diff --git a/.release-please-manifest.json b/.release-please-manifest.json index 5512d1466..043afdf6b 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,6 +1,6 @@ { - ".": "1.5.0", - "core": "1.5.0", - "dev": "1.5.0", - "integrations": "1.5.0" + ".": "1.6.0", + "core": "1.6.0", + "dev": "1.6.0", + "integrations": "1.6.0" } diff --git a/core/CHANGELOG.md b/core/CHANGELOG.md index 4e5bf22bd..b125d8330 100644 --- a/core/CHANGELOG.md +++ b/core/CHANGELOG.md @@ -1,5 +1,38 @@ # Changelog +## [1.6.0](https://github.com/google/adk-js/compare/adk-v1.5.0...adk-v1.6.0) (2026-08-05) + + +### Features + +* Add bearerTokenUserBuilder for A2A authentication (Part 1/2) ([#562](https://github.com/google/adk-js/issues/562)) ([f077722](https://github.com/google/adk-js/commit/f077722d54528c609c95fed51019fc013093a8e5)) +* CLI-level A2A authenticator for the dev server and Cloud Run deploy (Part 2/2) ([#559](https://github.com/google/adk-js/issues/559)) ([0c0bba2](https://github.com/google/adk-js/commit/0c0bba2cc4639ff89e4fa517ace25e34babb64b0)) +* Support ttl and expireTime session-expiration options in VertexAiSessionService.createSession ([#561](https://github.com/google/adk-js/issues/561)) ([b390217](https://github.com/google/adk-js/commit/b390217e65dc69af85373a8eac79f0bc3baae165)) +* **tools:** add getUserChoiceTool and requestInputTool for parity with adk-python ([#506](https://github.com/google/adk-js/issues/506)) ([03abf76](https://github.com/google/adk-js/commit/03abf761e97ef2c2902e776886b1a8d2a653a527)) +* Validate tool callback response types and prevent state event pollution ([#505](https://github.com/google/adk-js/issues/505)) ([b99f21b](https://github.com/google/adk-js/commit/b99f21b8a549d9b4e1255ae4233d9f691eeb9fe3)) + + +### Bug Fixes + +* **a2a:** stop restoring event branch from A2A peer metadata ([#606](https://github.com/google/adk-js/issues/606)) ([0000925](https://github.com/google/adk-js/commit/00009258373f8adc213171cf664dee2a21c19417)) +* accept the derived allowedTools alias in skill frontmatter validation ([#560](https://github.com/google/adk-js/issues/560)) ([fcfd043](https://github.com/google/adk-js/commit/fcfd04363ebbbea03e7a7c32d11f05358fdb4a4e)) +* **artifacts:** isolate in-memory composite keys ([#576](https://github.com/google/adk-js/issues/576)) ([693a1d7](https://github.com/google/adk-js/commit/693a1d7959f68a7e578312c5c88d9ad70c283cd1)) +* **core:** fall back to node:crypto so randomUUID cannot throw on Node ([#599](https://github.com/google/adk-js/issues/599)) ([3dc1b20](https://github.com/google/adk-js/commit/3dc1b2012cac86dbed249e0b3d17e16f1d0bd791)) +* **core:** use a cryptographically secure source for randomUUID ([#577](https://github.com/google/adk-js/issues/577)) ([81bcc8d](https://github.com/google/adk-js/commit/81bcc8dd4784d1d94e64b599f9d092a99333539d)) +* detect PowerShell 7+ (pwsh) in the UnsafeLocalCodeExecutor SHELL branch ([#568](https://github.com/google/adk-js/issues/568)) ([ce0e474](https://github.com/google/adk-js/commit/ce0e474bb5ab931894bf379588e357617ce0b5a1)) +* fail fast when a Vertex AI Express Mode API key cannot be used ([#563](https://github.com/google/adk-js/issues/563)) ([e1112c6](https://github.com/google/adk-js/commit/e1112c6df905853ad99d84f6490d12e4dbbbfd22)) +* gate the set_model_response workaround on canUseOutputSchemaWithTools (adk-python parity) ([#580](https://github.com/google/adk-js/issues/580)) ([5b65ee1](https://github.com/google/adk-js/commit/5b65ee109083002263f1e30593035e9778add996)) +* parse JSON bodies only in the toA2a server (drop express.urlencoded) ([#558](https://github.com/google/adk-js/issues/558)) ([605b469](https://github.com/google/adk-js/commit/605b46980cabd2a8928e08d3fc3669a1de13c24c)) +* pass -NoProfile to spawned PowerShell and /D to cmd.exe in UnsafeLocalCodeExecutor ([#566](https://github.com/google/adk-js/issues/566)) ([b56761b](https://github.com/google/adk-js/commit/b56761bfb0d9b0d139cc95ba1a6d1803732507dd)) +* reject zip-slip entries and non-bare skill names when loading zipped