)]}'
{
  "log": [
    {
      "commit": "71d4fd3e0c0afbc5162ad59dd94f14de0f7a19ee",
      "tree": "af0993785106ae0f5bce7e21ca56966b134cc7d2",
      "parents": [
        "764e1fac51a721dfbf806513b3366500bbb83449"
      ],
      "author": {
        "name": "Rolly Calma",
        "email": "115199279+Ghraven@users.noreply.github.com",
        "time": "Mon Jul 27 00:30:49 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:30:49 2026 +0100"
      },
      "message": "Use UTF-8 for adaptive CRAG docs (#852)"
    },
    {
      "commit": "764e1fac51a721dfbf806513b3366500bbb83449",
      "tree": "53a91169cbfdb82587fd98c87dc4f0ef10f7466e",
      "parents": [
        "0476e7276bb7658985ab00010d7433d5b29f3b20"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 16:18:28 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 16:18:28 2026 +0000"
      },
      "message": "chore(deps): bump prismjs and react-syntax-highlighter in /telemetry/ui (#857)\n\nBumps [prismjs](https://github.com/PrismJS/prism) to 1.30.0 and updates ancestor dependency [react-syntax-highlighter](https://github.com/react-syntax-highlighter/react-syntax-highlighter). These dependencies need to be updated together.\n\n\nUpdates `prismjs` from 1.29.0 to 1.30.0\n- [Release notes](https://github.com/PrismJS/prism/releases)\n- [Changelog](https://github.com/PrismJS/prism/blob/v2/CHANGELOG.md)\n- [Commits](https://github.com/PrismJS/prism/compare/v1.29.0...v1.30.0)\n\nUpdates `react-syntax-highlighter` from 15.5.0 to 16.1.1\n- [Release notes](https://github.com/react-syntax-highlighter/react-syntax-highlighter/releases)\n- [Changelog](https://github.com/react-syntax-highlighter/react-syntax-highlighter/blob/master/CHANGELOG.MD)\n- [Commits](https://github.com/react-syntax-highlighter/react-syntax-highlighter/compare/15.5.0...v16.1.1)\n\n---\nupdated-dependencies:\n- dependency-name: prismjs\n  dependency-version: 1.30.0\n  dependency-type: indirect\n- dependency-name: react-syntax-highlighter\n  dependency-version: 16.1.1\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0476e7276bb7658985ab00010d7433d5b29f3b20",
      "tree": "0dab8114b85abc6bc93eb8c6705059eedeec10d4",
      "parents": [
        "83ce6c623a09100b9214cec67a39a7bd28c9395d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:15:21 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:15:21 2026 +0100"
      },
      "message": "chore(deps): bump lilconfig and tailwindcss in /telemetry/ui (#855)\n\nBumps [lilconfig](https://github.com/antonk52/lilconfig) to 3.1.3 and updates ancestor dependency [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss). These dependencies need to be updated together.\n\n\nUpdates `lilconfig` from 3.1.0 to 3.1.3\n- [Release notes](https://github.com/antonk52/lilconfig/releases)\n- [Commits](https://github.com/antonk52/lilconfig/compare/v3.1.0...v3.1.3)\n\nUpdates `tailwindcss` from 3.4.1 to 3.4.19\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v3.4.19/packages/tailwindcss)\n\n---\nupdated-dependencies:\n- dependency-name: lilconfig\n  dependency-version: 3.1.3\n  dependency-type: indirect\n- dependency-name: tailwindcss\n  dependency-version: 3.4.19\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "83ce6c623a09100b9214cec67a39a7bd28c9395d",
      "tree": "d17677c58b392d30a87df3d79c5f77487d908e0e",
      "parents": [
        "7bde981fc9d47cc87a2880b14aa09b5e95262dea"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:14:47 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:14:47 2026 +0100"
      },
      "message": "chore(deps): bump cross-spawn from 7.0.3 to 7.0.6 in /telemetry/ui (#856)\n\nBumps [cross-spawn](https://github.com/moxystudio/node-cross-spawn) from 7.0.3 to 7.0.6.\n- [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/moxystudio/node-cross-spawn/compare/v7.0.3...v7.0.6)\n\n---\nupdated-dependencies:\n- dependency-name: cross-spawn\n  dependency-version: 7.0.6\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7bde981fc9d47cc87a2880b14aa09b5e95262dea",
      "tree": "703144114f60b059ab043310d1301313720c840f",
      "parents": [
        "6e70a80a3af532dbd7efb911f9ae7e164d82b155"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 16:12:39 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 16:12:39 2026 +0000"
      },
