Commit Graph

5041 Commits

Author SHA1 Message Date
github-actions[bot] 39fc1d71af [skip ci] Release new versions @e2b/python-sdk@2.41.0 e2b@2.41.0 2026-08-19 16:20:46 +00:00
cursor[bot] 6824cdf313 feat(sdk): route sandbox egress through your own SOCKS5 proxy (BYOP) (#1688)
Drafts the SDK surface for [bring your own
proxy](https://e2b-docs-byop-egress-proxy.mintlify.site/network/byop):
`network.egressProxy` / `network["egress_proxy"]` on sandbox create, on
`updateNetwork` / `update_network`, and in what `getInfo` / `get_info`
reports back. Tunneling happens on the host after the allow and deny
lists are evaluated, so nothing runs inside the sandbox and code running
there can neither see the proxy nor route around it.

## The spec pin comes first

The pinned infra spec marked `egressProxy` `x-not-implemented: true`,
which Redocly's `filter-out` decorator drops from both generated clients
— so the field did not exist in `schema.gen.ts` or in the Python client
models, and no handwritten surface could reach it.
[infra@0716edb9e8](https://github.com/e2b-dev/infra/commit/0716edb9e840f110c5f87c186876c01e61553098)
removes the flag, so the first commit bumps `spec/infra-ref` and re-runs
codegen rather than hand-writing the wire types.

The pin picks up three other spec changes, and all of them are invisible
to the SDKs: `AdminTeamRunningSandboxCounts`, the dead
`NodeDetail.cachedBuilds` field, and `/admin/sandboxes/running-counts`
are admin-tagged, and the envd spec is byte-identical between the two
commits (verified by comparing the `packages/envd/spec` trees at both
refs). `make codegen` could not run here because the VM has no Docker,
so the spec was replaced with the byte-identical upstream file at the
new pin and the two REST generators were run natively with the pinned
`@redocly/cli` and `e2b-openapi-python-client`.

## Usage

Create a sandbox that tunnels its egress:

```ts
import { Sandbox } from 'e2b'

const sandbox = await Sandbox.create({
  network: {
    egressProxy: {
      address: 'proxy.example.com:1080',
      username: 'proxy-user',
      password: 'proxy-password',
    },
  },
})
```

```python
from e2b import Sandbox

sandbox = Sandbox.create(
    network={
        "egress_proxy": {
            "address": "proxy.example.com:1080",
            "username": "proxy-user",
            "password": "proxy-password",
        },
    },
)
```

It composes with the rest of the network configuration — here everything
except `api.example.com` is denied, and what is allowed goes through
your proxy:

```ts
await Sandbox.create({
  network: {
    allowOut: ['api.example.com'],
    denyOut: ({ allTraffic }) => [allTraffic],
    egressProxy: { address: 'proxy.example.com:1080' },
  },
})
```

```python
Sandbox.create(
    network={
        "allow_out": ["api.example.com"],
        "deny_out": lambda ctx: [ctx.all_traffic],
        "egress_proxy": {"address": "proxy.example.com:1080"},
    },
)
```

Set or replace it on a sandbox that is already running, with no restart.
The update replaces the whole configuration instead of merging into it,
so an update that leaves the proxy out stops tunneling:

```ts
await sandbox.updateNetwork({
  allowOut: ['api.example.com'],
  denyOut: ({ allTraffic }) => [allTraffic],
  egressProxy: { address: 'proxy.example.com:1080' },
})

// Stop tunneling: an update without egressProxy clears it
await sandbox.updateNetwork({})
```

```python
sandbox.update_network({
    "allow_out": ["api.example.com"],
    "deny_out": lambda ctx: [ctx.all_traffic],
    "egress_proxy": {"address": "proxy.example.com:1080"},
})

# Stop tunneling: an update without egress_proxy clears it
sandbox.update_network({})
```

Read the active proxy back:

```ts
const info = await sandbox.getInfo()
console.log(info.network?.egressProxy)
// { address: 'proxy.example.com:1080', username: 'proxy-user' }
```

```python
info = sandbox.get_info()
print(info.network["egress_proxy"])
# {'address': 'proxy.example.com:1080', 'username': 'proxy-user'}
```

## Design notes

- **`SandboxEgressProxyOpts` in, `SandboxEgressProxyInfo` out.** The API
never returns the password, so the result type does not have the field —
the same split as `SandboxNetworkRule` / `SandboxNetworkRuleInfo`.
`fromApiEgressProxy` / `_from_client_egress_proxy` map the generated
type at the boundary and drop a password even if a future API version
starts echoing one back, so the type cannot quietly become a lie.
- **The body is rebuilt from known fields**, as `buildIamBody` already
does, so stray keys on the caller's object never reach the wire and a
later mutation of it cannot alter an in-flight request.
- **No client-side validation.** Address form, port range, hostname
resolution, the internal-range rejection and the
password-without-username rule are all the server's — it is the only
side that can check them, and each already comes back as a readable API
error.
- **`null` never reaches a consumer.** The wire field is nullable; both
SDKs normalize it (absent key in Python, `undefined` in JS), and an
explicit `null` / `None` from an untyped caller is treated as "no proxy"
on the way in.
- Both types are exported from the flat entry points (`index.ts`,
`__all__`).

## Testing

Unit-level in both SDKs — msw in JS (12 tests), the shared builders in
Python (11 tests, covering sync and async since they share the
builders). Integration coverage is not included on purpose: tunneling
needs a SOCKS5 proxy reachable from E2B's infrastructure, which CI has
no way to stand up, and the feature is gated behind a private-beta team
flag.

`pnpm run format`, `pnpm run lint` and `pnpm run typecheck` are clean
repo-wide. The remaining test failures in this environment are all
`AuthenticationException` / missing `E2B_API_KEY` in pre-existing
integration suites; no credentials were available on the VM.

## Notes

- BYOP is available on E2B Cloud and in BYOC. A sandbox that names a
proxy on a deployment built from open source `e2b-dev/infra` is rejected
as unsupported by the orchestrator, which is why the field carried
`x-not-implemented` upstream for a while.
- No Linear MCP was available in this run, so no issue is linked.


<div><a
href="https://cursor.com/agents/bc-653eef78-87bb-5c9c-92d8-e573cd7ba5be?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/8e94ee92-9b0d-11f1-ba66-0e7d0216e441"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Mish Ushakov <mishushakov@users.noreply.github.com>
2026-08-19 17:54:11 +02:00
cursor[bot] e2eebd570f fix(python-sdk): URL-encode namespaced template IDs and aliases (#1691)
Claimed clone of #1520 (EN-1379), rebuilt on current `main`. Please
close #1520 in favour of this PR.

## Summary

Namespaced template IDs and aliases contain a slash, but the Python SDK
interpolated them into the request path unencoded, so
`Template.exists("namespace/name")` requested
`/templates/aliases/namespace/name` instead of
`/templates/aliases/namespace%2Fname` — the slash split the route rather
than staying inside one path segment.

A new `encode_path_param` helper percent-encodes the `template_id` and
`alias` path params across every template build-API call site, in both
the sync and async implementations. This matches the JS SDK, which
already encodes path params: `openapi-fetch`'s default path serializer
runs each value through `encodeURIComponent`, so no JS change is needed.

## Usage

```python
from e2b import Template

# Namespaced templates now resolve to /templates/aliases/my-team%2Fmy-template
Template.exists("my-team/my-template")

# ... and to /templates/my-team%2Fmy-template/tags
Template.get_tags("my-team/my-template")
```

```python
from e2b import AsyncTemplate

await AsyncTemplate.exists("my-team/my-template")
```

## Changes on top of #1520

- Merged current `main` (the original branch was 26 commits behind), and
confirmed the fix still covers every path-param call site after the
merge.
- Added `tests/shared/template/test_build_api_path_encoding.py`: the
original PR only unit-tested the helper, which would not catch a call
site that forgot to encode, nor httpx decoding `%2F` back into a
separator. The new tests drive the sync and async build APIs through an
`httpx.MockTransport` and assert the raw request path for both a
namespaced alias and a namespaced template ID. Verified they fail when
the encoding is removed.

## Tests

- `pnpm run format`, `pnpm run lint`, `pnpm run typecheck` — all clean.
- `uv run pytest tests/shared` in `packages/python-sdk` — 139 passed, 1
skipped.

A changeset is included (`@e2b/python-sdk` patch); this is a Python-only
change, so the JS SDK is not bumped.

<div><a
href="https://cursor.com/agents/bc-538dde5d-ca2f-4beb-8471-be70e265337d?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/3b1a5376-9bd3-11f1-ba66-0e7d0216e441"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Tomas Valenta <49156497+ValentaTomas@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Mish Ushakov <mishushakov@users.noreply.github.com>
2026-08-19 15:44:16 +00:00
cursor[bot] fc34961205 test(python-sdk): drop httpcore-era stream reader tests after the pyqwest migration (#1690)
Claimed from #1656 via `/sdk claim` (requested by @mishushakov, the
original author). Same single commit, original authorship preserved.
**Supersedes #1656, which should be closed in favor of this PR** — I
don't have write access to close it myself.

---

`tests/test_file_stream_reader.py` was written against httpcore and
never migrated with the rest of the pyqwest stack — it builds bare
`httpx.Client()` instances, so it still passes green while exercising a
transport the SDK no longer ships. Both of its load-bearing premises are
dead:

- `_active_connections()` read `client._transport._pool.connections`, an
httpcore-only internal. `PyqwestTransport` has no `_pool` at all.
- `request.extensions["timeout"]["read"]` is no longer a per-chunk idle
bound. The pyqwest adapter collapses read/write into one whole-operation
deadline and exits the timeout scope before the body streams, so it
bounds nothing after the response head.

This deletes the five tests that asserted only httpcore behavior (both
idle-timeout tests, the slow-consumer test, both abandoned-reader tests)
plus the helper, and re-anchors the remaining eight on
`response.is_closed` — `FileStreamReader.close()`'s actual contract,
transport-agnostic and stronger than the pool check, since the
context-manager tests now also assert the response stays open
mid-stream.

Also removes `tests/bugs/`, whose sole file was a permanently
`@pytest.mark.skip`'d pyautogui repro against the `desktop` template.

The real streaming-idle coverage against actual pyqwest transports
already lives in `tests/test_volume_client.py`; the SDK stopped sending
per-request timeouts on streamed reads for this same reason in
`e2b/sandbox_sync/filesystem/filesystem.py`.

Test-only, so no changeset — matching the repo convention for
`test(...)` PRs.

## Usage examples

None — this PR touches only `packages/python-sdk/tests/`. There is no
change to any public API, so no user-facing usage differs.

## Verification

Re-ran the original PR's checks on this branch:

```
$ uv run pytest tests/test_file_stream_reader.py -v
8 passed in 0.31s          # was 13

$ uv run pytest tests/*.py -q
245 passed in 15.16s       # full python-sdk unit suite

$ uv run make format       # ruff format . -> 403 files left unchanged
$ uv run make lint         # ruff check . -> All checks passed!
$ uv run make typecheck    # ty check -> All checks passed!
```

Also confirmed nothing else in the repo references the deleted
`tests/bugs/`, `test_envelope_decode`, or `_active_connections`.

Closes SDK-324

<div><a
href="https://cursor.com/agents/bc-11701ccd-9302-40dc-b58b-33e570bed5c4?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/3b1a5376-9bd3-11f1-ba66-0e7d0216e441"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Mish Ushakov <mishushakov@users.noreply.github.com>
2026-08-19 17:30:52 +02:00
cursor[bot] e09b318f8c test: write test fixtures to temp dirs instead of the repo tree (#1689)
Clone of #1665, opened in response to `/sdk claim` on that PR. The
original #1665 (branch `bangui`, by @mishushakov) can be closed in
favour of this one — the tree here is byte-for-byte identical to its
head, and the original commit is carried over unmodified so authorship
and the `Co-Authored-By` trailer are preserved.

## What changed

Eight test files created their fixtures outside a temporary destination,
so running the suite left directories behind in the working tree.

The five CLI template tests called `fs.mkdtemp` with a bare relative
prefix. `mkdtemp` does not imply `os.tmpdir()` — a relative prefix
resolves against `process.cwd()`, so each run created
`packages/cli/e2b-<name>-testXXXXXX/`. They now join the prefix onto
`os.tmpdir()`.

On the JS SDK side, `getAllFilesInPath` and `spoolTarArchive` wrote into
`__dirname` and now `mkdtemp` under `os.tmpdir()`. `build.test.ts` built
its file context at `tests/template/folder`, relying on the implicit
caller-directory context; it now creates the context under `os.tmpdir()`
and passes it explicitly via `Template({ fileContextPath })`, matching
what the Python mirror in `test_build.py` already does with
`tempfile.mkdtemp` and `file_context_path`.

The Python suite needed no changes: every host-side write already goes
through `tmp_path`, `tempfile.mkdtemp`, or `TemporaryDirectory`.

No usage examples apply — this is a test-only change with no user-facing
surface.

## Verification

Re-ran everything on this branch rather than relying on the original
PR's numbers:

- `packages/cli`: full suite green, 17 files / 109 tests passed.
- `packages/js-sdk`: the two util test files, 24 tests passed.
- `git status` is clean after both runs, with no leftover fixture
directories anywhere in the tree — which is the behaviour this change is
about.
- `pnpm run format`, `pnpm run lint`, `pnpm run typecheck` all clean
across the JS and Python packages; `format` produced no diff.

No changeset: test-only changes do not ship in either published package.

Fixes SDK-334

<div><a
href="https://cursor.com/agents/bc-7faf51ae-b169-4787-9d84-a50ec291b656?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/3b1a5376-9bd3-11f1-ba66-0e7d0216e441"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Mish Ushakov <mishushakov@users.noreply.github.com>
2026-08-19 15:16:11 +00:00
cursor[bot] 02ba746e9f fix(deps): patch 4 advisories found by dependency audit (3 high, 1 medium) (#1685)
Daily dependency vulnerability audit. `pnpm audit` reported 8 findings
across 2 packages (3 distinct advisories, all high), and `pip-audit`
reported 1 (medium). All 4 have published patches, and every one is
applied here. Both ecosystems now report clean.

All findings were cross-referenced against the GitHub Advisory Database
via `gh api /advisories/<ghsa>` to confirm severity and first-patched
version before bumping.

## Advisories fixed

| Severity | CVSS | Advisory | Package | Was | Now |
| --- | --- | --- | --- | --- | --- |
| High | 7.5 |
[CVE-2026-14257](https://github.com/advisories/GHSA-mh99-v99m-4gvg) |
`brace-expansion` | 1.1.16 / 2.1.2 / 5.0.7 | 1.1.18 / 2.1.4 / 5.0.9 |
| High | 7.5 |
[CVE-2026-69152](https://github.com/advisories/GHSA-rgw5-rvv9-x895) |
`brace-expansion` | 1.1.16 / 2.1.2 / 5.0.7 | 1.1.18 / 2.1.4 / 5.0.9 |
| High | 7.5 |
[GHSA-5p4m-2wfm-xmqj](https://github.com/advisories/GHSA-5p4m-2wfm-xmqj)
(no CVE assigned) | `js-yaml` | 3.15.0 / 4.3.0 | 3.15.1 / 4.3.1 |
| Medium | 5.3 |
[CVE-2026-71554](https://github.com/advisories/GHSA-6hr6-w5qg-qmwg) |
`h2` | 4.3.0 | 4.4.1 |

The two `brace-expansion` CVEs are handled together because the second
one bypasses the mitigation added for the first, so only the 1.1.18 /
2.1.4 / 5.0.9 line is safe against both. Note that the existing
overrides already covered earlier rounds of these same advisories — they
were pinning 1.1.13 / 2.1.2 / 5.0.6 and js-yaml 3.15.0 / 4.2.0, which
have since been superseded.

## Why each one matters here

**`brace-expansion` (high, DoS).** Reachable through `glob > minimatch >
brace-expansion`, and `glob` is a *production* dependency of the
published `e2b` JS SDK — so this is the one finding that was not
dev-only. Worth noting for reviewers: `glob@13.0.6` requires
`minimatch@^10.2.2`, which in turn requires `brace-expansion@^5.0.8`, so
a fresh `npm install e2b` already resolves the patched 5.0.9 on its own.
No `js-sdk` manifest change is needed and end users were not exposed;
the override bump is what keeps this repo's own lockfile and CI off the
vulnerable versions.

**`js-yaml` (high, quadratic CPU in `!!omap`).** Dev-tooling only, via
`@changesets/read > ... > read-yaml-file` and `knip`.

**`h2` (medium, duplicate `Host` header / request smuggling).** A
production dependency of the Python SDK. Bumping `uv.lock` alone would
only fix this repo's dev environment, since `uv.lock` does not constrain
downstream installs — so the floor in `pyproject.toml` is raised too,
which is what actually prevents a consumer from resolving the vulnerable
4.3.0 or 4.4.0. `h2` 4.4.1 declares `requires_python >=3.10`, matching
the SDK's own `requires-python`, so no supported Python version is
dropped. This is the only user-facing change in the PR and it carries a
`patch` changeset.

This one is below the high/critical bar the audit normally acts on, and
is included because the remediation is a single in-range floor bump on a
dependency that ships to users.

## Changes

- `package.json` — retarget the `brace-expansion` and `js-yaml` pnpm
overrides at the new patched versions.
- `pnpm-lock.yaml`, `packages/python-sdk/uv.lock` — regenerated.
- `packages/python-sdk/pyproject.toml` — `h2>=4,<5` becomes
`h2>=4.4.1,<5`.
- `.changeset/bump-h2-4-4-1.md` — `patch` for `@e2b/python-sdk`.

No source code changed; this is dependency metadata only.

## Verification

All three audits are clean after the change:

```bash
pnpm audit                 # No known vulnerabilities found
pnpm audit --prod          # No known vulnerabilities found
cd packages/python-sdk && uv run --with pip-audit pip-audit
                           # No known vulnerabilities found
```

`pnpm run format`, `pnpm run lint`, and `pnpm run typecheck` all pass
with no diff.

Tests: 256 Python unit tests, 101 CLI tests, and 345 JS SDK tests pass.
The remaining suites could not run in this environment because no
`E2B_API_KEY` was available — every one of those failures is an
`AuthenticationError: API key is required` / `E2B_API_KEY must be set`
from a live-sandbox integration test, and none is related to this diff.
**The credential-gated integration suites should be confirmed green in
CI before merge.**

```bash
cd packages/python-sdk && uv run pytest tests --ignore=tests/async --ignore=tests/sync --ignore=tests/bugs --ignore=tests/shared -q
# 256 passed

cd packages/cli && npx vitest run
# 101 passed | 8 skipped

cd packages/js-sdk && npx vitest run --project unit --project connectionConfig --project template
# 345 passed; 267 failures, all missing-API-key
```

## Note on PR structure

The audit task asks for one PR per vulnerability. This run was scoped to
a single branch, so all 4 advisories are grouped here. That grouping is
also the correct shape for the two `brace-expansion` CVEs, which share
one fix and cannot be split. If separate PRs are preferred, the three
commits on this branch are already split by advisory group and can be
cherry-picked apart.

<div><a
href="https://cursor.com/agents/bc-c4b46d1f-a426-45b9-9c03-46e5decd398d?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/automations/979f8043-9b01-11f1-ba66-0e7d0216e441"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/view-automation-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/view-automation-light.png"><img
alt="View Automation" width="141" height="28"
src="https://cursor.com/assets/images/view-automation-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Mish Ushakov <mishushakov@users.noreply.github.com>
2026-08-19 14:36:24 +02:00
github-actions[bot] b71439b079 Merge branch 'main' of https://github.com/e2b-dev/E2B 2026-08-18 12:56:34 +00:00
github-actions[bot] 5951f14e81 [skip ci] Release new versions @e2b/python-sdk@2.40.0 e2b@2.40.0 2026-08-18 12:56:06 +00:00
Mish Ushakov e130ba7f3b chore(ci): remove the Dependabot changeset workflow (#1683)
Dependabot is being turned off for this repo, so
`.github/workflows/dependabot_changeset.yml` — which committed a `patch`
changeset to every Dependabot PR that touched a released package's
direct production dependencies — has nothing left to run on, and it goes
away along with the paragraph describing it in `.changeset/README.md`.
No other file referenced the workflow, and nothing about hand-written
changesets changes: `npx changeset` is still the way to add one.

Two follow-ups live outside this diff. The repo has no
`.github/dependabot.yml` (it never did), so the bumps we've been getting
came from GitHub's **Dependabot security updates** toggle — that has to
be switched off in *Settings → Advanced Security* for the PRs to
actually stop. And if "Dependabot Changeset" is listed as a required
check in branch protection, it needs removing there or PRs will wait on
a check that no longer runs; the `VERSION_BUMPER_APPID` /
`VERSION_BUMPER_SECRET` credentials this workflow used are worth
double-checking against the other workflows before revoking.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-18 14:55:14 +02:00
Mish Ushakov 65cd85d321 refactor(cli): remove the E2B_ACCESS_TOKEN auth path (#1679)
Stacked on #1680.

Auth moved to Hydra OAuth in #1481, which left `ensureAccessToken()`
with no callers and the module-level API client attaching a stale
`Authorization: Bearer <access token>` header to every request. This
drops `ensureAccessToken()`, the `accessToken` export, the
`E2B_ACCESS_TOKEN` arm of the auth error box, and the `apiHeaders`
wiring on `connectionConfig` — the only consumers of that header were
`template list`/`create`, and `/templates` is scoped by the API key
alone, while `auth login` / `auth configure` build their own clients
with Hydra JWTs. `requireApiKey: false` stays on the shared client, but
its justification is now that `e2b auth login` runs before any API key
exists and the client is built at import time.

User-facing effect: combined with #1680, the CLI ignores
`E2B_ACCESS_TOKEN` entirely, so CI setups can drop it and keep only the
API key.

```bash
# Before: both were commonly set in CI
export E2B_ACCESS_TOKEN=sk_e2b_...
export E2B_API_KEY=e2b_...

# Now: the API key alone authorizes everything the CLI calls
export E2B_API_KEY=e2b_...
e2b template list
e2b template create my-template
```

Part of
[SDK-6](https://linear.app/e2b/issue/SDK-6/mark-e2b-access-token-as-deprecated-inside-all-code-references).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-18 14:01:52 +02:00
Mish Ushakov 6248b12a5e feat(sdk): remove the deprecated accessToken option (#1680)
Removes the deprecated `accessToken` / `access_token` option from both
SDKs, along with its `E2B_ACCESS_TOKEN` environment fallback and the
`Authorization: Bearer` header it produced. The option was already
deprecated in both SDKs — `connectionConfig.ts` and
`connection_config.py` both pointed at `apiHeaders` / `api_headers` as
the replacement — and E2B access tokens are no longer accepted for API
authentication, so resolving one and putting it on the wire was dead
weight. Requests now authenticate with the API key alone.

Callers who need a bearer token for a custom deployment pass it
explicitly, which is what the deprecation notice already told them to
do:

```ts
// Before
const sandbox = await Sandbox.create({ accessToken: token })

// After
const sandbox = await Sandbox.create({
  apiHeaders: { Authorization: `Bearer ${token}` },
})
```

```python
# Before
config = ConnectionConfig(access_token=token)

# After
config = ConnectionConfig(api_headers={"Authorization": f"Bearer {token}"})
```

`Sandbox.envd_access_token` / `traffic_access_token` are unrelated
per-sandbox tokens and are unaffected, as is the volume client's `token`
(which never read the env var — there's a test asserting exactly that).

Part of
[SDK-6](https://linear.app/e2b/issue/SDK-6/mark-e2b-access-token-as-deprecated-inside-all-code-references).
The CLI half is stacked on top in #1679.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-18 14:01:51 +02:00
dependabot[bot] 07e35bcffc chore(deps): bump nanoid from 3.3.17 to 3.3.18 in the npm_and_yarn group across 1 directory (#1672)
Bumps the npm_and_yarn group with 1 update in the / directory:
[nanoid](https://github.com/ai/nanoid).

Updates `nanoid` from 3.3.17 to 3.3.18
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ai/nanoid/releases">nanoid's
releases</a>.</em></p>
<blockquote>
<h2>3.3.18</h2>
<ul>
<li>Fixed infinite loop on async for React Native (by <a
href="https://github.com/OvergrowthBeards-JB"><code>@​OvergrowthBeards-JB</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md">nanoid's
changelog</a>.</em></p>
<blockquote>
<h2>3.3.18</h2>
<ul>
<li>Fixed infinite loop on async for React Native (by <a
href="https://github.com/OvergrowthBeards-JB"><code>@​OvergrowthBeards-JB</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d"><code>9ad9805</code></a>
Release 3.3.18 version</li>
<li><a
href="https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8"><code>55e50a0</code></a>
Update CI action</li>
<li><a
href="https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0"><code>e10f8d4</code></a>
Update index.native.js (<a
href="https://redirect.github.com/ai/nanoid/issues/606">#606</a>)</li>
<li>See full diff in <a
href="https://github.com/ai/nanoid/compare/3.3.17...3.3.18">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=nanoid&package-manager=npm_and_yarn&previous-version=3.3.17&new-version=3.3.18)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts page](https://github.com/e2b-dev/E2B/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 11:18:43 +02:00
github-actions[bot] f5d702a520 [skip ci] Release new versions @e2b/python-sdk@2.39.1 2026-08-13 16:56:04 +00:00
Mish Ushakov 0d507cd53d fix(python-sdk): restore the http2 parameter on the transport factories (#1671)
The pyqwest migration in 2.38.0 dropped the `http2` parameter from
`get_transport` and `get_envd_transport` (added deliberately in #1347,
2.32.0) and collapsed the transport cache key to the proxy alone, so
`e2b-code-interpreter`'s Jupyter requests —
`get_transport(self.connection_config, http2=False)` — now raise
`TypeError: get_transport() got an unexpected keyword argument 'http2'`;
that is already live, since `e2b = "^2.26.0"` resolves to 2.38.x, and it
blocks the Python half of code-interpreter
[#328](https://github.com/e2b-dev/code-interpreter/pull/328). pyqwest
supports the capability, it just was not threaded through: this restores
the pre-2.38.0 signature (so no consumer code changes, only an `e2b`
floor bump) by passing `http_version=None if http2 else
HTTPVersion.HTTP1` into the pyqwest transports, and puts the HTTP
version back into both cache keys — without that, whichever caller asks
second is handed a transport of the wrong version. The default is
unchanged: `None` leaves TLS connections to ALPN (HTTP/2 against the E2B
API) and uses HTTP/1 for plaintext, exactly as today. HTTP/1.1 is not
cosmetic for the consumer — with HTTP/2 multiplexing, abandoning a
request only resets its stream, so the code-interpreter server never
sees the `http.disconnect` it needs to interrupt the kernel, while
HTTP/1.1's one connection per request closes the connection and the
server observes it.

## Usage

Both factories are internal (nothing is exported from
`e2b/__init__.py`), so there is no public API change; consumers reaching
into them get the 2.32.0 call back:

```python
from e2b.api.client_sync import get_transport, get_envd_transport

# Unchanged: ALPN negotiates the version (HTTP/2 against the E2B API).
transport = get_transport(config)

# Its own pool, pinned to HTTP/1.1, so a cancelled request closes the
# connection and the server observes the disconnect.
http1 = get_transport(config, http2=False)
envd_http1 = get_envd_transport(config, http2=False)
```

The async mirror (`e2b.api.client_async`) is identical.

## Tests

Six new cases in
`packages/python-sdk/tests/test_api_client_transport.py`, sync and
async: cache separation and identity across `http2` / proxy /
`for_streaming`, the `http_version` value actually reaching the pyqwest
transport (`[None, HTTP1, HTTP1]`), and a round trip proving the pinned
transport works. The negotiated version can't be observed locally — the
test echo server is plaintext, where both settings speak HTTP/1 — so it
is asserted at the constructor, with the reason in a comment; it was
verified by hand against `https://api.e2b.app/health` via the
`pyqwest.access` logger, which shows `"HTTP/2 200 OK"` on the default
and `"HTTP/1.1 200 OK"` with `http2=False` on both factories (and
confirms `httpx.Response.http_version` is unreliable through the adapter
— it reports HTTP/1.1 either way). 256 unit tests pass, plus `make
lint`, `make typecheck` and `make format`. No JS change: its transport
is an undici-dispatcher `fetch` with no HTTP-version knob, and the JS
half of code-interpreter #328 is a clean bump.

Closes
[SDK-335](https://linear.app/e2b/issue/SDK-335/python-sdk-get-transport-lost-its-http2-parameter-in-2380-breaking-e2b)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 17:56:26 +02:00
github-actions[bot] ce634ab5f2 [skip ci] Release new versions @e2b/python-sdk@2.39.0 e2b@2.39.0 2026-08-13 15:07:47 +00:00
Mish Ushakov 07eb9be196 feat(sdk): resolve iam token placeholders in network transform callbacks (#1616)
Stacked on #1606 (`iam-sdk-feature`) — merge that one first. This is the
second half of SDK-245: it makes the workload tokens registered by
`Sandbox.create`'s `iam` option usable, by letting a network rule's
`transform` be a **callback** that receives placeholder strings the
egress proxy resolves per request.

`iam.tokens.aws` is the literal string `${e2b.identity.tokens.aws}` (the
frozen backend spelling — a placeholder can only select a persisted
named token, never an inline audience or claim). The SDK never resolves
it: the wire payload carries the placeholder and the proxy substitutes a
freshly minted JWT-SVID when it forwards the request, so the token value
never reaches SDK-side code or the sandbox.

Referencing a name that isn't registered in `iam.tokens` fails with
`InvalidArgumentError` / `InvalidArgumentException` listing the names
that are — the proxy never turns an unregistered name into a token, so a
typo would otherwise surface as a confusing auth failure at the
destination. `updateNetwork` / `update_network` accepts the same
callbacks, but its payload carries no `iam` config, so token names can't
be validated client-side there and any name resolves to its placeholder.

Static `transform: { headers }` objects keep working unchanged
(including hand-written `${e2b.identity.tokens.<name>}` strings, which
stay the escape hatch for tokens the SDK doesn't know about).

Only `{ iam }` is exposed on the context for now — `${e2b.sandboxId}` /
`${e2b.teamId}` / `${e2b.executionId}` from the older prototype are not
part of the current backend design, so `sandbox` can be added later when
there is something to resolve.

## Usage

```ts
import { Sandbox, Secret } from 'e2b'

const sandbox = await Sandbox.create({
  iam: {
    tokens: {
      aws: Secret.iamToken({ audience: 'sts.amazonaws.com', tokenType: 'JWT-SVID' }),
    },
  },
  network: {
    // Only allow egress to hosts that have rules registered.
    allowOut: ({ rules }) => [...rules.keys()],
    rules: {
      'api.internal.example.com': [
        {
          transform: ({ iam }) => ({
            headers: { Authorization: `Bearer ${iam.tokens.aws}` },
          }),
        },
      ],
    },
  },
})
```

```python
from e2b import Sandbox, Secret

sandbox = Sandbox.create(
    iam={
        "tokens": {
            "aws": Secret.iam_token(audience="sts.amazonaws.com", token_type="JWT-SVID"),
        },
    },
    network={
        "allow_out": lambda ctx: list(ctx.rules.keys()),
        "rules": {
            "api.internal.example.com": [
                {
                    "transform": lambda ctx: {
                        "headers": {"Authorization": f"Bearer {ctx.iam.tokens['aws']}"},
                    },
                },
            ],
        },
    },
)
```

Both send:

```json
{
  "iam": { "tokens": { "aws": { "audience": "sts.amazonaws.com", "tokenType": "JWT-SVID" } } },
  "network": {
    "allowOut": ["api.internal.example.com"],
    "rules": {
      "api.internal.example.com": [
        { "transform": { "headers": { "Authorization": "Bearer ${e2b.identity.tokens.aws}" } } }
      ]
    }
  }
}
```

## Notes

- `allowOut` / `deny_out` selectors run **before** transforms are
resolved, so `ctx.rules` still hands back the rules you passed — a
rule's `transform` there is the union (object or callback), not the
materialized object. The `getInfo` view keeps its own narrowed
`SandboxNetworkRuleInfo` type.
- Token names are validated where they are registered and again before
interpolation: a name cannot be empty or contain `{`, `}` or control
characters. The proxy reads a placeholder up to its first `}`, so `a}b`
would mint the unrelated token `a` and leave `b}` as literal text, and a
`{` in a name can open a second placeholder. The interpolation check is
what covers `updateNetwork`, where any name the callback looks up
becomes a placeholder without passing through the `iam` config.
- Every lookup form on `iam.tokens` is guarded, not just `[name]`:
Python's map is a `Mapping` whose `__getitem__` owns resolution (so
`.get('typo')` raises instead of returning `None`), and membership
(`'aws' in ctx.iam.tokens` / `'aws' in iam.tokens`) answers "is it
registered?" without raising so a callback can branch on it. Lookup
checks own keys only, so an unregistered name colliding with an object
member (`constructor`, `__proto__`) reports as unregistered instead of
resolving to a built-in; the four properties the runtime itself reads
(`toJSON`, `then`, `toString`, `valueOf`) still resolve normally, so
serializing, awaiting or coercing the map does not trip the guard.
- A callback must be synchronous and return a plain transform object; a
promise (from an `async` callback), an array, a `Map`/`Date`/class
instance, or a missing return value is rejected with an actionable error
rather than silently creating a rule with no headers. The awaitable is
closed/caught so you don't also get an unawaited-coroutine warning or an
unhandled rejection.

## Tests

New payload-level tests: JS `tests/sandbox/networkTransform.test.ts`
(msw), Python `tests/shared/sandbox/test_network_transform.py` — shared
rather than mirrored into the sync and async suites, since they only
exercise the shared builders. They cover placeholder resolution,
enumerating and membership-testing registered tokens, `JSON.stringify`
of the context not tripping the guard, static transforms staying
byte-identical, `transform: null`, the unregistered-name rejection
through both `[name]` and `.get()`, the no-`iam` rejection,
non-transform and `async` return values, unusable token names (both
braces, a smuggled placeholder, a newline, empty) at registration and on
the update path, and the permissive `updateNetwork` path.

Verified against production on all three surfaces (JS, sync Python,
async Python), where:

1. a static transform carrying `Bearer ${e2b.identity.tokens.aws}` is
accepted by `validateNetworkRules` and round-trips through `getInfo` /
`get_info` unchanged;
2. the callback-resolved payload reaches the API and is answered with
the expected team-gating error (`400: Sandbox IAM workload tokens are
not available for your team.`), since `iam` is still feature-flagged;
3. a misspelled or unusable token name is rejected client-side before
any request is made.

Proxy-side substitution of the placeholder ships separately in belt
(EN-1864); until then the header value is forwarded verbatim, which is
why there is no end-to-end injection test here.

Part of SDK-245.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-13 16:58:44 +02:00
Mish Ushakov 64b25bb37b feat(sdk): add iam workload identity option and Secret.iamToken helper (#1606)
Implements the sandbox workload identity (IAM) feature from the [infra
spec](https://github.com/e2b-dev/belt/blob/main/spec/openapi-infra.yml)
(`SandboxIam` / `SandboxIamTokens` / `SandboxIamToken`, already present
in the pinned spec and generated clients) across the JS SDK and the sync
and async Python SDKs. `Sandbox.create` gains an `iam` option whose
non-empty `tokens` map enables workload identity, and a new `Secret`
class (exported from both main packages) provides `iamToken` /
`iam_token` to define the token values, per the SDK design. The design
doc's `filePath` field is deliberately omitted until it lands in the
OpenAPI spec, and plain `{ audience, tokenType }` objects are accepted
alongside `Secret.iamToken` results. The SDK builds the request body
from only the known token fields (stray properties never reach the wire,
undefined-valued map entries count as empty) and rejects tokens missing
`audience`/`tokenType` (`token_type` in Python) with
`InvalidArgumentError` / `InvalidArgumentException`. Covered by
request-body tests (msw in JS, `NewSandbox` payload tests in Python)
since the backend feature is team-gated; all three surfaces were also
smoke-tested end-to-end against production, where the payload is parsed
and answered with the expected team-gating error.

Fixes SDK-245.

## Usage

```ts
import { Sandbox, Secret } from 'e2b'

const sandbox = await Sandbox.create({
  iam: {
    tokens: {
      aws: Secret.iamToken({ audience: 'sts.amazonaws.com', tokenType: 'JWT-SVID' }),
    },
  },
})
```

```python
from e2b import Sandbox, Secret

sandbox = Sandbox.create(
    iam={
        "tokens": {
            "aws": Secret.iam_token(audience="sts.amazonaws.com", token_type="JWT-SVID"),
        },
    },
)
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-13 16:58:43 +02:00
Mish Ushakov 034c503f1f ci: guard production releases to main, harden the itinerary step (#1662)
Three fixes found while porting this workflow to
`e2b-dev/code-interpreter`
([#327](https://github.com/e2b-dev/code-interpreter/pull/327)).

**`release.yml` can be dispatched from any branch.** It is dispatch-only
and `workflow_dispatch` offers every branch in the picker, so a feature
branch carrying changesets would publish real packages to npm and PyPI
and push the version bump to itself. `preflight` now fails fast unless
the run is on `main`; candidates cut from a branch already go through
`release-candidate.yml`.

**The itinerary step can block a release.** It only feeds the Slack
messages, but a `changeset status` hiccup — or a typo in a future edit
to that inline `node -e` block, which no YAML validation catches — fails
`preflight` and stops the release. It is now `continue-on-error` with a
placeholder fallback in both messages, and the transform moved to
`.github/scripts/build_release_itinerary.cjs` next to `is_release.sh`,
where it can be run against fixture JSON. A package missing from the
label map now shows under its workspace name instead of being dropped by
`order.filter`, so a fourth publishable package would not silently
vanish from the notification.

**`report-failure` did not list `preflight`**, so whether a broken
preflight pings `#monitoring-releases` rested on `failure()` looking
past the job's direct dependencies — not documented either way, so the
job now depends on it explicitly.

Verified: the extracted script reproduces the current output exactly for
`e2b` / `@e2b/python-sdk` / `@e2b/cli`, in the same order, and handles
the empty and unlabeled-package cases; workflow validated against the
Actions schema; the script matches the repo's prettier config.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 14:15:14 +02:00
Mish Ushakov 11912ffa04 refactor(python-sdk): share one envd HTTP client across the sync sandbox modules (#1655)
The sync flavor built four envd HTTP clients per sandbox — `Filesystem`,
`Commands` and `Pty` each constructed their own — while the async flavor
built one in `Sandbox.__init__` and threaded it down; this builds it
once on the sync side too and passes it into the three modules. No
functional change: `get_envd_transport` already caches the pyqwest
transport per `(proxy, for_streaming)` process-wide, so those four
clients already shared one connection pool — the cost was a few
`httpx.Client` wrappers per sandbox, plus a sync/async divergence that
CLAUDE.md and TASTE.md both ask us to avoid. It also clears the last
cosmetic differences between the two flavors: async `Commands`/`Pty`
swap their `_check_health` lambda closure for the sync side's attribute
+ method, sync `Commands`/`Pty` drop a write-only `_envd_api_url`, and
async `Filesystem` builds its RPC client first to match sync — the three
constructor pairs now differ only in the sync/async client and RPC class
names. All constructors touched are internal, so there is no public API
change and nothing to show as a usage example.

Verified with 336 unit tests, 92 sync and 89 async integration tests
against prod (`commands`, `pty`, `files`), plus `make lint` and `make
typecheck`.

Closes
[SDK-322](https://linear.app/e2b/issue/SDK-322/python-sdk-share-one-envd-http-client-across-the-sync-sandbox-modules)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-10 18:40:42 +00:00
github-actions[bot] cfd4bedd90 Merge branch 'main' of https://github.com/e2b-dev/E2B 2026-08-10 17:57:16 +00:00
github-actions[bot] 6acbeb39ee [skip ci] Release new versions @e2b/python-sdk@2.38.0 e2b@2.38.3 2026-08-10 17:56:55 +00:00
dependabot[bot] 96256815f2 chore(deps): bump the npm_and_yarn group across 1 directory with 1 update (#1653)
Bumps the npm_and_yarn group with 1 update in the / directory:
[postcss](https://github.com/postcss/postcss).

Updates `postcss` from 8.5.22 to 8.5.25
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.25</h2>
<ul>
<li>Fixed 8.5.17 visitor regression.</li>
<li>Fixed <code>list.split()</code> for non-string values (by <a
href="https://github.com/amir-rezaei"><code>@​amir-rezaei</code></a>).</li>
</ul>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.25</h2>
<ul>
<li>Fixed 8.5.17 visitor regression.</li>
<li>Fixed <code>list.split()</code> for non-string values (by <a
href="https://github.com/amir-rezaei"><code>@​amir-rezaei</code></a>).</li>
</ul>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/postcss/commit/08c989c43cc87edb1ed71408c2f5164c54fc21df"><code>08c989c</code></a>
Release 8.5.25 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/24f681471645cd960ee760ab7f9e348fbabfd42c"><code>24f6814</code></a>
Fix 8.5.17 visitor regression</li>
<li><a
href="https://github.com/postcss/postcss/commit/f2fa53f11daab3a16c7eb8bcaf5a945142341df3"><code>f2fa53f</code></a>
Add supply chain security requirement to PostCSS plugin guide</li>
<li><a
href="https://github.com/postcss/postcss/commit/10edf0b0606f97b1510e040c27bfd078c48d6ea7"><code>10edf0b</code></a>
fix: return empty array for empty string in list.split (<a
href="https://redirect.github.com/postcss/postcss/issues/2121">#2121</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9"><code>0ebe8ad</code></a>
Release 8.5.24 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d"><code>73218c6</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a"><code>9a114f6</code></a>
Preserve the BOM when stringifying (<a
href="https://redirect.github.com/postcss/postcss/issues/2119">#2119</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1"><code>9069261</code></a>
Fix types check</li>
<li><a
href="https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd"><code>eb9e1fe</code></a>
Release 8.5.23 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84"><code>9d19c78</code></a>
Update dependencies</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/postcss/compare/8.5.22...8.5.25">compare
view</a></li>
</ul>
</details>
<br />

Updates `postcss` from 8.5.22 to 8.5.26
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.25</h2>
<ul>
<li>Fixed 8.5.17 visitor regression.</li>
<li>Fixed <code>list.split()</code> for non-string values (by <a
href="https://github.com/amir-rezaei"><code>@​amir-rezaei</code></a>).</li>
</ul>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.25</h2>
<ul>
<li>Fixed 8.5.17 visitor regression.</li>
<li>Fixed <code>list.split()</code> for non-string values (by <a
href="https://github.com/amir-rezaei"><code>@​amir-rezaei</code></a>).</li>
</ul>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/postcss/commit/08c989c43cc87edb1ed71408c2f5164c54fc21df"><code>08c989c</code></a>
Release 8.5.25 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/24f681471645cd960ee760ab7f9e348fbabfd42c"><code>24f6814</code></a>
Fix 8.5.17 visitor regression</li>
<li><a
href="https://github.com/postcss/postcss/commit/f2fa53f11daab3a16c7eb8bcaf5a945142341df3"><code>f2fa53f</code></a>
Add supply chain security requirement to PostCSS plugin guide</li>
<li><a
href="https://github.com/postcss/postcss/commit/10edf0b0606f97b1510e040c27bfd078c48d6ea7"><code>10edf0b</code></a>
fix: return empty array for empty string in list.split (<a
href="https://redirect.github.com/postcss/postcss/issues/2121">#2121</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9"><code>0ebe8ad</code></a>
Release 8.5.24 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d"><code>73218c6</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a"><code>9a114f6</code></a>
Preserve the BOM when stringifying (<a
href="https://redirect.github.com/postcss/postcss/issues/2119">#2119</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1"><code>9069261</code></a>
Fix types check</li>
<li><a
href="https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd"><code>eb9e1fe</code></a>
Release 8.5.23 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84"><code>9d19c78</code></a>
Update dependencies</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/postcss/compare/8.5.22...8.5.25">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts page](https://github.com/e2b-dev/E2B/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 19:55:44 +02:00
Mish Ushakov b048369307 feat(python-sdk): move the envd HTTP API client onto pyqwest (#1623)
## What

Tracked in [SDK-265](https://linear.app/e2b/issue/SDK-265) (part of the
[SDK-268](https://linear.app/e2b/issue/SDK-268) stack). Stacked on
#1603, at the top of the pyqwest stack (#1601#1602#1603 → this).
Migrate the envd HTTP API client — sandbox file transfers
(`files.read`/`write`), health checks — from httpx-native transports to
pyqwest via the httpx adapter, and dedupe the transport plumbing that
#1558 (envd RPC) and #1601 (REST) each carried a copy of. With this, all
Python SDK traffic runs on pyqwest: REST control plane (#1601), envd RPC
(#1558, connectrpc), envd HTTP API (this PR); the volume content client
(#1602) and template build uploads (#1603) sit below this one in the
stack.

## How

**Shared plumbing** (first commit): `e2b.api` becomes the canonical home
for the proxy narrowing (`proxy_to_config`, with stack-neutral error
messages), the pool tuning, and the flavor `ConnectionRetryTransport` +
a new `retrying_http_transport(proxy, read_timeout=None)` factory;
`e2b.envd.client_sync/client_async` import them instead of defining
their own (envd RPC behavior unchanged, pools stay separate —
unification is SDK-291).

**envd HTTP API** (second commit):

- `get_envd_transport(config, for_streaming=False)` returns
pyqwest-adapter transports cached per `(proxy, streaming)`;
`get_envd_api(config, base_url, for_streaming=False)` builds the httpx
client with sandbox headers + logging hooks. The per-thread (sync) /
per-loop (async) client caching in
`Filesystem`/`Commands`/`Pty`/`AsyncSandbox` is gone — one shared client
per module, same rationale as the `ApiClient` simplification in #1601.
- **Streamed downloads**: the streaming transport carries a 60s
`read_timeout` — an idle bound that resets on every read, capping stalls
without limiting total transfer time. It gets a dedicated pool because
reqwest's read timer keeps ticking while a request body is sent and
while waiting for the response head, so on the shared transport it would
cut off uploads and slow unary responses. An explicit `request_timeout`
becomes the whole-transfer deadline (adapter semantics) and is sent only
when the caller set one; `stream_idle_timeout` stays honored on the
async client via `wait_for` per read (so values above 60s work and `0`
disables), and is documented as ignored on the sync client, which cannot
interrupt a blocking read. Mirrors #1602's volume design.
- **Uploads**: buffered uploads keep `request_timeout` as a
whole-request deadline; streamed (file-like) uploads carry no
client-side timeout and are bounded server-side (envd's idle read
timeout) — both exactly the JS SDK's behavior (`getSignal` for buffered,
no signal for streams).
- **Multipart**: `files=` uploads go out as httpx's `MultipartStream`,
which implements *both* `SyncByteStream` and `AsyncByteStream`. The
pyqwest 0.7 adapter's sync content conversion matched `AsyncByteStream`
first and raised `TypeError("unreachable")` from inside the body
iterator, surfacing as a `WriteError` mid-request ("http2 error: stream
error sent by user"). Fixed upstream in
[pyqwest#196](https://github.com/curioswitch/pyqwest/pull/196), which
matches the sync case first — so this PR carries no workaround (the
stack requires **pyqwest 0.9**, set in #1601). The regression test
stays, now covering the upstream fix.
- The stream readers map the transport's idle timeout (builtin
`TimeoutError` under pyqwest) to the documented `httpx.ReadTimeout`;
`handle_envd_api_transport_exception`'s health-probe path keeps working
because the adapter maps HTTP/2 stream resets to
`httpx.RemoteProtocolError`.

- **RPC logging**: the `LoggingInterceptor` docstring no longer promises
its own removal. pyqwest does log requests
([pyqwest#197](https://github.com/curioswitch/pyqwest/pull/197)), but on
process-wide `pyqwest`/`pyqwest.access` loggers that can't carry the
per-sandbox `logger` and don't see streamed messages or the Connect
error code of a stream that fails inside a `200 OK` — so the interceptor
stays, with those loggers below it.
[pyqwest#192](https://github.com/curioswitch/pyqwest/pull/192), the
middleware it referenced, was closed in favor of #197.

- **Transports**: rebased onto #1603 on pyqwest 0.9, so the envd HTTP
API transports are the stock `PyqwestTransport`/`AsyncPyqwestTransport`
(the SDK's adapter subclasses are gone as of #1601 — 0.9 strips the
`Host` header and maps timeouts itself) with `follow_redirects=False`
and, for the streaming pool, the transport-wide `read_timeout`.

## Testing

- Unit: envd transport keying (streaming vs regular vs REST pools),
`get_envd_api` wiring (headers, transports), multipart regression
through a local server, stream-reader timeout mapping + per-read idle
bound (`tests/test_file_stream_reader.py`), rewritten client-lifecycle
tests (shared across threads). 236 unit tests green; lint + typecheck
green.
- Integration against production sandboxes: full `files` suites
sync+async (123 tests — these caught the multipart bug), `commands` +
`pty` suites both flavors (57 tests). All green.

## Usage example

No API changes:

