@openai/agents-core@0.19.0
OpenAI Agents SDK JavaScript v0.19.0 introduces bounds for agent tool streaming callbacks, strengthens state validation during checkpoint restarts and MCP resumes, enhances tool approval sandboxing and error redaction, and adds several MCP and session compaction fixes.
Why this signal matters
The @openai/agents-core 0.19.0 release brings multiple minor and patch fixes across tool execution, state restoration, and security controls. Key changes include: - Streaming Tool Callbacks: Agent tool streaming callbacks are now bounded to 1024 pending events by default; this can be adjusted or set to unlimited buffering using onStreamMaxPendingEvents . - Checkpoints & Resumption: Checkpoints started without initial input validation are rejected and restarted with original context. Resumed MCP calls are bound to original recipients, requiring fresh runs for unprovenanced legacy calls. - Approvals & Security: Conditional tool approvals are bound to isolated normalized execution inputs across core and Realtime. Uncopyable values are rejected before conditional approval. Default function-tool and Realtime approval parse failures are now redacted, requiring explicit policies for sensitive traces. - MCP Tool Management: Adds optional page limits for automatic tool listing, deduplication/handling for tools with normalized name collisions, and cache preservation during unrelated server invalidations. - Guardrails and History: Unvetted final outputs are withheld from session history if output guardrails fail. Adds an optional rollback budget for session compaction and configurable phase-two memory consolidation turns.
Actionable summary
OpenAI Agents SDK JS release @openai/agents-core@0.19.0 includes minor and patch updates: default 1024-event buffer limit on tool streaming callbacks, strict validation rejecting incomplete checkpoints, binding resumed MCP calls to original recipients, conditional tool approval isolation, sensitive trace error redactions, and MCP listing page limits.
- Agent usefulness
- 77/100
- Confidence
- 96%
- Canonical data
- JSON + Markdown
What builders should check
- Verify tool streaming workloads to ensure the default limit of 1024 pending events is sufficient, or configure onStreamMaxPendingEvents if higher buffering is needed.
- Review checkpoint restoration and durable approval flows to ensure compatibility with stricter validation for resumed MCP calls and checkpoint starts.
- Check sensitive-data tracing configurations if custom feedback or error function introspection relies on default error parse traces.