      "message": "chore(deps): bump @babel/runtime from 7.23.9 to 7.29.7 in /telemetry/ui (#854)\n\nBumps [@babel/runtime](https://github.com/babel/babel/tree/HEAD/packages/babel-runtime) from 7.23.9 to 7.29.7.\n- [Release notes](https://github.com/babel/babel/releases)\n- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/babel/babel/commits/v7.29.7/packages/babel-runtime)\n\n---\nupdated-dependencies:\n- dependency-name: \"@babel/runtime\"\n  dependency-version: 7.29.7\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6e70a80a3af532dbd7efb911f9ae7e164d82b155",
      "tree": "f53a1718f965fddfcfe8b7578880366f1773019f",
      "parents": [
        "d4d60f6f40c08f0102be1457ca91227ee80bb7eb"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:10:07 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:10:07 2026 +0100"
      },
      "message": "chore(deps): bump lodash from 4.17.21 to 4.18.1 in /telemetry/ui (#851)\n\nBumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.18.1.\n- [Release notes](https://github.com/lodash/lodash/releases)\n- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.18.1)\n\n---\nupdated-dependencies:\n- dependency-name: lodash\n  dependency-version: 4.18.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d4d60f6f40c08f0102be1457ca91227ee80bb7eb",
      "tree": "503ef3209b9d5391648ca7eefd02b39bed2142cb",
      "parents": [
        "268bb34ae88fbc8f4130e984d99f05cb0c227c3b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:09:49 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:09:49 2026 +0100"
      },
      "message": "chore(deps): bump react-router and react-router-dom in /telemetry/ui (#850)\n\nBumps [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) to 7.18.1 and updates ancestor dependency [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom). These dependencies need to be updated together.\n\n\nUpdates `react-router` from 6.22.1 to 7.18.1\n- [Release notes](https://github.com/remix-run/react-router/releases)\n- [Changelog](https://github.com/remix-run/react-router/blob/react-router@7.18.1/packages/react-router/CHANGELOG.md)\n- [Commits](https://github.com/remix-run/react-router/commits/react-router@7.18.1/packages/react-router)\n\nUpdates `react-router-dom` from 6.22.1 to 7.18.1\n- [Release notes](https://github.com/remix-run/react-router/releases)\n- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.1/packages/react-router-dom/CHANGELOG.md)\n- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.1/packages/react-router-dom)\n\n---\nupdated-dependencies:\n- dependency-name: react-router\n  dependency-version: 7.18.1\n  dependency-type: indirect\n- dependency-name: react-router-dom\n  dependency-version: 7.18.1\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "268bb34ae88fbc8f4130e984d99f05cb0c227c3b",
      "tree": "626053975c57ca9afbb3cd2be8616e9b0b6f04e1",
      "parents": [
        "946d4c5881e16386dc24c88ff77336dce374a1ae"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:09:30 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:09:30 2026 +0100"
      },
      "message": "chore(deps): bump hono from 4.12.18 to 4.12.32 in /website (#849)\n\nBumps [hono](https://github.com/honojs/hono) from 4.12.18 to 4.12.32.\n- [Release notes](https://github.com/honojs/hono/releases)\n- [Commits](https://github.com/honojs/hono/compare/v4.12.18...v4.12.32)\n\n---\nupdated-dependencies:\n- dependency-name: hono\n  dependency-version: 4.12.32\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "946d4c5881e16386dc24c88ff77336dce374a1ae",
      "tree": "b28fffaf4a27cec11f77fef6e5695502665d24f1",
      "parents": [
        "ff4a4070be3a7eab30e67673cbdd6074b72cde83"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:09:12 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:09:12 2026 +0100"
      },
      "message": "chore(deps-dev): bump vitest from 3.2.4 to 3.2.6 in /telemetry/ui (#848)\n\nBumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.4 to 3.2.6.\n- [Release notes](https://github.com/vitest-dev/vitest/releases)\n- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)\n- [Commits](https://github.com/vitest-dev/vitest/commits/v3.2.6/packages/vitest)\n\n---\nupdated-dependencies:\n- dependency-name: vitest\n  dependency-version: 3.2.6\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "ff4a4070be3a7eab30e67673cbdd6074b72cde83",
      "tree": "8e13f4daf1d28cc5f31745881c019c4aa7b79b8e",
      "parents": [
        "80f75b8ba714737f0bc89c7be799e85abf14883a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:08:50 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:08:50 2026 +0100"
      },
