Three things in Agno v3.1.0: (1) a new `agno.os.authz` package gives AgentOS a native role store, scope policy, audit log, and user directory, with pluggable native and `fga` authorization engines; (2) a new `agno.fs`/`DbFileSystem` adds dedicated `/filesystem` routes to AgentOS, but existing `agno_fs` tables must be migrated offline or they raise `SchemaOutdatedError`; (3) Breaking: `MCPConfig`'s bundled default tools and lifecycle tools (`continue_run`/`cancel_run`) switch from automatically included to explicit opt-in.
Three things in Haystack v3.3.0: (1) security — `anyio` is bumped to `>=4.14.2`, patching CVE-2026-63374 (GHSA-82r6-8w77-94w6); it's pulled in transitively through `httpx`/`openai`, so older versions were vulnerable; (2) performance — `SentenceWindowRetriever` now queries the Document Store once per `run`/`run_async` call instead of once per retrieved document; (3) Breaking: BM25L/BM25Plus (the default) now only return documents that contain at least one query term, which can shrink result counts; passing a negative `top_k` now raises `ValueError` instead of silently slicing; and a fix for lost whitespace at quoted sentence endings shifts chunk boundaries for re-indexed corpora.
Three things in Pydantic AI v2.52.0: (1) security — GHSA-v36g-jcw9-x7cw (moderate): attacker-controlled HTML with deeply nested elements fed into the local web_fetch tool could exhaust CPU/memory; provider-native web fetching is unaffected; patched in both 2.52.0 (v2) and 1.107.7 (v1); (2) a new Workspace abstraction — Coder/Shell/FileSystem and the rest of the harness now go through ctx.workspace, sharing one API across local execution and four sandbox backends (SSHWorkspace, BubblewrapSandbox, E2BSandbox, SpritesSandbox), with ModalSandboxSession renamed to ModalSandboxBackend; (3) pydantic-ai-harness jumps from 0.36.0 to 0.52.0 and now ships with every release, alongside the first pydantic-clai2 (`uvx pydantic-clai2`) CLI release, bundled with plugins like github, slack, notion, and logfire_mcp.
Three things in AG2 v1.1.1: (1) breaking — BedrockConfig switches from thread-wrapped boto3 to native async aiobotocore, and passing a boto3.Session now fails outright; (2) security — restricted shell mode parses a command into argv exactly once and runs that argv, so pipes, redirects, and globs can no longer smuggle a second command past the allowlist; (3) security — when multiple tools share a name, only one now resolves per turn, with code-declared tools taking priority over MCP or client tools. The version bump is a patch (1.1.0 → 1.1.1); the content is not.
Four things in Mastra @mastra/core@1.71.0: (1) Eager Tool Execution is on by default, starting a tool call as soon as its own arguments are ready instead of waiting for the whole step; (2) Observability Capabilities Negotiation lets Studio and custom clients probe which tracing APIs a storage backend supports before calling them, fixing hard 500s on legacy stores; (3) a new `@mastra/discord` channel, sandbox credential materialization, and server-side MongoDB Vector embeddings; (4) breaking: `@mastra/playground-ui`'s `TaskList` drops `title`, `TaskListHeader`, and `hideWhenEmpty`.
Four things worth knowing in Mastra @mastra/core@1.69.0: (1) a new Classifier primitive turns fixed-option LLM judgments into a first-class component you can register on a Mastra instance, with automatic tracing; (2) a Classifier can be used directly as a typed workflow step for branching, or wrapped in a ClassifierProcessor to guard agent input/output/streaming content, failing closed by default; (3) context.background.adopt() lets a tool acknowledge immediately while handing off a long-running background task, and @mastra/connect@0.3.0 ships ten new SaaS integrations at once; (4) breaking changes: @mastra/playground-ui's PageLayout/FluidHoverHighlight APIs were reworked, and the group option on trace queries is now deprecated.
Three things worth knowing about Pydantic AI v2.46.0: (1) the previous release (2.45.0) introduced TypeSafeModel — a provider for TypeSafe's Jev, a classifier that answers typed questions instead of writing text — and this release fills in what it couldn't do yet: filling tool call arguments and picking a type before filling a union output; (2) a new `typesafe_boolean_threshold` turns the yes/no decision boundary from a fixed distance-from-0.5 into a tunable parameter; (3) `supports_text_output` lets `LLMJudge` and `GEval` run on models that don't produce text at all, so Jev can now serve as the judge model in evals. No breaking changes.
