Download Latest Version v1.1.2 source code.zip (3.8 MB) Google Add to Preferred Sources
Home / v1.1.1
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-29 5.3 kB
v1.1.1 source code.tar.gz 2026-09-29 2.8 MB
v1.1.1 source code.zip 2026-09-29 3.6 MB
Totals: 3 Items   6.4 MB 5

v1.1.1

Breaking: Bedrock runs on aiobotocore

BedrockConfig now uses a native async client (aiobotocore) instead of wrapping synchronous boto3 in a thread per call and per streamed event. Every Converse request is also type-checked against the service's own stubs.

  • BedrockConfig(session=...) takes an aiobotocore.session.AioSession. A boto3.Session fails on the first call with AttributeError: 'Session' object has no attribute 'create_client'.
  • The bedrock extra installs aiobotocore>=3.9.1,<4 instead of boto3. If your application also installs boto3, pick a version whose botocore fits aiobotocore's pin.
  • Explicit keys and region_name passed together with session= now apply. They used to be silently ignored.

    :::python from aiobotocore.session import AioSession

    config = BedrockConfig(model=MODEL_ID, session=AioSession(profile="prod"))

Security

Restricted shell mode runs commands without a shell. With allowed=[...] or readonly=True, SandboxShellTool / ShellAdapter split the command into argv once, check that argv, and run exactly it. Nothing can expand after the check, so separators, substitutions and brace expansion can no longer smuggle a second command past the allow-list. Consequences:

  • Pipes, redirects, chaining, globs, ~ and variables are not available in restricted mode. Shell syntax is refused with a clear error, and globs reach the program literally.
  • readonly=True only allows commands that cannot write files or run other programs. find, file, sort, uniq and git … are no longer in the built-in set; list the ones you need in allowed.
  • blocked=[...] is unchanged and remains best-effort. It is not a security boundary.

    :::python shell = SandboxShellTool(LocalEnvironment("/repo"), allowed=["cat", "ls", "grep", "git log"])

Tools that share a name resolve to exactly one tool. A model call used to reach every tool with that name, so an approval decision on one did not bind its twin. Now each turn exposes one tool per name:

  • Tools declared in code override each other by order, and the later one wins. Agent(tools=[toolkit, my_deploy]) replaces the toolkit's deploy.
  • Tools discovered at runtime (MCP) and client tools rank below code-declared ones. An MCP server can no longer shadow a local tool; a colliding MCP tool is dropped with a warning suggesting tool_name_prefix.
  • Approval grants are keyed by tool implementation.

Redis pickle serializer. The docs now state that Serializer.PICKLE gives code execution to anyone who can write to the stream's Redis, so use it only with a fully trusted Redis instance. JSON remains the default.

Also in this release

  • Human input over AG-UI. A tool in a served agent can call context.input(). The question reaches the AG-UI client as the run's interrupt outcome, and the answer comes back in the next run's resume.
  • MCP conversations survive long turns. SessionStore idle expiry and LRU overflow no longer drop a conversation while a turn is running on it. Thanks to @simpleqt for finding and first fixing this.
  • One Authorization header. MCPToolkit and MCPServerTool send exactly one Authorization header on every provider, whatever the casing of an explicit header next to authorization_token.
  • Network fixes. delegate() closes its channel when the first message fails to send, and the context() tool rejects non-positive limit / recent_n.

What's Changed

Full Changelog: https://github.com/ag2ai/ag2/compare/v1.1.0...v1.1.1

Source: README.md, updated 2026-09-29