Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 29 additions & 0 deletions core/changelog.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion core/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.8.6
1.9.0
11 changes: 11 additions & 0 deletions framework/changelog.md
Original file line number Diff line number Diff line change
@@ -1,2 +1,13 @@
- feat: model allow and block lists accept `regex:` entries. The provider-key aggregate keeps an exact name next to a pattern that also covers it, the catalog allow check tries a pattern against the bare name and `provider/model`, and listings skip pattern entries
- fix: ClickHouse log store deletes no longer run as heavyweight `ALTER TABLE ... DELETE` mutations. The retention cleaner issued one such mutation per 100 rows, each rewriting the whole current-month part, and the once-a-minute stale-`processing` sweeps issued one per table unconditionally, filling replica disks in minutes. Every delete on the ClickHouse store (retention sweep, `Flush`/`FlushMCPToolLogs`, UI log deletes, async job and webhook delivery expiry) is now a single lightweight `DELETE FROM ... WHERE` per run, skipped entirely when nothing matches. The table TTL derived from `logs_store.retention_days` is now reconciled on every startup with `MODIFY TTL` (metadata only), so changing the value reaches existing tables; `0` leaves an existing TTL untouched (#7098)
- feat: access profiles and governance projects reference Virtual MCPs through `virtual_mcp_name`, so config files are portable across environments instead of carrying database-assigned integer IDs. Names resolve to stored records on startup and a name that matches nothing is refused; `virtual_mcp_id` is deprecated, still accepted, and wins when both are set. `mcp_configs` (`{ mcp_client_id, tools_to_execute }`) replaces the `mcp_servers` and `mcp_tool_overrides` include-exclude model with a single allowlist, where `["*"]` grants all tools including future ones, `[]` grants none, and a named list grants only those; the old keys are deprecated, still accepted, and folded into the new shape at load time (#7181)
- feat: `MCPToolLog` records governance entity names beside their IDs, so MCP tool logs carry the same attribution shape the `logs` table has instead of rendering raw UUIDs in the dashboard. `user_name`, `team_name`, `customer_name` and `business_unit_name` stop being `gorm:"-"` transients and become storage; the multi-valued `team_ids`/`team_names`, `customer_ids`/`customer_names` and `business_unit_ids`/`business_unit_names` sets are stored as index-aligned JSON arrays; and `budget_ids` and `rate_limit_ids` are recorded id-only, as in `logs`. Names are written from the request context at ingestion through the new `MCPToolLog.ApplyGovernance` in `framework/logstore/governance.go`, with nothing resolved on read. Added by migration `mcp_tool_logs_add_governance_snapshots` (#7154)
- feat: endpoint-attributed MCP observations are carried in the standard logging pipeline, so inspected MCP tool calls are logged with bounded identity (device, app key, server label, tool name, decision) sourced from the gateway rather than from payload-supplied headers. `SetMCPObservation` attaches the attribution to a `BifrostContext` and `applyMCPObservation` writes it onto the `MCPToolLog` from both `PreMCPHook` and `PostMCPHook`, snapshotting the observation so it cannot alias across async log entries (#6959)
- feat: the `error_type` classification vocabulary is threaded through the framework so `bifrost_error_requests_total` can carry a normalized fault-domain label alongside `status_code` (#7141)
- feat: model pricing supports time-of-day peak and off-peak rates. `TableModelPricing` gains `off_peak_cost_multiplier` (a nullable float) and `peak_hours` (a JSON-serialized `PeakHoursSchedule` of recurring weekly windows using IANA timezone names, weekday numbers and half-open `HH:MM` intervals that may wrap past midnight), added by migration `add_time_of_day_pricing_columns` and aliased into the datasheet package so the JSON shape stays self-contained. The cost engine evaluates the schedule against the request start time and scales usage-based charges by the multiplier when the request falls outside every peak window, applied once in `computeCostFromInput` so every modality is covered; flat `CostPerRequest` and `SearchQueriesCost` fees are excluded, as is `AdditionalCost`, which is discounted independently through its own pricing rows. Both fields are exposed on `PricingPatch` in the OpenAPI and governance schemas, with `off_peak_cost_multiplier` bounded to `(0, 1]` (#6574, #6575, #6576)
- feat: `SecretVar.RedactedIfSecret()` is used for non-credential fields in `ProviderConfig.Redacted()`, `Config.GetAllKeys()` and `Config.RedactMCPClientConfig()`, so regions, endpoints, service URLs and MCP connection strings surface as plaintext while anything env-var or vault-backed stays masked (#7085)
- feat: GA realtime transcription sessions are routed, governed, logged and priced through the normal framework pipeline, resolving the routing model from the nested `audio.input.transcription.model` that arrives in `session.update` rather than from the connect URL (#7089)
- feat: a `use_openai_endpoints` column on the provider keys table, added by migration `add_use_openai_endpoints_column`, opts a Bedrock key or alias into Bedrock's OpenAI-compatible endpoints instead of Converse (#7073)
- feat: the reserved tool-namespace list a provider keeps for its own server tools is read from the datasheet row `reserved_tool_namespaces`, so a namespace collision check no longer requires a code change (#7084)
- fix: `exchangeRefreshToken` includes `client_secret` only when the secret is non-empty, matching `exchangeCodeForTokensWithPKCE`. Public OAuth2 clients registered against servers that support only `token_endpoint_auth_method: none` have no secret, and unconditionally setting `client_secret=` sent an empty `client_secret_post` attempt that strict authorization servers answered with `invalid_client`, flipping the token row to `needs_reauth` even though the refresh token was valid (#7042)
- fix: the virtual key `allowed_models: ["*"]` handling for governance added in #6767 is reverted, returning the wildcard-with-empty-synced-catalog case to its previous behaviour (#7053)
2 changes: 1 addition & 1 deletion framework/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.2
1.7.0
1 change: 1 addition & 0 deletions plugins/compat/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
