Skip to content

chore(deps): update LangChain Deep Agents Code to 0.1.55 - #8620

Draft
prekshivyas wants to merge 65 commits into
NVIDIA:mainfrom
prekshivyas:patch-walker/langchain-deep-agents-code-0.1.54-401c6b2528
Draft

chore(deps): update LangChain Deep Agents Code to 0.1.55#8620
prekshivyas wants to merge 65 commits into
NVIDIA:mainfrom
prekshivyas:patch-walker/langchain-deep-agents-code-0.1.54-401c6b2528

Conversation

@prekshivyas

@prekshivyas prekshivyas commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

Updates LangChain Deep Agents Code from 0.1.34 to 0.1.55 using the sealed NemoPin migration evidence. This PR remains draft for human review.

Related Issue

No issue closure is claimed by this draft.

Changes

  • Applies only paths authorized by sha256:296dd3487f41b6db94cf6cba42daf8e08bc1f9bb864ecc5f613f60c48f7bfe7a.
  • Migrates the exact base 5bb69ed66947fbd2fab6133748866567eb520692 across 21 adjacent release ranges.
  • Changed paths: agents/langchain-deepagents-code/Dockerfile, agents/langchain-deepagents-code/Dockerfile.base, agents/langchain-deepagents-code/dcode-wrapper.sh, agents/langchain-deepagents-code/dependency-review.md, agents/langchain-deepagents-code/manifest.yaml, agents/langchain-deepagents-code/patch-managed-deepagents-code.py, agents/langchain-deepagents-code/profile-plugin/pyproject.toml, agents/langchain-deepagents-code/profile-plugin/src/nemoclaw_deepagents_profile/__init__.py, agents/langchain-deepagents-code/progressive_tool_disclosure.py, agents/langchain-deepagents-code/requirements.in, agents/langchain-deepagents-code/requirements.lock, agents/langchain-deepagents-code/start.sh, agents/langchain-deepagents-code/validate-nemotron-ultra-profile.py, agents/langchain-deepagents-code/validate-observability.py, agents/langchain-deepagents-code/validate-progressive-tool-disclosure.py, docs/deployment/set-up-mcp-bridge.mdx, docs/get-started/quickstart-langchain-deepagents-code.mdx, src/lib/actions/sandbox/rebuild-flow-helpers.test.ts, src/lib/agent/base-image.test.ts, src/lib/agent/deep-agents-code-base-image.test.ts, src/lib/agent/onboard-terminal-fixtures.test.ts, src/lib/agent/onboard-terminal-fixtures.ts, src/lib/agent/onboard-terminal.test.ts, src/lib/onboard.ts, src/lib/onboard/created-sandbox-finalization.test.ts, src/lib/onboard/dcode-selection-drift.test.ts, src/lib/onboard/dcode-selection-drift.ts, src/lib/onboard/machine/handlers/sandbox-checkpoint-crash-recovery.test.ts, src/lib/onboard/machine/handlers/sandbox.ts, src/lib/onboard/sandbox-lifecycle.test.ts, src/lib/onboard/sandbox-lifecycle.ts, src/lib/sandbox-base-image-agent-resolution.test.ts, src/lib/sandbox-base-image-release-resolution.test.ts, src/lib/sandbox-base-image/resolution-key.test.ts, test/Dockerfile.dcode-profile-missing-dependencies, test/cli/connect-terminal-agent.test.ts, test/deepagents-code-tui-startup-check.test.ts, test/e2e/e2e-cloud-experimental/checks/03-deepagents-code-nemotron-ultra-profile.sh, test/e2e/e2e-cloud-experimental/checks/04-deepagents-code-fresh-reonboard.sh, test/e2e/e2e-cloud-experimental/checks/10-deepagents-code-tui-startup.sh, test/e2e/e2e-cloud-experimental/checks/12-deepagents-code-thread-auto-approval.sh, test/e2e/lib/select-authorized-chat-model.mts, test/e2e/live/mcp-bridge-servers.ts, test/e2e/support/authorized-chat-model-selection.test.ts, test/e2e/support/platform-parity-cloud-experimental.test.ts, test/fixtures/deepagents-progressive-disclosure-harness.py, test/fixtures/langchain-deepagents-code/server.py, test/helpers/langchain-deepagents-code-patch-fixture.ts, test/issue-5667-hosted-inference-model-namespace.test.ts, test/langchain-deepagents-code-direct-module-patch.test.ts, test/langchain-deepagents-code-image.test.ts, test/langchain-deepagents-code-nemotron-profile-plugin.test.ts, test/langchain-deepagents-code-progressive-tool-disclosure.test.ts, test/mcp-bridge-servers.test.ts, test/onboard-mcp-observability-redirect.test.ts, test/onboard-prepared-build-context.test.ts, test/onboard-terminal-dashboard.test.ts

