github langchain-ai/deepagents deepagents==0.7.0

See the docs for curated release notes.

⚠ BREAKING CHANGES

  • create_deep_agent no longer includes TodoListMiddleware by default, the write_todos tool, todos state channel, and todo-planning prompt are now absent. Pass middleware=[TodoListMiddleware()] to restore them on the main agent; add it to each SubAgent's middleware to restore them there. (#4929) (9340518)
  • Default agent prompts are now lean: the authored base prompt is empty, and tool-usage prose that duplicates tool schemas is trimmed. BASE_AGENT_PROMPT is deprecated (removal in deepagents==0.9.0) but remains importable and still returns the previous authored prompt verbatim; pass it as create_deep_agent(system_prompt=BASE_AGENT_PROMPT) to restore the old behavior. (#4859) (#4979) (a8d1b32) (d9f54fc)
  • The built-in tool-usage prompt constants TASK_SYSTEM_PROMPT, ASYNC_TASK_SYSTEM_PROMPT, SUMMARIZATION_SYSTEM_PROMPT, FILESYSTEM_SYSTEM_PROMPT, and EXECUTION_SYSTEM_PROMPT are removed, and the system_prompt default on SubAgentMiddleware, AsyncSubAgentMiddleware, SummarizationToolMiddleware, and create_summarization_tool_middleware is now None, which injects no prose. Pass your own string to restore prompt text. (#4859) (a8d1b32)
  • FilesystemBackend and LocalShellBackend now default to virtual_mode=True. Filesystem paths are anchored under root_dir, .. traversal is rejected, and paths resolving outside root_dir raise ValueError. Previously an unspecified virtual_mode emitted a deprecation warning and fell back to False, where absolute host paths were used as-is and .. could escape root_dir. Pass virtual_mode=False explicitly to restore the old filesystem behavior. (#4541) (540a0fa)
  • Agents now see a destructive, recursive delete filesystem tool whenever the backend supports it, and filesystem permissions classify delete as a write operation — so an existing rule allowing writes to a path also authorizes recursively deleting that subtree unless a narrower deny or interrupt rule covers the target. Because recursive deletes affect descendants, deny and interrupt checks use bulk path overlap instead of exact-path matching. To keep the previous behavior, add a deny or interrupt rule, or omit delete from FilesystemMiddleware(tools=...). Missing paths return a not-found error, CompositeBackend reports an unsupported-operation error when a routed sub-backend cannot delete, and the tool is hidden from the model entirely when the backend itself does not implement it. (#3659) (#3691) (#3765) (#3851) (f2a21ec)
  • write_file can now create a file if it is missing and replaces it entirely if it already exists, instead of returning a file-exists error. The write_file tool description no longer requires reading the file first. There is no "create-only" compatibility mode. Workflows, prompts, tests, or guardrails that relied on the file-exists error to force edit_file usage or to protect existing content must omit write_file, add explicit permission or interrupt rules, or use edit_file where preserving existing content matters. (#4109) (2506fcc)
  • Removed deprecated backend compatibility shims. Callers must pass concrete BackendProtocol instances (not factories), configure StoreBackend with an explicit namespace, and use the current ls / glob / grep / ReadResult APIs. (#4541) (540a0fa)
  • The deprecated files_update attribute and constructor keyword are removed from WriteResult and EditResult. Custom backends must stop passing files_update=, and callers must stop reading result.files_update; state writes are emitted directly by StateBackend. (#4541) (540a0fa)
  • Removed the deprecated BackendProtocol methods ls_info, als_info, glob_info, aglob_info, grep_raw, and agrep_raw. Use ls / glob / grep and their async counterparts. (#4541) (540a0fa)
  • SummarizationMiddleware(history_path_prefix=...) was removed and now raises TypeError. Configure CompositeBackend(artifacts_root=...) instead. (#4541) (540a0fa)
  • Agent-facing ls and glob tool output now renders empty results as No files found instead of []; direct backend APIs continue to return structured empty LsResult and GlobResult values. Callers that parse tool output should update those checks. (#3709) (efafd1e)
  • read_file no longer renders raw text with a fixed-width cat -n-style line-number gutter and tab separator. Line and continuation markers are dynamically aligned and separated from source content by two spaces, and the LINE_NUMBER_WIDTH constant is removed from deepagents.backends.utils and deepagents.middleware.filesystem. Callers that parse raw tool output should update those parsers. (#4561) (cf057b4)

