async streaming.
  • Legacy execute_python_code, execute_python_file, and execute_python_code_stream are blocked in model, dispatcher, and tool-provider invocation, even with enable_unsafe_python=True or a registered sandbox provider. Trusted direct utility calls remain available under application-managed isolation. Use safe_expression for data-only calculations or a custom tool backed by a real sandbox for agent code execution.
  • LightDAG is single-host, uses local SQLite, and supports one active scheduler per run with multiple async workers. Execution is at-least-once; external side effects still require idempotency or dedicated isolation.
  • Distributed workers, a Web UI, automatic deployment, and built-in code sandboxing are outside this release. Real-backend security acceptance remains opt-in; this release does not claim certification of external memory services.

Verification

  • Full tracked test suite: 365 passed, 1 skipped.
  • The skipped test requires an explicitly configured isolated, disposable Mem0 Graph backend.
  • Python 3.10, 3.11, 3.12, and 3.13 CI passed.
  • Offline LightDAG decomposition, failed verification, repair, and integration example passed.
  • Package build, isolated wheel import/version check, compileall, and git diff --check passed.

Credits And References

  • Core Dynamic DAG and security-context implementation: #105.
  • Thanks to long6177 for the async-generator fix (#108), ct-jaryn for the MCP documentation (#109), harshadkhetpal for the Python parsing improvements (#95, completed in #111), and Vivek Gupta / vivekgupta-memcode for the optional Memcode adapter (#106, completed in #112).
  • Additional executor dispatch hardening: #110.

Full changes: v0.10.2...v0.11.0