fix(code): bust CDN cache on forced dcode update checks - #4862
Merged
Mason Daugherty (mdrxy) merged 1 commit intoJul 20, 2026
Conversation
`dcode update` already bypasses the local version cache, but PyPI's JSON API is served through a CDN that can return a stale answer for a few seconds after a release. That made a first `dcode update` report "already on the latest version" while a retry seconds later found the new release. When the local cache is bypassed, send `Cache-Control: no-cache` / `Pragma: no-cache` headers and a unique cache-busting query parameter so the CDN cache key misses and the response is fetched fresh from origin. Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Mason Daugherty (mdrxy)
marked this pull request as ready for review
July 20, 2026 19:14
Mason Daugherty (mdrxy)
deleted the
mdrxy/code/update-check-cdn-cache-bust
branch
July 20, 2026 19:31
Mason Daugherty (mdrxy)
pushed a commit
that referenced
this pull request
Jul 22, 2026
> [!CAUTION] > Merging this PR will automatically publish to **PyPI** and create a **GitHub release**. For the full release process, see [`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md). --- _Release notes preview: keep this section in sync with the package `CHANGELOG.md`. The published GitHub release body is extracted from the merged `CHANGELOG.md` by `release.yml`, not from this PR description._ --- ## [0.1.45](deepagents-code==0.1.44...deepagents-code==0.1.45) (2026-07-22) ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](#4880), [#4870](#4870)) - Added a filesystem tool allowlist for `dcode` with `--allow-fs-tools` ([#4635](#4635)) - Added a GLM-5.2 harness profile ([#4710](#4710)) - Added a built-in thread inspector skill ([#4769](#4769)) - Replaced Gemini 3.5 Flash with Gemini 3.6 Flash in the model switcher ([#4890](#4890)) - Show experimental mode in the splash screen and debug console ([#4863](#4863)) - Gate debug console click-to-copy behind a checkbox ([#4810](#4810)) ### Bug Fixes - Improved scratch-file handling by allowing cleanup of agent-created scratch files and safe OS-temp scratch artifacts ([#4860](#4860), [#4869](#4869)) - Skip grading during `/goal` proposals ([#4941](#4941)) - Improved MCP approval handling: Esc now aborts project MCP approval, disabled MCP servers are honored for plugins, remembered approvals are preserved with the env allowlist, and approvals are shared across Git worktrees ([#4888](#4888), [#4848](#4848), [#4889](#4889), [#4939](#4939)) - Hardened installer downloads and paths ([#4871](#4871)) - Fixed forced `dcode update` checks to bust the CDN cache ([#4862](#4862)) - Prevented failed exit setup from stranding the app ([#4913](#4913)) - Fixed routing so `ctrl+x` goes to the focused `ask_user` input ([#4926](#4926)) - Show `-m` prompts as queued immediately on startup ([#4861](#4861)) - Kept harness-profile diagnostics out of terminal output ([#4943](#4943)) - Avoid tracking inline restart callers ([#4894](#4894)) - Fixed debug console thread ID copying on click ([#4945](#4945)) ### Performance Improvements - Reduced exit latency by coordinating async shutdown teardown ([#4831](#4831)) - Sped up local context detection ([#4922](#4922)) _End release notes preview._ --- > [!NOTE] > A **New Contributors** section is appended to the GitHub release notes automatically at publish time (see [Release Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline), step 2). --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Marcelo5444
pushed a commit
to Marcelo5444/deepagents
that referenced
this pull request
Jul 30, 2026
…ai#4862) `dcode update` now returns fresh results even in the seconds right after a new release lands on PyPI. --- `dcode update` already calls `is_update_available(bypass_cache=True)`, which skips the local on-disk version cache. But PyPI's JSON API is served through a CDN (Fastly), so immediately after a release an edge node can keep serving a stale copy until the purge propagates. That's why a first `dcode update` reported "Already on the latest version (v0.1.43)" while a retry seconds later found v0.1.44. When the local cache is bypassed, the PyPI requests now also defeat the CDN edge cache: they send `Cache-Control: no-cache` / `Pragma: no-cache` request headers and append a unique cache-busting query parameter so the CDN cache key misses and the response comes fresh from origin. A shared `_pypi_request_kwargs` helper applies this consistently to the version check, the per-release pre-release-pin lookup, and the SDK release-time lookup. Routine (non-forced) refreshes are unchanged. Made by [Open SWE](https://openswe.vercel.app/agents/f2647aaa-94ac-f901-c39d-e081d0eb1f79) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Marcelo5444