Features

  • Custom middleware passed to create_deep_agent(..., middleware=[...]) can replace a default middleware instance when .name matches, so defaults such as SummarizationMiddleware can be overridden without also excluding the built-in instance. (#4251) (90c8472)
  • FilesystemMiddleware(tools=[...]) accepts a keyword-only allowlist of built-in filesystem tools, typed by the newly exported FsToolName literal ("ls", "read_file", "write_file", "edit_file", "delete", "glob", "grep", "execute"); pass "all" or omit the argument to keep every tool. A list must include "read_file" or the constructor raises ValueError. Omitted built-in tools are non-executable, and custom user tools are unaffected. (#4325) (#4698) (704a70d) (9709525)
  • Shorten LLM-facing descriptions for the task tool and filesystem tools (read_file, grep, edit_file, glob, execute). (#5009) (761f5f0)
  • GrepResult and GlobResult now carry a truncated flag so supporting backends can return valid partial results when a match cap or backend deadline is reached; agent-facing tool output adds a note telling the model to narrow the search. FilesystemBackend returns partial grep and glob results on its backend timeout rather than erroring, while other backend or middleware timeouts may still return errors. Its glob also gains brace expansion such as *.{py,md} (already supported by the state and store backends). (#4063) (ef591e7)
  • The agent-facing grep match cap is configurable: FilesystemMiddleware(grep_max_count=...) sets the default (1000; None disables it) and the model can override it per call through the tool's new max_count argument. grep / agrep on BackendProtocol and all built-in backends accept a keyword-only max_count. Local ripgrep output is streamed and terminated once the cap is reached. Direct FilesystemBackend.grep() callers can request surrounding lines with keyword-only context_lines. (#4570) (#4706) (8e86f5e) (65230df)
  • Paginated built-in read_file responses report the returned source-line range and next offset; total and remaining line counts are included when the backend knows the file length. Resume offsets remain safe when sandbox or middleware limits shorten the visible page. (#4540) (8321194)
  • Optional video frame extraction for read_file, enabled by the new deepagents[video] extra. Video files are sampled into JPEG frames, with offset and limit interpreted as seconds. Without the extra, existing generic video/file content-block behavior remains. (#4094) (b927147)
  • FilesystemMiddleware can capture oversized execute tool output directly inside the sandbox artifact path on compatible, opted-in BaseSandbox implementations to reduce round trips; LangSmithSandbox opts in by default. (#4230) (02f5bd7)
  • Automatically enable Fireworks prompt-cache session affinity when a compatible langchain-fireworks installation is available. (#4598) (5d878bf)
  • Add a built-in NVIDIA Nemotron 3 Ultra harness profile and NVIDIA NIM app-origin attribution. (#4192) (#4455) (d5a60ec) (4cb4749)
  • RubricMiddleware now accepts any positive max_iterations cap instead of enforcing a hard upper bound. (#4405) (d6692a7)

