[1.20.0] - 2026-10-02
Added
- agent-framework-foundry-hosting: Host native workflows over Foundry Responses and Foundry Invocations (#8947, #8966)
- agent-framework-duckdb, agent-framework-sql-server, agent-framework-typesafe: Add DuckDB and SQL Server native vector-store connectors and the TypeSafe AI connector (#8675, #8686, #8592)
- agent-framework, agent-framework-core: Add response-stream gates and buffering, session-scoped file-access isolation, an
AgentExecutorcheckpoint-stateTypedDict, and opt-inFunctionInvocationContextinjection for skill scripts (#8829, #8542, #8284, #8749) - agent-framework-foundry, agent-framework-foundry-hosting, agent-framework-openai: Add native computer-use support to Responses clients and Foundry project embeddings (#8751, #8454)
- agent-framework-azure-ai-search: Support
knowledge_source_paramsinAzureAISearchContextProvider(#8673) - agent-framework-mongodb, samples: Add a MongoDB agent RAG sample (#8725)
Changed
- agent-framework-foundry-hosting: [BREAKING] Redesign Foundry hosting around request-scoped agent factories, persistent sandbox-isolated sessions, parsed and durable Invocations runs, and configurable Responses history, background execution, and options (#8372, #8593, #8741, #8794, #8894)
- agent-framework-core: Harden approval and MCP runtime context handling, treat matched function results as terminal, require session-backed local approvals, and fail closed when approval bindings or agent-tool approvals cannot be resolved (#8579, #8589, #8750, #8780, #8527)
- agent-framework-declarative: [BREAKING - experimental] Align workflow state attribute lookup, bound PowerFx state construction, normalize workflow HTTP request URLs, and preserve expression results in
SendActivityoutput (#8893, #8511, #8588, #8509) - agent-framework-gemini, agent-framework-core: [BREAKING] Add Gemini Embedding 2 and vector task options, use the
GOOGLE_*settings namespace, and support operation-specific embedding options in shared vector APIs (#8798) - agent-framework-ag-ui, agent-framework-core: Treat matched tool results as terminal; make disconnected AG-UI runs durable, emit
RUN_STARTEDbefore execution when IDs are supplied, and isolate custom approval-state namespaces (#8579, #8672, #8807, #8714) - agent-framework, agent-framework-core: Bound the
allintegration set to the current release cohort to avoid pip resolver backtracking, and supportmsgspec0.22 for Python 3.15 installations - agent-framework-a2a, agent-framework-anthropic, agent-framework-azure-contentunderstanding, agent-framework-azure-cosmos-memory, agent-framework-bedrock, agent-framework-claude, agent-framework-copilotstudio, agent-framework-declarative, agent-framework-devui, agent-framework-foundry, agent-framework-foundry-hosting, agent-framework-github-copilot, agent-framework-hosting, agent-framework-hosting-responses, agent-framework-hosting-telegram, agent-framework-mem0, agent-framework-purview, agent-framework-redis: Add missing
py.typedmarkers and enforce their presence in package checks (#8823) - agent-framework-bedrock: Forward Converse guardrail and additional-model-request options, send user images, and stream through ConverseStream (#8680, #8683, #8685)
- agent-framework-chatkit: Support structured input and generated-image conversion (#8843, #8844)
- agent-framework-orchestrations: Create Magentic managers per workflow, optionally disable return-to-previous handoff routing, gate sequential output on approval, and validate generated handoffs before routing (#8581, #8639, #8595, #8587)
- agent-framework-redis: Allow
RedisHistoryProviderto borrow a Redis client, clarify context-retrieval scope, and declare the current Python<3.15limit imposed byredisvl(#8883, #8584) - agent-framework-postgres, agent-framework-hyperlight: Restore supported Python 3.15 dependency resolution (#8505)
- agent-framework-foundry: Require Azure Monitor OpenTelemetry 1.8.10 for trace propagation and support Azure AI Projects through 2.7 (#8512, #8751)
- agent-framework-hyperlight, agent-framework-monty: Clarify CodeAct guest-package installation and host-network access (#8781)
- tests: Refresh root and Lab development dependencies, type checkers, transitive security dependencies, and lockfiles; require Python 3.15 checks and add bounded Windows 3.14 meta-package install coverage (#8505, #8612, #8650, #8727, #8942, #8945)
- docs, samples: Cross-reference security patterns, clarify file-search retrieval scope, improve local-shell filtering guidance, and correct README instructions (#8726, #8591, #8766, #8822)
Fixed
- agent-framework-openai: Isolate OpenAI metadata defaults from Azure-routed clients (#8969)
