This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Affected surfaces
Summary
AI summaryAdd local Ollama and open‑source model support via LiteLLM, improve OpenRouter/Hosted‑tool handling, and reject unsafe remote file URLs.
Full changelog
Patch release for local and open-source model routing, hosted-tool compatibility on non-OpenAI routes, and safer remote file downloads.
This release is most relevant for FastAPI and Agent Swarm CLI users who route requests through LiteLLM, Ollama, OpenRouter, Chat Completions, or custom OpenAI-compatible gateways.
What's Changed
Provider routing and local models
- Add local Ollama and open-source model support through LiteLLM for Agent Swarm CLI request routing in https://github.com/VRSEN/agency-swarm/pull/688.
- Preserve explicit local LiteLLM base URLs, strip only the TUI bridge loopback URL for local model defaults, and avoid incomplete Ollama provider configuration in https://github.com/VRSEN/agency-swarm/pull/689.
Hosted tools and OpenRouter compatibility
- Handle OpenAI hosted tools safely when a request routes an agency to OpenRouter, LiteLLM, Chat Completions, custom gateways, or other non-Responses backends in https://github.com/VRSEN/agency-swarm/pull/697.
- Replace unsupported hosted tools with same-name unavailable function stubs, preserve compatible same-name local
FunctionToolreplacements, and use the existing IPython-backed Agency Swarm replacement forcode_interpreterwhen available in https://github.com/VRSEN/agency-swarm/pull/697. - Route exact OpenRouter
base_urloverrides through the framework OpenRouter chat wrapper, and normalize OpenRouterextra_body.reasoninginto typed model settings in https://github.com/VRSEN/agency-swarm/pull/697.
Compatibility and file handling
- Keep compatibility for projects that still patch
parse_agent_flowswith the legacy two-value return shape, while preserving the current three-value communication-flow contract in https://github.com/VRSEN/agency-swarm/pull/706. - Reject remote file URL names that contain path separators or Windows drive qualifiers before temporary download paths are created in https://github.com/VRSEN/agency-swarm/pull/705.
Maintenance
- Split response-history coverage into focused helpers, samples, integration tests, and sanitizer unit tests in https://github.com/VRSEN/agency-swarm/pull/690.
- Update dependencies and lockfile entries for MCP, OpenAI, termcolor, datamodel-code-generator, Ruff, langchain-core, FastAPI, and ipykernel in https://github.com/VRSEN/agency-swarm/pull/692, https://github.com/VRSEN/agency-swarm/pull/693, https://github.com/VRSEN/agency-swarm/pull/694, https://github.com/VRSEN/agency-swarm/pull/695, https://github.com/VRSEN/agency-swarm/pull/696, https://github.com/VRSEN/agency-swarm/pull/699, https://github.com/VRSEN/agency-swarm/pull/700, https://github.com/VRSEN/agency-swarm/pull/701, https://github.com/VRSEN/agency-swarm/pull/702, and https://github.com/VRSEN/agency-swarm/pull/703.
- Bump package metadata to
1.10.2in https://github.com/VRSEN/agency-swarm/pull/706.
Compatibility Notes
- This is a patch release. No intentional breaking public API change is included.
- OpenAI Responses routes keep OpenAI hosted tools available. Non-Responses and non-OpenAI routes receive safe function-compatible replacements or unavailable stubs instead of sending unsupported hosted-tool payloads.
- The 1.10.1 flow-parser compatibility behavior is now kept on the main 1.10.x release line.
Full Changelog: https://github.com/VRSEN/agency-swarm/compare/v1.10.1...v1.10.2
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v1.10.3 Prevents fresh installs with openai-agents==0.14.8 from resolving incompatible OpenAI >=2.45 versions.
Beta — feedback welcome: [email protected]