From cca79d096e7a66d8acfcc925b3eb2ff2bc836fe7 Mon Sep 17 00:00:00 2001 From: Tim O'Farrell Date: Fri, 5 Jun 2026 11:47:43 -0600 Subject: [PATCH] chore: bump software-agent-sdk to 1.26.0 (#1186) Update agentServer version pin in config/defaults.json from 1.25.0 to 1.26.0. This drives all four packages (openhands-agent-server, openhands-sdk, openhands-tools, openhands-workspace) which are released in lockstep. Also update matching test expectations and example version strings in dev-safe.mjs, check-sdk-version-sync.mjs, and AGENTS.md. Co-authored-by: openhands --- AGENTS.md | 4 ++-- __tests__/scripts/dev-safe.test.ts | 10 +++++----- config/defaults.json | 2 +- scripts/check-sdk-version-sync.mjs | 12 ++++++------ scripts/dev-safe.mjs | 4 ++-- 5 files changed, 16 insertions(+), 16 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 9eef3803ef..8d450c771d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -509,10 +509,10 @@ When adding code that needs a new string, decide up front which rule it falls un - `scripts/dev-safe.mjs` uses `uvx` for temporary agent-server installation — no permanent `uv tool install` needed. Environment variables (highest precedence first): - `OH_AGENT_SERVER_LOCAL_PATH` — absolute path to a local `software-agent-sdk` checkout. Runs the local checkout via `uvx` with `--with-editable` for `openhands-sdk`/`openhands-tools`/`openhands-workspace` and `--reinstall` for `openhands-agent-server`, so SDK edits are picked up on restart. Highest precedence. - `OH_AGENT_SERVER_GIT_REF` — git commit SHA or branch name (takes precedence over version) - - `OH_AGENT_SERVER_VERSION` — specific PyPI version (e.g., "1.25.0") + - `OH_AGENT_SERVER_VERSION` — specific PyPI version (e.g., "1.26.0") - `OH_SECRET_KEY` — secret key for settings encryption; auto-generated and persisted to `~/.openhands/agent-canvas/secret-key.txt` on first run (same file Docker uses), ensuring dev mode and Docker share the same key when both mount the same `~/.openhands` directory. Override with the env var to pin a specific key. - `SESSION_API_KEY` / `OH_SESSION_API_KEYS_0` / `VITE_SESSION_API_KEY` — session API key for agent-server authentication; auto-generated using `crypto.randomBytes(32)` if not set, passed to both agent-server (`OH_SESSION_API_KEYS_0`) and frontend (`VITE_SESSION_API_KEY`) - - Default: released PyPI version `1.25.0` for agent-server SDK libraries + - Default: released PyPI version `1.26.0` for agent-server SDK libraries - Security: `scripts/dev-safe.mjs` and `scripts/dev-with-automation.mjs` auto-generate random API keys when needed and persist the defaults so static builds, localStorage, and restarted services stay in sync: - `SESSION_API_KEY` — 64-character hex (256-bit) for agent-server API authentication; persisted at `~/.openhands/agent-canvas/session-api-key.txt` unless overridden via env var diff --git a/__tests__/scripts/dev-safe.test.ts b/__tests__/scripts/dev-safe.test.ts index 9ff3f42e9a..5d52723348 100644 --- a/__tests__/scripts/dev-safe.test.ts +++ b/__tests__/scripts/dev-safe.test.ts @@ -389,16 +389,16 @@ describe("buildAgentServerCommand", () => { // Defaults to the released PyPI version with all SDK packages pinned to same version expect(cmd.args).toEqual([ "--from", - "openhands-agent-server==1.25.0", + "openhands-agent-server==1.26.0", "--with", - "openhands-sdk==1.25.0", + "openhands-sdk==1.26.0", "--with", - "openhands-tools==1.25.0", + "openhands-tools==1.26.0", "--with", - "openhands-workspace==1.25.0", + "openhands-workspace==1.26.0", "agent-server", ]); - expect(cmd.source).toBe("PyPI (1.25.0, default)"); + expect(cmd.source).toBe("PyPI (1.26.0, default)"); }); it("uses specific PyPI