This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+2 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, https://github.com/i-am-bee/beeai-framework/issues/1470, and https://github.com/i-am-bee/beeai-framework/issues/1462 across a mixed release.
Full changelog
Features
- adapters: upgrade LangChain packages to 1.x (#1491) (3ee516a), closes #1470
- upgrade MiniMax default model to M3 (with Python/TypeScript provider) (#1416) (4900cf0), closes #1462
- serializer: function deserialization is opt-in, disabled by default
Bug Fixes
- adapters: inline a2a data: URIs as base64 (#1508) (1d5900c)
- adapters: resolve hardcoded modelId in LangChainEmbeddingModel (#1501) (0902b9a)
- deps: bump wikipedia to ^2.5.0 (5da8ffd)
- deps: pin vulnerable transitive TypeScript dependencies (#1471) (#1515) (a20b658)
- serializer: disable function deserialization by default (GHSA-phhm-7927-g88p) (#1551) (c3db2b4)
- serializer: prevent unsafe deserialization paths (#1543) (04d1c2d)
- tools: address small Python and TypeScript polish issues (#1485) (7c98eba)
- tools: clean up LLMTool prompt template (#1483) (e94c3d1)
- workflows: call Tavily API directly in competitive-analysis example (678dccf)
- serializer*: await async function results in deserialization test
Full Changelog: https://github.com/i-am-bee/beeai-framework/compare/typescript_v0.1.29...typescript_v0.1.30
Breaking Changes
- Serializer function deserialization is now disabled by default (opt-in required)
Security Fixes
- Serializer: disable function deserialization by default (GHSA-phhm-7927-g88p) and prevent unsafe deserialization paths
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About beeai-framework
Build production-ready AI agents in both Python and Typescript.
Related context
Related tools
Beta — feedback welcome: [email protected]