skills (adk-python parity) ([#584](https://github.com/google/adk-js/issues/584)) ([4fe80b0](https://github.com/google/adk-js/commit/4fe80b0ef7e5df1803c76e8681cd9740fcf6ebf5)) +* **runner:** persist events returned by onEventCallback ([#575](https://github.com/google/adk-js/issues/575)) ([c4c5582](https://github.com/google/adk-js/commit/c4c55829394cb4f15fa13f54235a9a77c5417e54)) +* **security:** prevent prototype pollution via untrusted map keys ([#619](https://github.com/google/adk-js/issues/619)) ([2c07ad3](https://github.com/google/adk-js/commit/2c07ad3741cd84788d0b30a793587d5dd4b46106)) +* surface root-cause MCP session errors instead of swallowing them ([#527](https://github.com/google/adk-js/issues/527)) ([13d7304](https://github.com/google/adk-js/commit/13d7304a0611fe8f1dc00a2e5de9dc3ac4d63943)) +* treat @google/genai ApiError 404 as session not found in VertexAiSessionService ([#567](https://github.com/google/adk-js/issues/567)) ([5331c77](https://github.com/google/adk-js/commit/5331c771cde1c3af8ef1d87e44d41161c9919721)) +* unsafe A2A peer-supplied transferToAgent metadata ([#596](https://github.com/google/adk-js/issues/596)) ([d3f250e](https://github.com/google/adk-js/commit/d3f250e876d0a76f4d09b3439e84e7dbd1fc32ec)) +* **utils:** fix sibling-directory escape in materializeFiles path check ([#603](https://github.com/google/adk-js/issues/603)) ([868ca1f](https://github.com/google/adk-js/commit/868ca1f373a175c7fe2c788b167f05a58e6eed2e)) +* zip-slip blacklist bypass in isDangerousZipEntryName ([#621](https://github.com/google/adk-js/issues/621)) ([7bc05f6](https://github.com/google/adk-js/commit/7bc05f6156e3e121663acee2c6476e953a626b61)) + ## [1.5.0](https://github.com/google/adk-js/compare/adk-v1.4.0...adk-v1.5.0) (2026-07-29) diff --git a/core/package.json b/core/package.json index 678f8c0c9..4dde99c49 100644 --- a/core/package.json +++ b/core/package.json @@ -1,6 +1,6 @@ { "name": "@google/adk", - "version": "1.5.0", + "version": "1.6.0", "description": "Google ADK JS", "author": "Google", "license": "Apache-2.0", diff --git a/core/src/version.ts b/core/src/version.ts index 011010f66..d7f305136 100644 --- a/core/src/version.ts +++ b/core/src/version.ts @@ -5,4 +5,4 @@ */ // version: major.minor.patch -export const version = '1.5.0'; // x-release-please-version +export const version = '1.6.0'; // x-release-please-version diff --git a/dev/CHANGELOG.md b/dev/CHANGELOG.md index 8d5ef704f..1e82e30b1 100644 --- a/dev/CHANGELOG.md +++ b/dev/CHANGELOG.md @@ -1,5 +1,29 @@ # Changelog +## [1.6.0](https://github.com/google/adk-js/compare/devtools-v1.5.0...devtools-v1.6.0) (2026-08-05) + + +### Features + +* CLI-level A2A authenticator for the dev server and Cloud Run deploy (Part 2/2) ([#559](https://github.com/google/adk-js/issues/559)) ([0c0bba2](https://github.com/google/adk-js/commit/0c0bba2cc4639ff89e4fa517ace25e34babb64b0)) + + +### Bug Fixes + +* **cli:** check isCancel before coercing the project prompt in adk create ([#570](https://github.com/google/adk-js/issues/570)) ([c6f8b2f](https://github.com/google/adk-js/commit/c6f8b2f7482ab18a66d1b0c726e4b524802d2b8b)) +* **cli:** make the getting-started path actually work ([#624](https://github.com/google/adk-js/issues/624)) ([6ea645c](https://github.com/google/adk-js/commit/6ea645cab6c2b20fe91f054cbe2f08beffb3dfb9)) +* create dev-package temp directories atomically with mkdtemp (no predictable parent) ([#615](https://github.com/google/adk-js/issues/615)) ([81c1422](https://github.com/google/adk-js/commit/81c1422268f1295d7ae99e05a7d74cc51682362f)) +* **deploy:** reject unsafe appName/project/region in generated Dockerfile ([#604](https://github.com/google/adk-js/issues/604)) ([dadce1a](https://github.com/google/adk-js/commit/dadce1a1169a56b73e0d152b8c8d584b5b52b7c7)) +* make streaming and stateDelta optional on RunAgentRequest ([#585](https://github.com/google/adk-js/issues/585)) ([1df47e9](https://github.com/google/adk-js/commit/1df47e9733e0f2b0aac1bcbda24b7f1a8ae73d9b)) +* **security:** prevent prototype pollution