Release ranges

Range Commits State Concerns
0.1.34 → 0.1.35 bd9bafaad3f509daab5772ff published 1
0.1.35 → 0.1.36 09daab5772ff2f56309d821d published 1
0.1.36 → 0.1.37 2f56309d821ddef6369aed1a published 2
0.1.37 → 0.1.38 def6369aed1a4338671aa1d9 published 4
0.1.38 → 0.1.39 4338671aa1d98eb909a59b82 published 1
0.1.39 → 0.1.40 8eb909a59b82019489edb9c0 published 6
0.1.40 → 0.1.41 019489edb9c0d46a2cb033b8 published 4
0.1.41 → 0.1.42 d46a2cb033b818679a1a88a3 published 3
0.1.42 → 0.1.43 18679a1a88a3e14e0adcbe78 published 2
0.1.43 → 0.1.44 e14e0adcbe782b9cd08f0492 published 5
0.1.44 → 0.1.45 2b9cd08f04927794b61a6e76 published 4
0.1.45 → 0.1.46 7794b61a6e76efa86c51fedd published 1
0.1.46 → 0.1.47 efa86c51fedd8aa29ddc2833 published 3
0.1.47 → 0.1.48 8aa29ddc2833803b8329db7d published 3
0.1.48 → 0.1.49 803b8329db7d44910bc2ef3f published 0
0.1.49 → 0.1.50 44910bc2ef3f63adb9645687 published 2
0.1.50 → 0.1.51 63adb9645687d2b663fca277 published 0
0.1.51 → 0.1.52 d2b663fca277b428644d31dd published 3
0.1.52 → 0.1.53 b428644d31dd0bd15dc0e1c5 published 2
0.1.53 → 0.1.54 0bd15dc0e1c581258067f4c7 published 0
0.1.54 → 0.1.55 81258067f4c780fe3d3cbcd2 published 9