Three things worth knowing about Microsoft Agent Framework python-1.19.0: (1) four BREAKING changes land together, covering HTTP cookie persistence, MCP skill archive format, MCP session scoping, and Redis history key scoping; (2) a new generic vector store provider protocol ships with three new connectors at once — MongoDB (alpha), Azure DocumentDB (alpha), and Azure Cosmos DB NoSQL; (3) built-in orchestration workflows now have stable names and registered checkpoint types, so the built-in sequential/concurrent/handoff/group-chat patterns can be restored after a restart, not just custom workflows.
CrewAI 1.15.22 in three points: (1) a new `llm_overlay` context variable that routes a specific agent role to a different model at runtime, instead of hardcoding the model when the agent is created; (2) CrewAI Platform integration gains an application catalog, connection aliases, setup-time integration validation, and deployment-failure logging; (3) tracing now captures human feedback and pause events; no breaking changes in this release.
Pydantic AI v2.44.0 in three points: (1) four security patches, the most serious being `web_fetch` running both its HTML conversion and charset decoding in superlinear time on the event loop — an attacker-chosen page can stall every agent sharing that process; (2) three compatibility notes: `RunContext.enqueue()` is now safe to call from worker threads, UI adapter requests must carry a JSON `Content-Type`, and a capability's `@durable_operation` invoked from a per-request hook now dispatches properly instead of running inline; (3) a new Vercel AI SDK/Eve migration skill, and `AgentRunResult` now settles into a stable serialized shape.
Agno v3.0.10 in three points: (1) `CodingTools.run_shell` moves from enabled-by-default to requiring `enable_run_shell=True`, and restricted mode no longer routes commands through a shell at all, closing off interpreter-RCE-style shell injection; (2) `PublicSurface(authorization=True, mcp=True)` now accepts only localhost by default — non-local callers need an explicit `MCPConfig(allowed_hosts=[...])` allowlist; (3) new `AzureOpenAIResponses` model, an Elasticsearch vector database, and a `DocumentationMarkdown` transform that converts Mintlify/Fumadocs docs sites into plain Markdown.
Mastra @mastra/core@1.67.0 in four points: (1) the Studio Workflow Builder backend lets an editor-owned agent generate and persist workflow definitions directly — describe a flow in natural language and get a real, runnable workflow back; (2) the new `@mastra/connect` package wraps Mastra Platform integration connections as agent tools, with credentials injected by the platform's connection proxy so agent code never touches a secret; (3) `Memory.updateThreadResourceId()` lets a thread be transferred to a new `resourceId`, implemented transactionally across every major SQL adapter; (4) breaking: `subscribeQueuedMessages` is renamed `subscribeThreadEvents`, and `ArchilFilesystem.grep()` is renamed `diskGrep()`.
Temporal v1.32.0 highlights: (1) Standalone Activities reach GA, with delayed starts, operator APIs (pause/resume/reset), and batch operations; (2) Nexus callbacks now route by URL scheme by default, removing the old header-based config — a breaking, security-driven change; (3) the Unified Query Converter becomes the default, tightening type validation and empty-string filtering on Visibility queries.
Mastra @mastra/core@1.65.0 highlights: (1) a new advanced trace query contract implemented across ClickHouse, DuckDB, and Postgres, with bounded time ranges, recursive predicates, and cursor pagination; (2) tenant-scoped batch deletion (up to 1,000 traces per request) that cascades to spans/scores/feedback/metrics/logs; (3) breaking: `@mastra/factory`'s `defineBoard()` becomes a typed phase contract, the global rules object is removed, and two `@mastra/playground-ui` components got renamed slots/props.
Pydantic AI v2.42.0 highlights: (1) a new `GitHubCopilotProvider` lets Agents use GitHub Copilot's OpenAI-compatible API directly as a model backend; (2) `DeferredToolResults.approvals` now rejects invalid values outright — a compatibility change; (3) fixes for Bedrock Converse sampling settings, `$ref` resolution in code-mode function schemas, and lost Anthropic error-recovery state across normalized history.
Agno 3.0.6 highlights: (1) `MCPConfig(stateless=True)` serves `/mcp` without session tracking so any replica can answer any request, removing the need for session affinity in multi-instance deployments (at the cost of server-initiated notifications and SSE resumability); (2) `MCPTools(protocol_mode="auto")` negotiates the newest MCP protocol era both sides support, including the sessionless capability from the 2026-07-28 spec, while the default `"legacy"` mode keeps today's behavior unchanged; (3) adds an AgentOS MCP Server Card (`GET /mcp/server-card`), `.zip`/`.eml` file uploads, `AuthorizationConfig.excluded_route_paths`, and fixes for Anthropic thinking-block replay, Gemini image MIME types, and more. No breaking changes in this release.
