Skip to content

release: 0.23.0 - #5226

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Automated release PR. Before merging, regenerate tests/fixtures/released_api_contract.json, review the release notes, and run the required checks. See .github/RELEASING.md. Tags and GitHub Releases are published manually.

0.23.0 (2026-09-28)

Features

  • mcp: add configurable MCP listing page limits (#5133) (9a21ab1)
  • sandbox: add opt-in Docker removal protection (#5116) (ae5803f)
  • sandbox: allow configuring memory consolidation turns (#5135) (daa1bcb)
  • sessions: add an opt-in encrypted history scan budget (#5118) (a2fdb94)

Bug Fixes

  • avoid awaiting cleanup during coroutine closure (#5163) (719c4e7)
  • ci: validate release source before building distributions (#5220) (2747c1c)
  • core/extensions: respect sensitive trace capture for model metadata (#5129) (88b722d)
  • core: bound agent tool streaming callback backlogs (#5106) (f23da76)
  • core: isolate nested agent tool state across fresh runs (#5123) (46cc8d8)
  • core: preserve closed parent constraints in singleton allOf (#5131) (f010d18)
  • core: preserve guarded final outputs in agent tools (#5115) (f3a15f6)
  • core: preserve structured guardrail diagnostics and agent output during persistence (#5016) (51bcea7)
  • core: preserve tool identity during asynchronous enablement (#5136) (f2ae64c)
  • core: redact default tool failure details (#5112) (40956e0)
  • core: redact streaming task exception tracebacks (#5121) (c329e92)
  • core: reject silently discarded kwargs tool arguments (#5174) (a9b1ce7)
  • core: resolve tools after agent start hooks (#5124) (5237420)
  • core: restore nested agent tool state against the tool's own agent (#5142) (ad93f54)
  • core: retry pre-request WebSocket handshake failures (#4780) (265f16f)
  • core: scope function tool approvals to their owning agent (#5144) (de25d82)
  • core: select built-in shell and apply_patch tools by their own type (#4952) (eb68131)
  • core: serialize only traced fields in ModelSettings.to_traceable_dict (#5003) (57f0b38)
  • core: validate agent tool stream callbacks before execution (#5125) (fae72a4)
  • core: validate tool_use_behavior callback results (#5173) (5a2d63f)
  • deps-dev: bump coverage from 7.10.3 to 7.16.1 (#5152) (47c21ee)
  • deps-dev: bump dapr from 1.16.0 to 1.18.3 (#5154) (e94309d)
  • deps-dev: bump pymongo from 4.16.0 to 4.18.1 (#5155) (971c5f3)
  • deps: bump anyio from 4.10.0 to 4.14.2 (#5091) (0910b46)
  • deps: bump cbor2 from 5.9.0 to 6.1.4 (#5153) (34952bc)
  • deps: bump runloop-api-client from 1.31.0 to 1.32.0 (#5156) (32edd3c)
  • deps: update httpx2 requirement from >=2.12.0 to >=2.13.0 in /examples/realtime/twilio (#5147) (153b3f1)
  • deps: update httpx2 requirement from >=2.12.0 to >=2.13.0 in /examples/realtime/twilio_sip (#5151) (a62e594)
  • deps: update pyjwt requirement from >=2.13.0 to >=2.14.0 in /examples/realtime/twilio (#5149) (5ed5727)
  • deps: update twilio requirement from <10,>=9 to >=9.11.1,<10 in /examples/realtime/twilio (#5148) (59d860f)
  • deps: update uvicorn requirement from >=0.52.4 to >=0.53.0 in /examples/realtime/twilio_sip (#5150) (04e699f)
  • discard previous stream event aliases on model timeout (#5216) (de3b1d7)
  • escape terminal controls in result diagnostics (#5219) (e80737c)
  • examples: keep realtime debug error summaries payload-free (#5200) (e7d7097)
  • examples: keep Redis connection details out of diagnostics (#5205) (c2321d2)
  • examples: prevent auto-running the local Temporal shell workflow (#5218) (5b50815)
  • examples: restrict the Realtime demo to local bounded sessions (#5111) (4adad5e)
  • extensions: close owned event streams when runs fail (#5060) (d5abd9f)
  • extensions: honor run tracing policy in Codex command spans (#5138) (78e5b4d)
  • extensions: keep SQLite usage capture off the event loop (#4981) (8e338e5)
  • extensions: keep the current branch when a forced delete_branch fails (#5081) (165390c)
  • extensions: preserve filtered history during automatic compaction (#5103) (27625dd)
  • extensions: preserve subprocess errors for non-UTF8 stderr (#5186) (549fcee)
  • extensions: validate MongoDB session identifiers (#5104) (442469e)
  • isolate nested agent tool state across fresh runs (46cc8d8)
  • keep the file when apply_patch does a case-only rename (#4890) (71306bf)
  • mcp: bind resumed MCP calls to their original recipients (#5119) (bd91ae6)
  • mcp: escape duplicate tool names in diagnostics (#5217) (fc4d832)
  • mcp: keep the Streamable HTTP session usable after a 5xx (#5061) (29aa40b)
  • mcp: preserve cache invalidation during refresh (#4807) (5e7afe4)
  • mcp: stop swallowing worker task cancellation (#5055) (c4c04b6)