      "message": "chore(deps): bump next from 15.5.18 to 15.5.21 in /website (#847)\n\nBumps [next](https://github.com/vercel/next.js) from 15.5.18 to 15.5.21.\n- [Release notes](https://github.com/vercel/next.js/releases)\n- [Commits](https://github.com/vercel/next.js/compare/v15.5.18...v15.5.21)\n\n---\nupdated-dependencies:\n- dependency-name: next\n  dependency-version: 15.5.21\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "80f75b8ba714737f0bc89c7be799e85abf14883a",
      "tree": "472868031f15581cd146788b36316d84165e8b6a",
      "parents": [
        "805131a742b6ac5742e494fe45c74400c60455d5"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 17:08:03 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 17:08:03 2026 +0100"
      },
      "message": "chore(deps): bump fast-uri from 3.1.2 to 3.1.4 in /website (#846)\n\nBumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.4.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n  dependency-version: 3.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "805131a742b6ac5742e494fe45c74400c60455d5",
      "tree": "eaa12a334454a6eb4b7eb32fb65822dfa3321a7c",
      "parents": [
        "f9b9fd6204fd616ef815df95523ae1cc453861a0"
      ],
      "author": {
        "name": "Han Nguyen",
        "email": "45792660+hannguyen0712@users.noreply.github.com",
        "time": "Fri Jul 24 02:59:12 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 10:59:12 2026 +0100"
      },
      "message": "feat: add Langfuse tracing integration (LangfuseBridge) (#844)\n\n* feat: add Langfuse integration (LangfuseBridge) (#206)\n\nImplements all features scoped in #206 via lifecycle hooks, built on\nOpenTelemetryBridge and the OTel-native Langfuse SDK:\n\n- One trace per application execution call (via the #203 interface)\n- One span per step; one span per __tracer span call\n- State observations: action inputs/read state and results/written state\n  as observation input/output (capture_state\u003dFalse to disable);\n  log_attributes as observation metadata\n- Access to the Langfuse client via bridge.langfuse_client\n- app_id/partition_key map to Langfuse session/user (overridable)\n- Injects a should_export_span filter so Burr spans survive langfuse\n  v4\u0027s default LLM-only export filtering (public: burr_span_export_filter)\n\nUses the OTel bridge instead of the tracking/client.py pattern per the\nissue thread (May 31): the SDK\u0027s OTel rewrite and the closure of #205\nmade this the cleaner path, and it nests third-party OTel LLM\ninstrumentation inside step spans automatically.\n\nIncludes tests, docs, a runnable example, and a langfuse pyproject extra.\n\n* fix: JSON-serialize complex logged attributes for Langfuse metadata\n\nOTel attributes reject sequences of non-primitives, so list-of-dict values\n(e.g. chat_history logged by @trace) were dropped with a warning. Complex\nvalues are now JSON-serialized into observation metadata.\n\n* fix(langfuse): preserve OTel provider context\n\nRoute Burr spans through custom tracer providers and propagate session and user attributes to child instrumentation. Serialize mixed-type sequences before passing them to OpenTelemetry.\n\n* fix: import propagate_attributes defensively for langfuse\u003c3.9\n\nPropagate_attributes was added in langfuse 3.9.0 and  Python 3.9 CI resolves an older 3.x (v4 requires py3.10+), so the unconditional import failed and was masked as \u0027plugin missing\u0027. Falls back to per-span session/user attributes on older SDKs, with a regression test.\n\n* fix(langfuse): support v3 attribute API\n\nLangfuse 3.7 is the latest SDK available on Python 3.9 and does not export propagate_attributes. Fall back to per-span legacy attributes.\n\n---------\n\nCo-authored-by: jernejfrank \u003cjernej@safeintelligence.ai\u003e"
    },
    {
      "commit": "f9b9fd6204fd616ef815df95523ae1cc453861a0",
      "tree": "e3130693db6aa4b98ff556af167f7d33f6f11bf8",
      "parents": [
        "7f7fe34ab2d230667269b7fd9ee6ac2677faa4a6"
      ],
      "author": {
        "name": "Rolly Calma",
        "email": "115199279+Ghraven@users.noreply.github.com",
        "time": "Thu Jul 23 23:05:24 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 15:05:24 2026 +0000"
      },
      "message": "fix: use utf-8 in CI smoke server script (#843)"
    },
    {
      "commit": "7f7fe34ab2d230667269b7fd9ee6ac2677faa4a6",
      "tree": "9c98526fb85ad071133404b52a6bf7f311cd8617",
      "parents": [
        "d887c2fe6d4be6ec5693bf5b784995f829df0a31"
      ],
      "author": {