Concern dispositions

Concern Surface Planned disposition Failure prevented Remaining gate
langchain-deep-agents-code-0.1.34..0.1.35-lifecycle-state-1 lifecycle state test 0.1.55 reports lifecycle state: ### Features - Added a /context usage report for inspecting context consumption ([#5407](langchain-ai/deepagents#5407... none
langchain-deep-agents-code-0.1.35..0.1.36-lifecycle-state-1 lifecycle state test 0.1.54 reports lifecycle state: ### Features - Added Meta muse-spark-1.2 to the model switcher (#5389). - Improved di... none
langchain-deep-agents-code-0.1.36..0.1.37-lifecycle-state-1 lifecycle state test 0.1.53 reports lifecycle state: ### Features - Added pricing coverage with Baseten built-in overrides and local fallback overrides when genai-prices is missing data ([#5312](h... none
langchain-deep-agents-code-0.1.36..0.1.37-runtime-topology-2 runtime topology test 0.1.53 reports runtime topology: ### Features - Added pricing coverage with Baseten built-in overrides and local fallback overrides when genai-prices is missing data ([#5312](... none
langchain-deep-agents-code-0.1.37..0.1.38-compatibility-change-1 compatibility change test 0.1.52 reports compatibility change: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langc... none
langchain-deep-agents-code-0.1.37..0.1.38-configuration-2 configuration test 0.1.52 reports configuration: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langchain-ai... none
langchain-deep-agents-code-0.1.37..0.1.38-execution-control-3 execution control guard 0.1.52 reports execution control: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langchai... none
langchain-deep-agents-code-0.1.37..0.1.38-lifecycle-state-4 lifecycle state test 0.1.52 reports lifecycle state: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langchain-... none
langchain-deep-agents-code-0.1.38..0.1.39-configuration-1 configuration test 0.1.51 reports configuration: ### Features - The status bar and usage view now show the running session cost. (#5036) -... none
langchain-deep-agents-code-0.1.39..0.1.40-compatibility-change-1 compatibility change test 0.1.50 reports compatibility change: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feed... none
langchain-deep-agents-code-0.1.39..0.1.40-execution-control-2 execution control guard 0.1.50 reports execution control: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedbac... none
langchain-deep-agents-code-0.1.39..0.1.40-lifecycle-state-3 lifecycle state test 0.1.50 reports lifecycle state: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedback ... none
langchain-deep-agents-code-0.1.39..0.1.40-packaging-artifact-4 packaging artifact test 0.1.50 reports packaging artifact: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedba... none
langchain-deep-agents-code-0.1.39..0.1.40-runtime-topology-5 runtime topology test 0.1.50 reports runtime topology: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedback... none
langchain-deep-agents-code-0.1.39..0.1.40-security-identity-6 security identity guard 0.1.50 reports security identity: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedbac... none
langchain-deep-agents-code-0.1.40..0.1.41-compatibility-change-1 compatibility change test 0.1.49 reports compatibility change: ### Features - Added recognition for LangSmith Gateway credentials. (#5042) - Adde... none
langchain-deep-agents-code-0.1.40..0.1.41-execution-control-2 execution control guard 0.1.49 reports execution control: ### Features - Added recognition for LangSmith Gateway credentials. (#5042) - Added s... none
langchain-deep-agents-code-0.1.40..0.1.41-lifecycle-state-3 lifecycle state test 0.1.49 reports lifecycle state: ### Features - Added recognition for LangSmith Gateway credentials. (#5042) - Added sla... none
langchain-deep-agents-code-0.1.40..0.1.41-runtime-topology-4 runtime topology test 0.1.49 reports runtime topology: ### Features - Added recognition for LangSmith Gateway credentials. (#5042) - Added sl... none
langchain-deep-agents-code-0.1.41..0.1.42-compatibility-change-1 compatibility change test 0.1.48 reports compatibility change: ### Features - Added Fireworks kimi-k3, GLM-5.2-Fast, and Kimi-K3 to model selection and recommended models. ([#5082](https://github.com/l... none
langchain-deep-agents-code-0.1.41..0.1.42-execution-control-2 execution control guard 0.1.48 reports execution control: ### Features - Added Fireworks kimi-k3, GLM-5.2-Fast, and Kimi-K3 to model selection and recommended models. ([#5082](https://github.com/lang... none
langchain-deep-agents-code-0.1.41..0.1.42-lifecycle-state-3 lifecycle state test 0.1.48 reports lifecycle state: ### Features - Added Fireworks kimi-k3, GLM-5.2-Fast, and Kimi-K3 to model selection and recommended models. ([#5082](https://github.com/langch... none
langchain-deep-agents-code-0.1.42..0.1.43-compatibility-change-1 compatibility change test 0.1.47 reports compatibility change: ### Features - Added yolo mode to the Shift+Tab approval cycle (#5035). - Show... none
langchain-deep-agents-code-0.1.42..0.1.43-execution-control-2 execution control guard 0.1.47 reports execution control: ### Features - Added yolo mode to the Shift+Tab approval cycle (#5035). - Show th... none
langchain-deep-agents-code-0.1.43..0.1.44-compatibility-change-1 compatibility change test 0.1.46 reports compatibility change: ### Highlights - Auto mode is now generally available. #4957 - Added configurable ... none
langchain-deep-agents-code-0.1.43..0.1.44-configuration-2 configuration test 0.1.46 reports configuration: ### Highlights - Auto mode is now generally available. #4957 - Added configurable Auto go... none
langchain-deep-agents-code-0.1.43..0.1.44-execution-control-3 execution control guard 0.1.46 reports execution control: ### Highlights - Auto mode is now generally available. #4957 - Added configurable Aut... none
langchain-deep-agents-code-0.1.43..0.1.44-protocol-schema-4 protocol schema test 0.1.46 reports protocol schema: ### Highlights - Auto mode is now generally available. #4957 - Added configurable Auto ... none
langchain-deep-agents-code-0.1.43..0.1.44-security-identity-5 security identity guard 0.1.46 reports security identity: ### Highlights - Auto mode is now generally available. #4957 - Added configurable Aut... none