- agent-framework-core: Apply MCP security labels before dynamically discovered and progressively disclosed tools become callable (#8972)
- agent-framework-core: Reduce response-stream hot-path overhead and avoid loading tool-approval middleware for agent runs without middleware (#8971)
- agent-framework-core: Preserve functional-workflow replay identity, scope invocation arguments and activity IDs to workflow runs, deduplicate fan-out targets, propagate nested cancellation arguments, and support orchestration checkpoint deserialization (#8887, #8596, #8549, #8739, #8602, #8723)
- agent-framework-core: Preserve repeated history turns, compaction through middleware rewrites, checkpoint dictionary subclasses, response metadata, annotations, native vector keys, integer precision, and boolean set values (#8800, #8671, #8519, #8464, #8701, #8535, #8637, #8681)
- agent-framework-core: Improve MCP skill archive and resource validation, stop failed MCP lifecycle owners, distinguish missing tool arguments from parse failures, settle fatal unknown calls, and omit absent MCP prompt-argument descriptions (#8937, #8690, #8755, #8609, #8640, #8733)
- agent-framework-core: Run response-stream cleanup hooks after transform failures, report unreadable history records and actionable file-write errors, handle concurrent file-store deletion, and preserve Unicode display paths (#8774, #8778, #8710, #8457, #8630)
- agent-framework-core: Coerce typed environment settings, detect postponed middleware annotations, preserve
Anycompatibility and structured approval output, and expose validated agent lifecycle methods (#8926, #8648, #8660, #8548, #8709) - agent-framework-core: Preserve usage-detail copies, skip empty prepended instructions, reject ambiguous media inputs and empty mode sets, surface switch-condition errors, validate tool-evaluation keys, and copy only requested vector-search pages (#8613, #8524, #8557, #8536, #8490, #8560, #8544)
- agent-framework-core: Treat missing streamed text deltas as empty and avoid spurious warnings for staged approvals (#8699, #8895)
- agent-framework-core, agent-framework-openai: Close Chat Completions SDK streams deterministically when consumers stop early or stream transforms fail (#8773)
- agent-framework-ag-ui, agent-framework-openai: Preserve Responses API citations through AG-UI, convert image inputs, read tool-call IDs from result events, and allow text events with dictionary JSON schemas (#8948, #8737, #8734, #8604)
- agent-framework-openai: Accept the registered
audio/mpegmedia type for MP3 input in both OpenAI chat clients (#8787) - agent-framework-foundry-hosting: Harden Responses request parsing, sandbox isolation, toolbox context and feature headers, cancellation completion, incomplete finish reasons, and OAuth consent-origin handling (#8899, #8717, #8722, #8565, #8478, #8713)
- agent-framework-foundry, agent-framework-openai: Preserve Foundry background local-tool replay and empty hosted-MCP allowlists (#8670, #8576)
- agent-framework-openai, agent-framework-foundry-hosting, agent-framework-tools: Preserve shell outcome fidelity, route unmarked shell calls to registered local executors, and improve shell and file-access validation (#8934, #8720, #8507)
- agent-framework-anthropic, agent-framework-bedrock, agent-framework-gemini, agent-framework-ollama: Send single stop strings as lists; avoid mutating Anthropic caller metadata and response schemas (#8736, #8816, #8735)
- agent-framework-ollama: Preserve zero embedding
keep_alive, include tool names on result messages, and reject non-image data instead of sending it as an image (#8928, #8815, #8917) - agent-framework-declarative: Evaluate
autoSendexpressions before output, avoid repeated workflow-reference traversal, and includeInvokeAzureAgentinput arguments in agent text (#8508, #8510, #8547) - agent-framework-orchestrations: Parse fenced JSON from group-chat managers and preserve multimodal user content during handoff (#8850, #8551)
- agent-framework-github-copilot: Forward function-invocation keyword arguments to agent tools (#8868)
- agent-framework-a2a: Keep streaming session state current and accept integer agent timeouts (#8646, #8516)
- agent-framework-azure-cosmos, agent-framework-azure-documentdb: Preserve nulls in negated Cosmos equality filters and omit nulls from DocumentDB membership filters (#8771, #8654)
- agent-framework-redis: Preserve memory-vectorizer data types and repeated history turns (#8629, #8800)
- agent-framework-hosting-telegram: Ignore commands addressed to other bots (#8803)
- agent-framework-hyperlight: Retain cached tool identities (#8598)
- agent-framework-tools: Support short Docker command flags (#8644)
Full Changelog: python-1.19.0...python-1.20.0