        "name": "Hemanth Savasere",
        "email": "hemanth.savasere@gmail.com",
        "time": "Thu Jul 23 20:07:50 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 07:37:50 2026 -0700"
      },
      "message": "Feature : Migrate telemetry UI from Create React App to Vite (#793)\n\n* feat(ui): add Vite configuration\n\n* feat(ui): add Vitest configuration\n\n* feat(ui): add tsconfig.node.json for Vite config\n\n* feat(ui): update tsconfig.json for Vite compatibility\n\n* feat(ui): add root index.html for Vite\n\n* feat(ui): replace react-app-env.d.ts with vite-env.d.ts\n\n* feat(ui): replace Jest setupTests.ts with Vitest setup\n\n* fix(ui): replace broken CRA smoke test with render-without-crashing test\n\n* feat(ui): remove CRA reportWebVitals and its usage\n\n* feat(ui): remove CRA public/index.html template (replaced by root index.html)\n\n* feat(ui): swap CRA deps for Vite/Vitest, update scripts\n\n* feat(ui): regenerate package-lock.json with Vite deps\n\n* feat(server): update asset mount from /static to /assets for Vite\n\n* ci: update Node.js version from 16.x to 18.x for Vite\n\n* docs(ui): replace CRA README with Vite content\n\n* docs: update proxy configuration reference from package.json to vite.config.ts\n\n* docs: fix UI directory path from burr/ui to telemetry/ui\n\n* fix(ui): correct .eslintrc.js typo in .prettierignore\n\n* fix(ui): add postcss.config.js and autoprefixer for Tailwind CSS v3 with Vite\n\n* fix(ui): add build config files to .eslintignore and apply prettier formatting\n\n- Add postcss.config.js, vite.config.ts, vitest.config.ts to .eslintignore\n  (these use Node.js globals but ESLint env only has browser:true)\n- Apply prettier formatting fixes from npm run format:fix\n- Ensures CI workflow (ui.yml) passes cleanly with Node.js 18.x\n\n* chore: format model_costs.json with prettier\n\n* changes to resolve npm warnings\n\n* Changes in the tracking server to be running on port 7241\n\n* ci: bump Node.js from 18.x to 22.x in ui.yml\n\n* chore: pin @types/node to ^20 to match supported Node floor\n\n* chore(ui): add ASF license headers to 5 new Vite config files\n\n---------\n\nCo-authored-by: Elijah Ben Izzy \u003celijahbenizzy@users.noreply.github.com\u003e"
    },
    {
      "commit": "d887c2fe6d4be6ec5693bf5b784995f829df0a31",
      "tree": "96c0f39c381448b791d11bf8bb8fa723a25f305e",
      "parents": [
        "4a419f18ce34831a47f1fc377800812d0f0c04db"
      ],
      "author": {
        "name": "Shabbir Hussain",
        "email": "72.shabbir@gmail.com",
        "time": "Mon Jul 20 21:11:50 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 21:11:50 2026 -0700"
      },
      "message": "feat: add milestone management workflow (#750)"
    },
    {
      "commit": "4a419f18ce34831a47f1fc377800812d0f0c04db",
      "tree": "4f1bcc2c58bddb061c1e6f70674d1cefd3ac1478",
      "parents": [
        "0f0a1d12460252402060e80ef4769260a1867904"
      ],
      "author": {
        "name": "Ethan Lin",
        "email": "103916325+ethanlin01x@users.noreply.github.com",
        "time": "Sun Jul 19 05:12:40 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 21:12:40 2026 +0000"
      },
      "message": "docs: fix broken CODE_OF_CONDUCT and developer setup links in README (#838)"
    },
    {
      "commit": "0f0a1d12460252402060e80ef4769260a1867904",
      "tree": "31071c115da7702b2843314c4ce13544d7a2900b",
      "parents": [
        "22b6f4a0b876441ab6948bd67e90d7afebe296bc"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Jul 18 18:08:20 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 14:08:20 2026 -0700"
      },
      "message": "ci: base stale-assignment clock on human activity, not updated_at (#823)\n\nThe stale-assignment workflow measured inactivity from issue.updated_at.\nThat field is bumped by *any* change to the issue, including the bot\u0027s own\nwarning comment and label edits. Each weekly warn therefore reset the clock,\ncapping daysSinceUpdate at the warn interval so the 21-day unassign branch\nwas never reached: the bot warned forever and never removed an assignee.\n\nObserved on apache/burr#400: warnings at 17 then exactly 14 days later 14,\nagain 16 then 20 days, while the assignee was never unassigned.\n\nCompute inactivity from the most recent of: last non-bot comment, the\nassignment event for a current assignee (so a freshly assigned issue is not\ninstantly stale), and issue creation time. Bot comments no longer pollute the\nsignal, so the clock accumulates and the unassign threshold is reachable.\nReuse the paginated comments for the recent-warn spam guard.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e"
