chore: bump agent-server 1.39.1, automation 1.5.0, typescript-client 1.36.1 (#16197)

This commit is contained in:
Hiep Le
2026-07-30 19:05:17 +07:00
committed by GitHub
parent bab763e4d4
commit ca982d66bb
8 changed files with 30 additions and 24 deletions
+2 -2
View File
@@ -491,10 +491,10 @@ When adding code that needs a new string, decide up front which rule it falls un
- `scripts/dev-safe.mjs` uses `uvx` for temporary agent-server installation — no permanent `uv tool install` needed. Environment variables (highest precedence first):
- `OH_AGENT_SERVER_LOCAL_PATH` — absolute path to a local `software-agent-sdk` checkout. Runs the local checkout via `uvx` with `--with-editable` for `openhands-sdk`/`openhands-tools`/`openhands-workspace` and `--reinstall` for `openhands-agent-server`, so SDK edits are picked up on restart. Highest precedence.
- `OH_AGENT_SERVER_GIT_REF` — git commit SHA or branch name (takes precedence over version)
- `OH_AGENT_SERVER_VERSION` — specific PyPI version (e.g., "1.38.0")
- `OH_AGENT_SERVER_VERSION` — specific PyPI version (e.g., "1.39.1")
- `OH_SECRET_KEY` — secret key for settings encryption; auto-generated and persisted to `~/.openhands/agent-canvas/secret-key.txt` on first run (same file Docker uses), ensuring dev mode and Docker share the same key when both mount the same `~/.openhands` directory. Override with the env var to pin a specific key.
- `SESSION_API_KEY` / `OH_SESSION_API_KEYS_0` / `VITE_SESSION_API_KEY` — session API key for agent-server authentication; auto-generated using `crypto.randomBytes(32)` if not set, passed to both agent-server (`OH_SESSION_API_KEYS_0`) and frontend (`VITE_SESSION_API_KEY`)
- Default: released PyPI version `1.38.0` for agent-server SDK libraries
- Default: released PyPI version `1.39.1` for agent-server SDK libraries
- Security: launchers generate and persist a 64-character session API key at `~/.openhands/agent-canvas/session-api-key.txt` unless overridden. The agent-server and automation backend share that session key. `OH_SECRET_KEY` protects settings encryption and is persisted separately at `~/.openhands/agent-canvas/secret-key.txt`.
- `scripts/dev-safe.mjs` should fail fast if `uvx` cannot be spawned (for example missing PATH entries).
+5 -5
View File
@@ -389,18 +389,18 @@ describe("buildAgentServerCommand", () => {
// Defaults to the released PyPI version with all SDK packages pinned to same version
expect(cmd.args).toEqual([
"--from",
"openhands-agent-server==1.38.0",
"openhands-agent-server==1.39.1",
"--with",
"openhands-sdk==1.38.0",
"openhands-sdk==1.39.1",
"--with",
"openhands-tools==1.38.0",
"openhands-tools==1.39.1",
"--with",
"openhands-workspace==1.38.0",
"openhands-workspace==1.39.1",
"--with",
"agent-client-protocol<0.11",
"agent-server",
]);
expect(cmd.source).toBe("PyPI (1.38.0, default)");
expect(cmd.source).toBe("PyPI (1.39.1, default)");
});
it("uses specific PyPI version when OH_AGENT_SERVER_VERSION is set with all packages pinned", () => {
+2 -2
View File
@@ -1,9 +1,9 @@
{
"_comment": "Single source of truth for version pins, ports, paths, and defaults shared across the npm and Docker install paths. Read by scripts/dev-safe.mjs, scripts/dev-with-automation.mjs, docker/entrypoint.sh (via generated defaults.env), and .github/workflows/docker.yml.",
"versions": {
"agentServer": "1.38.0",
"agentServer": "1.39.1",
"agentCanvas": "1.7.2",
"automation": "1.4.1"
"automation": "1.5.0"
},
"compatibility": {
"minimumAgentServer": "1.28.0"
+4 -4
View File
@@ -13,7 +13,7 @@
"@microlink/react-json-view": "1.31.20",
"@monaco-editor/react": "4.7.0",
"@openhands/extensions": "0.11.0",
"@openhands/typescript-client": "1.34.0",
"@openhands/typescript-client": "1.36.1",
"@react-router/node": "7.17.0",
"@react-router/serve": "7.17.0",
"@tailwindcss/vite": "4.2.4",
@@ -4181,9 +4181,9 @@
}
},
"node_modules/@openhands/typescript-client": {
"version": "1.34.0",
"resolved": "https://registry.npmjs.org/@openhands/typescript-client/-/typescript-client-1.34.0.tgz",
"integrity": "sha512-29nuKB7m1aOBHJWPgAY8ahZlsnJGkgByuoAQzYjY/lHzUClhM9RCJ0vgghm9cblADiYf+mUAOEL9AaOkXH2ahQ==",
"version": "1.36.1",