via untrusted map keys ([#619](https://github.com/google/adk-js/issues/619)) ([2c07ad3](https://github.com/google/adk-js/commit/2c07ad3741cd84788d0b30a793587d5dd4b46106)) + + +### Dependencies + +* The following workspace dependencies were updated + * dependencies + * @google/adk bumped from ^1.5.0 to ^1.6.0 + ## [1.5.0](https://github.com/google/adk-js/compare/devtools-v1.4.0...devtools-v1.5.0) (2026-07-29) diff --git a/dev/package.json b/dev/package.json index 6117df13a..11c448224 100644 --- a/dev/package.json +++ b/dev/package.json @@ -1,6 +1,6 @@ { "name": "@google/adk-devtools", - "version": "1.5.0", + "version": "1.6.0", "description": "Google ADK JS Development Tools", "author": "Google", "license": "Apache-2.0", @@ -55,7 +55,7 @@ }, "dependencies": { "@clack/prompts": "^0.11.0", - "@google/adk": "^1.5.0", + "@google/adk": "^1.6.0", "@mikro-orm/mariadb": "^6.6.6", "@mikro-orm/mssql": "^6.6.6", "@mikro-orm/mysql": "^6.6.6", diff --git a/dev/src/version.ts b/dev/src/version.ts index 011010f66..d7f305136 100644 --- a/dev/src/version.ts +++ b/dev/src/version.ts @@ -5,4 +5,4 @@ */ // version: major.minor.patch -export const version = '1.5.0'; // x-release-please-version +export const version = '1.6.0'; // x-release-please-version diff --git a/integrations/CHANGELOG.md b/integrations/CHANGELOG.md index 7b35e8f9b..e4c798025 100644 --- a/integrations/CHANGELOG.md +++ b/integrations/CHANGELOG.md @@ -1,5 +1,19 @@ # Changelog +## [1.6.0](https://github.com/google/adk-js/compare/integrations-v1.5.0...integrations-v1.6.0) (2026-08-05) + + +### Miscellaneous Chores + +* **integrations:** Synchronize adk versions + + +### Dependencies + +* The following workspace dependencies were updated + * dependencies + * @google/adk bumped from ^1.5.0 to ^1.6.0 + ## [1.5.0](https://github.com/google/adk-js/compare/integrations-v1.4.0...integrations-v1.5.0) (2026-07-29) diff --git a/integrations/package.json b/integrations/package.json index b7c467b4c..249a4e5b6 100644 --- a/integrations/package.json +++ b/integrations/package.json @@ -1,6 +1,6 @@ { "name": "@google/adk-integrations", - "version": "1.5.0", + "version": "1.6.0", "description": "Google ADK JS Integrations", "author": "Google", "license": "Apache-2.0", @@ -40,6 +40,6 @@ "prepublishOnly": "npm run build" }, "dependencies": { - "@google/adk": "^1.5.0" + "@google/adk": "^1.6.0" } } diff --git a/integrations/src/version.ts b/integrations/src/version.ts index b17ce86a7..8d323204d 100644 --- a/integrations/src/version.ts +++ b/integrations/src/version.ts @@ -5,4 +5,4 @@ */ // version: major.minor.patch -export const version = '1.5.0'; // x-release-please-version +export const version = '1.6.0'; // x-release-please-version diff --git a/package-lock.json b/package-lock.json index e29a4a190..5f83f3847 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "adk", - "version": "1.5.0", + "version": "1.6.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "adk", - "version": "1.5.0", + "version": "1.6.0", "license": "Apache-2.0", "workspaces": [ "core", @@ -41,7 +41,7 @@ }, "core": { "name": "@google/adk", - "version": "1.5.0", + "version": "1.6.0", "license": "Apache-2.0", "dependencies": { "@a2a-js/sdk": "^0.3.10", @@ -91,11 +91,11 @@ }, "dev": { "name": "@google/adk-devtools", - "version": "1.5.0", + "version": "1.6.0", "license": "Apache-2.0", "dependencies": { "@clack/prompts": "^0.11.0", - "@google/adk": "^1.5.0", + "@google/adk": "^1.6.0", "@mikro-orm/mariadb": "^6.6.6", "@mikro-orm/mssql": "^6.6.6", "@mikro-orm/mysql": "^6.6.6", @@ -331,10 +331,10 @@ }, "integrations": { "name": "@google/adk-integrations", - "version": "1.5.0", + "version": "1.6.0", "license": "Apache-2.0", "dependencies": { - "@google/adk": "^1.5.0" + "@google/adk": "^1.6.0" } }, "node_modules/@a2a-js/sdk": { diff --git a/package.json b/package.json index 36cc0d747..4087b6b3f 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "adk", - "version": "1.5.0", + "version": "1.6.0", "description": "Google ADK JS", "author": "Google", "license": "Apache-2.0",