  • memory: preserve encrypted SQLite history on wrong-key pops (#5083) (0f87da2)
  • memory: reject blank SQLite branch names (588826c)
  • memory: require encrypted envelopes for session history (#5204) (bb7cd2e)
  • preserve function tool Annotated constraints (#5212) (ee9a12a)
  • preserve SDK error metadata after late tool timeouts (#5194) (160ed62)
  • preserve streamed cancellation and pending guardrail cleanup (#5224) (0d6b741)
  • realtime: bound incoming WebSocket message size by default (#5102) (5a80698)
  • realtime: end event iteration when session close starts (#5172) (f9108bd)
  • realtime: enforce Realtime tool output guardrails (#5127) (518b1f2)
  • realtime: name the agent whose turn ended in agent_end (#5073) (49660c5)
  • realtime: preserve heard audio during later responses (#5193) (86a13db)
  • realtime: redact exception details from Realtime tool error events (#5132) (a58d03c)
  • realtime: reset per-connection state on close (#5069) (a34b396)
  • redis: validate session keys before clearing (#5202) (b3d5c1d)
  • refresh encrypted session visibility before compaction (#5209) (92a2c60)
  • reject ambiguous canonical Docker removal paths (#5221) (0da7889)
  • reject host sources in dictionary sandbox manifests (a4fe85c)
  • reject premature Chat Completions stream EOF (#5211) (220e307)
  • Reject silently discarded kwargs tool arguments (a9b1ce7)
  • responses: preserve terminal errors through stream cleanup (#5187) (2b0361d)
  • sandbox: add opt-in bounded workspace outbox reads (#5128) (465860b)
  • sandbox: bootstrap Docker workspace before removal binding (#5210) (f162205)
  • sandbox: check sandbox apply_patch approval scope (#5146) (d303ce8)
  • sandbox: enforce grants during recursive removal (#5206) (2f8c9ac)
  • sandbox: keep UnixLocal workspace-root removal off the event loop (#4941) (c467732)
  • sandbox: limit Darwin host PATH read grants to the child environment (#5139) (9316424)
  • sandbox: make Docker persist_workspace archives restorable by hydrate_workspace (#4834) (6492137)
  • sandbox: normalize UnixLocal snapshot special files and symlinks (#4831) (08e5c43)
  • sandbox: preserve multiline skill frontmatter descriptions (#5098) (9415f7e)
  • sandbox: preserve nested paths in workspace snapshots (#5189) (61e98ab)
  • sandbox: preserve symlink targets during snapshot restore (#5208) (00e2aa4)
  • sandbox: preserve UnixLocal hardlink snapshots and validate before clearing (#5188) (99f8d77)
  • sandbox: reject host sources in dictionary sandbox manifests (#5100) (a4fe85c)
  • sandbox: reject privileged storage with read-only host grants (#5117) (c641e39)
  • sandbox: reject special files in shared UnixLocal file I/O (#5177) (848ba47)
  • sandbox: scope exclusive Add File creation to UnixLocal (#4893) (ec8e836)
  • sandbox: validate host grants against normalized workspace roots (#5099) (91f5cfd)
  • scope function tool approvals to their owning agent (de25d82)
  • sessions: accept namespaced compaction model names (#5225) (360d726)
  • sessions: add an optional compaction rollback item budget (#5137) (a264757)
  • sessions: close SQLiteSession connections owned by exited worker threads (#5090) (0b6fcd8)
  • sessions: match literal Unicode content in AdvancedSQLiteSession (#5143) (581863a)
  • sessions: recover fresh streamed handoffs after session append failures (#4835) (cd437f0)
  • sessions: recover handoffs after cancelled compaction (#5197) (802cc03)
  • sessions: reject blank SQLite branch names (#5179) (588826c)
  • sessions: reset compaction response chain on clear_session (#5000) (525cd20)
  • sessions: strip output-only metadata from compaction replay (#5196) (5cdcf84)
  • summarize verbose connector output (#5203) (8575b93)
  • tests: restore any_llm_model in sys.modules after stubbed imports (#5049) (65a9921)
  • tracing: keep the export batch when an item has values that aren't JSON serializable (#4984) (74461d0)
  • tracing: omit reasoning from default trace exports (#5108) (de0aa85)
  • tracing: preserve exporter overrides during shutdown (#5199) (4658a0e)
  • tracing: retry rate-limited trace exports (Fixes #5023) (#5052) (06298d5)
  • validate tool_use_behavior callback results (5a2d63f)
  • voice: finish streamed transcription on end of input (#5195) (c42f3c6)
  • voice: finish transcription iterators when sessions close during setup (#4995) (60ed116)
  • voice: honor pipeline tracing opt-out inside caller traces (#5120) (76547e5)
  • voice: preserve legacy positional config arguments (#5198) (5813d84)
  • voice: raise the builtin TimeoutError from _wait_for_event on 3.10 (#5075) (079b844)
  • voice: stop forcing the STT session logging header (#5114) (7fce7f6)