- fix: removed the namespace-tool flattening that ran under `should_convert_params`; it spliced nested functions into the top-level list without a namespace prefix, so two namespaces sharing a function name produced duplicate tool names and an upstream 400. Flattening now lives in Bifrost core for every provider whose wire lacks the `namespace` type, with unique `<namespace>__<function>` names and response-side mapping back. `should_convert_params` is still accepted so existing configs load, but it no longer changes any request (#7048)
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/compat/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0.2.2
0.3.0
5 changes: 5 additions & 0 deletions plugins/governance/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
- feat: MCP tool logs record governance entity names beside their IDs, so the plugin stamps `user_name`, `team_name`, `customer_name`, `business_unit_name` and the multi-valued team, customer and business-unit sets onto the log entry at ingestion instead of leaving the dashboard to render raw UUIDs (#7154)
- feat: endpoint-attributed MCP inspections carry bounded identity (device, app key, server label, tool name, decision) from the gateway into the MCP authorization path, so an inspected tool call is attributed without trusting payload-supplied headers (#6959)
- feat: governance errors are classified into the normalized `error_type` vocabulary, so a 429 raised by a governance rate limit is distinguishable from an upstream 429 on `bifrost_error_requests_total` (#7141)
- feat: model allow and block lists accept `regex:` entries. The `*_patterns` fields added earlier in this release window were withdrawn in favour of the prefix form, which needs no new schema fields (#6988, #7133, #7134)
- fix: `UsageTracker.Cleanup()` cancels and waits for the periodic reset worker before taking its final budget and rate-limit snapshots. It previously dumped first, so `trackerCancel()` could cancel an in-flight rate-limit dump and fail with `failed to dump rate limits to database: context canceled`, and the final dump was not guaranteed to be the tracker's last database writer. A queued ticker event can no longer start another reset cycle during shutdown, the current cycle stops when the tracker context is cancelled, and `context.Canceled` is treated as an expected result only when that context was actually cancelled (#7099) [@Constantine3](https://github.com/Constantine3)
2 changes: 1 addition & 1 deletion plugins/governance/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.7.2
1.8.0
1 change: 1 addition & 0 deletions plugins/jsonparser/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/jsonparser/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.2
1.6.3
6 changes: 6 additions & 0 deletions plugins/logging/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
- feat: MCP tool log rows carry governance entity names alongside their IDs, written from the request context at ingestion, so nothing is resolved on read (#7154)
- feat: endpoint-attributed MCP observations are written onto both the pending and the final MCP tool log entry, with the observation snapshotted so it cannot alias across async entries (#6959)
- feat: cost recalculation honours time-of-day peak and off-peak pricing, scaling usage-based charges by `off_peak_cost_multiplier` when a request falls outside every declared peak window (#6575)
- feat: GA realtime transcription sessions are logged and priced through the standard pipeline with transcription-aware pricing (#7089)
- fix: a request whose caller disconnected before the upstream finished is logged and finalized deterministically rather than roughly half the time, so abandoned requests no longer leave a log row stuck in its pending state (#6972)
- docs: clarified that `CountRecalcTargets` reads a materialized view that can lag, so its `Total` is an approximation rather than an exact count (#7078)
2 changes: 1 addition & 1 deletion plugins/logging/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.7.2
1.8.0
1 change: 1 addition & 0 deletions plugins/maxim/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/maxim/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.7.2
1.7.3
1 change: 1 addition & 0 deletions plugins/mocker/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/mocker/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.2
1.6.3
1 change: 1 addition & 0 deletions plugins/modelcatalogresolver/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/modelcatalogresolver/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.1.2
1.1.3
1 change: 1 addition & 0 deletions plugins/otel/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/otel/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.5.2
1.5.3
1 change: 1 addition & 0 deletions plugins/prompts/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/prompts/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.1.2
1.1.3
1 change: 1 addition & 0 deletions plugins/routing/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- fix: a continuation turn, such as a tool result following a prior user message, is classified instead of skipped when no active session state is found. `BuildInputWithDisposition` now returns the populated `ComplexityInput` including `LastUserText` for trailing-continuation turns in both the chat and responses paths, and `computeComplexity` falls back to classifying that recovered text, so new or recovered sessions get a tier assignment; the skip path applies only when `LastUserText` is also empty (#7122)
2 changes: 1 addition & 1 deletion plugins/routing/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.0.2
1.1.0
1 change: 1 addition & 0 deletions plugins/semanticcache/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- chore: upgraded core to v1.9.0 and framework to v1.7.0
2 changes: 1 addition & 1 deletion plugins/semanticcache/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.2
1.6.3
1 change: 1 addition & 0 deletions plugins/telemetry/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- feat: `bifrost_error_requests_total` carries a normalized `error_type` label alongside `status_code`, drawn from a closed prefix-structured vocabulary (`caller_*`, `policy_*`, `provider_*`, `bifrost_*`, `_OTHER`), so alarm expressions can separate fault domains with a single regex instead of enumerating status codes (#7141)
2 changes: 1 addition & 1 deletion plugins/telemetry/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.2
1.7.0
Loading
Loading