```python
sbx = Sandbox.create()
sbx.files.write("hello.txt", "hi")            # multipart/octet-stream over pyqwest
with sbx.files.read("hello.txt", format="stream") as stream:
    for chunk in stream:                       # stalls bounded by 60s idle read timeout
        ...
```

Only visible behavior shift: on the **sync** client, `files.read(...,
format="stream", stream_idle_timeout=...)` is now a documented no-op
(the transport-wide 60s idle bound applies); the async client honors it
as before.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-10 19:46:38 +02:00
Mish Ushakov b3a7c9f44a feat(python-sdk): move template build-context uploads onto pyqwest (#1603)
## What

Stacked on #1602 (which is stacked on #1601). Migrates the **template
build-context uploads** (streaming the build archive to S3 presigned
URLs in `build_api.upload_file`) onto
[pyqwest](https://github.com/curioswitch/pyqwest) via its
httpx-compatible transport adapter.

Originally deferred from #1601 because S3 presigned URLs reject chunked
transfer encoding and Content-Length framing through reqwest was
unverified. Verified at the wire level (raw-socket capture server):
httpx's Content-Length — derived from the spooled archive (sync) or set
explicitly on the async-iterator body (async) — is forwarded by the
adapter and reqwest keeps Content-Length framing for streamed bodies, no
chunked fallback.


> [!NOTE]
> Rebased onto #1601, which locks **pyqwest 0.9.0**. Two knock-on
changes here: the upload client uses the stock
`PyqwestTransport`/`AsyncPyqwestTransport` (0.9.0's adapter subsumes
what the SDK's transport subclasses did, so #1601 deleted them), and it
builds its proxy from `proxy_to_config(...)` following #1601's rename.

## How

- `e2b/template_sync/build_api.py` / `template_async/build_api.py`:
`upload_file` uses a one-off pyqwest transport instead of the generated
client's httpx transport.
- **Redirects stay with the httpx client.** pyqwest 0.9.0 makes
reqwest's internal redirect following configurable, so it's turned off
on the upload transport: otherwise reqwest would replay the entire
archive body against a new location without httpx knowing. The httpx
client inherits the API client's `follow_redirects` (off), matching the
httpx transport this replaced — so an unexpected hop surfaces as a
failed upload rather than a silent re-upload.
- `verify_ssl=False` on the generated client is no longer honored for
uploads (pyqwest has no insecure-TLS option), and `http2=False` is gone
(S3 negotiates HTTP/1.1 via ALPN anyway).
- The 1-hour upload timeout now bounds the entire upload rather than
each socket write — arguably the intended meaning for that endpoint.

## Testing

- `tests/{sync,async}/*/test_upload_file.py` (the #1243 regression tests
— Content-Length present and equal to the body, no chunked encoding)
pass through pyqwest; the capture handlers now compare header names
case-insensitively since hyper lowercases them where httpcore
title-cased.
- New in both mirrors: `test_upload_file_leaves_redirects_to_httpx` — a
307 on the upload URL surfaces as `FileUploadException` and the capture
server sees exactly one PUT, guarding against reqwest silently following
the hop and replaying the archive.
- Lint (`ruff`), typecheck (`ty`), upload-file suites: green (10/10).

## Usage example

No API changes — template builds upload their context exactly as before:

```python
from e2b import Template

template = Template().from_image("ubuntu:22.04").copy("data/", "/data")
Template.build(template, alias="my-template")   # archive upload now goes through pyqwest
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-10 19:46:38 +02:00
Mish Ushakov 458c2c4362 feat(python-sdk): move the volume content client onto pyqwest (#1602)
## What

Stacked on #1601. Migrates the **volume content client**
(`Volume`/`AsyncVolume` file operations) onto
[pyqwest](https://github.com/curioswitch/pyqwest) via its
httpx-compatible transport adapter — the same stock httpx transport
adapter + connection-retry stack the REST API client uses after #1601.

Originally deferred from #1601 because
`Volume.read_file(format="stream")` relied on httpx's per-read `read`
timeout as an *idle* timeout, which the adapter can't express per
request (it converts the httpx timeout dict into a whole-request
deadline, and the sync adapter doesn't bound body reads at all).
Unblocked by pyqwest's transport-constructor `read_timeout`, which maps
to reqwest's `ClientBuilder::read_timeout` — verified behaviorally
(local slow-chunk server, sync + async) to be a true per-read idle
timeout: it resets after each successful read, covers body reads, and a
healthy stream longer than the timeout completes untouched.


> [!NOTE]
> Rebased onto #1601, which maps `httpx.Proxy` onto pyqwest's `Proxy`
object and locks pyqwest 0.9.0. Following that: this PR builds its
transport from `proxy_to_config(...)` instead of `proxy_to_url(...)`,
uses the stock `PyqwestTransport`/`AsyncPyqwestTransport` (0.9.0's
adapter drops the redundant `Host` header and maps pyqwest's timeouts
and connection, network, and protocol failures to their httpx
counterparts, so the SDK's transport subclasses are gone), and turns
reqwest's internal redirects off so httpx owns them, as the generated
volume client expects.

## How

- `e2b/volume/client_sync/__init__.py` / `client_async/__init__.py` move
to the same stock adapter + connection-retry stack as the API client.
Caches become process-global, keyed by (proxy, streaming) — previously
one pool per thread (sync) / per event loop (async).
- Streamed downloads go through a **dedicated streaming transport** with
`read_timeout=60s`. It can't live on the shared transport: reqwest's
read timer keeps running while a request body is sent and while waiting
for the response head (verified empirically — a 2.4 s upload against a
0.5 s `read_timeout` dies mid-send), so a shared `read_timeout` would
cut off `write_file` uploads and slow unary responses longer than the
idle bound. Uploads and unary calls stay on a transport without it,
bounded by their whole-request deadlines as before.
- The 60 s default matches the JS SDK exactly: JS bounds stream start by
`requestTimeoutMs` (60 s default) and idle gaps by `streamIdleTimeoutMs
?? requestTimeoutMs`; the Python streaming transport's `read_timeout`
bounds the response head and each idle gap at 60 s, resetting on every
chunk, wire-only (a slow consumer doesn't trip it — verified).
- `AsyncVolume.read_file` keeps honoring an explicit
`stream_idle_timeout` **per call**, the same way JS honors
`streamIdleTimeoutMs` and #1558 bounds stream setup: `asyncio.wait_for`
around each read (response head and every chunk). Explicit values run on
the *regular* transport, so a value above the 60 s transport bound isn't
capped by it and `0` disables idle bounding entirely, restoring the
previous contract. The sync client keeps the parameter but **ignores**
it — it has no way to interrupt a blocking read into the Rust transport,
so its bound must live in the transport.
- Streamed reads are sent without a per-request timeout so the adapter
imposes no whole-request deadline on long downloads; an explicitly
passed `request_timeout` becomes the total-transfer deadline.
- A stalled read surfaces as `httpx.ReadTimeout`, keeping the
established contract: the 0.9.0 adapter maps its own timeouts, and the
async flavor remaps the per-read `stream_idle_timeout` (an
`asyncio.wait_for` expiry) to match.
- Proxy narrowing follows #1601: `str`, `httpx.URL`, and reducible
`httpx.Proxy` values work; inexpressible extras raise
`InvalidArgumentException`.

## Testing

- `tests/test_volume_client.py` rewritten: process-global transport
caching (shared across threads and event loops), streaming vs regular
transport separation, plus end-to-end streamed reads through
`Volume.read_file`/`AsyncVolume.read_file` against a local chunked
server — a healthy stream longer than the idle timeout completes (proves
the timeout resets per read), a mid-body stall raises
`httpx.ReadTimeout`, a slow response head on a *non-streamed* read is
not cut off by the idle bound, and a slow response head on a streamed
read is (JS handshake-timeout parity). Async `stream_idle_timeout`: an
explicit value aborts a stall, a value above the transport bound isn't
capped by it, and `0` disables idle bounding.
- Volume content integration tests couldn't run end-to-end (the test
team's key gets `403: use of volumes is not enabled`); the
mock-transport volume content tests and the local-server stream tests
cover that path.
- Lint (`ruff`), typecheck (`ty`), unit suite: green.

## Usage example

No API changes for the common path:

```python
volume = Volume.connect(volume_id, token=token)
stream = volume.read_file("big.bin", format="stream")     # stalls bounded by the
for chunk in stream:                                      # transport-wide idle read
    ...                                                   # timeout (httpx.ReadTimeout)

volume.read_file("big.bin", format="stream", stream_idle_timeout=5)  # sync: accepted, ignored

async_volume = await AsyncVolume.connect(volume_id, token=token)
stream = await async_volume.read_file(
    "big.bin", format="stream", stream_idle_timeout=5     # async: honored per read,
)                                                         # 0 disables idle bounding
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-10 19:46:37 +02:00
Mish Ushakov a874ced97a feat(python-sdk): move the REST API client onto pyqwest's httpx transport adapter (#1601)
## What

Migrate all httpx REST API client traffic in the Python SDK — the E2B
control plane (sandbox lifecycle, listing, templates, volumes control
plane) — to [pyqwest](https://github.com/curioswitch/pyqwest) (Rust
reqwest/hyper), using its httpx-compatible transport adapter
(`pyqwest.httpx.PyqwestTransport` / `AsyncPyqwestTransport`). The
generated openapi client and `ApiClient`/`AsyncApiClient` keep their
httpx surface — logging event hooks, per-request timeouts, headers, and
redirects behave as before — only the transport underneath is swapped.

envd RPC already runs on pyqwest via connectrpc (#1558). This PR touches
only the control-plane client; the rest of the stack builds on it: #1623
(envd HTTP API client), #1602 (volume content client), #1603 (template
uploads).

Requires **pyqwest 0.9** — pinned in `pyproject.toml` (`>=0.9.0,<0.10`)
with `uv.lock` refreshed. 0.8 brought the `Proxy` object
([pyqwest#194](https://github.com/curioswitch/pyqwest/pull/194)) and
request loggers
([pyqwest#197](https://github.com/curioswitch/pyqwest/pull/197)); 0.9
([release
notes](https://github.com/curioswitch/pyqwest/discussions/214)) folds
the two adapter workarounds this PR used to carry into the adapter
itself and makes redirect handling configurable, so the SDK no longer
subclasses the adapter at all.

## How

- `e2b/api/client_sync/__init__.py` / `client_async/__init__.py`:
`get_transport` now returns a pyqwest-backed httpx transport — a
`SyncHTTPTransport`/`HTTPTransport` (`tls_include_system_certs=True`,
proxy, pool tuning mapped from
`E2B_KEEPALIVE_EXPIRY`/`E2B_MAX_KEEPALIVE_CONNECTIONS`), wrapped in a
`ConnectionRetryTransport` for connect-only retries honoring
`E2B_CONNECTION_RETRIES`, wrapped in the stock
`PyqwestTransport`/`AsyncPyqwestTransport` httpx adapter.
- pyqwest transports are thread-safe and loop-independent (I/O runs on a
Rust tokio runtime), so the caches are process-global keyed by proxy —
previously one pool per thread (sync) / per event loop (async).
- **`ApiClient` sheds its threading machinery**: the
`transport_factory`/`async_transport_factory` plumbing, the thread-local
`httpx.Client` cache, and the per-loop `WeakKeyDictionary` of
`AsyncClient`s are gone. A single lazily-created httpx client (the
generated base behavior, the same shape the volume client already uses)
serves all threads and event loops; `httpx.Client` is documented
thread-safe and nothing below it is loop-bound. Closing that client
can't tear down the shared pool — the adapter transports don't override
`close()`/`aclose()`.
- **Host header** (upstream in 0.9): sending the `Host` header httpx
auto-adds on an HTTP/2 connection makes the E2B API edge reset the
stream with `PROTOCOL_ERROR` (reproduced with plain pyqwest against
`api.e2b.app`); hyper derives `Host`/`:authority` from the URL. The
adapter now skips a `host` header matching the URL, so the SDK-side
strip is gone — and unlike that strip, a genuinely custom `Host`
override is still forwarded.
- **Timeout exceptions** (upstream in 0.9): pyqwest raises the builtin
`TimeoutError`; the adapter maps it to `httpx.ReadTimeout` both while
awaiting the response head and while reading the body, preserving the
`httpx.TimeoutException` contract for callers. Connection, network, and
protocol failures likewise arrive as
`httpx.ConnectError`/`ConnectTimeout`, `httpx.ReadError`/`WriteError`,
and `httpx.RemoteProtocolError` instead of leaking pyqwest/builtin
types.
- **Redirects**: the pyqwest transports are built with
`follow_redirects=False` (0.9 made it configurable; reqwest's default is
to follow). Otherwise redirects are followed inside the transport,
hiding 3xx responses from httpx and leaving `response.history` empty —
even though the generated clients ask for no redirect following. httpx
owns them again, as with the transports this replaced.
- **Proxy**: `proxy=` accepts a URL string, `httpx.URL`, or an
`httpx.Proxy` — including its credentials (sent as
`Proxy-Authorization`) and any headers configured for the proxy, via
pyqwest's `Proxy` object. `proxy_to_config` normalizes all three into a
`ProxyConfig` tuple that both keys the transport cache and builds the
`pyqwest.Proxy`, so the same proxy URL with different credentials or
headers gets its own pool. A per-proxy `ssl_context` has no counterpart
and raises `InvalidArgumentException` rather than being silently
dropped. (`ProxyConfig` is a `NamedTuple`, not a frozen dataclass:
`tests/test_env_var_parsing.py` reloads `e2b.api`, and a dataclass
`__eq__` compares class identity, so keys built before and after a
reload would silently stop matching.)
- **`ProxyTypes` is ours now**: the public type of the `proxy` option
(already exported from `e2b`) used to be imported at runtime from
httpx's private `_types` module in eleven modules. It is defined there
as `Union[str, URL, Proxy]` — exactly the three forms the SDK's two
narrowers accept — so it's spelled out once in `e2b.connection_config`
and imported from there. Same public name, same type to a type checker,
no private-module dependency, and a place for a pyqwest proxy type to
land as the remaining transports move off httpx.
`e2b.envd.client_shared.proxy_to_url` took a bare `object` while
`e2b.api.proxy_to_config` took `Optional[ProxyTypes]`; both now say the
same thing. `isinstance` narrowing stays rather than duck-typing
`.url`/`.auth` — httpx is a required dependency here (the generated REST
client *is* an httpx client, and envd file transfers use httpx
directly), so probing attributes would trade a clear
`InvalidArgumentException` on a mistyped argument for no dependency
savings.
- **Request logs**: pyqwest logs one line per request on the
`pyqwest.access` logger and lifecycle records on `pyqwest`, both at
`DEBUG` — the transport-level diagnostics httpcore used to provide, now
that httpcore is out of the path. Noted on `get_transport`; the SDK's
own `logger` option is unchanged and sits above it on the httpx client.
- **HTTP/2**: negotiated via ALPN for TLS connections (reqwest default),
equivalent to the `http2=True` transports this replaces.

## What stays behind (handled by the stacked PRs)

- **envd HTTP API client** (file transfers, health checks): #1623, which
also dedupes the transport plumbing this PR and #1558 each carry a copy
of (the proxy narrowing, pool tuning, retry transport — envd keeps
byte-identical duplicates until then).
- **Volume content client**: its streaming download relies on httpx's
per-read `read` timeout as an *idle* timeout, which the adapter can't
express per request — #1602.
- **Template build context upload**: one-off httpx client PUTing to S3
presigned URLs — #1603.

## Timeout semantics note

`request_timeout` was previously httpx's per-phase timeout
(connect/read/write each bounded separately, so a slow multi-phase
request could exceed it in total). Through the adapter it becomes an
overall deadline per API call (async: headers + body; sync: up to
response headers). For the SDK's REST calls — all unary with small JSON
bodies — this is a tightening, arguably closer to what `request_timeout`
promises.

## Testing

- `tests/test_api_client_transport.py` rewritten for the new semantics:
global per-proxy transport caching, a single httpx client shared across
threads/loops (including 32-way concurrent request tests against a local
server), timeout → `httpx.ReadTimeout` mapping for both the response
head and a stalled body (slow/stalling local server), redirects
surfacing to httpx (302 returned as-is, `response.history` populated
when the caller opts in), the connection-only retry policy,
`proxy_to_config` conversion, and sync+async round-trips through a real
local HTTP server exercising pyqwest end to end. The two host-header
unit tests are gone with the subclasses they tested — that behavior is
the adapter's now.
- Two tests cover the pyqwest proxy/logging surface: an echo server
standing in for a proxy asserts that the absolute-form request target,
`Proxy-Authorization`, and the extra proxy header actually arrive, and
the `pyqwest.access` record is asserted for an API call.
- On pyqwest 0.9.0 from PyPI: `uv sync --locked`, unit suite
(`tests/*.py`, 238 passed), `ruff check`, `ty check` — all green.
- Integration against the production API (real key) was run on 0.8.0:
`tests/sync/api_sync`, `tests/async/api_async`,
create/kill/timeout/connect — all green. (These initially failed with
`RemoteProtocolError: StreamReset` until the host header stopped being
forwarded, so they genuinely exercise the new stack; that fix now comes
from the adapter.)

## Usage example

No API changes for the common path:

```python
from e2b import Sandbox

sbx = Sandbox.create()          # control-plane calls now go through pyqwest
Sandbox.list()
sbx.kill()
```

Proxy handling — URL strings and `httpx.Proxy` objects work, credentials
and proxy headers included:

```python
Sandbox.create(proxy="http://user:pass@localhost:8030")            # ok (unchanged)
Sandbox.create(proxy=httpx.Proxy("http://localhost:8030",
                                 auth=("user", "pass")))           # sent as Proxy-Authorization
Sandbox.create(proxy=httpx.Proxy("http://localhost:8030",
                                 headers={"X-Auth": "t"}))         # sent to the proxy
Sandbox.create(proxy=httpx.Proxy("https://localhost:8030",
                                 ssl_context=ctx))                 # raises InvalidArgumentException
```

`ProxyTypes` — already exported from `e2b` — is now defined by the SDK
rather than re-exported from `httpx._types`, with the same three
members:

```python
from e2b import ProxyTypes   # Union[str, httpx.URL, httpx.Proxy]
```

Transport-level HTTP logs, replacing the httpcore records this migration
removes:

```python
import logging

logging.basicConfig()
logging.getLogger("pyqwest.access").setLevel(logging.DEBUG)

Sandbox.create()
# DEBUG pyqwest.access - HTTP Request: POST https://api.e2b.app/sandboxes "HTTP/2 201 Created"
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-10 19:46:37 +02:00
Mish Ushakov cab27aa6fa fix(sdk): clean up sandbox when MCP gateway startup fails (#1548)
## Problem

Fixes #1498.