Bug Fixes

  • Keep fields marked with PrivateStateAttr, including fields declared through create_deep_agent(state_schema=...), out of subagent inputs and returned parent-state updates. (#4587) (a4662c0)
  • Preserve ContextT through the create_deep_agent(..., middleware=[...]) type annotation so type checkers accept context-aware middleware when a matching context_schema is passed. (#4055) (7be76c7)
  • Accept YAML list values as well as comma-separated strings for skill allowed-tools frontmatter, and make skill truncation warnings actionable with field name, path, length, configured limit, and impact. (#4140) (#4141) (d62534c) (2f5f5b8)
  • Align filesystem instructions with the tools that remain after allowlist and backend-capability filtering, so agents no longer reference hidden grep/glob tools or prohibit equivalent shell search when dedicated search tools are unavailable. (#4920) (#4921) (d3650c7) (b65cc00)
  • Propagate default-backend failures from CompositeBackend.ls("/") and CompositeBackend.als("/") instead of returning successful route-only listings. (#4925) (4c3b166)
  • Correct CompositeBackend.glob / CompositeBackend.aglob routing so explicit default-backend paths such as /tools do not also return files from routed backends such as /memories. (#4531) (cbdb0a7)
  • Propagate default- and routed-backend failures from root CompositeBackend.glob(..., path=None) / aglob(..., path=None) and path="/" searches instead of returning incomplete successful results. (#4063) (ef591e7)
  • Constrain sandbox glob and slash-pattern grep searches to their declared search root by treating leading / as search-root-relative, rejecting .. traversal segments, and filtering symlink-resolved matches outside the root. (#4588) (c6c7213)
  • Unify grep(..., glob=...) include-glob semantics across filesystem and in-memory backends: basename patterns like *.py match at any depth, and slash-containing patterns like src/**/*.py match relative paths consistently. (#3936) (feab6e0)
  • Improve agent-facing grep descriptions and no-match hints to steer regex-looking patterns toward literal searches, route slash-containing sandbox include-globs correctly, and shorten default search timeouts so bad patterns and huge trees return guidance faster. (#4168) (b1dbf5e)
  • Align sandbox delete behavior with other backends by returning not-found errors for missing paths, and avoid over-blocking unrelated sibling deletes when deny rules use glob patterns. (#4321) (d77496b)
  • Improve rubric grader failure diagnostics with configured model, structured-output strategy, and integer HTTP status when available. (#4938) (#4967) (f51d3a0) (bca70aa)
  • Emit max_iterations_reached as the terminal RubricMiddleware status when the iteration cap is exhausted, instead of a final needs_revision event that will not loop. (#4406) (a51c8d2)
  • Handle missing async subagent URLs consistently in check_async_task and cancel_async_task. (#3967) (b0d92c0)

Performance Improvements

  • Run LangSmith sandbox commands over the async client. (#5061) (0d08747)

Thanks to our community contributors: @kavishkartha05 (Twitter, LinkedIn), @nv-kasikritc

Internal maintainers: @nick-hollon-lc, @imnishitha, @hntrl, @srimanthtangedipalli-eng, @ramon-langchain, @jkennedyvz, @ccurme, @davibinboi, @mdrxy

Released by: @mdrxy

Git log since deepagents==0.6.12

This commit history includes changes to this package. Commits are listed newest first.

