Skip to content

harness-sdk

v1.5.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic agentic-ai agents ai anthropic autonomous-agents
+13 more
bedrock genai litellm llama llm machine-learning mcp multi-agent-systems ollama openai opentelemetry python strands-agents

Affected surfaces

auth

Summary

AI summary

Updates feat, fix, and graph across a mixed release.

Full changelog

What's Changed

  • feature(graph): Allow cyclic graphs by @mkmeral in https://github.com/strands-agents/sdk-python/pull/497
  • chore: request to include code snippet section by @poshinchen in https://github.com/strands-agents/sdk-python/pull/654
  • feat: Add configuration option to MCP Client for server init timeout by @fhwilton55 in https://github.com/strands-agents/sdk-python/pull/657
  • fix: Properly handle prompt=None & avoid agent hanging by @zastrowm in https://github.com/strands-agents/sdk-python/pull/643
  • feat: add structured_output_span by @poshinchen in https://github.com/strands-agents/sdk-python/pull/655
  • litellm - set 1.73.1 as minimum version by @pgrayy in https://github.com/strands-agents/sdk-python/pull/668
  • feat: expose tool_use and agent through ToolContext to decorated tools by @dbschmigelski in https://github.com/strands-agents/sdk-python/pull/557
  • session manager - prevent file path injection by @pgrayy in https://github.com/strands-agents/sdk-python/pull/680
  • fix: only set signature in message if signature was provided by the model by @clareliguori in https://github.com/strands-agents/sdk-python/pull/682
  • fix: Add openai dependency to sagemaker dependency group by @zastrowm in https://github.com/strands-agents/sdk-python/pull/678
  • Have [all] group reference the other optional dependency groups by name by @zastrowm in https://github.com/strands-agents/sdk-python/pull/674
  • fix: append blank text content if assistant content is empty by @poshinchen in https://github.com/strands-agents/sdk-python/pull/677
  • feat: add cached token metrics support for Amazon Bedrock by @oaltagar-aws in https://github.com/strands-agents/sdk-python/pull/531

New Contributors

  • @fhwilton55 made their first contribution in https://github.com/strands-agents/sdk-python/pull/657
  • @oaltagar-aws made their first contribution in https://github.com/strands-agents/sdk-python/pull/531

Full Changelog: https://github.com/strands-agents/sdk-python/compare/v1.4.0...v1.5.0

Security Fixes

  • Session manager now prevents file path injection

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track harness-sdk

Get notified when new releases ship.

Sign up free

About harness-sdk

A model-driven approach to building AI agents in just a few lines of code.

All releases →

Beta — feedback welcome: [email protected]