Merge https://github.com/google/adk-python/pull/5489 Closes #5488 ## Summary Bumps the `litellm` constraint from `<=1.82.6` to `>=1.83.7,<=1.83.14` in both the base project dependencies and the `[test]` extras. The current cap was added in [`77f1c41`](https://github.com/google/adk-python/commit/77f1c41) to exclude the March 2026 supply-chain compromise of litellm 1.82.7 and 1.82.8. Since then, **five CVEs have been disclosed against litellm `<=1.82.6`** (2 critical, 3 high), with patches in 1.83.0 and 1.83.7. The new lower bound (1.83.7) is strictly above the originally compromised versions, so the original concern is still respected. The upper bound is pinned to the current latest release on PyPI (1.83.14) per reviewer request, mirroring the project's prior exact-version cap pattern. New litellm releases will require an explicit ADK PR to admit, the same way `<=1.82.6` did. Full CVE list and rationale in the linked issue (#5488). ## Diff Two identical edits, one in project deps (line 126) and one in `[test]` extras (line 145): ```diff - "litellm>=1.75.5,<=1.82.6", # ... supply chain attack ... + "litellm>=1.83.7,<=1.83.14", # For LiteLlm class. Lower bound: 5 CVE patches (2026-04). Upper bound pinned to current latest; bump deliberately. See #5488. ``` ## Testing plan 1. Re-installed `google-adk` (editable) against the updated constraint; pip resolved litellm to 1.83.13 (latest stable compatible with the rest of the lockfile, inside the new `[1.83.7, 1.83.14]` window). 2. Ran `tests/unittests/models/test_litellm.py` and `tests/unittests/models/test_litellm_import.py`; **all 259 tests pass**. Output below. 3. Verified `pyproject.toml` is parseable as TOML. ### Upstream litellm test output ``` collected 259 items tests/unittests/models/test_litellm.py ................................. [ 12%] ........................................................................ [ 40%] ........................................................................ [ 68%] ........................................................................ [ 96%] ....... [ 98%] tests/unittests/models/test_litellm_import.py ... [100%] ============================= 259 passed in 6.57s ============================== ``` ## Heads up: litellm hard-pins python-dotenv While verifying, we discovered that **litellm 1.83.7 (and every subsequent version through 1.83.14) hard-pins `python-dotenv==1.0.1`** as an unconditional core dependency. By contrast, litellm 1.82.6 declared `python-dotenv>=0.2.0` (loose). This does **not** affect adk-python itself -- ADK declares `python-dotenv>=1,<2`, which admits `1.0.1` cleanly. But any downstream project that has tightened `python-dotenv` (e.g. `>=1.2.x`) will hit a resolver conflict after this bump and may need to either relax its python-dotenv constraint or apply a package-manager override. This is a litellm anti-pattern, not an ADK problem; included here so reviewers know to expect downstream issues of that shape. ## Out of scope `langgraph` has a similar dep cap (`<0.4.8`) and one medium-severity CVE ([GHSA-g48c-2wqr-h844](https://github.com/advisories/GHSA-g48c-2wqr-h844)), but bumping past 0.4.x requires porting ADK's use of the removed `graph.graph` API (per [#1687](https://github.com/google/adk-python/pull/1687)). That is real engineering work, not a dep cap bump, and is left as a separate effort. COPYBARA_INTEGRATE_REVIEW=https://github.com/google/adk-python/pull/5489 from cwest:topic/bump-litellm-cap 559f0c2ee9d1e911bcc83832d4dee9ccbafa5c12 PiperOrigin-RevId: 906979886
Agent Development Kit (ADK)
<html>An open-source, code-first Python framework for building, evaluating, and deploying sophisticated AI agents with flexibility and control.
Important Links: Docs, Samples, Java ADK, Go ADK & ADK Web.
</html>Agent Development Kit (ADK) is a flexible and modular framework that applies software development principles to AI agent creation. It is designed to simplify building, deploying, and orchestrating agent workflows, from simple tasks to complex systems. While optimized for Gemini, ADK is model-agnostic, deployment-agnostic, and compatible with other frameworks.
🔥 What's new
-
Custom Service Registration: Add a service registry to provide a generic way to register custom service implementations to be used in FastAPI server. See short instruction. (391628f)
-
Rewind: Add the ability to rewind a session to before a previous invocation (9dce06f).