  • 77f0d9a release(deepagents): 0.7.0 (#4297)
  • fef1ff3 chore(deps): raise langchain-anthropic minimum to 1.5.3 (#5120)
  • 0d08747 perf(langsmith-sandbox): run LangSmith sandbox commands over the async client (#5061)
  • c0afec5 feat(code): add Claude Opus 5 support (#5049)
  • 761f5f0 feat(sdk): trim built-in tool descriptions (#5009)
  • d9f54fc refactor(sdk,evals): deprecate legacy base agent prompt (#4979)
  • 9340518 feat(sdk,code,quickjs)!: make the ToDoListMiddleware list opt-in (#4929)
  • 9a24baf refactor(sdk): correct prompt docs and harden rubric diagnostics (#4989)
  • d046427 revert(code,sdk): revert SystemPromptConfig (#4969)
  • f51d3a0 fix(sdk): diagnose rubric grader structured output errors (#4938)
  • bca70aa fix(sdk): include HTTP status in rubric grader errors (#4967)
  • a8d1b32 feat(sdk,code,quickjs): lean system prompt by default, restorable (#4859)
  • 540a0fa refactor(sdk)!: remove deprecated backend compatibility shims (#4541)
  • 9f92d2f build(sdk): raise dependency minimums (#4936)
  • 4c3b166 fix(sdk): propagate root listing errors from CompositeBackend (#4925)
  • d3650c7 fix(sdk): condition large-result guidance on visible tools (#4920)
  • b65cc00 fix(sdk): condition execute search guidance on visible tools (#4921)
  • a8e4768 docs(sdk): explain backend file operation semantics (#4919)
  • 9e8d478 refactor(sdk): extract prompt caching helpers (#4892)
  • 8326177 chore(deps): bump pyasn1 from 0.6.3 to 0.6.4 in /libs/deepagents (#4897)
  • 8400b89 chore(deps-dev): bump setuptools from 82.0.1 to 83.0.0 in /libs/evals (#4896)
  • b708207 chore(deps-dev): bump pillow from 12.2.0 to 12.3.0 in /libs/evals (#4876)
  • 29d6046 chore(deps): require langchain-quickjs 0.3.3 (#4802)
  • 9709525 fix(sdk): remove excluded tools from ToolNode (#4698)
  • e61156d test(sdk): handle expected middleware warnings (#4717)
  • 5d878bf feat(sdk): use FireworksPromptCachingMiddleware for session affinity (#4598)
  • 8e86f5e feat(sdk): add total match cap and streaming to grep (#4570)
  • cf057b4 fix(sdk)!: disambiguate read_file line gutters (#4561)
  • 8321194 feat(sdk): report remaining lines for paginated reads (#4540)
  • 65230df feat(sdk): support surrounding lines in filesystem grep results (#4706)
  • a4662c0 fix(sdk): isolate private custom state from subagents (#4587)
  • 44daa24 chore(repo): raise LangChain integration minimums (#4601)
  • c6c7213 fix(langsmith-sandbox): sandbox glob path boundary checks (#4588)
  • d5a60ec feat(sdk): add NVIDIA Nemotron 3 Ultra harness profile (#4192)
  • cbdb0a7 fix(sdk): isolate composite glob paths (#4531)
  • 7be76c7 fix(sdk): preserve ContextT on create_deep_agent middleware (#4055)
  • d62534c fix(sdk): accept list format for skill allowed-tools (#4140)
  • 2f5f5b8 fix(sdk): make skill truncation warnings actionable (#4141)
  • 56c5a5e feat(sdk): improve system prompt configurability (#4437)
  • 4cb4749 feat(sdk): add NVIDIA NIM app-origin attribution (#4455)
  • b1dbf5e fix(sdk): improve grep literal guidance and sandbox glob routing (#4168)
  • ef591e7 feat(sdk): bound grep/glob with partial results and a truncated flag (#4063)
  • d77496b fix(sdk): sandbox not-found contract and glob deny over-blocking on delete (#4321)
  • 704a70d feat(sdk): add enabled_tools allowlist to FilesystemMiddleware (#4325)
  • feab6e0 fix(sdk): unify grep include-glob semantics across backends (#3936)
  • b0d92c0 fix(sdk): move get_sync() inside try in check_async_task and cancel_async_task (#3967)
  • d4ba51c docs(sdk): expand profiles package docstring with directory layout (#4041)
  • b927147 feat(sdk): optional video frame extraction on read_file (#4094)
  • d6692a7 feat(code,sdk): add rubric iteration controls (#4405)
  • a51c8d2 fix(sdk): emit terminal rubric iteration status (#4406)
  • 90c8472 feat(sdk): allow users to override default middleware by name (#4251)
  • 02f5bd7 feat(sdk): reduce round trips when offloading large tool results with sandbox.execute (#4230)
  • 8e8680b build(deps): refresh dependency minimums (#4331)
  • 23500f4 chore(deps): bump langgraph-checkpoint from 4.1.0 to 4.1.1 in /libs/deepagents (#4274)
  • 965cbd5 chore(repo): cut over v0.7 to main (#4280)

Don't miss a new deepagents release

NewReleases is sending notifications on new releases.