0.23.0 (2026-10-01)
Features
- mcp: add configurable MCP listing page limits (#5133) (9a21ab1)
- sandbox: add opt-in Docker removal protection (#5116) (ae5803f)
- sandbox: allow configuring memory consolidation turns (#5135) (daa1bcb)
- sessions: add an opt-in encrypted history scan budget (#5118) (a2fdb94)
Bug Fixes
- avoid awaiting cleanup during coroutine closure (#5163) (719c4e7)
- ci: update and group CodeQL actions together (#5262) (f76153c)
- ci: validate release source before building distributions (#5220) (2747c1c)
- core/extensions: respect sensitive trace capture for model metadata (#5129) (88b722d)
- core: bound agent tool streaming callback backlogs (#5106) (f23da76)
- core: isolate nested agent tool state across fresh runs (#5123) (46cc8d8)
- core: preserve closed parent constraints in singleton allOf (#5131) (f010d18)
- core: preserve guarded final outputs in agent tools (#5115) (f3a15f6)
- core: preserve structured guardrail diagnostics and agent output during persistence (#5016) (51bcea7)
- core: preserve tool identity during asynchronous enablement (#5136) (f2ae64c)
- core: redact default tool failure details (#5112) (40956e0)
- core: redact streaming task exception tracebacks (#5121) (c329e92)
- core: reject silently discarded kwargs tool arguments (#5174) (a9b1ce7)
- core: resolve tools after agent start hooks (#5124) (5237420)
- core: restore nested agent tool state against the tool's own agent (#5142) (ad93f54)
- core: retry pre-request WebSocket handshake failures (#4780) (265f16f)
- core: scope function tool approvals to their owning agent (#5144) (de25d82)
- core: select built-in shell and apply_patch tools by their own type (#4952) (eb68131)
- core: serialize only traced fields in ModelSettings.to_traceable_dict (#5003) (57f0b38)
- core: validate agent tool stream callbacks before execution (#5125) (fae72a4)
- core: validate tool_use_behavior callback results (#5173) (5a2d63f)
- deps-dev: bump coverage from 7.10.3 to 7.16.1 (#5152) (47c21ee)
- deps-dev: bump cryptography from 50.0.0 to 50.0.1 (#5234) (e6c6806)
- deps-dev: bump dapr from 1.16.0 to 1.18.3 (#5154) (e94309d)
- deps-dev: bump pymongo from 4.16.0 to 4.18.1 (#5155) (971c5f3)
- deps-dev: bump ruff from 0.9.2 to 0.16.8 (#5249) (9d2b318)
- deps-dev: bump textual from 8.2.3 to 8.2.8 (#5248) (f2df6e4)
- deps-dev: bump types-pynput from 1.8.1.20250809 to 1.8.1.20260712 (#5246) (582d048)
- deps: bump actions/create-github-app-token from 2.2.2 to 3.2.0 (#5245) (e6467e2)
- deps: bump anyio from 4.10.0 to 4.14.2 (#5091) (0910b46)
- deps: bump astral-sh/setup-uv from 9.0.0 to 10.2.0 (#5252) (52aa07c)
- deps: bump cbor2 from 5.9.0 to 6.1.4 (#5153) (34952bc)
- deps: bump pyjwt from 2.13.0 to 2.15.0 (#5271) (dc81a17)
- deps: bump runloop-api-client from 1.31.0 to 1.32.0 (#5156) (32edd3c)
- deps: bump temporalio from 1.26.0 to 1.33.0 (#5233) (6b5bad7)
- deps: bump the codeql group with 2 updates (#5273) (fffe955)
- deps: bump urllib3 from 2.7.0 to 2.8.0 (#5256) (28e9f4f)
- deps: update httpx2 requirement from >=2.12.0 to >=2.13.0 in /examples/realtime/twilio (#5147) (153b3f1)
- deps: update httpx2 requirement from >=2.12.0 to >=2.13.0 in /examples/realtime/twilio_sip (#5151) (a62e594)
- deps: update httpx2 requirement from >=2.13.0 to >=2.13.1 in /examples/realtime/twilio (#5266) (ed1145f)
- deps: update httpx2 requirement from >=2.13.0 to >=2.13.1 in /examples/realtime/twilio_sip (#5269) (a5d7fd4)
- deps: update httpx2 requirement in /examples/realtime/twilio (ed1145f)
- deps: update httpx2 requirement in /examples/realtime/twilio_sip (a5d7fd4)
- deps: update openai requirement from <4,>=3.17.0 to >=3.19.1,<4 in /examples/realtime/twilio_sip (#5270) (093e183)