pushed a commit
to Marcelo5444/deepagents
that referenced
this pull request
Jul 30, 2026
> [!CAUTION] > Merging this PR will automatically publish to **PyPI** and create a **GitHub release**. For the full release process, see [`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md). --- _Release notes preview: keep this section in sync with the package `CHANGELOG.md`. The published GitHub release body is extracted from the merged `CHANGELOG.md` by `release.yml`, not from this PR description._ --- ## [0.1.45](langchain-ai/deepagents@deepagents-code==0.1.44...deepagents-code==0.1.45) (2026-07-22) ### Features - Added the Hooks v2 execution engine and typed hooks data models ([langchain-ai#4880](langchain-ai#4880), [langchain-ai#4870](langchain-ai#4870)) - Added a filesystem tool allowlist for `dcode` with `--allow-fs-tools` ([langchain-ai#4635](langchain-ai#4635)) - Added a GLM-5.2 harness profile ([langchain-ai#4710](langchain-ai#4710)) - Added a built-in thread inspector skill ([langchain-ai#4769](langchain-ai#4769)) - Replaced Gemini 3.5 Flash with Gemini 3.6 Flash in the model switcher ([langchain-ai#4890](langchain-ai#4890)) - Show experimental mode in the splash screen and debug console ([langchain-ai#4863](langchain-ai#4863)) - Gate debug console click-to-copy behind a checkbox ([langchain-ai#4810](langchain-ai#4810)) ### Bug Fixes - Improved scratch-file handling by allowing cleanup of agent-created scratch files and safe OS-temp scratch artifacts ([langchain-ai#4860](langchain-ai#4860), [langchain-ai#4869](langchain-ai#4869)) - Skip grading during `/goal` proposals ([langchain-ai#4941](langchain-ai#4941)) - Improved MCP approval handling: Esc now aborts project MCP approval, disabled MCP servers are honored for plugins, remembered approvals are preserved with the env allowlist, and approvals are shared across Git worktrees ([langchain-ai#4888](langchain-ai#4888), [langchain-ai#4848](langchain-ai#4848), [langchain-ai#4889](langchain-ai#4889), [langchain-ai#4939](langchain-ai#4939)) - Hardened installer downloads and paths ([langchain-ai#4871](langchain-ai#4871)) - Fixed forced `dcode update` checks to bust the CDN cache ([langchain-ai#4862](langchain-ai#4862)) - Prevented failed exit setup from stranding the app ([langchain-ai#4913](langchain-ai#4913)) - Fixed routing so `ctrl+x` goes to the focused `ask_user` input ([langchain-ai#4926](langchain-ai#4926)) - Show `-m` prompts as queued immediately on startup ([langchain-ai#4861](langchain-ai#4861)) - Kept harness-profile diagnostics out of terminal output ([langchain-ai#4943](langchain-ai#4943)) - Avoid tracking inline restart callers ([langchain-ai#4894](langchain-ai#4894)) - Fixed debug console thread ID copying on click ([langchain-ai#4945](langchain-ai#4945)) ### Performance Improvements - Reduced exit latency by coordinating async shutdown teardown ([langchain-ai#4831](langchain-ai#4831)) - Sped up local context detection ([langchain-ai#4922](langchain-ai#4922)) _End release notes preview._ --- > [!NOTE] > A **New Contributors** section is appended to the GitHub release notes automatically at publish time (see [Release Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline), step 2). --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
dcode updatenow returns fresh results even in the seconds right after a new release lands on PyPI.dcode updatealready callsis_update_available(bypass_cache=True), which skips the local on-disk version cache. But PyPI's JSON API is served through a CDN (Fastly), so immediately after a release an edge node can keep serving a stale copy until the purge propagates. That's why a firstdcode updatereported "Already on the latest version (v0.1.43)" while a retry seconds later found v0.1.44.When the local cache is bypassed, the PyPI requests now also defeat the CDN edge cache: they send
Cache-Control: no-cache/Pragma: no-cacherequest headers and append a unique cache-busting query parameter so the CDN cache key misses and the response comes fresh from origin. A shared_pypi_request_kwargshelper applies this consistently to the version check, the per-release pre-release-pin lookup, and the SDK release-time lookup. Routine (non-forced) refreshes are unchanged.Made by Open SWE