- Breaking (license): relicensed from MIT to Apache-2.0, along with the rest of
the repository in Caveman 3.0.0. Releases before this one keep the MIT license. onDecisionandonDiagnosticaccept async sinks: a rejected promise is
swallowed like a throw, asonReportalready was, instead of an unhandled
rejection that terminates Node.- Callers that only waited on another call's shared capabilities fetch no longer
record its failure in the breaker: one refused connect at cold start is one
failure, not one per waiter. A call its host aborts records nothing (it used to
record a success, so a cancelled half-open probe closed the breaker) and frees
the probe slot. NewCircuitBreaker.release(). - A runtime token is trimmed of surrounding whitespace; any other character
outside printable ASCII isinvalid_configuration, as in Python. - An
https://orsocksHTTPS_PROXY/HTTP_PROXYisinvalid_configuration
with the unsupported scheme named byready()andpreflight(), instead of
runtime_unavailableon every call.MiddlewareErrortakes an optional detail. retrieve()(and so the recovery binding) throws
MiddlewareError('invalid_request')for arguments that are not an object with
a stringhandle, never aTypeError.- The
version_unverifiedwarn-once line readsCaveman middleware is running on an unverified framework version, because that call proceeds. - CommonJS
node16consumers can useimport sdk = require(...)and
import * aswith values: the.d.ctsshims re-export values, not only types. @caveman-ai/sdk/middlewareis stable: the@experimentalmarker is gone,
and it follows semver, because@caveman-ai/middleware1.0 depends on it.- A candidate whose
sourceIdis not a scope token is skipped as
unsupported, as in Python. - Exporter: cost is always exported as
doubleValue, a whole-dollar amount
too, as in Python. - Middleware transport honors
HTTPS_PROXY/HTTP_PROXY/NO_PROXYwithout
NODE_USE_ENV_PROXY, never proxies loopback, and adds acaoption. - Plan validation is total: any malformed plan is
invalid_plan, never
adapter_error. - The breaker, Retry-After and the capabilities TTL use a monotonic clock.
Retrieve and delete have their own concurrency budget. Server-advertised
deadlines are capped (5 s optimize, 30 s retrieve). - Stricter endpoint parsing; BOM-prefixed responses are rejected; a 429 with a
bad UTF-8 body is stillcapacity. preflight()reportsunknown_capabilitywhen no transform is usable.
counts.skippedmeans sent minus replaced. A stale-revision refresh runs
inline through the breaker.- New
unsupported_providerandunsupported_requestreason codes. - Exporter: user-supplied cache-creation attributes pass through again and
are no longer clamped. Cost is also emitted ascaveman.usage.cost_usd
(gen_ai.usage.cost_usdis deprecated). - New read-only
MiddlewareRuntime.strict. decline()accepts any catalogReasonCodeand an optional adapter id,
which the warn-once log line then names.typesVersionsand.d.ctsshims: TypeScript projects using node10 or
node16 CommonJS resolution can import both entry points without
skipLibCheck.@caveman-ai/sdk/middlewareimplements middleware protocol 1.1:- capabilities are parsed tolerantly, cached for 300 s and refreshed
single-flight - plans survive a policy-revision change
- errors are handled as the protocol specifies, including
Retry-After - a new circuit breaker opens after 5 consecutive or 10 of 20 failures and
counts deadlines - per-candidate budgets replace the whole-call bypass
- capabilities are parsed tolerantly, cached for 300 s and refreshed
- Security: replacements must be
exact_ccr, carry the recovery marker and
handle, and be strictly shorter in UTF-8 bytes.recovery: "none"output is
never applied. - Fixed a per-request memory leak (
AbortSignal.any). The runtime token no
longer appears inJSON.stringifyorutil.inspect. - Local data errors no longer count as runtime outages, and 4xx responses no
longer clear cached capabilities. - New options:
maxConcurrency,allowInsecureTransport,onDecision,
tracer,meter. Endpoint path prefixes work, anddeadlineMsdefaults to
the runtime's advertised value. - The constructor never throws: endpoint and option errors warn once and show
up inready()/preflight().decline()no longer throws in strict mode. - Breaking (experimental subpath):
recovery()returnsnullfor an invalid scope.deleteSession()returns aSessionDeleteResult.validateCapabilitiesis removed.- Scopes are normalized: values that aren't valid tokens are hashed to
h-….
- Requests send
Caveman-Middleware-Features,Caveman-Middleware-Clientand
W3C trace context. - Node floor lowered to
>=22.12. CommonJSrequire()works through
require(esm). - OTel exporter:
cacheCreationTokensis emitted as
gen_ai.usage.cache_creation.input_tokens. - Release process: each release gets a GitHub Release with these notes and a
CycloneDX SBOM of its dependency graph.
Verify this release
- Registry provenance (trusted publishing from this workflow): https://www.npmjs.com/package/@caveman-ai/sdk/v/1.2.0#provenance
- CycloneDX SBOM of the published dependency graph: attached
.cdx.json - Built from annotated, GitHub-verified tag
sdk-ts-v1.2.0onmain