Skip to content

harness-sdk

v1.5.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 11mo AI Agents & Assistants
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-framework agentic agentic-ai agents ai ai-agents
+14 more
anthropic autonomous-agents bedrock generative-ai harness llm llm-agent mcp multi-agent-systems openai python sdk strands-agents typescript

Affected surfaces

auth

Summary

AI summary

Updates feat, fix, and graph across a mixed release.

Full changelog

What's Changed

  • feature(graph): Allow cyclic graphs by @mkmeral in https://github.com/strands-agents/sdk-python/pull/497
  • chore: request to include code snippet section by @poshinchen in https://github.com/strands-agents/sdk-python/pull/654
  • feat: Add configuration option to MCP Client for server init timeout by @fhwilton55 in https://github.com/strands-agents/sdk-python/pull/657
  • fix: Properly handle prompt=None & avoid agent hanging by @zastrowm in https://github.com/strands-agents/sdk-python/pull/643
  • feat: add structured_output_span by @poshinchen in https://github.com/strands-agents/sdk-python/pull/655
  • litellm - set 1.73.1 as minimum version by @pgrayy in https://github.com/strands-agents/sdk-python/pull/668
  • feat: expose tool_use and agent through ToolContext to decorated tools by @dbschmigelski in https://github.com/strands-agents/sdk-python/pull/557
  • session manager - prevent file path injection by @pgrayy in https://github.com/strands-agents/sdk-python/pull/680
  • fix: only set signature in message if signature was provided by the model by @clareliguori in https://github.com/strands-agents/sdk-python/pull/682
  • fix: Add openai dependency to sagemaker dependency group by @zastrowm in https://github.com/strands-agents/sdk-python/pull/678
  • Have [all] group reference the other optional dependency groups by name by @zastrowm in https://github.com/strands-agents/sdk-python/pull/674
  • fix: append blank text content if assistant content is empty by @poshinchen in https://github.com/strands-agents/sdk-python/pull/677
  • feat: add cached token metrics support for Amazon Bedrock by @oaltagar-aws in https://github.com/strands-agents/sdk-python/pull/531

New Contributors

  • @fhwilton55 made their first contribution in https://github.com/strands-agents/sdk-python/pull/657
  • @oaltagar-aws made their first contribution in https://github.com/strands-agents/sdk-python/pull/531

Full Changelog: https://github.com/strands-agents/sdk-python/compare/v1.4.0...v1.5.0

Security Fixes

  • Session manager now prevents file path injection

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track harness-sdk

Get notified when new releases ship.

Sign up free

About harness-sdk

A model-driven approach to building AI agents in just a few lines of code.

All releases →

Related context

Earlier breaking changes

Beta — feedback welcome: [email protected]