`Sandbox.create` allocates a remote sandbox before starting
`mcp-gateway`. If gateway startup fails, creation throws before the
sandbox object is returned. As a result, the caller has no sandbox ID to
clean up, and the orphaned sandbox continues consuming resources until
it times out.

This state transition exists in synchronous Python, asynchronous Python,
and JavaScript/TypeScript.

## Changes

- Add a rollback boundary around MCP gateway startup in all three SDK
implementations: on failure, best-effort kill the newly allocated
sandbox, then re-raise.
- Surface gateway startup failure as `SandboxError` (JS) /
`SandboxException` (Python) with a `Failed to start MCP gateway:
<stderr>` message. Previously the intended message was unreachable dead
code — foreground `commands.run` already throws on non-zero exit — so
callers got a bare `CommandExitError`/`CommandExitException`.
- In async Python, re-raise `asyncio.CancelledError` from the
best-effort `kill()` so caller cancellation (e.g. `asyncio.timeout`) is
honored; only ordinary cleanup failures are suppressed and never mask
the original error.
- Add integration coverage for synchronous Python, asynchronous Python,
and TypeScript. The tests pin the sandbox to the base template (which
has no `mcp-gateway` binary) so gateway startup genuinely fails after
allocation.
- Add a patch changeset for `e2b` and `@e2b/python-sdk`.

## Usage Behavior

No API changes. A failed creation no longer leaves a sandbox behind, and
the error is now descriptive:

```ts
try {
  const sandbox = await Sandbox.create({ mcp: { ... } })
} catch (err) {
  // err is SandboxError: "Failed to start MCP gateway: <stderr>"
  // the allocated sandbox has already been killed — no orphan is left running
}
```

## Validation

All three integration tests verified against real infra: creation
rejects with the documented error and no sandbox remains.

## Notes

Supersedes #1547 by @hxaxd (squash-merged into this branch to preserve
attribution).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: 苏紫辰 <155808914+hxaxd@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 17:26:08 +02:00
github-actions[bot] e6111419b5 [skip ci] Release new versions e2b@2.38.2 2026-08-07 14:48:17 +00:00
Mish Ushakov d5a382ed67 chore(js-sdk): bump undici to ^7.29.0 and optional undici8 to 8.10.0 (#1645)
Bumps both undici dependencies in the js-sdk past the 2026-07-24
security advisories: the required `undici` from `^7.28.0` to `^7.29.0`,
and the optional `undici8` (`npm:undici@…`) from 8.8.0 to 8.10.0. Both
releases patch one High
([GHSA-4cwx-7wf7-3272](https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272),
cache-control parsing / cross-user disclosure) and four Medium
advisories, clearing the open Dependabot alerts for undici; 8.10.0
additionally fixes HTTP/2 request settling, refused-stream retries and
GOAWAY handling, which we exercise because every dispatcher the SDK
builds sets `allowH2: true`.

A root `pnpm.overrides` entry (`undici@>=7.0.0 <7.29.0`) is included
because miniflare pins undici at exactly 7.28.0, which would otherwise
keep a vulnerable copy in the lockfile; with it, the lockfile carries
only 7.29.0 and 8.10.0. No code change was needed and there is no
user-facing API change — 7.29.0 still requires Node `>=20.18.1` and
8.10.0 still requires `>=22.19.0`, matching the `UNDICI_8_MIN_NODE` gate
in `packages/js-sdk/src/undici.ts`, so `getUndiciPackageCandidates()`
picks the same package on the same Node versions.

`format`, `lint` and `typecheck` pass, `tests/undici.test.ts` is 9/9,
and `test:cf` was run to confirm miniflare still boots on the overridden
undici. The remaining vitest projects need `E2B_API_KEY`, which isn't
available locally, so they're left to CI. A patch changeset for `e2b` is
included.

Linear:
[SDK-317](https://linear.app/e2b/issue/SDK-317/js-sdk-bump-optional-undici8-dependency-to-8100)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 14:29:06 +00:00
Mish Ushakov 6cce3fde9d ci: pin GitHub Actions to full commit SHAs (#1646)
Every external action in `.github/` is now referenced by a 40-character
commit SHA with the release tag as a trailing comment, so a compromised
or retagged upstream release cannot silently change what runs in CI —
this covers 78 `uses:` refs across 15 files, leaving in-repo
`./.github/...` composite-action and reusable-workflow refs as-is since
they are not a supply-chain surface. Each SHA was resolved from the tag
the workflow already floated on and re-verified against the GitHub API,
so the change is behaviour-preserving; all 15 files were also re-checked
as valid YAML.

Two pins are worth a reviewer's attention:

- **`pnpm/action-setup` is pinned to v4.3.0, not v4.4.0.** Upstream's
`v4.4.0` tag points at the same commit as `v5.0.0`, while the floating
`v4` tag we were on still resolves to v4.3.0 — pinning to v4.4.0 would
have silently jumped a major.
- **`actions/checkout@v3` and `actions/create-github-app-token@v1` are
pinned at their latest v3/v1 SHAs rather than bumped** to v4/v2, keeping
this PR to pinning alone; bumping those majors is a good follow-up.

A second commit unifies `dorny/paths-filter`, which was the one action
already pinned (at v3.0.3 in the Dependabot changeset workflow) and
would otherwise have left the repo carrying two SHAs for the same
action; its comment justified the pin as being "rather than floating on
`v3`", which no longer distinguishes it now that everything is pinned,
so it is rewritten to keep only the still-relevant `pull_request_target`
warning.

One gap this PR does not close: there is no `.github/dependabot.yml` in
the repo, so nothing will keep these SHAs current and they will drift
away from upstream security fixes — adding a `github-actions` ecosystem
entry (which understands SHA pins with version comments and bumps both)
is worth doing separately. No SDK or CLI package is touched, so no
changeset is needed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 07:16:51 -07:00
github-actions[bot] 2d2823c94a [skip ci] Release new versions @e2b/python-sdk@2.37.1 e2b@2.38.1 2026-08-07 14:15:10 +00:00
Mish Ushakov 88f41f3927 fix(python-sdk): port current JS stripAnsi regex to strip_ansi_escape_codes (#1545)
## Summary

The Python SDK's `strip_ansi_escape_codes` (used to clean template build
log messages) still used the old ansi-regex pattern, while the JS SDK's
`stripAnsi` was rewritten in #895. This ports the current JS regex to
Python so both SDKs clean logs identically: OSC sequences (hyperlinks,
window titles) are matched non-greedily up to the first string
terminator — including content spanning newlines — and CSI sequences are
stripped without requiring a terminator.

Following review feedback, both implementations now also strip the
remaining ECMA-48 string controls — DCS (Sixel, tmux passthrough), SOS,
PM, and APC — through their string terminator, so control payloads don't
leak into cleaned logs. This goes beyond upstream `chalk/ansi-regex`,
click, and Rich, none of which fully strip DCS payloads, and restores
what the old Python pattern handled.

Also mirrors the Python test suite into the JS SDK (which previously had
no `stripAnsi` tests) — 20 identical cases per side — and verified
byte-for-byte identical output between the two implementations on all of
them. Includes a patch changeset for `e2b` and `@e2b/python-sdk`.

## Example

Log messages that previously leaked OSC or DCS sequences into template
build output are now cleaned:

```python
from e2b.template.utils import strip_ansi_escape_codes

strip_ansi_escape_codes("\x1b]8;;https://e2b.dev\x07E2B\x1b]8;;\x07")  # "E2B"
strip_ansi_escape_codes("\x1b]0;title\nstill title\x07done")           # "done"
strip_ansi_escape_codes("\x1b[38:2::255:0:0mRED\x1b[0m")               # "RED"
strip_ansi_escape_codes("\x1bPq#0;2;0;0;0~~@@\x1b\\image")             # "image" (Sixel DCS)
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 15:04:40 -07:00
Mish Ushakov 26ee42c10a chore: upgrade pnpm to 10.34.5 and delay fresh releases by 3 days (#1644)
Bumps pnpm 9.15.5 → 10.34.5 in all three places it is pinned
(`.tool-versions`, the root `packageManager` field, and
`codegen.Dockerfile` — pnpm 10 self-manages from `packageManager`, so a
mismatched Docker pin would make it re-download itself on every `make
generate`) and sets `minimumReleaseAge: 4320` in `pnpm-workspace.yaml`,
so a freshly published version is not resolved until it is 3 days old;
CI is unaffected because every workflow installs with
`--frozen-lockfile` and nothing installs a just-published package.

Two pnpm 10 breaking changes needed handling: dependency lifecycle
scripts no longer run by default, so `esbuild` and `workerd` are
allowlisted via `pnpm.onlyBuiltDependencies` for binary resolution while
`bufferutil`, `msw`, and `utf-8-validate` are explicitly declined via
`pnpm.ignoredBuiltDependencies` (which also keeps the "Ignored build
scripts" warning off every install); and pnpm 10 stopped public-hoisting
`*prettier*`/`*eslint*`, which broke `pnpm run format` in both JS
packages with `prettier: command not found` — prettier was never
declared anywhere and only resolved because pnpm 9 hoisted it out of
`json-schema-to-typescript`, so it is now a root devDependency alongside
`oxlint`, resolved to the 3.6.2 already in the lockfile for zero
formatting churn.

`engines.pnpm` moves to `>=10.16.0 <11` so, with `engine-strict`, pnpm 9
fails with an actionable "install the required pnpm version globally"
message instead of silently installing.

Verified with a clean `node_modules` + `--frozen-lockfile` install and
green `lint`, `typecheck`, `format`, and both JS builds, plus a
from-scratch re-resolve of the whole tree to confirm
`minimumReleaseAgeStrict` (which silently defaults to `true` once the
age is set explicitly) does not trap any current range; enforcement was
checked empirically — with the setting, `wrangler@^4` resolves to
4.118.0 (6d old) rather than 4.119.0 (1d old). The lockfile diff is
limited to the prettier entry plus pnpm 10's importer-section reordering
and new `libc:` fields, with no dependency version drift.

No changeset: nothing in a published package changed. A follow-up to
pnpm 11 is deliberately out of scope — it removes both build-script
fields in favor of `allowBuilds`, restricts `.npmrc` to auth/registry
settings, and replaces the npm-delegating `pnpm publish`, which the
release flow depends on.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 16:29:18 +02:00
Mish Ushakov 998e560a1a fix(python-sdk): relax wcmatch constraint to >=10.1,<12 (#1638) 2026-08-05 19:08:11 +02:00
Mish Ushakov 86f7b8e2f8 fix(js-sdk): export the Git argument and status types (#1642)
Carries the change from #1635 (by @karpovantonme) into `main` as a
single squash commit — #1635 was retargeted at
`fix/export-git-argument-types`, merged there, and this PR promotes that
branch.

`Git.reset()`, `Git.restore()` and `Git.status()` are public, but the
types naming their arguments and results were not reachable from the
package entry point.

`src/index.ts` re-exported fifteen `Git*` types and omitted
`GitResetMode`, `GitResetOpts` and `GitRestoreOpts`. `GitStatusLabel`
was worse off — `src/sandbox/git/index.ts` re-exported `GitBranches`,
`GitConfigScope`, `GitFileStatus` and `GitStatus` from `./utils` but not
`GitStatusLabel`, so it was unreachable from anywhere in the package,
even though it is the type of `GitFileStatus.status`.

The practical effect: you could call the methods, but you could not name
what you pass them, so you could not write a typed wrapper.

```ts
// before — all four fail
import type {
  GitResetMode,
  GitResetOpts,
  GitRestoreOpts,
  GitStatusLabel,
} from 'e2b'

// the workaround people end up with
type ResetMode = Parameters<Git['reset']>[0] extends { mode?: infer M } ? M : never
```

```ts
// after
import { Sandbox } from 'e2b'
import type { GitResetMode, GitResetOpts, GitStatusLabel } from 'e2b'

async function hardResetTo(sbx: Sandbox, repo: string, target: string) {
  const mode: GitResetMode = 'hard'
  const opts: GitResetOpts = { mode, target, cwd: repo }
  return sbx.git.reset(opts)
}

function isBlocking(status: GitStatusLabel) {
  return status === 'conflict' || status === 'deleted'
}
```

## On SDK parity

Python already exports `GitResetMode` (`e2b.GitResetMode`), so this
brings JS up to it. The other three have no Python counterpart by
design: the sync and async implementations take keyword arguments rather
than option objects, so there is nothing shaped like
`GitResetOpts`/`GitRestoreOpts`, and `GitFileStatus.status` is typed as
a plain `str` there, so there is no `GitStatusLabel` either. Nothing to
mirror on the Python side.

## Notes

- Type-only re-exports, no runtime change. Changeset included (`e2b`:
patch).
- No test: a missing re-export is invisible to `tsc --noEmit` because
`packages/js-sdk/tsconfig.json` includes only `src`, so an `import type
… from '../src'` test passes either way. A declaration-reading test was
dropped from #1635 during review.

## Not touched

The same gap exists for a few non-Git types — `FilesystemListOpts`,
`WatchOpts`, `PtyCreateOpts` and `PtyConnectOpts` are exported from
their own modules but not from `src/index.ts`. Scope kept to the Git
surface, as in #1635.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Anton Karpov <30812217+karpovantonme@users.noreply.github.com>
Co-authored-by: Anton Karpov <karpovantonme@gmail.com>
2026-08-05 15:49:02 +02:00
Mish Ushakov 9c555a12aa ci: add a changeset to Dependabot pull requests automatically (#1639)
Dependabot bumps of a direct production dependency of `e2b`, `@e2b/cli`
or `@e2b/python-sdk` need a changeset to reach users, and they kept
merging without one (#1461, #1443). This workflow commits a `patch`
changeset naming every released package the bump touches, and stays out
of the way otherwise — dev-only bumps, transitive-only lockfile bumps,
and pull requests that already carry a hand-written changeset are all
skipped. The push uses the version-bumper App token rather than
`GITHUB_TOKEN`, whose commits do not start workflow runs, so the
required checks would never report on the new head commit and the pull
request would be unmergeable.

For #1461 it would have committed `.changeset/dependabot-1461.md`:

```md
---
'e2b': patch
---

Update the `undici` dependency to 7.28.0.
```

The `changes` job now skips the Dependabot metadata lookup once a
changeset is on the branch, so the workflow's own commit never sends
`fetch-metadata` looking for metadata on a pull request that is no
longer all-Dependabot commits, and `dorny/paths-filter` is SHA-pinned as
the one third-party action this trigger reaches.

Verified by running the commit step against a scratch repository with
the exact expression outputs for single-package, grouped multi-package
and Python-only bumps, then parsing each result with changesets' own
`@changesets/parse`. Two things to watch on the first live run: the
org-level `verification/cla-signed` check has to accept the App's
commit, and adding a commit stops Dependabot auto-rebasing the branch
(`@dependabot rebase` still works, and the workflow rewrites the
changeset afterwards).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

SDK-311

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 16:20:31 +02:00
github-actions[bot] 7a1fe4528c [skip ci] Release new versions @e2b/python-sdk@2.37.0 e2b@2.38.0 2026-08-03 19:45:46 +00:00
Joe Lombrozo 2821fb0b69 feat(sdk): route volume content to BYOC cluster domain (#1634)
When a team is connected to a custom (BYOC) cluster, the volume API now
returns that cluster's domain in the create and get responses. The JS
and Python (sync + async) SDKs use this domain as the destination for
volume content requests instead of the default api.<E2B_DOMAIN> host,
falling back to the configured domain when none is returned.

The domain field is read defensively from the response until
spec/infra-ref is bumped to the infra commit that adds it and `make
codegen` regenerates the typed schema.


Claude-Session: https://claude.ai/code/session_01212WCmNz1prPKrjhTv2PDj

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Matt Brockman <matt.brockman@e2b.dev>
2026-08-03 10:24:15 -07:00
github-actions[bot] 9ef3f1dbbe [skip ci] Release new versions @e2b/cli@2.16.1 @e2b/python-sdk@2.36.0 e2b@2.37.0 2026-07-31 19:39:47 +00:00
Mish Ushakov 1ebe925ee0 fix(js-sdk): detect web platform objects by shape, not by class (#1618)
SDK-299

## Symptom

Two shapes of failure, one cause.

Every control-plane call crashing in an app that embeds the SDK next to
a server shim:

```
TypeError: Failed to parse URL from [object Request]
    at fetch (…/undici/index.js:157:10)
    at wrapped (…/e2b/src/undici.ts:126)
```

…and, quietly, uploads that arrive at the sandbox containing the eight
bytes `[object Blob]` instead of the file.

## Root cause

`value instanceof Blob` does not answer *"is this a Blob"*, it answers
*"was this minted by the `Blob` class this module happens to see"*. In a
Node process those are different questions: libraries replace the web
globals exactly the way they replace `globalThis.fetch` —
`@hono/node-server` installs its own `Request`, remix's
`installGlobals()` swaps `Request`/`Blob`/`File`, `web-streams-polyfill`
swaps `ReadableStream`, jsdom-style test environments bring their own
copies of all of them — and values also cross realms (`node:vm`,
`worker_threads`). `src/undici.ts` already late-binds the global `fetch`
for this reason; the brand checks never got the same treatment.

It is reachable with a **single** shim install, no exotic dependency
duplication:

1. `openapi-fetch` captures `Request: CustomRequest =
globalThis.Request` when the client is created (`dist/index.mjs:11`) and
mints every request from it,
2. `EnvdApiClient` is built once in the `Sandbox` constructor and stored
(`src/sandbox/index.ts:201`), so it outlives anything that swaps the
global afterwards,
3. from then on the SDK checks each request against a class that did not
mint it. Which copy "wins" the global is import-order dependent, so the
crash appears and disappears with unrelated dependency changes.

Verified locally, frame for frame: real `undici`/`undici8` throw
`TypeError: Failed to parse URL from [object Request]` for **any**
`Request` they did not mint — including Node's native one — so the
destructure in `toUndiciRequestInput` is load-bearing and a missed brand
check is fatal rather than merely slower.

## The whole family

Every brand check on the data path had the same defect, and each one
failed differently:

| Site | Misfires on | User-visible effect |
| --- | --- | --- |
| `undici.ts` `toUndiciRequestInput` | foreign `Request` | **every API
call throws** `Failed to parse URL from [object Request]` |
| `api/inflight.ts` `limitConcurrency` | foreign `Request` | abort
signal ignored while the request waits for a slot |
| `utils.ts` `toBlob` | foreign `Blob` | upload body is the text
`"[object Blob]"` |
| `utils.ts` `toBlob` | foreign `ReadableStream` | upload body is the
text `"[object ReadableStream]"` |
| `utils.ts` `toUploadBody` (gzip) | foreign `ReadableStream` |
`pipeThrough(new CompressionStream())` never settles — the upload hangs
|
| `utils.ts` `toUploadBody` | foreign `ReadableStream` | file buffered
into memory instead of streamed (OOM on large files) |
| `filesystem/index.ts` `hasStreamableData` | foreign `ReadableStream` |
same, plus the multipart path is chosen for a stream |
| `volume/index.ts` `readFile` | foreign `Blob`/`ArrayBuffer` |
**returns an empty file** |
| `undici.ts` `toUndiciRequestInput` (body) | foreign `Request`'s stream
body | body sent as the text `"[object ReadableStream]"` |

The `Blob`/stream rows are silent data corruption, confirmed against
real undici:

```js
await new Response(foreignBlob).text() // → "[object Blob]"
await new Response(foreignStream).text() // → "[object ReadableStream]"
```

## Fix

New internal `src/is.ts` asks what a value *is*: `instanceof` stays the
fast path, then it falls back to the members and `Symbol.toStringTag`
the platform guarantees (`isRequestLike`, `isBlobLike`,
`isReadableStreamLike`, `isArrayBufferLike`). Nothing is added to the
public surface.

Detection alone is not enough where the SDK hands data back to the
platform — the platform brand-checks too, and a detected-but-not-adopted
foreign stream would be stringified instead of buffered, i.e. worse than
before. So the conversions adopt what they detect:

- `toBlob` copies a foreign `Blob`'s bytes (`new Blob([await
data.arrayBuffer()], { type: data.type })`) and pumps a foreign stream
through a native one via its reader;
- the adoption itself is not class-dependent, which took two rounds to
get right (see *Adoption* below);
- `toUploadBody` returns `{ body, streamed }` instead of leaving
`filesystem`/`volume` to re-derive "did it stream?" with another brand
check on the result — only that function knows the decision it made.

### What used to break

```ts
import { serve } from '@hono/node-server' // installs its own globalThis.Request
import { Sandbox } from 'e2b'

const sandbox = await Sandbox.create()
await sandbox.files.write('/tmp/a.txt', 'hi') // TypeError: Failed to parse URL from [object Request]
```

```ts
import { ReadableStream } from 'web-streams-polyfill' // not the native class

// Used to upload the literal text "[object ReadableStream]"; with gzip it hung.
await sandbox.files.write('/tmp/big.bin', bigPolyfillStream, { gzip: true })
```

### Adoption

The platform accepts exactly two kinds of stream body: **its own
class**, and **any async iterable** (verified against `undici@8`/Node —
everything else is stringified). Async iterability is the half that
survives a replaced global, since a native stream stays async-iterable
even when `globalThis.ReadableStream` is a polyfill. Hence two helpers,
each named for the contract it satisfies:

- `toDispatchableStream` — for request bodies: passes through the
platform's own class *or* an async iterable, adopts the rest. Adopting
on `!(stream instanceof ReadableStream)` alone would have been
class-dependent in the same way as the bug: with a polyfilled global, a
perfectly good native stream fails the check and gets re-wrapped into a
polyfill instance the platform likes *less*.
- `toNativeStream` — for `pipeThrough(new CompressionStream(…))`, the
stricter consumer: it insists on its own class, so async iterability is
not enough there and every foreign stream is adopted.

Everything that isn't already a stream reaches the gzip path through
`toBlob`, whose result is always a native `Blob`, so the gzip path needs
no blob branch of its own. That in turn means nothing ever calls
`stream()` on a `Blob` the SDK didn't make, so `isBlobLike` only
requires `arrayBuffer` beyond the tag — one less requirement is one less
implementation whose upload would silently be the text `"[object
Blob]"`.

The same reasoning applies one level down: a `Request` from another
fetch implementation exposes *that* implementation's stream as its
`body`, so accepting the Request without adopting its body would only
move the stringification, not remove it.

## Tests

`tests/foreignPlatformObjects.ts` provides the fixtures: `ForeignBlob`
and `foreignReadableStream` are separate implementations rather than
subclasses (a subclass still passes `instanceof`, so it would prove
nothing), and `foreignRequestClasses()` returns two sibling subclasses
of the native `Request` — instances of one are fully functional Requests
that the other disowns, which is what the shims actually produce.

- `tests/is.test.ts` — the four predicates, including the negatives that
keep them honest (a `URL`, a string, an `IncomingMessage`-shaped `{ url,
method, headers }`).
- `tests/utils.test.ts` — content round-trips for
`toBlob`/`toUploadBody` across native/foreign `Blob`s and streams, plus
a gzip round-trip through `DecompressionStream` for all four input
kinds.
- `tests/undici.test.ts` — a disowned `Request` reaches undici
destructured as `(url, init)`; and, on Node, the same request goes
through the **real** undici `fetch` (via `MockAgent`, so no network) and
is matched on method, path and headers.
- `tests/api/inflight.test.ts` — an already-aborted disowned `Request`
rejects with `AbortError` without consuming a slot.

Each adoption rule has a test that fails without it: dropping the
async-iterable clause fails the "does not re-wrap a native stream when
the global class was replaced" case, using `toDispatchableStream` in the
gzip path fails the async-iterable gzip case, and dropping the body
adoption fails with `expected '[object ReadableStream]' to be 'hello'`.

Red/green: with `src/` reverted, the three Request tests fail (the
undici one with the production error, `ERR_INVALID_URL { input: '[object
Request]' }`) and the data-path tests fail with `expected '[object
Blob]' to be 'hello'` / `expected '[object ReadableStream]' to be
'hello'`.

Verification run: unit + `connectionConfig` (129), `tests/sandbox/files`
+ `tests/volume` against prod (92 passed, real streamed/gzipped
uploads), all four changed files green on Node, Bun, Deno and workerd,
plus `tsc`, `lint`, `prettier` and `build`.

## Out of scope

`network.rules instanceof Map` (`sandboxApi.ts`) and the `instanceof
Error` checks are left alone: nothing replaces `globalThis.Map`, and the
errors are ours. Python needs no counterpart — its REST stack takes
bytes/iterables and has no equivalent brand checks.

Supersedes #1610 (@himself65), which fixed the `Request` half of this
and diagnosed the crash; the reproduction there is what led to auditing
the rest.


🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-31 12:28:51 -07:00
Mish Ushakov 2df7651ee6 test(sdk): run firewall transform tests against an httpbin sidecar sandbox (#1631)
Follow-up to #1632, which added the template this depends on. Now
rebased onto `main`, so this is just the test change.

## Problem

The firewall transform tests asserted header injection by curling
`httpbin.e2b.team`, an externally hosted service the suite had to keep
alive.

## Fix

Starts a sidecar sandbox from the `httpbin` template instead: the rule
is keyed on the sidecar's `getHost(8080)` and the assertion reads the
injected header back from `/headers`, in the JS, sync Python, and async
Python suites. The sidecar's ready command has already passed by the
time `create` resolves, so the server is serving and no readiness
polling is needed. The template name lives in one fixture per SDK —
`httpbinTemplate` in `tests/template.ts` and the `httpbin_template`
fixture in `conftest.py`.

Also drops two comments merged in #1632 that claimed the tests spawn
`e2b/httpbin`. The bare alias is what resolves, same as `base` — the
team slug only appears in the display name.

⚠️ Do not merge before **Build and push prepared templates** has been
dispatched with `template: httpbin` — the tests resolve the template by
name and fail until it exists on the E2B team.

Verified against production: all three tests pass with the injected
header reflected by the sidecar, spawning the template by its bare alias
with a key that owns it — the same situation as CI.

SDK-304

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-30 23:37:14 +02:00
Mish Ushakov b54e8d10df ci: add an httpbin template and a dropdown to pick which one to build (#1632)
## Problem

The firewall transform tests assert header injection by curling
`httpbin.e2b.team`, an externally hosted service the suite has to keep
alive. Transforms are applied by the egress proxy on the way *out* of a
sandbox, so the target has to be publicly reachable — which rules out a
CI service container, but not another sandbox.

## Change

Adds a `httpbin` template (`templates/httpbin`): go-httpbin on
`debian:bookworm-slim`, SHA256-pinned against the release
`checksums.txt` the way `templates/base` pins its Node install. Neither
official image can serve as an E2B base — `ghcr.io/mccutchen/go-httpbin`
is distroless (no shell, and `dockerfileParser.ts:79` rejects
multi-stage so the binary can't be copied out), and
`kennethreitz/httpbin` is Ubuntu 18.04 whose build fails on E2B's
`fuse3` install (both verified by building).

`templates.yml` gains a `template` choice input (`all` / `base` /
`httpbin`) rather than a second near-identical workflow file. `all` is
the default so a plain dispatch behaves as before, and the DockerHub
image job is skipped for `httpbin`, which has no image counterpart.

The template stays **private to the E2B team**, like `base` — publishing
would only expose it to other projects, and the tests that spawn it use
our API key anyway. The alias is passed unprefixed because the server
namespaces it with the team slug, so the name the tests resolve is
**`e2b/httpbin`**; only `base` predates namespacing and stays bare.

Merge this, then dispatch **Build and push prepared templates** with
`template: httpbin` — #1631 stacks on top and resolves the template as
`e2b/httpbin`.

<sub>Stack created with <a
href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a
href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>

SDK-304

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-30 23:06:40 +02:00
Mish Ushakov 4a2571d321 test(js-sdk): wait for workers.dev propagation in the CF deploy suite (#1592)
## Problem

The `cloudflare-deploy` CI job intermittently fails with `non-JSON
response (404): <!DOCTYPE html>...` ([example
run](https://github.com/e2b-dev/E2B/actions/runs/30009788154/job/89214641280)).
The truncated HTML boilerplate is easy to mistake for a Cloudflare
captcha/challenge page, but it's the standard Cloudflare **404** page:
each `wrangler deploy --temporary` lands on a brand-new account
subdomain (`e2b-js-sdk-smoke.<random>.workers.dev`), and Cloudflare
serves "nothing is here yet" until the route propagates to the edge. The
in-test retry window (initial attempt + 10 retries × 3s ≈ 35s) wasn't
always enough.

## Fix

- `setup.mts`: after the deploy, poll the worker URL until the worker
itself answers (405 to GET — the worker is POST-only), with a 240s
deadline. Tests only start once the route is live. Only the propagation
404 and thrown fetch errors (transient DNS/connect) keep the poll
waiting — any other status (403 challenge, 500 from a broken worker,
...) is a real failure and fails the setup immediately, with the error
page's `<title>` in the message.
- `run.test.ts`: retry only on the propagation 404 / `fetch failed`, so
other Cloudflare error pages propagate on the first attempt; include the
page `<title>` in the `non-JSON response` error, since the truncated
body is boilerplate shared by every Cloudflare error page.

Test-only change, no changeset.

## Verification

Ran `pnpm test:cf:deploy` against real Cloudflare (both revisions):

```
Deployed: https://e2b-js-sdk-smoke.quick-bike.workers.dev
Worker route not live yet (404), waiting...
Worker route not live yet (404), waiting...
Worker is live.

 Test Files  1 passed (1)
      Tests  1 passed (1)
```

The fresh subdomain served 404 for ~6s post-deploy — exactly the failure
mode from CI — then the suite passed on the first test attempt. `pnpm
run format`, `lint`, and `typecheck` pass.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-30 09:30:43 -07:00
Mish Ushakov 86934c779c ci(js-sdk): make the Cloudflare deploy test leg advisory (#1622)
## Problem

The `cloudflare-deploy` leg deploys to a brand-new Cloudflare preview
account on every run, so it inherits that account's propagation and
read-after-write races — the fresh `workers.dev` subdomain 404s until
the route reaches the edge, and the subdomain API can 404 the script it
just accepted (`This Worker does not exist on your account [code:
10007]`). That fails ~1 run in 8 (6 of ~46 runs since 2026-07-24)
without saying anything about the SDK, and the job gates both the
required `SDK Tests Status` check and the release workflow's `publish`
step — both of today's release runs were blocked by it
([30473411814](https://github.com/e2b-dev/E2B/actions/runs/30473411814),
[30474175682](https://github.com/e2b-dev/E2B/actions/runs/30474175682)).

## Fix

`continue-on-error` on that matrix leg only, so it still runs and still
reports on every PR but no longer blocks merges or releases. The signal
survives: a genuine bundle regression (e.g. the #1579 Workers startup
crash) is rejected at upload deterministically, not intermittently.

Follow-ups to make the leg reliably green again: #1592 (propagation
poll, still open) plus a retry around `wrangler deploy --temporary` for
the 10007 race.

CI-only change — no changeset, no user-facing surface.

Closes SDK-301

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-30 09:30:35 -07:00
dependabot[bot] 45d26792f1 chore(deps-dev): bump datamodel-code-generator from 0.34.0 to 0.64.0 in /packages/python-sdk in the uv group across 1 directory (#1621)
> [!NOTE]
> Manual follow-up commit on top of Dependabot's bump (addressing review
feedback): the codegen image pin was out of sync, so this PR also bumps
it and carries the regenerated output.

### Manual changes on top of the bump

- `codegen.Dockerfile` bumped from `datamodel-code-generator==0.34.0` to
`0.64.0`. `pyproject.toml`'s `codegen` group and the Dockerfile must
stay in sync (the comment above the group says so) — CI's `Generated
files` check regenerates from the image, so leaving the image at
`0.34.0` would make `make init` produce output CI rejects.
- `packages/python-sdk/e2b/sandbox/mcp.py` regenerated with `0.64.0`.
Two output changes:
- builtin generics (`list[str]`, `dict[str, Any]` instead of
`List`/`Dict`), fine on the SDK's `>=3.10` floor;
- `additionalProperties: false` in `spec/mcp-server.json` is now honored
as PEP 728 `closed=True` (`0.34.0` silently dropped it), and `TypedDict`
is imported from `typing_extensions` accordingly.
- `typing-extensions>=4.1.0` → `>=4.10.0`. `closed=True` is evaluated at
class-creation time, i.e. on `import e2b`, and 4.10.0 is the first
release whose `TypedDict` accepts the keyword (4.9.0 raises `TypeError:
_TypedDictMeta.__new__() got an unexpected keyword argument 'closed'`).
- Changeset added (`patch` for `@e2b/python-sdk`), since the regenerated
file and the dependency floor ship to users.

Nothing changes for callers at runtime — `McpServer` is still a plain
dict at the call site:

```python
from e2b import Sandbox

sbx = Sandbox.create(mcp={"duckduckgo": {}, "brave": {"braveApiKey": "..."}})
```

The `closed` types are also inert for type checkers in practice, because
the public `McpServer` is `Union[BaseMcpServer, GitHubMcpServer]` and
the second arm is a `Dict[str, ...]`. Verified: `pyright` and `mypy`
both clean against the snippet above, `ruff`/`ty`/`pnpm typecheck`
clean, 283 offline Python unit tests pass, and regenerating with the
full pinned toolchain (`python:3.10` + `black==26.3.1` + the other
Dockerfile pins) reproduces the committed file byte-for-byte.

---

Bumps the uv group with 1 update in the /packages/python-sdk directory:
[datamodel-code-generator](https://github.com/koxudaxi/datamodel-code-generator).

Updates `datamodel-code-generator` from 0.34.0 to 0.64.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/koxudaxi/datamodel-code-generator/releases">datamodel-code-generator's
releases</a>.</em></p>
<blockquote>
<h2>0.64.0</h2>
<h2>Breaking Changes</h2>
<h3>Code Generation Changes</h3>
<ul>
<li>Self-referencing fields are now quoted with
<code>--disable-future-imports</code> - When
<code>--disable-future-imports</code> is set (no <code>from __future__
import annotations</code> and no native PEP 649 deferred evaluation on
Python &lt; 3.14), self-referencing and forward-referencing field
annotations in regular <code>BaseModel</code> classes are now emitted as
quoted forward references instead of bare names. Previously such
annotations were left unquoted, producing invalid code that raised
<code>NameError</code> (Ruff F821) at class-evaluation time. Output for
the common case (with <code>from __future__ import annotations</code> or
Python 3.14 native deferred annotations) is unchanged. Users who
snapshot/golden-file generated output for the
<code>--disable-future-imports</code> configuration with
self-referencing models will see the annotation change from unquoted to
quoted, e.g. <code>children: Optional[List[Node]]</code> →
<code>children: Optional[List[&quot;Node&quot;]]</code>. (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3387">#3387</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Update CHANGELOG for 0.63.0 by <a
href="https://github.com/dcg-generated-docs"><code>@​dcg-generated-docs</code></a>[bot]
in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3345">koxudaxi/datamodel-code-generator#3345</a></li>
<li>Deduplicate module content builder by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3346">koxudaxi/datamodel-code-generator#3346</a></li>
<li>Deduplicate import reference helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3348">koxudaxi/datamodel-code-generator#3348</a></li>
<li>Refactor jsonschema root model registration by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3352">koxudaxi/datamodel-code-generator#3352</a></li>
<li>Refactor XML Schema literal helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3349">koxudaxi/datamodel-code-generator#3349</a></li>
<li>Move builtin formatter helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3351">koxudaxi/datamodel-code-generator#3351</a></li>
<li>Deduplicate Pydantic v2 config helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3350">koxudaxi/datamodel-code-generator#3350</a></li>
<li>Deduplicate DataType type hint rendering by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3354">koxudaxi/datamodel-code-generator#3354</a></li>
<li>Fix <code>constr()</code> for string fields carrying
minItems/maxItems by <a
href="https://github.com/DarkaMaul"><code>@​DarkaMaul</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3353">koxudaxi/datamodel-code-generator#3353</a></li>
<li>Cover non-finite import idempotence by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3367">koxudaxi/datamodel-code-generator#3367</a></li>
<li>Deduplicate input text detection by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3357">koxudaxi/datamodel-code-generator#3357</a></li>
<li>Remove stale protobuf coverage pragma by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3358">koxudaxi/datamodel-code-generator#3358</a></li>
<li>Cover explicit null OpenAPI media schemas by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3360">koxudaxi/datamodel-code-generator#3360</a></li>
<li>Simplify Python version feature checks by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3361">koxudaxi/datamodel-code-generator#3361</a></li>
<li>Speed up CI checks by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3378">koxudaxi/datamodel-code-generator#3378</a></li>
<li>Add maintainer link to docs footer and README by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3379">koxudaxi/datamodel-code-generator#3379</a></li>
<li>Use builtin formatter in CI by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3380">koxudaxi/datamodel-code-generator#3380</a></li>
<li>Split coverage by OS by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3381">koxudaxi/datamodel-code-generator#3381</a></li>
<li>Simplify import removal cleanup by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3362">koxudaxi/datamodel-code-generator#3362</a></li>
<li>Pin deprecation warning stacklevel by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3363">koxudaxi/datamodel-code-generator#3363</a></li>
<li>Pin public module exports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3364">koxudaxi/datamodel-code-generator#3364</a></li>
<li>Cover to_hashable branch cases by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3366">koxudaxi/datamodel-code-generator#3366</a></li>
<li>Cover stable toposort behavior by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3369">koxudaxi/datamodel-code-generator#3369</a></li>
<li>Extract registry render helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3371">koxudaxi/datamodel-code-generator#3371</a></li>
<li>Fix minItems for arrays of URI strings by <a
href="https://github.com/sjh9714"><code>@​sjh9714</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3377">koxudaxi/datamodel-code-generator#3377</a></li>
<li>Deduplicate config value validators by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3372">koxudaxi/datamodel-code-generator#3372</a></li>
<li>Cover CLI option metadata helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3374">koxudaxi/datamodel-code-generator#3374</a></li>
<li>Cover Pydantic v2 version fallback by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3368">koxudaxi/datamodel-code-generator#3368</a></li>
<li>Fix nullable JSON Schema const enums by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3355">koxudaxi/datamodel-code-generator#3355</a></li>
<li>Pin patchable generation seams by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3365">koxudaxi/datamodel-code-generator#3365</a></li>
<li>Cover utility helper behavior by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3375">koxudaxi/datamodel-code-generator#3375</a></li>
<li>Cover DefaultPutDict behavior by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3376">koxudaxi/datamodel-code-generator#3376</a></li>
<li>Cover validator config normalization by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3373">koxudaxi/datamodel-code-generator#3373</a></li>
<li>Avoid expensive runtime type checks by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3382">koxudaxi/datamodel-code-generator#3382</a></li>
<li>Avoid eager builtin formatter import by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3383">koxudaxi/datamodel-code-generator#3383</a></li>
<li>Avoid eager TOML parser import by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3384">koxudaxi/datamodel-code-generator#3384</a></li>
<li>Stabilize msgspec payload tests by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3385">koxudaxi/datamodel-code-generator#3385</a></li>
<li>Avoid eager input parser imports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3386">koxudaxi/datamodel-code-generator#3386</a></li>
<li>Avoid eager parser model imports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3388">koxudaxi/datamodel-code-generator#3388</a></li>
<li>Avoid eager AsyncAPI converter imports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3389">koxudaxi/datamodel-code-generator#3389</a></li>
<li>Dispose parser on parse errors by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3390">koxudaxi/datamodel-code-generator#3390</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/koxudaxi/datamodel-code-generator/blob/main/CHANGELOG.md">datamodel-code-generator's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.64.0">0.64.0</a>
- 2026-06-14</h2>
<h2>Breaking Changes</h2>
<h3>Code Generation Changes</h3>
<ul>
<li>Self-referencing fields are now quoted with
<code>--disable-future-imports</code> - When
<code>--disable-future-imports</code> is set (no <code>from __future__
import annotations</code> and no native PEP 649 deferred evaluation on
Python &lt; 3.14), self-referencing and forward-referencing field
annotations in regular <code>BaseModel</code> classes are now emitted as
quoted forward references instead of bare names. Previously such
annotations were left unquoted, producing invalid code that raised
<code>NameError</code> (Ruff F821) at class-evaluation time. Output for
the common case (with <code>from __future__ import annotations</code> or
Python 3.14 native deferred annotations) is unchanged. Users who
snapshot/golden-file generated output for the
<code>--disable-future-imports</code> configuration with
self-referencing models will see the annotation change from unquoted to
quoted, e.g. <code>children: Optional[List[Node]]</code> →
<code>children: Optional[List[&quot;Node&quot;]]</code>. (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3387">#3387</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Update CHANGELOG for 0.63.0 by <a
href="https://github.com/dcg-generated-docs"><code>@​dcg-generated-docs</code></a>[bot]
in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3345">koxudaxi/datamodel-code-generator#3345</a></li>
<li>Deduplicate module content builder by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3346">koxudaxi/datamodel-code-generator#3346</a></li>
<li>Deduplicate import reference helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3348">koxudaxi/datamodel-code-generator#3348</a></li>
<li>Refactor jsonschema root model registration by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3352">koxudaxi/datamodel-code-generator#3352</a></li>
<li>Refactor XML Schema literal helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3349">koxudaxi/datamodel-code-generator#3349</a></li>
<li>Move builtin formatter helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3351">koxudaxi/datamodel-code-generator#3351</a></li>
<li>Deduplicate Pydantic v2 config helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3350">koxudaxi/datamodel-code-generator#3350</a></li>
<li>Deduplicate DataType type hint rendering by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3354">koxudaxi/datamodel-code-generator#3354</a></li>
<li>Fix <code>constr()</code> for string fields carrying
minItems/maxItems by <a
href="https://github.com/DarkaMaul"><code>@​DarkaMaul</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3353">koxudaxi/datamodel-code-generator#3353</a></li>
<li>Cover non-finite import idempotence by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3367">koxudaxi/datamodel-code-generator#3367</a></li>
<li>Deduplicate input text detection by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3357">koxudaxi/datamodel-code-generator#3357</a></li>
<li>Remove stale protobuf coverage pragma by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3358">koxudaxi/datamodel-code-generator#3358</a></li>
<li>Cover explicit null OpenAPI media schemas by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3360">koxudaxi/datamodel-code-generator#3360</a></li>
<li>Simplify Python version feature checks by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3361">koxudaxi/datamodel-code-generator#3361</a></li>
<li>Speed up CI checks by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3378">koxudaxi/datamodel-code-generator#3378</a></li>
<li>Add maintainer link to docs footer and README by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3379">koxudaxi/datamodel-code-generator#3379</a></li>
<li>Use builtin formatter in CI by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3380">koxudaxi/datamodel-code-generator#3380</a></li>
<li>Split coverage by OS by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3381">koxudaxi/datamodel-code-generator#3381</a></li>
<li>Simplify import removal cleanup by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3362">koxudaxi/datamodel-code-generator#3362</a></li>
<li>Pin deprecation warning stacklevel by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3363">koxudaxi/datamodel-code-generator#3363</a></li>
<li>Pin public module exports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3364">koxudaxi/datamodel-code-generator#3364</a></li>
<li>Cover to_hashable branch cases by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3366">koxudaxi/datamodel-code-generator#3366</a></li>
<li>Cover stable toposort behavior by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3369">koxudaxi/datamodel-code-generator#3369</a></li>
<li>Extract registry render helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3371">koxudaxi/datamodel-code-generator#3371</a></li>
<li>Fix minItems for arrays of URI strings by <a
href="https://github.com/sjh9714"><code>@​sjh9714</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3377">koxudaxi/datamodel-code-generator#3377</a></li>
<li>Deduplicate config value validators by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3372">koxudaxi/datamodel-code-generator#3372</a></li>
<li>Cover CLI option metadata helpers by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3374">koxudaxi/datamodel-code-generator#3374</a></li>
<li>Cover Pydantic v2 version fallback by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3368">koxudaxi/datamodel-code-generator#3368</a></li>
<li>Fix nullable JSON Schema const enums by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3355">koxudaxi/datamodel-code-generator#3355</a></li>
<li>Pin patchable generation seams by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3365">koxudaxi/datamodel-code-generator#3365</a></li>
<li>Cover utility helper behavior by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3375">koxudaxi/datamodel-code-generator#3375</a></li>
<li>Cover DefaultPutDict behavior by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3376">koxudaxi/datamodel-code-generator#3376</a></li>
<li>Cover validator config normalization by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3373">koxudaxi/datamodel-code-generator#3373</a></li>
<li>Avoid expensive runtime type checks by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3382">koxudaxi/datamodel-code-generator#3382</a></li>
<li>Avoid eager builtin formatter import by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3383">koxudaxi/datamodel-code-generator#3383</a></li>
<li>Avoid eager TOML parser import by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3384">koxudaxi/datamodel-code-generator#3384</a></li>
<li>Stabilize msgspec payload tests by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3385">koxudaxi/datamodel-code-generator#3385</a></li>
<li>Avoid eager input parser imports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3386">koxudaxi/datamodel-code-generator#3386</a></li>
<li>Avoid eager parser model imports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3388">koxudaxi/datamodel-code-generator#3388</a></li>
<li>Avoid eager AsyncAPI converter imports by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3389">koxudaxi/datamodel-code-generator#3389</a></li>
<li>Dispose parser on parse errors by <a
href="https://github.com/koxudaxi"><code>@​koxudaxi</code></a> in <a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/pull/3390">koxudaxi/datamodel-code-generator#3390</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/53a25ab8ddb132ac68a2795247fc855b8f445d84"><code>53a25ab</code></a>
Fast path schema output (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3410">#3410</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/ee2087f32e6100f5c3642e7ea8506aa38e9df26c"><code>ee2087f</code></a>
Skip discriminator import scan (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3411">#3411</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/bdf5ddfc27f94a06ba8d289759193bb09daadd34"><code>bdf5ddf</code></a>
fix: quote self-referencing fields when --disable-future-imports is set
(<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3387">#3387</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/ad4ec877fa6708baebdaaf820171d24bfe5bf0cb"><code>ad4ec87</code></a>
Cache payload validation strategies (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3409">#3409</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/b191d52a0a1d83edeac9553119f70b2f5c131126"><code>b191d52</code></a>
Shard Python tests (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3408">#3408</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/29dd6d74c95dd7799d51f2c707db24862809eb23"><code>29dd6d7</code></a>
Cache parsed sources (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3407">#3407</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/93e2fe3cf5774d5e4d2083fac365e5bcbf0a647a"><code>93e2fe3</code></a>
Defer generation refresh (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3406">#3406</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/bb01d9c628f9077cc5dd72320ae60a18abd5b790"><code>bb01d9c</code></a>
Lazy root format exports (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3405">#3405</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/48237ed8c3af3bb58b5e6b274925ebb646412d3a"><code>48237ed</code></a>
Fast path JSON schemas (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3404">#3404</a>)</li>
<li><a
href="https://github.com/koxudaxi/datamodel-code-generator/commit/b21d106c88ac22f137cd4562389ad95a50c2e912"><code>b21d106</code></a>
Slot generation facts (<a
href="https://redirect.github.com/koxudaxi/datamodel-code-generator/issues/3403">#3403</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.34.0...0.64.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=datamodel-code-generator&package-manager=uv&previous-version=0.34.0&new-version=0.64.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts page](https://github.com/e2b-dev/E2B/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Mish Ushakov <10400064+mishushakov@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-07-30 18:15:52 +02:00
Tomas Srnka 6733f36755 fix(sdk): align Python Fedora/Alpine image defaults with JS (#1625)
Python `from_fedora_image` defaulted to `fedora:42` (end-of-life) and
`from_alpine_image` to `alpine:3.22`, while JS already pinned
`fedora:44`/`alpine:3.24` — the same call produced a different base
image per SDK. Aligns Python; also fixes the JS type docs, which still
named the old defaults.

```python
Template().from_fedora_image()  # fedora:44 (was fedora:42)
Template().from_alpine_image()  # alpine:3.24 (was alpine:3.22)
```

Follow-up to #1612; both defaults are still unreleased.
2026-07-30 16:04:39 +00:00
Tomas Srnka 1504fbc843 SDK: fromFedoraImage/fromAlpineImage/fromArchImage helpers (#1612)
## What
Adds the missing non-Debian base-image convenience helpers to **both
SDKs**, mirroring the existing
`fromUbuntuImage`/`fromDebianImage`/`fromPythonImage`/`fromNodeImage`/`fromBunImage`:

- **JS/TS** (`packages/js-sdk`): `fromFedoraImage(variant?)`,
`fromAlpineImage(variant?)`, `fromArchImage(variant?)` + unit tests
- **Python** (`packages/python-sdk`): `from_fedora_image(variant)`,
`from_alpine_image(variant)`, `from_arch_image(variant)` + sync/async
unit tests

## Why
This is the **customer-facing half** of infra **#3381** (distro-aware
template provisioning). The engine now builds + boots
Ubuntu/Debian/Fedora/RHEL-family/Arch/Alpine on real KVM; before this PR
the SDK exposed distro helpers for the Debian family only, so
Fedora/Alpine/Arch were reachable only via the generic `fromImage()`.
These give them first-class parity.

## Verification (honest)
- **New helper unit tests pass locally** — JS `fromDistroImages.test.ts`
→ 6/6 green (`vitest`, no auth). Python `test_from_distro_images.py`
(sync + async) committed.
- **Full integration suite**: requires E2B API keys — fails locally with
`AuthenticationError` **identically on `main`** (215/187/29), i.e.
**zero regression** from this change; CI runs it with secrets.
- Lint scoped to the touched files.

## Not in this PR
The public **docs** still state *"only Debian-based images …
Alpine/RedHat not supported"* — but that text lives in
**`e2b-dev/docs`**, not this monorepo, so it's a **separate docs PR**
(being opened against `e2b-dev/docs`). Flagging so this + that land
together.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-30 12:17:02 +02:00
Mish Ushakov 9e3e52b4fb Add --user/--cwd/--env terminal flags to sandbox create & connect (#1501)
Exposes `--user`, `--cwd`, and repeatable `--env KEY=VALUE` flags on
`e2b sandbox create` (and the deprecated `spawn` alias) and `e2b sandbox
connect`, forwarding them to the underlying PTY session so the connected
terminal starts as the given user, in the given working directory, and
with the given environment variables. The SDKs already supported these
PTY options — this just wires them through the CLI. The `--env` arg
parser is extracted into a shared `src/utils/env.ts` and reused across
`create`, `connect`, and `exec`. Added unit tests for the parser and CLI
tests covering the new flags; a changeset is included for `@e2b/cli`.

## Usage

```bash
# Start the terminal as root, in /app, with custom env vars
e2b sandbox create base --user root --cwd /app --env FOO=bar --env TOKEN=abc123

# Same flags when attaching to an already-running sandbox
e2b sandbox connect <sandboxID> --user root --cwd /app --env FOO=bar
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-29 17:33:43 -07:00
Mish Ushakov 05b7a792ff fix(ci): depend on the SDK via workspace:^ so releases tag the version bump (#1619)
Closes
[SDK-298](https://linear.app/e2b/issue/SDK-298/release-tags-point-at-the-commit-before-the-version-bump).
Replaces #1615, which moved the tags after the fact instead of removing
the reason they were misplaced.

## The bug

Every published release tag pointed at the commit *preceding* its own
version bump:

```console
$ git show '@e2b/python-sdk@2.35.0:packages/python-sdk/pyproject.toml' | head -3
[project]
name = "e2b"
version = "2.34.0"      # ← tagged 2.35.0
```

Anything that builds from a git tag rather than a registry got the
previous release: distro packagers, `pip install git+…@tag`, any bisect
over a release regression. `python3Packages.e2b` in nixpkgs shipped
1.5.0 as 1.5.1 from June 2025.

## Root cause: a dependency cycle

`changeset publish` tags whatever commit it publishes from, so the fix
is to commit the version bump first. That was impossible:

```
tag              must point at →  release commit
release commit   must contain   →  pnpm-lock.yaml
pnpm-lock.yaml   contains       →  integrity hash of a tarball this release uploads
```

`packages/cli` depended on `e2b` by registry range, so `changeset
version` rewrote that range and the lockfile had to be re-resolved
against a tarball that did not exist yet. The lockfile could only be
refreshed *after* publishing, which forced the commit — and therefore
the tags — after it too.

## The fix

`packages/cli`: `"e2b": "^2.36.1"` → `"e2b": "workspace:^"`.

The lockfile now records `link:../js-sdk` and stops changing at release
time, so the release commit is complete before anything is uploaded:

| | before | after |
|---|---|---|
| 1 | `pnpm run version` | `pnpm run version` |
| 2 | publish **+ tag** ← wrong commit | **commit** (local) |
| 3 | refresh `pnpm-lock.yaml` (retry ≤6×) | publish **+ tag** ← right
commit |
| 4 | commit + push | push |

That deletes the lockfile-refresh step and its whole
registry-propagation retry loop (#1589), and `createGithubReleases:
true` keeps doing the tagging and GitHub releases — no custom tagging
code. Keeping the commit local also improves recovery: a publish that
uploads *nothing* leaves the branch untouched with the changesets
intact, so re-dispatching retries cleanly.

### Landing that commit is now mandatory, so the push is resilient

Once the tags point at a local commit, getting it onto the branch stops
being bookkeeping. `changesets/action` pushes each tag as soon as
`changeset publish` reports it (`runPublish` → `git.pushTag`), *before*
it propagates a non-zero exit — so three things changed:

- **The push is gated on the tags themselves** — `git tag --points-at
HEAD` — not on whether the publish step succeeded. The tags are the
thing that has to end up reachable, so they are the right thing to ask.
A partial failure (npm succeeds, then python-sdk's `postPublish` fails
on PyPI) used to skip the push and strand tags on a commit that reached
no branch while `main` kept the old versions.

I first wrote this as `!cancelled() && (success() ||
steps.release.outputs.published == 'true')`, which was wrong in both
directions: `success()` fires in exactly the case that must be skipped
(publish exits 0 having uploaded nothing → pushes a bump with no tags,
cementing a version that can never be published), and `published` is
left unset when the action *throws* after tagging (`core.setOutput` runs
only on a normal return from `runPublish`, but `git.pushTag` happens
inside it) — so it was skipped in the very case it existed for. The tag
gate also covers `@e2b/python-sdk`, which the npm-derived output never
did, since `privatePackages.tag` is on.

- **A partial publish is reported, not swallowed.** It still has to land
— otherwise the pushed tags hang off no branch — but the bump is then on
the branch with the changesets consumed, so re-dispatching will not
retry what failed. The step now names the tags that did land and points
out that `postPublish`'s PyPI upload was skipped (the root script is
`changeset publish && ... postPublish`, so a non-zero npm exit
short-circuits it).
- **A non-fast-forward is reconciled with a merge,** not a rebase (which
would orphan the tags) and not a hard failure. Hard-failing left an
already-published release needing manual git surgery, and a naive
re-dispatch would publish nothing (versions already on the registry),
tag nothing, and report **success** — quietly recreating SDK-298.
- **`git add -A` replaces `commit -am`,** which cannot stage new files.
`changeset version` writes each `CHANGELOG.md` fresh, so no release
commit has ever contained one:

  ```console
  $ git show --stat cf8296cf8 | tail -4
   .changeset/lucky-pandas-wave.md    |  5 ---
   packages/cli/package.json          |  4 +-
   packages/js-sdk/package.json       |  2 +-
   pnpm-lock.yaml                     | 77 +-----------------
  ```

## The published packages do not change

`pnpm publish` (which `changeset publish` uses in a pnpm workspace)
rewrites the protocol. Verified on the real CLI package with the
workspace SDK at 9.9.9:

```
e2b dependency -> ^9.9.9
PASS: no workspace: in published manifest
```

## Verification

| check | result |
|---|---|
| `pnpm install --frozen-lockfile` on a clean clone | consistent |
| `pnpm run version` touches the lockfile? | **no** — `git diff
pnpm-lock.yaml` empty after bumping sdk 2.36.1→2.36.2, cli→2.16.1 |
| tags land on the release commit | `PASS e2b@2.36.2`, `PASS
@e2b/python-sdk@2.36.0`; tagged trees contain `"version": "2.36.2"` /
`version = "2.36.0"` |
| CLI still bumped when the SDK is | yes, `updateInternalDependencies`
still sees the internal dep |
| CLI typecheck / tests | clean / 102 passed (1 pre-existing failure
needs `E2B_API_KEY` + a built `dist`) |
| CLI bundle | builds, contains the workspace SDK, zero external
`require("e2b")` |
| `pnpm publish` git checks | `changeset publish` passes
`--no-git-checks` for pnpm ≥5 (repo pins 9.15.5); added explicitly to
the RC flows, which publish from a feature branch with an uncommitted
bump |
| `prepack` guard | `npm pack` fails and produces no tarball; `pnpm
pack` passes and rewrites to `^2.36.1` |
| `pnpm publish` lifecycle | runs `prepublishOnly` + `prepack` +
`prepare`, so the RC still builds; `pnpm pack` runs only `prepack` +
`prepare` (0.37 s, no rebuild) |
| `pnpm publish --provenance` | flag accepted (pnpm forwards to the npm
publish it spawns) |
| `pnpm link --global` | links the workspace CLI (2.16.0) and resolves
`workspace:^`; tested against an isolated `PNPM_HOME` |
| `pnpm version` / `pnpm pkg` | pnpm forwards both to npm verbatim, so
these are the same code path as before — neither resolves dependencies,
so `workspace:` is inert there |
| lockfile vs `exclude-links-from-lockfile=true` | `--frozen-lockfile`
green with the new `link:../js-sdk` entry, including after a
release-style version bump |

## Everything packs and publishes with pnpm

Only pnpm rewrites `workspace:`. `npm pack` copies the protocol into the
tarball verbatim and `npm install` then refuses it. Rather than hand-pin
the range back before each npm call, every flow that produces or
installs a CLI tarball now uses pnpm:

| flow | before | after |
|---|---|---|
| `pkg_artifacts.yml` | `npm pack` | `pnpm pack` |
| `publish_candidates.yml` | `npm publish --provenance` | `pnpm publish
--provenance --no-git-checks` |
| `.github/actions/build-cli` | `npm install -g .` | `pnpm link
--global` |

The `build-cli` action was a **third** npm consumer of the manifest,
missed on the first pass. It only worked because npm symlinks a local
directory for `-g` without resolving its dependencies at all — verified:
a control package depending on `chalk` installed with exit 0 and chalk
was never fetched. Force packing (`install_links=true`) and it dies with
`EUNSUPPORTEDPROTOCOL`.

Moving the rewrite to pack time changes *when* it resolves, which
matters in `pkg_artifacts.yml`: `pnpm pack` uses whatever version the
workspace SDK has at that moment, and that job renames the SDK to an
unpublished prerelease. Packing the CLI first was required —

```console
# SDK renamed first (wrong order)
CLI packed with e2b -> ^2.36.2-fake-branch.0   # never published → ETARGET

# CLI packed first (as merged)
e2b-cli-2.16.1-fake-branch.0.tgz -> e2b: ^2.36.1   # published, resolvable
```

`publish_candidates.yml` needs the opposite order and already had it:
the SDK RC *is* published first, so the CLI correctly pins that RC.
`--no-git-checks` is new there — candidates are cut from a feature
branch with the version bump uncommitted, so `pnpm publish` would
otherwise refuse.

### Not enforced, deliberately

I went down a path here and backed out of it, so it is worth recording.
I first added a
`prepack` guard on `packages/cli` that refused to build a tarball for
any packer but
pnpm. It had three bypasses: `npm_config_user_agent` is inherited, so
npm spawned from
pnpm still reports `pnpm/…` and sailed through it; and
`--ignore-scripts` and
`npm install -g <dir>` never run lifecycle scripts at all. I then
replaced it with a
step that installed the packed tarball with npm on every PR, which did
cover all of
those (verified: it rejects an `npm pack` tarball with
`EUNSUPPORTEDPROTOCOL` while
`pnpm pack` resolves the range to `^2.36.1`).

Both are now gone, in favour of keeping this PR to its actual subject.
So the rewrite is
unverified: the existing flows all use `pnpm pack`/`pnpm publish`, and
`changeset publish` picks pnpm by detecting the workspace, so it happens
— but nothing
catches it if a future flow reaches for npm instead. The tarball-install
step is a cheap
seven lines if we later decide we want it.

## Behavior change worth knowing

CLI tests previously resolved `e2b` from `node_modules`, i.e. the
*previously released* SDK, while `tsconfig.json` and the tsdown bundle
already used `../js-sdk/src`. `vitest.config.ts` now has a matching
alias, so all three agree and tests exercise the SDK that ships. The
alias is load-bearing — without it the workspace package's `main`
(`dist/index.js`) doesn't exist until the SDK is built:

```
Error: Failed to resolve entry for package "e2b".
⎯⎯⎯⎯⎯⎯ Failed Tests 11 ⎯⎯⎯⎯⎯⎯⎯
```

A broken SDK in the tree now fails CLI tests. `cli_tests.yml` and
`pkg_artifacts.yml` already built the SDK before the CLI, so no CI
ordering changed.

## Not retagging the past

Tags up to `e2b@2.36.1` / `@e2b/cli@2.16.0` / `@e2b/python-sdk@2.35.0`
stay off by one — moving published tags breaks anyone who pinned them.
**Build those versions from the npm tarball or the PyPI sdist, not from
the git tag.** That matters for distro packagers: `python3Packages.e2b`
in nixpkgs shipped 1.5.0 as 1.5.1 for exactly this reason. This caveat
is recorded here and in [SDK-298](https://linear.app/e2b/issue/SDK-298)
rather than in the repo.

## Follow-up

SDK-298 also notes `packages/python-sdk/pyproject.toml` pins
`uv_build>=0.10.0,<0.11.0`, so packagers on uv 0.11.x must patch it to
build at all. And `e2b-dev/code-interpreter` has the same tag bug in its
own publish workflow.

> **Corrections to earlier versions of this description:**
>
> 1. It suggested demoting `e2b` to a `devDependency` since the bundle
inlines it. That breaks the CLI — but *not* for the reason given next.
> 2. It then claimed `tsdown.config.ts` derives `alwaysBundle` from
`dependencies`, so removing `e2b` makes it *external* and the CLI ships
a bare `require("e2b")`. **That is backwards.** tsdown externalizes
exactly the production dependencies (`getProductionDeps` = `dependencies
∪ peerDependencies ∪ optionalDependencies`), so listing `e2b` there is
what would externalize it; `alwaysBundle` exists to cancel that. A
devDependency is *also* inlined. Verified with a control: moving `e2b`
to `devDependencies` still emits zero `require("e2b")`, while adding it
to `excludedPackages` is what produces the bare require and drops the
bundle from 2.14 MB to 1.84 MB.
>
> The real reason it must stay a dependency is runtime resolution: the
SDK reaches `undici`, `glob` and `tar` through `dynamicImport`, which is
deliberately opaque to bundlers, so they resolve from `node_modules` at
run time. The CLI declares none of them and gets all three via `e2b`:
>
> ```
> undici: present   undici8: present   glob: present   tar: present
> ```
>
> Without them `e2b template build` loses `glob`/`tar` and
`loadUndici()` returns `undefined`, silently downgrading every request
to the global `fetch` and giving up H2 and proxy support. So: **do not
demote `e2b` to a devDependency.** This warning lives only here — there
is no in-repo note for it.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-29 16:59:33 +00:00
Mish Ushakov 2c061eb8cf chore(cli): migrate dashboard links to project-era tab entrypoints (#1605)
## Summary

Following the dashboard's teams→projects rename (e2b-dev/dashboard#521),
this PR points the `--project` flag help at the dashboard's
`?tab=general` entrypoint (General settings, where the project ID lives)
instead of the old `?tab=team`, and adds a `@e2b/cli` patch changeset.
It also rewrites the CLI README's headless-auth note to use
`E2B_API_KEY` (the supported browserless path) instead of
`E2B_ACCESS_TOKEN`, pointing at the dashboard's API Keys tab, and drops
the now-redundant `E2B_ACCESS_TOKEN` vs `E2B_API_KEY` callout. The SDKs'
`?tab=keys` and the CLI's `?tab=personal` links stay unchanged — those
tabs remain valid entrypoints.

## Example

```
$ e2b template create --help
  -t, --project <project-id>  specify the project ID that the operation will be associated with.
                              You can find project ID in the project settings in the E2B dashboard
                              (https://e2b.dev/dashboard?tab=general).
```

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-29 18:21:35 +02:00