langchain-deep-agents-code-0.1.44..0.1.45-compatibility-change-1 compatibility change test 0.1.45 reports compatibility change: ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](langchain-ai/deepagents#48... none
langchain-deep-agents-code-0.1.44..0.1.45-execution-control-2 execution control guard 0.1.45 reports execution control: ### Features - Added the Hooks v2 execution engine and typed hooks data models (#4880... none
langchain-deep-agents-code-0.1.44..0.1.45-lifecycle-state-3 lifecycle state test 0.1.45 reports lifecycle state: ### Features - Added the Hooks v2 execution engine and typed hooks data models (#4880, ... none
langchain-deep-agents-code-0.1.44..0.1.45-packaging-artifact-4 packaging artifact test 0.1.45 reports packaging artifact: ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](langchain-ai/deepagents#4880... none
langchain-deep-agents-code-0.1.45..0.1.46-runtime-topology-1 runtime topology test 0.1.44 reports runtime topology: ### Bug Fixes - Improved approval handling by hiding the Auto option when it isn't eligible and moving Auto mode path checks off the event loo... none
langchain-deep-agents-code-0.1.46..0.1.47-compatibility-change-1 compatibility change test 0.1.43 reports compatibility change: ### Features - Added classifier-backed Auto approval mode behind DEEPAGENTS_CODE_EXPERIMENTAL=1 ([#4804](https://github.com/langchain-ai/d... none
langchain-deep-agents-code-0.1.46..0.1.47-execution-control-2 execution control guard 0.1.43 reports execution control: ### Features - Added classifier-backed Auto approval mode behind DEEPAGENTS_CODE_EXPERIMENTAL=1 ([#4804](https://github.com/langchain-ai/deep... none
langchain-deep-agents-code-0.1.46..0.1.47-lifecycle-state-3 lifecycle state test 0.1.43 reports lifecycle state: ### Features - Added classifier-backed Auto approval mode behind DEEPAGENTS_CODE_EXPERIMENTAL=1 ([#4804](https://github.com/langchain-ai/deepag... none
langchain-deep-agents-code-0.1.47..0.1.48-compatibility-change-1 compatibility change test 0.1.42 reports compatibility change: ### Features - Plugins are now generally available. (#4797) - Added search to the ... none
langchain-deep-agents-code-0.1.47..0.1.48-execution-control-2 execution control guard 0.1.42 reports execution control: ### Features - Plugins are now generally available. (#4797) - Added search to the plu... none
langchain-deep-agents-code-0.1.47..0.1.48-lifecycle-state-3 lifecycle state test 0.1.42 reports lifecycle state: ### Features - Plugins are now generally available. (#4797) - Added search to the plugi... none
langchain-deep-agents-code-0.1.49..0.1.50-compatibility-change-1 compatibility change test 0.1.40 reports compatibility change: ### Features - Added plugin marketplace support (#4554). - Added an “always allow”... none
langchain-deep-agents-code-0.1.49..0.1.50-execution-control-2 execution control guard 0.1.40 reports execution control: ### Features - Added plugin marketplace support (#4554). - Added an “always allow” op... none
langchain-deep-agents-code-0.1.51..0.1.52-compatibility-change-1 compatibility change test 0.1.38 reports compatibility change: ### Features * Improve /goal criteria UX (#4694) ([06f46ff](https://github.com/l... none
langchain-deep-agents-code-0.1.51..0.1.52-configuration-2 configuration test 0.1.38 reports configuration: ### Features * Improve /goal criteria UX (#4694) ([06f46ff](https://github.com/langchai... none
langchain-deep-agents-code-0.1.51..0.1.52-lifecycle-state-3 lifecycle state test 0.1.38 reports lifecycle state: ### Features * Improve /goal criteria UX (#4694) ([06f46ff](https://github.com/langch... none
langchain-deep-agents-code-0.1.52..0.1.53-configuration-1 configuration test 0.1.37 reports configuration: ### Features * Add Meta model provider (#4650) ([70829c5](https://github.com/langchain-ai... none
langchain-deep-agents-code-0.1.52..0.1.53-security-identity-2 security identity guard 0.1.37 reports security identity: ### Features * Add Meta model provider (#4650) ([70829c5](https://github.com/langchai... none
langchain-deep-agents-code-0.1.54..0.1.55-compatibility-change-1 compatibility change test 0.1.35 reports compatibility change: ### Features * Restore interrupted prompt to input on ESC (#4544) ([fccf037](https... none
langchain-deep-agents-code-0.1.54..0.1.55-configuration-2 configuration test 0.1.35 reports configuration: ### Features * Restore interrupted prompt to input on ESC (#4544) ([fccf037](https://gith... none
langchain-deep-agents-code-0.1.54..0.1.55-execution-control-3 execution control guard 0.1.35 reports execution control: ### Features * Restore interrupted prompt to input on ESC (#4544) ([fccf037](https://... none
langchain-deep-agents-code-0.1.54..0.1.55-lifecycle-state-4 lifecycle state test 0.1.35 reports lifecycle state: ### Features * Restore interrupted prompt to input on ESC (#4544) ([fccf037](https://gi... none
langchain-deep-agents-code-0.1.54..0.1.55-protocol-schema-5 protocol schema test 0.1.35 reports protocol schema: ### Features * Restore interrupted prompt to input on ESC (#4544) ([fccf037](https://gi... none
langchain-deep-agents-code-0.1.54..0.1.55-code-impact-configuration-1 mapped configuration test The exact-ref diff reports configuration changes in .pre-commit-config.yaml, libs/acp/deepagents_acp/server.py, libs/acp/tests/test_agent.py. Mapped NemoClaw examples: src/lib/a... none
langchain-deep-agents-code-0.1.54..0.1.55-code-impact-contract-or-schema-2 mapped contract or schema test The exact-ref diff reports contract or schema changes in libs/acp/deepagents_acp/_version.py, libs/acp/deepagents_acp/server.py, libs/code/deepagents_code/_ask_user_types.py. Ma... none
langchain-deep-agents-code-0.1.54..0.1.55-code-impact-security-3 mapped security test The exact-ref diff reports security changes in libs/code/deepagents_code/_cli_context.py, libs/code/deepagents_code/_env_vars.py, libs/code/deepagents_code/_repository_bounds.py... none
langchain-deep-agents-code-0.1.54..0.1.55-code-impact-test-4 mapped test test The exact-ref diff reports test changes in libs/acp/tests/chat_model.py, libs/acp/tests/test_agent.py, libs/code/tests/integration_tests/benchmarks/test_local_context_benchmarks... none

