This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+9 more
Affected surfaces
ReleasePort's take
Light signalThe sdk-py release now percent‑encodes caller‑supplied identifiers in URL paths and updates several dependencies (idna, urllib3, langsmith, ty) to newer versions.
Why it matters: Percent‑encoding prevents malformed URLs that could cause request failures or security issues; dependency bumps include bug fixes and minor feature improvements across the SDK stack.
Summary
AI summaryUpdates deps, sdk-py, and langgraph across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
feat(sdk-py) support metadata filter for crons search/count feat(sdk-py) support metadata filter for crons search/count Source: llm_adapter@2026-05-22 Confidence: high |
— |
| Dependency | Medium |
chore(deps) bump idna from 3.11 to 3.15 in /libs/sdk-py chore(deps) bump idna from 3.11 to 3.15 in /libs/sdk-py Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Dependency | Medium |
chore(deps) bump urllib3 from 2.6.3 to 2.7.0 in /libs/sdk-py chore(deps) bump urllib3 from 2.6.3 to 2.7.0 in /libs/sdk-py Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Dependency | Medium |
chore(deps) bump langsmith from 0.7.31 to 0.8.0 in /libs/sdk-py chore(deps) bump langsmith from 0.7.31 to 0.8.0 in /libs/sdk-py Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Dependency | Medium |
chore(deps) bump ty from 0.0.23 to 0.0.33 in /libs/sdk-py chore(deps) bump ty from 0.0.23 to 0.0.33 in /libs/sdk-py Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Bugfix | Medium |
fix(sdk-py) percent-encode caller-supplied identifiers in URL paths fix(sdk-py) percent-encode caller-supplied identifiers in URL paths Source: llm_adapter@2026-05-22 Confidence: high |
— |
| Other | Medium |
chore(langgraph) bump langchain-core to 1.4.0 chore(langgraph) bump langchain-core to 1.4.0 Source: llm_adapter@2026-05-22 Confidence: low |
— |
| Other | Medium |
bump alpha packages to official versions bump alpha packages to official versions Source: llm_adapter@2026-05-22 Confidence: low |
— |
Full changelog
Changes since sdk==0.3.14
- release(checkpoint): 4.1.1 (#7890)
- release(sdk-py): 0.3.15 (#7891)
- fix(sdk-py): percent-encode caller-supplied identifiers in URL paths (#7893)
- release(langgraph): 1.2.1 (#7883)
- chore(deps): bump idna from 3.11 to 3.15 in /libs/sdk-py (#7863)
- chore(deps): bump urllib3 from 2.6.3 to 2.7.0 in /libs/sdk-py (#7764)
- chore(deps): bump langsmith from 0.7.31 to 0.8.0 in /libs/sdk-py (#7789)
- release: bump alpha packages to official versions (#7775)
- chore(langgraph): bump langchain-core to 1.4.0 (#7767)
- feat(sdk-py): support metadata filter for crons search/count (#7737)
- chore(deps): bump ty from 0.0.23 to 0.0.33 in /libs/sdk-py (#7666)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]