- deps: update openai requirement from <4,>=3.8.0 to >=3.17.0,<4 in /examples/realtime/twilio_sip (#5232) (5541111)
- deps: update openai requirement in /examples/realtime/twilio_sip (093e183)
- deps: update openai requirement in /examples/realtime/twilio_sip (5541111)
- deps: update pyjwt requirement from >=2.13.0 to >=2.14.0 in /examples/realtime/twilio (#5149) (5ed5727)
- deps: update pyjwt requirement from >=2.14.0 to >=2.15.0 in /examples/realtime/twilio (#5267) (0b60281)
- deps: update pyjwt requirement in /examples/realtime/twilio (0b60281)
- deps: update starlette requirement from >=1.6.0 to >=1.7.0 in /examples/realtime/twilio (#5265) (1e1cd73)
- deps: update starlette requirement from >=1.6.0 to >=1.7.0 in /examples/realtime/twilio_sip (#5268) (36d7944)
- deps: update starlette requirement in /examples/realtime/twilio (1e1cd73)
- deps: update starlette requirement in /examples/realtime/twilio_sip (36d7944)
- deps: update twilio requirement from <10,>=9 to >=9.11.1,<10 in /examples/realtime/twilio (#5148) (59d860f)
- deps: update urllib3 requirement from >=2.7.0 to >=2.8.0 in /examples/realtime/twilio (#5231) (c513dd1)
- deps: update urllib3 requirement in /examples/realtime/twilio (c513dd1)
- deps: update uvicorn requirement from >=0.52.4 to >=0.53.0 in /examples/realtime/twilio_sip (#5150) (04e699f)
- discard previous stream event aliases on model timeout (#5216) (de3b1d7)
- escape terminal controls in result diagnostics (#5219) (e80737c)
- examples: keep realtime debug error summaries payload-free (#5200) (e7d7097)
- examples: keep Redis connection details out of diagnostics (#5205) (c2321d2)
- examples: prevent auto-running the local Temporal shell workflow (#5218) (5b50815)
- examples: restrict the Realtime demo to local bounded sessions (#5111) (4adad5e)
- extensions: close owned event streams when runs fail (#5060) (d5abd9f)
- extensions: honor run tracing policy in Codex command spans (#5138) (78e5b4d)
- extensions: keep SQLite usage capture off the event loop (#4981) (8e338e5)
- extensions: keep the current branch when a forced delete_branch fails (#5081) (165390c)
- extensions: preserve filtered history during automatic compaction (#5103) (27625dd)
- extensions: preserve subprocess errors for non-UTF8 stderr (#5186) (549fcee)
- extensions: validate MongoDB session identifiers (#5104) (442469e)
- keep the file when apply_patch does a case-only rename (#4890) (71306bf)
- mcp: bind resumed MCP calls to their original recipients (#5119) (bd91ae6)
- mcp: escape duplicate tool names in diagnostics (#5217) (fc4d832)
- mcp: keep the Streamable HTTP session usable after a 5xx (#5061) (29aa40b)
- mcp: preserve cache invalidation during refresh (#4807) (5e7afe4)
- mcp: stop swallowing worker task cancellation (#5055) (c4c04b6)
- memory: preserve encrypted SQLite history on wrong-key pops (#5083) (0f87da2)
- memory: require encrypted envelopes for session history (#5204) (bb7cd2e)
- migrate Vercel sandboxes to the owned provider client (#5255) (9706013)
- normalize nullable Chat Completions token counts (#5238) (1ac6d82)
- normalize nullable token counts in remaining provider paths (#5260) (1c5c275)
- preserve completed tool results when resuming approvals (#5240) (872e2d6)
- preserve function tool Annotated constraints (#5212) (ee9a12a)
- preserve SDK error metadata after late tool timeouts (#5194) (160ed62)
- preserve streamed cancellation and pending guardrail cleanup (#5224) (0d6b741)
- realtime: bound incoming WebSocket message size by default (#5102) (5a80698)
- realtime: end event iteration when session close starts (#5172) (f9108bd)
- realtime: enforce Realtime tool output guardrails (#5127) (518b1f2)
- realtime: name the agent whose turn ended in agent_end (#5073) (49660c5)