Immutable artifacts

Artifact SHA-256
deepagents_code-0.1.55-py3-none-any.whl 3a0d3e332f132d0e…
deepagents_code-0.1.55.tar.gz 91c30b62cb96d5e8…

Validation receipt

Gate Current result
targeted Pending on this exact draft head
full-e2e Pending on this exact draft head

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: exact-head review passed at chore(deps): update LangChain Deep Agents Code to 0.1.55 #8620 (review).
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: docs-updated
  • Evidence: docs/deployment/set-up-mcp-bridge.mdx and docs/get-started/quickstart-langchain-deepagents-code.mdx accurately document the changed Deep Agents Code behavior and versions. The documented deepagents-code 0.1.55 and deepagents 0.7.5 versions match the manifest, inputs, lockfile, and profile plugin. npm run docs passed with 0 errors and two pre-existing Fern warnings.
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run validate:pr passed after refreshing origin/main when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification:
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result:
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Patch-Walker-Manifest: sha256:401c6b25284280b8da7158afba26762cef533a4650b99f06c212c8e9abc6e4c5

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Aug 8, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 6c6f16c5-7e29-484d-af21-bbf87ec4d00a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / low confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: PR review advisor failed: PR review advisor SDK execution failed: session: terminology-review-analysis omitted required analysis; turn: terminology-review-analysis: terminology-review-analysis omitted required analysis

Model lanes

  • GPT-5.6 Terra (primary): Failed
  • Nemotron 3 Ultra (second opinion): Failed

Second-opinion terminology and E2E selections are advisory. Live E2E does not run automatically for pull requests.