"resolved": "https://registry.npmjs.org/@openhands/typescript-client/-/typescript-client-1.36.1.tgz",
"integrity": "sha512-5/o5woxXH5YU0Ve6uvG+vhBHfb3kNB4pBzKBPqefj+EpaCZI/ue8xm3TuGApGzEEf4wQErFM7Vi81xU+L/mC7A==",
"license": "MIT",
"dependencies": {
"@openrouter/sdk": "^0.13.24",
+1 -1
View File
@@ -24,7 +24,7 @@
"@microlink/react-json-view": "1.31.20",
"@monaco-editor/react": "4.7.0",
"@openhands/extensions": "0.11.0",
"@openhands/typescript-client": "1.34.0",
"@openhands/typescript-client": "1.36.1",
"@react-router/node": "7.17.0",
"@react-router/serve": "7.17.0",
"@tailwindcss/vite": "4.2.4",
+6 -6
View File
@@ -19,7 +19,7 @@
*
* Usage:
* node scripts/check-sdk-version-sync.mjs
* EXPECTED_SDK_VERSION=1.38.0 node scripts/check-sdk-version-sync.mjs
* EXPECTED_SDK_VERSION=1.39.1 node scripts/check-sdk-version-sync.mjs
* node scripts/check-sdk-version-sync.mjs --check-pypi
*
* Environment variables:
@@ -78,7 +78,7 @@ Triggering from other repos:
-H "Authorization: token \$GITHUB_TOKEN" \\
-H "Accept: application/vnd.github.v3+json" \\
https://api.github.com/repos/OpenHands/OpenHands/dispatches \\
-d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.38.0"}}'
-d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.39.1"}}'
`);
process.exit(0);
}
@@ -260,9 +260,9 @@ async function fetchPyPIDependencies(packageName, version) {
* Parse PyPI requires_dist array and extract SDK package versions
*
* PyPI returns dependencies in PEP 508 format like:
* "openhands-sdk>=1.38.0,<2.0.0"
* "openhands-tools==1.38.0"
* "openhands-workspace (>=1.38.0)"
* "openhands-sdk>=1.39.1,<2.0.0"
* "openhands-tools==1.39.1"
* "openhands-workspace (>=1.39.1)"
*/
function parseSdkVersionsFromRequiresDist(requiresDist) {
const versions = {};
@@ -276,7 +276,7 @@ function parseSdkVersionsFromRequiresDist(requiresDist) {
}
// Extract the version number - look for patterns like:
// ">=1.38.0", "==1.38.0", "(>=1.38.0)", "~=1.38.0"
// ">=1.39.1", "==1.39.1", "(>=1.39.1)", "~=1.39.1"
// After the package name and before any comma or closing paren
const versionPattern = /[><=~!]+\s*([0-9]+(?:\.[0-9]+)*)/;
const match = dep.match(versionPattern);
+2 -2
View File
@@ -48,7 +48,7 @@ const LOCAL_AGENT_SERVER_SUBDIRS = [
"openhands-workspace",
];
const DEFAULT_AGENT_SERVER_VERSION = SHARED_DEFAULTS.versions.agentServer;
// Temporary transitive-dep pin: openhands-sdk 1.38.0 leaves agent-client-protocol
// Temporary transitive-dep pin: openhands-sdk 1.39.1 leaves agent-client-protocol
// unbounded (>=0.10.1), but acp 0.11.0 reordered the ACP prompt() args and breaks
// the SDK's ACP client. Hold acp <0.11 until a fixed SDK ships. See config/defaults.json.
const AGENT_CLIENT_PROTOCOL_CONSTRAINT =
@@ -399,7 +399,7 @@ export function validateFrontendDependencies(
* edits are picked up without a manual reinstall. The agent-server itself
* is rebuilt from local source on each invocation (--reinstall).
* - OH_AGENT_SERVER_GIT_REF: Git commit SHA or branch name
* - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.38.0")
* - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.39.1")
*
* If none are set, defaults to the released version specified by
* DEFAULT_AGENT_SERVER_VERSION. Set OH_AGENT_SERVER_GIT_REF to use a
+8 -2
View File
@@ -338,11 +338,15 @@ class McpService {
return client.startOAuth(request as MCPTestRequest);
}
// typescript-client 1.36 types the OAuth probes with the generated
// agent-server models, which describe the opaque `oauth_state` JSON blobs as
// `unknown` rather than the recursive `MCPJsonValue` the local types use. The
// wire shape is unchanged, so narrow back to the app's boundary type.
private static async getOAuthStatusWithClient(
client: MCPClient,
jobId: string,
): Promise<MCPOAuthStatusResponse> {
return client.getOAuthStatus(jobId);
return (await client.getOAuthStatus(jobId)) as MCPOAuthStatusResponse;
}
private static async submitOAuthCallbackWithClient(
@@ -350,7 +354,9 @@ class McpService {
jobId: string,
callbackUrl: string,
): Promise<MCPOAuthStatusResponse> {
return client.submitOAuthCallback(jobId, { callback_url: callbackUrl });
return (await client.submitOAuthCallback(jobId, {
callback_url: callbackUrl,
})) as MCPOAuthStatusResponse;
}
}