Mastra @mastra/core@1.64.0 highlights: (1) a new reusable sandbox template (`@mastra/platform-workspace` plus `@mastra/e2b`) lets sandboxes start from a pre-cloned, pre-built repo image, cutting cold-start time for code sessions and workspace-backed agents; (2) `MastraSandboxOptions.workingDirectory` unifies default working-directory behavior across every sandbox provider (Docker, E2B, Vercel, Railway, etc.); (3) breaking: `@mastra/factory`'s `sandbox` config changes from an options object to a callback, and `@mastra/playground-ui` removes `Chip`/`ChipsGroup`/`StatusBadge` in favor of `Badge`.
Pydantic AI 2.38.0 highlights: (1) new typed `CustomEvent`/`CapabilityEvent` — application code and capabilities can now emit custom events into the Agent's run event stream and subscribe with `@on_event`, filling in a general-purpose observability and extension layer; (2) `RunContext` gains `context_window_used` and `ModelProfile` gains `context_window`, so agent code can read how much of the model's context window remains, for the first time; (3) new model support for `gemini-3.8-flash`, Claude Fable 5.1, and Claude Mythos 5.1, plus a new `VLLMProvider`. No breaking changes in this release.
Agno 3.0.5 highlights: (1) Knowledge ingestion no longer swallows embedding failures — a new partial status sits between completed and failed, and embedders raise EmbeddingError instead of returning an empty vector; (2) Breaking: code catching ModelProviderError around Bedrock embedding failures stops working — switch to EmbeddingError — and the content status API returns 404 for missing content again; (3) adds an opt-in embedding retry, a GandrTools text-to-speech toolkit, an llmman model provider, and an embed_before_replace guard that stops a failed re-ingest from wiping existing data.
Agno 3.0.2 highlights: (1) Agents/Teams/Workflows/Toolkits can now be published directly as individually named MCP tools via MCPConfig.tools or component.as_tool(), instead of wrapping everything in run_agent(agent_id=...); (2) three behavior changes that don't bump the major version but will bite you: metadata resolution order flips (call-site now wins over component), MCPConfig rejects unknown fields at construction, and BaseRemote.acancel_run gains a required auth_token parameter; (3) four new integrations — Synthorai model provider, WaveSpeed image/video generation, Serply search, and AtomicMail inbox — plus a naming cleanup around mcp=/MCPConfig/default_tools (old names stay as aliases until 3.1).
Pydantic AI 2.36.0 highlights: (1) new `@durable_operation` decorator turns any custom capability method into a replay-safe durable unit under Temporal/Prefect/DBOS and other engines; (2) a public backend API (`BaseDurabilityCapability`, `CallableOperationBackend`, `RegisteredOperationBackend`) lets third-party durable engines integrate with zero private imports — verified against three out-of-tree engines; (3) one compatibility tightening: MCP tools can no longer opt out of durable execution via tool metadata (previously allowed on DBOS), plus a Prefect dynamic-tool cache-key fix.
Mastra @mastra/core@1.63.0 in three points: (1) a new `AdaptableLogger` contract writes trace_id/span_id straight into native log records, replacing the old dual-write wrapper — `PinoLogger` in `@mastra/loggers` is the first to support it; (2) `@mastra/deployer` adds a standalone worker entry with a `/health` endpoint (503 while starting, 200 once ready) so deployment platforms can judge whether a rollout is safe; (3) breaking change: `@mastra/playground-ui`'s DataList drops `variant="lined"`/`flushLeft`/`flushRight`/`MonoCell` in favor of `DataList.TextCell font="mono"`.
CrewAI 1.15.18 highlights: (1) conversational Flow is officially promoted from crewai.experimental to a stable API — the canonical implementation moves to crewai.flow, while crewai.experimental.conversational stays importable as a compatibility alias, so existing code doesn't break; (2) the shim currently emits no deprecation warning, so migrating is entirely opt-in for now; (3) also fixes a wrong Claude Sonnet 4.6 context-window mapping and a too-low Anthropic max_tokens default for large tool calls. No breaking changes.
Mastra @mastra/core@1.62.0 has three highlights: (1) new Computer-Use Sandboxes let agents drive a virtual desktop through the Daytona or E2B Desktop providers — 11 tools for screenshots, clicks, typing, and scrolling; (2) new `@mastra/elasticsearch` and `@mastra/valkey`/`@mastra/valkey-streams` storage backends widen production storage options; (3) 7 breaking changes, including dropped Cloudflare KV/ClickHouse support for background task storage, a changed `DaytonaSandbox` command result format, and the removed `persistPartialOnAbort` option on `agent.stream()`.