E2E guidance

Advisory only. A maintainer can dispatch the default E2E suite for the commit under review.

Recommended E2E: managed-image-protected-runtime

Manual-only E2E: cloud-onboard, managed-image-multiarch-startup, security-posture, hermes-e2e, onboard-repair, onboard-resume, ubuntu-repo-cloud-langchain-deepagents-code, cloud-inference, full-e2e, openshell-gateway-upgrade
The manual PR workflow does not run these selectors for the commit under review. Run them from reviewed code on main.

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@wscurran wscurran added chore Build, CI, dependency, or tooling maintenance integration: dcode LangChain Deep Code integration behavior labels Aug 10, 2026
prekshivyas and others added 23 commits August 10, 2026 23:40
Patch-Walker-Manifest: sha256:8279988a3938893965e7bc766045724eec1002b2414d3a6b8c2592fad171b915

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:b7e646df4250c7db583e43cbefb22396c34223f17c96131c2b51a100e33c45a5

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:c183e4c8434a7ccaf81bda28855c4053493c123a9512b96030c2ffcecaf972e4

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: cb7f2bd

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:da475ad603206b3f6e1f2695c73db3a8bc3822a6f8171561d5d3468c3fffdb88

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: 6f4ff97

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:c32c67048bc75f609052e90addc9b78762f86f91d9838553a723b1a9a1c26e32

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: b9a0d98

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:7fdf2235fd56d1601b370cec62fb65fe8108d4a97ba6c17dd30b99ef2012d578

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: 9257fe0

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:47bdfef8c819151f04bb9505a7e83d51898cd293a3bb9d5fbd29fc085ff05029

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: 96b1d67

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: aaaf5c1

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:3ccad3f783db42f985c67ed4f5f97d23b9cce24fb3b8ba9ca71e4487ba3f12ac

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:f931c9c6cd30be3ad7ef0bccdb1e61c6e58e18818e3c347f3f9abb58b86bd619

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
NemoPatch-Base: 97ee9ce

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:35cd4232285f2e6e04eb511e1eebbf3c7ddbb9955c9d1d073a769a704636600e

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas
prekshivyas requested a review from ericksoa August 13, 2026 01:57

@prekshivyas prekshivyas left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact draft head a800a7f. This is my own PR, so GitHub does not permit an independent approval or request-changes review from this account.

The sealed migration record is unusually complete: it enumerates all 20 adjacent releases, pins the 0.1.54 wheel/sdist and resolved lock graph, records downstream patches and guards, updates the version selectors coherently, and links exact-head managed-image and Deep Agents E2E evidence including the six auto-approval checks. I did not find a new snapshot-specific security defect beyond the recorded migration controls.

This draft is not ready to leave draft state now. GitHub reports the branch as CONFLICTING/DIRTY against current main; required commit-lint, DCO, documentation-receipt, and maintainer-edit checks are cancelled, and both advisor lanes failed without producing a review. Resolve the current-base conflicts without weakening the migration guards, rerun the dependency concern audit and exact-head CI/E2E on the resulting head, refresh the documentation-writer receipt, complete the unchecked Quality Gates line, and obtain an independent maintainer review. The trailing quoted NemoPatch status block in the PR body should also be cleaned up before readiness.

Security review of this snapshot:

  • Input validation: PASS — model-selection, profile, disclosure, and patch fixtures cover the changed upstream contracts.
  • Authentication and authorization: PASS — auto-approval changes remain explicitly gated and exact-head E2E covers the six cases.
  • Secrets and sensitive data: PASS — no credential material is added to runtime selectors, patches, docs, or evidence.
  • Injection risks: PASS — dependency installation and patching remain hash/shape guarded rather than accepting runtime fragments.
  • Data exposure and privacy: PASS — MCP/observability changes retain existing redaction and route boundaries.
  • Cryptography: PASS — package and lock identities are recorded with immutable hashes.
  • Dependencies and supply chain: WARNING — the snapshot evidence is strong, but it must be reconciled and re-audited after resolving current-main conflicts.
  • System security: PASS for this snapshot — image patching, startup, approval, lifecycle, and protected-runtime tests cover the changed surfaces.
  • Testing and verification: FAIL for readiness — the branch conflicts with current main, required checks are cancelled, automated advisors failed, and independent review is still absent.