-
New CodeExecutor: Introduces a new AgentEngineSandboxCodeExecutor class that supports executing agent-generated code using the Vertex AI Code Execution Sandbox API (ee39a89)
✨ Key Features
-
Rich Tool Ecosystem: Utilize pre-built tools, custom functions, OpenAPI specs, MCP tools or integrate existing tools to give agents diverse capabilities, all for tight integration with the Google ecosystem.
-
Code-First Development: Define agent logic, tools, and orchestration directly in Python for ultimate flexibility, testability, and versioning.
-
Agent Config: Build agents without code. Check out the Agent Config feature.
-
Tool Confirmation: A tool confirmation flow(HITL) that can guard tool execution with explicit confirmation and custom input.
-
Modular Multi-Agent Systems: Design scalable applications by composing multiple specialized agents into flexible hierarchies.
-
Deploy Anywhere: Easily containerize and deploy agents on Cloud Run or scale seamlessly with Vertex AI Agent Engine.
🚀 Installation
Stable Release (Recommended)
You can install the latest stable version of ADK using pip:
pip install google-adk
To install optional integrations, you can use the following command:
pip install "google-adk[extensions]"
The release cadence is roughly bi-weekly.
This version is recommended for most users as it represents the most recent official release.
Development Version
Bug fixes and new features are merged into the main branch on GitHub first. If you need access to changes that haven't been included in an official PyPI release yet, you can install directly from the main branch:
pip install git+https://github.com/google/adk-python.git@main
Note: The development version is built directly from the latest code commits. While it includes the newest fixes and features, it may also contain experimental changes or bugs not present in the stable release. Use it primarily for testing upcoming changes or accessing critical fixes before they are officially released.
🤖 Agent2Agent (A2A) Protocol and ADK Integration
For remote agent-to-agent communication, ADK integrates with the A2A protocol. See this example for how they can work together.
📚 Documentation
Explore the full documentation for detailed guides on building, evaluating, and deploying agents:
🏁 Feature Highlight
Define a single agent:
from google.adk.agents import Agent
from google.adk.tools import google_search
root_agent = Agent(
name="search_assistant",
model="gemini-2.5-flash", # Or your preferred Gemini model
instruction="You are a helpful assistant. Answer user questions using Google Search when needed.",
description="An assistant that can search the web.",
tools=[google_search]
)
Define a multi-agent system:
Define a multi-agent system with coordinator agent, greeter agent, and task execution agent. Then ADK engine and the model will guide the agents to work together to accomplish the task.
from google.adk.agents import LlmAgent, BaseAgent
# Define individual agents
greeter = LlmAgent(name="greeter", model="gemini-2.5-flash", ...)
task_executor = LlmAgent(name="task_executor", model="gemini-2.5-flash", ...)
# Create parent agent and assign children via sub_agents
coordinator = LlmAgent(
name="Coordinator",
model="gemini-2.5-flash",
description="I coordinate greetings and tasks.",
sub_agents=[ # Assign sub_agents here
greeter,
task_executor
]
)
Development UI
A built-in development UI to help you test, evaluate, debug, and showcase your agent(s).
Evaluate Agents
adk eval \
samples_for_testing/hello_world \
samples_for_testing/hello_world/hello_world_eval_set_001.evalset.json
🤝 Contributing
We welcome contributions from the community! Whether it's bug reports, feature requests, documentation improvements, or code contributions, please see our
- General contribution guideline and flow.
- Then if you want to contribute code, please read Code Contributing Guidelines to get started.
Community Repo
We have adk-python-community repo that is home to a growing ecosystem of community-contributed tools, third-party service integrations, and deployment scripts that extend the core capabilities of the ADK.
Vibe Coding
If you want to develop agent via vibe coding the llms.txt and the llms-full.txt can be used as context to LLM. While the former one is a summarized one and the later one has the full information in case your LLM has big enough context window.
Community Events
- [Completed] ADK's 1st community meeting on Wednesday, October 15, 2025. Remember to join our group to get access to the recording, and deck.
📄 License
This project is licensed under the Apache 2.0 License - see the LICENSE file for details.
Happy Agent Building!