Haystack 3.1.0 highlights: (1) Experimental `CompactionHook` with `SlidingWindowCompactor` (drop old turns) and `ToolResultPruningCompactor` (replace old tool results with placeholders) for managing context blowup in long conversations; (2) `AgentTool` lets you wrap a full Agent as another Agent's tool — the caller sees only the final reply, not intermediate steps; (3) Multiple pipeline deserialization and Jinja sandbox RCE vulnerabilities patched, plus several behavioral changes requiring migration (e.g. `Agent.state_schema` semantics changed, `custom_filters` now requires `unsafe=True`).
Agno 3.0 in three points: (1) Runs table restructuring — runs move from session JSON blobs into a dedicated agno_runs table, reducing write amplification from O(N²) to O(N); you must run MigrationManager before upgrading or you'll hit MigrationRequiredError; (2) New Tool Result Offloading and Media Offloading — tool results over 16,000 characters and images/audio/video get moved to AgentFS or S3, leaving only a slim envelope in messages; (3) Breaking changes are extensive — multiple Agent parameter renames, reasoning=True removed, DuckDuckGoTools methods renamed, etc. This is an upgrade that requires going through the migration guide item by item.
These seven tools are not one product category: LangGraph, MAF, and Mastra emphasize durable workflows; CrewAI and AG2 emphasize multi-agent collaboration; Pydantic AI emphasizes typed Python agents; DSPy optimizes AI programs against data and metrics. Choose the control model first.
LlamaIndex and Haystack are code-first frameworks; RAGFlow and Dify are managed application platforms; R2R packages retrieval as an API service. Choose how much control your team needs over ingestion, retrieval, and operations before choosing a tool.
CrewAI 1.15.17 highlights: (1) declarative Flow definitions can now enable conversational mode — the framework auto-synthesizes built-in conversation methods, no Python `Flow` subclass required; (2) conversational mode is explicitly marked as opt-in to reduce misuse risk; (3) fixes for AMP slug loss during slug-reference tool resolution and chunking of oversized single messages. No breaking changes.
CrewAI (GitHub 57.4k stars, MIT, PyPI 11.6M weekly downloads) defines agents by role, goal, and backstory, then groups them into crews for collaboration. Unlike LangGraph's graph-first and MAF's workflow-first approach, CrewAI is team-first — you don't draw nodes and edges, you describe who's on the team and what each person does. It fully removed its LangChain dependency in late 2024 and is now a standalone framework. The commercial side splits into the open-source package and AMP, a managed platform adding visual building, deployment, tracing, and compliance.
LlamaIndex (51,775 GitHub stars, MIT, verified 2026-08-21) has moved its center of gravity from indexing to Workflows: the standalone llama-index-workflows package pulls 2.81M weekly PyPI downloads, more than the 1.97M of the llama-index umbrella package itself. This post covers the core abstractions, the trade-off against hand-rolling a pipeline, and a hands-on test of its defaults on Traditional Chinese text — at the same chunk_size=1024, English fits 4,645 characters and Traditional Chinese only 1,332. Plus one fact you need before choosing: the TypeScript port is archived and unmaintained.
Mastra 1.60.0 highlights: (1) Stored Agents gain durable: true for durable execution without redeployment, inheriting the server's cache/pubsub for multi-replica persistence; (2) new @mastra/cloudflare-sandbox provider executes commands and file operations through a deployed Sandbox Bridge Worker; (3) @mastra/mcp supports the stateless 2026-07-28 MCP protocol revision and multi-turn elicitation. No breaking changes.
AG2 v1.0.2 highlights: (1) AG2 agents can now be exposed as ACP agents, serving remote clients over HTTP/WebSocket; (2) A2A agent cards switch from plaintext to signed-and-verified, plus gRPC TLS transport; (3) LiveAgent adds ElevenLabs as a voice provider, and community extensions (Tenki sandbox, TealTiger governance middleware) land for the first time. No breaking changes.
Mastra 1.59.0 highlights: (1) CostGuardProcessor renamed and upgraded to TokenCostControl, now supporting user/organization/session tiered budgets with warnAtPercent alerts; (2) Breaking: Factory's autoRunEnabled now defaults to false — rule-suggested executions enter a proposed state pending approval; (3) New listActiveThreadRuns() for low-cost querying of in-progress runs, enabling status-polling UIs.
Sorted by GitHub Stars, a survey of 15 mainstream AI Agent frameworks in 2026 — their positioning, key features, and ideal use cases. Not a ranking — it's a map.