Files reviewed: the complete 58-file dependency, image, patch, startup, onboarding/lifecycle, workflow, documentation, fixture, integration, and E2E snapshot diff plus its sealed release/concern record.

Patch-Walker-Manifest: sha256:915347d21e9b7a3d8b9d1fad9b139f6f82ef09af10c830e17a5551d510003ad9

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas prekshivyas changed the title chore(deps): update LangChain Deep Agents Code to 0.1.54 chore(deps): update LangChain Deep Agents Code to 0.1.55 Aug 14, 2026
Patch-Walker-Manifest: sha256:bf74c3d92c6ce5151e93f061e8a1e189867ec0be7b9e926a45b2be805a670b95

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:e612a14b43abae07cf861a1b70e803d4e4aa8aeaa4d9376f93ca906e279f48fd

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:976f52de5b167a34ae47a3ab2c17fca0f29fea0242245bca0b617e178f0001a0

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:976f52de5b167a34ae47a3ab2c17fca0f29fea0242245bca0b617e178f0001a0

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:5dc2d5d75a3a8b88bb06b8a166faedf6194b4985bce04f875202ddf1850283f5

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:5dc2d5d75a3a8b88bb06b8a166faedf6194b4985bce04f875202ddf1850283f5

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:532f2bc4e8a9189c8f60d01c026e91e688b91cada4029b3ddeae2a14680d2391

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:6d488d6fe71db78aa10e3a2eaea714947716c55696c15d3bd4fc12d37af1c858

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:6d488d6fe71db78aa10e3a2eaea714947716c55696c15d3bd4fc12d37af1c858

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:2d916300af0856eae97cddbd7bbfc8c3c6682de1e03232b35a36863dcbcd38db

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

@prekshivyas prekshivyas left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gate review of commit f473c25e9ca5806a97cae25b58c0a551f953cb42.

This is not an approval or a completed dependency-security acceptance. The PR is correctly draft, currently conflicts with the base branch, and has failed required checks. The CLI failure is the same existing src/lib/actions/sandbox/stop.test.ts timeout seen on unrelated commits, but both review-advisor lanes also failed and the exact migration still requires the stated human review of the sealed patch-walker evidence and 0.1.34-to-0.1.55 dependency behavior.

Security gate status: secrets PASS from the reviewed diff/metadata; input validation, authorization, error handling, and configuration require completion of the dependency migration review; dependencies BLOCKED; cryptography N/A; security tests BLOCKED; system security BLOCKED by conflict and red CI.

I cannot formally approve a PR authored by this GitHub account. Rebase/resolve the conflicts, refresh the migration evidence against current main, complete the dependency-sensitive review, and obtain a green latest-commit gate before taking this out of draft.

@prekshivyas prekshivyas self-assigned this Aug 15, 2026
Patch-Walker-Manifest: sha256:296dd3487f41b6db94cf6cba42daf8e08bc1f9bb864ecc5f613f60c48f7bfe7a

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

@prekshivyas prekshivyas left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 789b74f. No new blocking finding in the exact-head delta.

The staging QA failure was real: the recorded staging source carried Deep Agents Code 0.1.34 / SDK 0.7.0a6 while the PR profile requires 0.1.55 / 0.7.5. The latest fix preserves the recorded staging tree but overlays only the exact candidate-owned Dockerfile, lockfile, and required patch after regular-file/non-symlink shape checks; it also validates the candidate base build arguments. The workflow contract passes 19/19 and diff check passes.

Documentation review is exact and passes: docs/deployment/set-up-mcp-bridge.mdx and docs/get-started/quickstart-langchain-deepagents-code.mdx accurately describe the changed versions and behavior, and the docs build passes. I cannot approve this PR because it is my own and remains a draft; CI is still running.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Build, CI, dependency, or tooling maintenance integration: dcode LangChain Deep Code integration behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants