This release includes 4 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates 1.11.0] - 2026-07-09, TTL, and https://github.com/microsoft/agent-framework/pull/7033 across a mixed release.
Full changelog
[1.11.0] - 2026-07-09
Added
- agent-framework-core: Add message injection middleware so tools or host code can enqueue messages into an active run and drain them into the next model call within the same
AgentSession(#6998) - agent-framework-core: Integrate message injection into
create_harness_agentand the harness console sample so a running harness agent can be nudged mid-turn (#7027) - agent-framework-core: Add progressive MCP disclosure so agents can discover, load, and unload MCP tool schemas on demand while keeping the
allowed_toolsboundary intact (#6850) - agent-framework-core: Add
refresh_interval(TTL) toCachingSkillsSourceso cached skill lists expire and re-fetch on a configured interval (#6977) - agent-framework-core, agent-framework-foundry-hosting: Add
SkillsSourceContext(invoking agent plus optional session) threaded through the skills source pipeline, enabling context-aware filtering and per-key cache isolation (#6895) - agent-framework-core: Allow disabling approval for
SkillsProvidertools (#6867) - agent-framework-core: Allow opting out of
FileAccessProvidertool approval (#6879) - agent-framework-core: Allow custom argument parsing for inline skill scripts so non-conforming tool-call argument shapes (for example, vLLM) can be handled (#6817)
- agent-framework-hosting, agent-framework-hosting-responses: Add a hosting protocol helper surface (
AgentState,WorkflowState,SessionStore,AgentRunArgs,WorkflowRunArgs) and Responses helpers (create_response_id,responses_session_id,responses_to_run,responses_from_run,responses_from_streaming_run) (#6891) - agent-framework-ag-ui: Add FastAPI SSE keepalive support for long, output-silent streams (#6980)
- agent-framework-github-copilot: Forward
skill_directoriesanddisabled_skillsto the Copilot session (#6937) - agent-framework-openai: Allow
tool_choice: requiredwhenallowed_toolsis set (#7024) - agent-framework-anthropic, agent-framework-core, agent-framework-foundry-hosting, agent-framework-gemini, agent-framework-openai: Mark hosted/provider-executed tool calls as informational-only via
Content.informational_onlyso they remain visible in transcripts without local re-invocation (#6997) - samples: Add a deterministic action-boundary validation middleware sample (#6528)
- samples: Add Agent Harness blog post accompanying samples, part 3 (#6741)
- samples: Add a declarative Foundry Hosted Agent workflow sample (#6897)
Changed
- agent-framework-core: [BREAKING — experimental] Extract caching from
SkillsProviderinto aCachingSkillsSourcedecorator (#6847) - agent-framework-core: [BREAKING — experimental] Treat nested
SKILL.mdcontent as part of the parent skill instead of discovering it as a separate skill root (#6849) - agent-framework-core: [BREAKING — experimental]
FileAccess/FileMemoryreplace_linesnow performs literal replacement (including line deletion) instead of always re-adding a line terminator (#6859) - agent-framework-core: Remove the experimental marker from the Skills API now that its surface is stable (#6974)
- agent-framework-core: Lazy-load root
agent_frameworkexports to reduce import cost for narrow-surface scenarios (#6962) - agent-framework-a2a, agent-framework-claude, agent-framework-copilotstudio, agent-framework-core, agent-framework-durabletask, agent-framework-github-copilot, agent-framework-purview: Implement ADR-0029
service_session_idlifecycle mapping, separating durable continuation state, per-run identity forwarding, and telemetry conversation-id extraction (#6724) - agent-framework-azurefunctions, agent-framework-core, agent-framework-durabletask: [BREAKING] Support multi-workflow hosting and sub-workflows on the Durable Task host, including per-workflow durable naming and nested human-in-the-loop request routing (#6696)
- agent-framework-ag-ui: [BREAKING] Canonicalize AG-UI interrupt and resume handling around
RUN_FINISHED.outcome.interruptsand canonicalResumeEntrypayloads (#6925) - agent-framework-mem0: Support the mem0ai 2.x OSS search call shape (#7004)
- agent-framework-mistral: Widen the
uv_buildbackend requirement to allow neweruvreleases (#7033) - agent-framework-lab: Raise the
agentlightningdependency ceiling for thelightningextra (#6984) - agent-framework-claude, agent-framework-durabletask, agent-framework-gemini, agent-framework-monty, agent-framework-openai: Raise dependency floors to the first versions that provide the SDK APIs and typing consumed by these packages
- docs: Clarify
AgentSession.service_session_idscoping to document backing API key/project boundaries and hosted multi-tenant guidance (#6993) - docs: Add security guidance for external skill sources and script execution to harness feature docstrings (#6936)
- samples: Bump
viteand@vitejs/plugin-react-swcin the ChatKit integration sample frontend (#6613) - samples: Add a multi-tenant hosting security consideration note to the A2A sample (#6983)
- samples: Update Foundry Hosted Agent samples for the v2 protocol changes (#6841)
- samples: Use a writable runtime directory for the Foundry Skills sample (#6606)
- tests: Add Agent typing smoke tests across chat clients (#6950)
- tests: Skip NumPy stubs during mypy typing to unblock scheduled dependency-maintenance typing runs (#6969)
- tests: Consolidate Dependabot dependency updates for dev tooling (
uv,ruff,pytest,mypy,pyright,mcp,opentelemetry-sdk,poethepoet) across the workspace and package dev-dependency groups (#6984, #7033) - tests: Bump the transitive
js-yamldependency in the DevUI frontend lockfile (#6813)
Fixed
- agent-framework-core: Parse the structured response value from the final message instead of concatenated text, avoiding spurious
ValidationError/JSONDecodeError(#6383) - agent-framework-core: Fix
read_skill_resourceinstruction dropping the.mdextension (#7031) - agent-framework-core: Bind policy-enforcement approvals to a single tool invocation (call id, function, arguments, security label, and session) and consume them on first use (#6966)
- agent-framework-core: Process messages to an executor serially within a superstep to prevent concurrent handler invocations for the same target executor (#6776)
- agent-framework-core: Auto-inject local conversation history on stateless clients even when non-history context providers (for example,
SkillsProviderandFileAccessProvider) are registered (#6810) - agent-framework-core: Improve the error message when a
TypeVaris used in handler/executor registration (#4553) - agent-framework-anthropic, agent-framework-core: Fix Anthropic requests that mix tool calls and tool results in one assistant message, and return a deterministic result when the function-loop limit is reached with a blank final response (#6794)
- agent-framework-anthropic, agent-framework-core, agent-framework-foundry-hosting, agent-framework-openai: Fix Foundry reasoning/MCP compaction so reasoning output keeps its provider id and reasoning plus MCP call pairs stay atomic (#6907)
- agent-framework-anthropic: Normalize a single Anthropic tool value the same as a one-item sequence during request preparation (#6903)
- agent-framework-anthropic: Migrate structured outputs to the stable
output_config.formatshape to avoid malformed/concatenated JSON when tools are also present (#5884) - agent-framework-azure-ai-search: Pass
include_reference_source_datain agentic search requests sosource_datais populated on returned references (#5100) - agent-framework-bedrock: Fix non-ASCII escaping in JSON content blocks returned by the Converse API (#6628)
- agent-framework-foundry: Strip tools from the Foundry agent request on the preview path (
allow_preview=True) to avoidinvalid_payloaderrors (#6644) - agent-framework-gemini: Fix
GeminiChatClientdropping image/file content on multimodal messages (#6751) - agent-framework-claude, agent-framework-core, agent-framework-github-copilot, agent-framework-ollama: Fix response metadata construction so usage, finish reason, raw response, continuation token, and structured value are propagated consistently across providers (#6955)
- agent-framework-a2a: Accept A2A data URIs whose media type includes parameters before the
;base64marker (#6818) - agent-framework-ag-ui: Prefer explicit AG-UI resume payloads over message-derived responses (#6360)
- agent-framework-ag-ui: Clear queued approvals on cancel so cancelled flows do not leave stale prompts for later turns (#6947)
- agent-framework-ag-ui: Preserve the streamed text message id in mixed snapshots with pending tool calls and streamed trailing text (#6269)
- agent-framework-devui: Fix
list[Message]input handling for declarativeToolAgententries (#6534) - agent-framework-devui: Fix DevUI deployment Dockerfile auth args (#6150)
- agent-framework-hyperlight: Harden workspace staging against symlinks and reparse points that could escape the sandbox workspace/mount root (#6856)
- agent-framework-openai: Fix
web_search_optionssent to the Azure OpenAI Chat Completions API (#6225) - docs: Fix stale
ChatAgentreferences in_clients.pydocstrings and make tool-support examples copy/paste-safe (#6924) - samples: Fix an invalid
optionskwarg in the workflow shared-session sample (#6294) - docs: Add prerequisite command documentation for Python hosting samples (#5935)
Removed
- agent-framework-hosting-telegram: [BREAKING] Remove the unreleased hosting-telegram package and the earlier host/channel surface from the workspace, superseded by the new hosting protocol helper surface (#6891)
Full Changelog: https://github.com/microsoft/agent-framework/compare/python-1.10.0...python-1.11.0
Breaking Changes
- Extract caching from `SkillsProvider` into a `CachingSkillsSource` decorator (experimental breaking change).
- Treat nested `SKILL.md` content as part of the parent skill instead of discovering it as a separate skill root (experimental breaking change).
- Change `FileAccess`/`FileMemory` `replace_lines` to perform literal replacement including line deletion (experimental breaking change).
- Remove the unreleased `agent-framework-hosting-telegram` package and its hosting/channel surface.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About agent-framework
A framework for building, orchestrating and deploying AI agents and multi-agent workflows with support for Python and .NET.
Related context
Related tools
Earlier breaking changes
- vpython-1.8.0 [BREAKING — experimental] Refactor Skill API to async resource and script lookup
- vpython-1.8.0 [BREAKING] Upgrade github-copilot-sdk to v1.0.0 (stable)
- vdotnet-1.9.0 Removes [Experimental] tag from .NET Orchestrations, marking them stable.
- vpython-1.7.0 Remove Python-only declarative actions and rename alias kinds to C# canonical names in agent-framework-declarative.
- vpython-1.6.0 Enable instrumentation by default in agent-framework-core and agent-framework-foundry.
Beta — feedback welcome: [email protected]