Skip to content

📦 chore: npm audit & bump @librechat/agents to v3.1.67 - #12710

Merged
danny-avila merged 4 commits into
devfrom
chore/update-packages-2026-04-16
Apr 17, 2026
Merged

danny-avila merged 4 commits into
devfrom
chore/update-packages-2026-04-16

Conversation

@danny-avila

@danny-avila danny-avila commented Apr 17, 2026 •

Copy link
Copy Markdown
Collaborator

v3.1.67

🔍 Fix: Deferred tools no longer inflate instruction token accounting

PR: #105 | Ref: LibreChat#12702

Deferred tool definitions (tools registered for tool_search with defer_loading: true) were counted in both toolSchemaTokens and getTokenBudgetBreakdown().toolCount even though they are never bound to the model until discovered at runtime. For large MCP registries (e.g. 292 tools), this inflated the reported instruction overhead enough to trigger spurious context-overflow errors.

A new getActiveToolDefinitions() private helper now filters out defer_loading === true entries that have not yet appeared in discoveredToolNames. Both calculateInstructionTokens() and getTokenBudgetBreakdown() route through it, matching the existing bind-time filter in getEventDrivenToolsForBinding().

Before: All registered tool definitions, including hundreds of deferred ones, were counted in the token budget. Agents with large tool catalogs could fail to invoke with "context overflow" before sending a single message.

After: Only active (non-deferred or already-discovered) tools consume token budget. toolCount updates live after markToolsAsDiscovered(), while toolSchemaTokens remains a snapshot from the last calculateInstructionTokens() call. A regression test pins this snapshot semantic.


🧠 Fix: Widen AnthropicClientOptions['thinking'] for Claude Opus 4.7 adaptive display

PR: #106

Claude Opus 4.7 omits reasoning content by default unless the caller opts in via thinking.display = 'summarized'. Downstream consumers (e.g. LibreChat's Anthropic helpers) previously had to use unsafe casts to pass { type: 'adaptive', display: 'summarized' } because the ThinkingConfig type only accepted the upstream AnthropicInput['thinking'] shape.

A new ThinkingConfigAdaptive variant is added ({ type: 'adaptive'; display?: 'summarized' | 'omitted' }), and AnthropicClientOptions now overrides the thinking property via Omit<AnthropicInput, 'thinking'> so it accepts either the standard config or the adaptive variant without casting.

Before: Passing display: 'summarized' required as unknown as ... casts.
After: The type accepts the adaptive display field natively.


📦 Chore: npm audit fix

Patch-level dependency updates in package-lock.json to resolve npm audit advisories. No functional changes.


Full Changelog: LibreChat-AI/agents@v3.1.65...v3.1.67

…rades

- Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser.
- Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions.
- Enhanced integrity checks and licensing information for new and updated packages.
…ge.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes.
….4.0 and 5.6.0 respectively

- Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes.
- Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality.
…ge.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
Copilot AI review requested due to automatic review settings April 17, 2026 02:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Dependency maintenance PR to address npm audit findings and update @librechat/agents, along with related resolution/lockfile updates in this monorepo.

Changes:

  • Bump dompurify to ^3.4.0 across client packages and enforce it for monaco-editor via root overrides.
  • Bump @librechat/agents to ^3.1.67 in both API workspace package manifests.
  • Update root overrides for fast-xml-parser (and update the root lockfile to reflect the new resolved dependency graph).

Reviewed changes

Copilot reviewed 5 out of 6 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
packages/client/package.json Bumps dompurify dependency.
client/package.json Bumps dompurify dependency.
packages/api/package.json Bumps @librechat/agents version.
api/package.json Bumps @librechat/agents version.
package.json Updates overrides (notably fast-xml-parser and monaco-editor → dompurify).
package-lock.json Updates resolved dependency tree for the audit/bumps (agents, dompurify, opentelemetry, protobufjs, etc.).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread package.json
@danny-avila danny-avila changed the title 📦 chore: npm audit & bump @librechat/agents 📦 chore: npm audit & bump @librechat/agents to v3.1.67 Apr 17, 2026
@danny-avila
danny-avila merged commit b579390 into dev Apr 17, 2026
19 checks passed
@danny-avila
danny-avila deleted the chore/update-packages-2026-04-16 branch April 17, 2026 02:44
@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-12710 index is now live on the MCP server.
Deploy run

krgokul pushed a commit to syedhabib39/LibreChat that referenced this pull request Apr 20, 2026
…I#12710)

* chore: Update package-lock.json with new dependencies and version upgrades

- Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser.
- Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions.
- Enhanced integrity checks and licensing information for new and updated packages.

* chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes.

* chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively

- Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes.
- Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality.

* chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
krgokul pushed a commit to syedhabib39/LibreChat that referenced this pull request Apr 21, 2026
…I#12710)

* chore: Update package-lock.json with new dependencies and version upgrades

- Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser.
- Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions.
- Enhanced integrity checks and licensing information for new and updated packages.

* chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes.

* chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively

- Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes.
- Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality.

* chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
jcbartle pushed a commit to jcbartle/LibreChat that referenced this pull request May 11, 2026
…I#12710)

* chore: Update package-lock.json with new dependencies and version upgrades

- Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser.
- Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions.
- Enhanced integrity checks and licensing information for new and updated packages.

* chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes.

* chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively

- Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes.
- Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality.

* chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
ThomasVuNguyen pushed a commit to ThomasVuNguyen/LibreChat that referenced this pull request Jul 15, 2026
…I#12710)

* chore: Update package-lock.json with new dependencies and version upgrades

- Added new dependencies for @langchain/anthropic and @langchain/core, including @anthropic-ai/sdk and fast-xml-parser.
- Updated existing dependencies for @librechat/agents, @opentelemetry/api-logs, @opentelemetry/core, and related packages to their latest versions.
- Enhanced integrity checks and licensing information for new and updated packages.

* chore: Update @librechat/agents dependency to version 3.1.66 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.65 to 3.1.66 across multiple package.json files to ensure consistency and access to the latest features and fixes.

* chore: Update dompurify and fast-xml-parser dependencies to version 3.4.0 and 5.6.0 respectively

- Bumped the version of dompurify across multiple package.json files to ensure consistency and access to the latest features and security fixes.
- Updated fast-xml-parser to the latest version in relevant package.json files for improved functionality.

* chore: Update @librechat/agents dependency to version 3.1.67 in package.json and package-lock.json

- Bumped the version of @librechat/agents from 3.1.66 to 3.1.67 across multiple package.json files to ensure consistency and access to the latest features and fixes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants