📦 chore: npm audit & bump @librechat/agents to v3.1.67 - #12710
Merged
Merged
Conversation
…rades - Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser. - Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions. - Enhanced integrity checks and licensing information for new and updated packages.
…ge.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes.
….4.0 and 5.6.0 respectively - Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes. - Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality.
…ge.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
Contributor
There was a problem hiding this comment.
Pull request overview
Dependency maintenance PR to address npm audit findings and update @librechat/agents, along with related resolution/lockfile updates in this monorepo.
Changes:
- Bump
dompurifyto^3.4.0across client packages and enforce it formonaco-editorvia root overrides. - Bump
@librechat/agentsto^3.1.67in both API workspace package manifests. - Update root overrides for
fast-xml-parser(and update the root lockfile to reflect the new resolved dependency graph).
Reviewed changes
Copilot reviewed 5 out of 6 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| packages/client/package.json | Bumps dompurify dependency. |
| client/package.json | Bumps dompurify dependency. |
| packages/api/package.json | Bumps @librechat/agents version. |
| api/package.json | Bumps @librechat/agents version. |
| package.json | Updates overrides (notably fast-xml-parser and monaco-editor → dompurify). |
| package-lock.json | Updates resolved dependency tree for the audit/bumps (agents, dompurify, opentelemetry, protobufjs, etc.). |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
@librechat/agents@librechat/agents to v3.1.67
Contributor
GitNexus: 🚀 deployedThe |
krgokul
pushed a commit
to syedhabib39/LibreChat
that referenced
this pull request
Apr 20, 2026
…I#12710) * chore: Update package-lock.json with new dependencies and version upgrades - Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser. - Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions. - Enhanced integrity checks and licensing information for new and updated packages. * chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes. * chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively - Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes. - Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality. * chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
krgokul
pushed a commit
to syedhabib39/LibreChat
that referenced
this pull request
Apr 21, 2026
…I#12710) * chore: Update package-lock.json with new dependencies and version upgrades - Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser. - Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions. - Enhanced integrity checks and licensing information for new and updated packages. * chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes. * chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively - Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes. - Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality. * chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
jcbartle
pushed a commit
to jcbartle/LibreChat
that referenced
this pull request
May 11, 2026
…I#12710) * chore: Update package-lock.json with new dependencies and version upgrades - Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser. - Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions. - Enhanced integrity checks and licensing information for new and updated packages. * chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes. * chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively - Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes. - Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality. * chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
ThomasVuNguyen
pushed a commit
to ThomasVuNguyen/LibreChat
that referenced
this pull request
Jul 15, 2026
…I#12710) * chore: Update package-lock.json with new dependencies and version upgrades - Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser. - Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions. - Enhanced integrity checks and licensing information for new and updated packages. * chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes. * chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively - Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes. - Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality. * chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json - Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
v3.1.67
🔍 Fix: Deferred tools no longer inflate instruction token accounting
PR: #105 | Ref: LibreChat#12702
Deferred tool definitions (tools registered for
tool_searchwithdefer_loading: true) were counted in bothtoolSchemaTokensandgetTokenBudgetBreakdown().toolCounteven though they are never bound to the model until discovered at runtime. For large MCP registries (e.g. 292 tools), this inflated the reported instruction overhead enough to trigger spurious context-overflow errors.A new
getActiveToolDefinitions()private helper now filters outdefer_loading === trueentries that have not yet appeared indiscoveredToolNames. BothcalculateInstructionTokens()andgetTokenBudgetBreakdown()route through it, matching the existing bind-time filter ingetEventDrivenToolsForBinding().Before: All registered tool definitions, including hundreds of deferred ones, were counted in the token budget. Agents with large tool catalogs could fail to invoke with "context overflow" before sending a single message.
After: Only active (non-deferred or already-discovered) tools consume token budget.
toolCountupdates live aftermarkToolsAsDiscovered(), whiletoolSchemaTokensremains a snapshot from the lastcalculateInstructionTokens()call. A regression test pins this snapshot semantic.🧠 Fix: Widen
AnthropicClientOptions['thinking']for Claude Opus 4.7 adaptive displayPR: #106
Claude Opus 4.7 omits reasoning content by default unless the caller opts in via
thinking.display = 'summarized'. Downstream consumers (e.g. LibreChat's Anthropic helpers) previously had to use unsafe casts to pass{ type: 'adaptive', display: 'summarized' }because theThinkingConfigtype only accepted the upstreamAnthropicInput['thinking']shape.A new
ThinkingConfigAdaptivevariant is added ({ type: 'adaptive'; display?: 'summarized' | 'omitted' }), andAnthropicClientOptionsnow overrides thethinkingproperty viaOmit<AnthropicInput, 'thinking'>so it accepts either the standard config or the adaptive variant without casting.Before: Passing
display: 'summarized'requiredas unknown as ...casts.After: The type accepts the adaptive display field natively.
📦 Chore: npm audit fix
Patch-level dependency updates in
package-lock.jsonto resolvenpm auditadvisories. No functional changes.Full Changelog: LibreChat-AI/agents@v3.1.65...v3.1.67