This PR was generated with Release Please. See documentation.

@jbeckwith-oai
jbeckwith-oai marked this pull request as ready for review September 28, 2026 18:18
@jbeckwith-oai
jbeckwith-oai requested review from a team, rm-openai and seratch as code owners September 28, 2026 18:18
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T18:21:04.289394Z f71c24c Draft marked ready
🔒 Security Review ✅ Completed 2026-09-28T18:20:57.461918Z f71c24c Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f71c24cbf5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml
[project]
name = "openai-agents"
version = "0.22.3"
version = "0.23.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate the released API contract for 0.23.0

When this release candidate is installed or checked in CI, the package reports version 0.23.0 while tests/fixtures/released_api_contract.json still declares v0.22.3. Consequently, test_released_api_contract_fixture_matches_installed_version and make check-released-api-contract VERSION=0.23.0 reject the candidate; bypassing those checks would also leave the new public API surface absent from the frozen 0.23.0 compatibility baseline. Regenerate and commit the fixture for this candidate before merging.

Useful? React with 👍 / 👎.

Comment thread CHANGELOG.md
* **extensions:** preserve filtered history during automatic compaction ([#5103](https://github.com/openai/openai-agents-python/issues/5103)) ([27625dd](https://github.com/openai/openai-agents-python/commit/27625dd2f4ca0faf64cb468da15a9c56d80452c9))
* **extensions:** preserve subprocess errors for non-UTF8 stderr ([#5186](https://github.com/openai/openai-agents-python/issues/5186)) ([549fcee](https://github.com/openai/openai-agents-python/commit/549fcee5e1ed919d5011136c1a6c48f9a681532a))
* **extensions:** validate MongoDB session identifiers ([#5104](https://github.com/openai/openai-agents-python/issues/5104)) ([442469e](https://github.com/openai/openai-agents-python/commit/442469e40d8e582d70daff3a38c40f68c4bf03d1))
* isolate nested agent tool state across fresh runs ([46cc8d8](https://github.com/openai/openai-agents-python/commit/46cc8d8d13cac3d641d9c159f20d0cb665aca4c7))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove duplicate changelog entries

When users read the 0.23.0 release notes, six fixes appear twice because conventional subjects from the commit bodies were emitted in addition to the scoped commit subjects: 46cc8d8, a9b1ce7, de25d82, 5a2d63f, 588826c, and a4fe85c each occur twice. This overstates the release contents and gives several changes conflicting scoped and unscoped descriptions, so deduplicate these entries before publishing the changelog.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

BackendSpanExporter drops the whole batch on HTTP 429 instead of retrying with Retry-After

0 participants