version when OH_AGENT_SERVER_VERSION is set with all packages pinned", () => { diff --git a/config/defaults.json b/config/defaults.json index 3c8a1ef86d..0496274f83 100644 --- a/config/defaults.json +++ b/config/defaults.json @@ -2,7 +2,7 @@ "_comment": "Single source of truth for version pins, ports, paths, and defaults shared across the npm and Docker install paths. Read by scripts/dev-safe.mjs, scripts/dev-with-automation.mjs, docker/entrypoint.sh (via generated defaults.env), and .github/workflows/docker.yml.", "versions": { - "agentServer": "1.25.0", + "agentServer": "1.26.0", "agentCanvas": "1.0.0-rc.3", "automation": "1.0.0a6", "automationSdk": "1.22.1" diff --git a/scripts/check-sdk-version-sync.mjs b/scripts/check-sdk-version-sync.mjs index e4336b54d2..317b25d75f 100644 --- a/scripts/check-sdk-version-sync.mjs +++ b/scripts/check-sdk-version-sync.mjs @@ -19,7 +19,7 @@ * * Usage: * node scripts/check-sdk-version-sync.mjs - * EXPECTED_SDK_VERSION=1.25.0 node scripts/check-sdk-version-sync.mjs + * EXPECTED_SDK_VERSION=1.26.0 node scripts/check-sdk-version-sync.mjs * node scripts/check-sdk-version-sync.mjs --check-pypi * * Environment variables: @@ -79,7 +79,7 @@ Triggering from other repos: -H "Authorization: token \$GITHUB_TOKEN" \\ -H "Accept: application/vnd.github.v3+json" \\ https://api.github.com/repos/OpenHands/agent-canvas/dispatches \\ - -d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.25.0"}}' + -d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.26.0"}}' `); process.exit(0); } @@ -268,9 +268,9 @@ async function fetchPyPIDependencies(packageName, version) { * Parse PyPI requires_dist array and extract SDK package versions * * PyPI returns dependencies in PEP 508 format like: - * "openhands-sdk>=1.25.0,<2.0.0" - * "openhands-tools==1.25.0" - * "openhands-workspace (>=1.25.0)" + * "openhands-sdk>=1.26.0,<2.0.0" + * "openhands-tools==1.26.0" + * "openhands-workspace (>=1.26.0)" */ function parseSdkVersionsFromRequiresDist(requiresDist) { const versions = {}; @@ -284,7 +284,7 @@ function parseSdkVersionsFromRequiresDist(requiresDist) { } // Extract the version number - look for patterns like: - // ">=1.25.0", "==1.25.0", "(>=1.25.0)", "~=1.25.0" + // ">=1.26.0", "==1.26.0", "(>=1.26.0)", "~=1.26.0" // After the package name and before any comma or closing paren const versionPattern = /[><=~!]+\s*([0-9]+(?:\.[0-9]+)*)/; const match = dep.match(versionPattern); diff --git a/scripts/dev-safe.mjs b/scripts/dev-safe.mjs index e809d7e7b0..223db70068 100644 --- a/scripts/dev-safe.mjs +++ b/scripts/dev-safe.mjs @@ -420,7 +420,7 @@ export function validateFrontendDependencies( * edits are picked up without a manual reinstall. The agent-server itself * is rebuilt from local source on each invocation (--reinstall). * - OH_AGENT_SERVER_GIT_REF: Git commit SHA or branch name - * - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.25.0") + * - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.26.0") * * If none are set, defaults to the released version specified by * DEFAULT_AGENT_SERVER_VERSION. Set OH_AGENT_SERVER_GIT_REF to use a @@ -463,7 +463,7 @@ export function buildAgentServerCommand(env = process.env) { // All four must come from the same ref so inter-package APIs stay in sync. // // --reinstall is required because the git branch may carry the same version - // string as the current PyPI release (e.g. both "1.25.0"). Without it, uv + // string as the current PyPI release (e.g. both "1.26.0"). Without it, uv // silently reuses the cached PyPI wheels and the git ref is never actually // used, even though it was explicitly requested. const baseGitUrl = `git+${AGENT_SERVER_GIT_REPO}@${gitRef}`;