v0.22.0
Amazon Bedrock works end to end
- Streaming (#191). ConverseStream is decoded as AWS event-stream frames, with CRC checks and AWS's documented event shapes. Tool calls get their real arguments, not
{}. A dropped or corrupt stream is an error, never an empty successful turn. - Authentication (#200). Requests are SigV4-signed, checked against AWS's published SigV4 test vectors. Bedrock API keys (
AWS_BEARER_TOKEN_BEDROCK) are supported. The secret access key is never sent as a bearer token. - Credentials come from
api_key(access:secret[:token], or a Bedrock API key) or from the standardAWS_*environment variables, read on each request.
Bedrock support is tested against AWS's published vectors and mock servers, not a live endpoint.
Anthropic
- Redacted thinking (#199).
redacted_thinkingblocks are kept and sent back unmodified, as the API requires when thinking is used with tools. - Other unknown block types are now skipped with a warning instead of silently shifting content.
Behaviour changes
- Compaction floor (#190).
MIN_HEADROOM_RATIOis 0.30 (was 0.15). At the default budget, tool-heavy sessions no longer lose the original task prompt when compacting. Measured offline in #189. - Bedrock IAM credentials are now signed by yoagent. If you used a signing proxy, set
AWS_REGIONor put a placeholderauthorizationheader inModelConfig.headers. - Bedrock credential resolution. Credentials are resolved by protocol, so an unrelated
API_KEYis never sent to AWS.
Also
Content::Thinkinggainsredactedandredacted_protocol. This is non-breaking, because the variant is#[non_exhaustive].- New dependencies:
sha2andhmac. - A weekly mutation-testing CI job; the first full baseline is in
docs/evals/mutation-baseline.md.
See CHANGELOG.md for details.