- realtime: preserve heard audio during later responses (#5193) (86a13db)
- realtime: redact exception details from Realtime tool error events (#5132) (a58d03c)
- realtime: reset per-connection state on close (#5069) (a34b396)
- redis: validate session keys before clearing (#5202) (b3d5c1d)
- refresh encrypted session visibility before compaction (#5209) (92a2c60)
- reject ambiguous canonical Docker removal paths (#5221) (0da7889)
- reject premature Chat Completions stream EOF (#5211) (220e307)
- responses: preserve terminal errors through stream cleanup (#5187) (2b0361d)
- sandbox: add opt-in bounded workspace outbox reads (#5128) (465860b)
- sandbox: bootstrap Docker workspace before removal binding (#5210) (f162205)
- sandbox: check sandbox apply_patch approval scope (#5146) (d303ce8)
- sandbox: enforce grants during recursive removal (#5206) (2f8c9ac)
- sandbox: keep UnixLocal workspace-root removal off the event loop (#4941) (c467732)
- sandbox: limit Darwin host PATH read grants to the child environment (#5139) (9316424)
- sandbox: make Docker persist_workspace archives restorable by hydrate_workspace (#4834) (6492137)
- sandbox: normalize UnixLocal snapshot special files and symlinks (#4831) (08e5c43)
- sandbox: preserve multiline skill frontmatter descriptions (#5098) (9415f7e)
- sandbox: preserve nested paths in workspace snapshots (#5189) (61e98ab)
- sandbox: preserve symlink targets during snapshot restore (#5208) (00e2aa4)
- sandbox: preserve UnixLocal hardlink snapshots and validate before clearing (#5188) (99f8d77)
- sandbox: reject host sources in dictionary sandbox manifests (#5100) (a4fe85c)
- sandbox: reject privileged storage with read-only host grants (#5117) (c641e39)
- sandbox: reject special files in shared UnixLocal file I/O (#5177) (848ba47)
- sandbox: scope exclusive Add File creation to UnixLocal (#4893) (ec8e836)
- sandbox: validate host grants against normalized workspace roots (#5099) (91f5cfd)
- schema: decode URI fragments before pointer traversal (#5272) (b64cad4)
- sessions: accept namespaced compaction model names (#5225) (360d726)
- sessions: add an optional compaction rollback item budget (#5137) (a264757)
- sessions: close SQLiteSession connections owned by exited worker threads (#5090) (0b6fcd8)
- sessions: match literal Unicode content in AdvancedSQLiteSession (#5143) (581863a)
- sessions: recover fresh streamed handoffs after session append failures (#4835) (cd437f0)
- sessions: recover handoffs after cancelled compaction (#5197) (802cc03)
- sessions: reject blank SQLite branch names (#5179) (588826c)
- sessions: reset compaction response chain on clear_session (#5000) (525cd20)
- sessions: strip output-only metadata from compaction replay (#5196) (5cdcf84)
- summarize verbose connector output (#5203) (8575b93)
- tests: restore any_llm_model in sys.modules after stubbed imports (#5049) (65a9921)
- tracing: keep the export batch when an item has values that aren't JSON serializable (#4984) (74461d0)
- tracing: omit reasoning from default trace exports (#5108) (de0aa85)
- tracing: preserve exporter overrides during shutdown (#5199) (4658a0e)
- tracing: retry rate-limited trace exports (Fixes #5023) (#5052) (06298d5)
- use gpt-transcribe as the default voice STT model (#5276) (430da63)
- voice: finish streamed transcription on end of input (#5195) (c42f3c6)
- voice: finish transcription iterators when sessions close during setup (#4995) (60ed116)
- voice: honor pipeline tracing opt-out inside caller traces (#5120) (76547e5)
- voice: preserve legacy positional config arguments (#5198) (5813d84)
- voice: raise the builtin TimeoutError from _wait_for_event on 3.10 (#5075) (079b844)
- voice: stop forcing the STT session logging header (#5114) (7fce7f6)