    },
    {
      "commit": "22b6f4a0b876441ab6948bd67e90d7afebe296bc",
      "tree": "8567cc9979b32e914650759815671f1cf4e14d36",
      "parents": [
        "6294847aaeecd31243d221679900f3f868662d1f"
      ],
      "author": {
        "name": "Vaquar Khan",
        "email": "vaquar.cna@gmail.com",
        "time": "Sat Jul 18 16:07:51 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 14:07:51 2026 -0700"
      },
      "message": "feat(ui): add dark mode support with system preference and toggle (#209) (#830)\n\nPhase 1: enable the dark mode mechanism and apply it to the app shell.\n\n- tailwind.config.js: change darkMode from invalid \u0027false\u0027 to \u0027class\u0027\n- Add useTheme hook: respects system preference via prefers-color-scheme,\n  allows manual override, persists choice to localStorage, reacts to OS changes\n- Add ThemeToggle component (sun/moon button) replacing the previously broken radio\n- Apply dark: variants to the app shell: container, desktop + mobile sidebar,\n  nav links, disclosure menus, breadcrumb, and project list table\n- Mount theme initialization at App root to apply the dark class on load\n\nLight mode is unchanged (all changes are additive dark: variants). Remaining\nper-view component coverage will follow in subsequent PRs.\n\nCo-authored-by: vaquarkhan \u003cvaquarkhan@users.noreply.github.com\u003e"
    },
    {
      "commit": "6294847aaeecd31243d221679900f3f868662d1f",
      "tree": "30abe71f7de669c46706e8811cd419fb0fcbb517",
      "parents": [
        "19d3fcfcf00015039a94463158fe40d22a2a2c89"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sun Jul 12 08:41:47 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 12 08:41:47 2026 -0700"
      },
      "message": "Add Condition.safe_expr for opt-in restricted AST evaluation (#820)\n\n* feat: add Condition.safe_expr for opt-in restricted AST evaluation (#817)\n\nIntroduce Condition.safe_expr() as the opt-in safe sibling of Condition.expr().\nWhere expr() uses eval() (acceptable for developer-authored strings, unsafe\nfor less-trusted input), safe_expr() parses the expression, validates every\nAST node against a tight allowlist at call time, and then interprets the\nvalidated tree directly. eval()/compile() are never invoked on the parsed\ntree -- the safety argument depends on this.\n\nAllowed grammar: constants, Name lookup (resolved against state), Attribute\naccess (dunder names rejected -- closes __class__.__bases__.__subclasses__()),\nSubscript, Compare, BoolOp, UnaryOp, arithmetic BinOp, literal containers,\nand Call only to a whitelist of safe builtins (len/abs/min/max/sum/all/any/\nstr/int/float/bool). Everything else -- lambdas, comprehensions, IfExp,\nwalrus, f-strings, bitwise ops, arbitrary calls, bytes/Ellipsis constants --\nraises ValueError at safe_expr() call time, before the Condition is built.\n\nBackward compatible: Condition.expr is unchanged. safe_expr is exported as\nburr.core.safe_expr alongside expr. expr\u0027s docstring now cross-references\nsafe_expr for the untrusted-input use case.\n\nCo-Authored-By: Claude Opus 4.7 \u003cnoreply@anthropic.com\u003e\n\n* style: apply black to tests/core/test_action.py\n\n---------\n\nCo-authored-by: Claude Opus 4.7 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "19d3fcfcf00015039a94463158fe40d22a2a2c89",
      "tree": "24584694b7ed6fe00590df32173692fe6adddc69",
      "parents": [
        "2e021569e17ef60a06d11be9f222522431e7d316"
      ],
      "author": {
        "name": "Timothy Lee",
        "email": "tnln3rd@gmail.com",
        "time": "Sun Jul 12 08:30:59 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 12 08:30:59 2026 -0700"
      },
      "message": "ci: release CI follow-ups: tighter coverage (#832)\n\n* ci: add files/scripts\n\nRename examples/deep-researcher/utils.py to deep_researcher_utils.py to\navoid basename collision with four other ASF-owned utils.py files that\nApache RAT skips. Update .rat-excludes and the application import accordingly.\n\nThread --skip-signing through cmd_verify in scripts/apache_release.py so\nCI can run full artifact verification without GPG keys present.\n\nExtend Apache RAT scanning to wheel (.whl) artifacts in addition to source\nand sdist tarballs, so license header regressions in packaged files are\ncaught before the release vote.\n\nCloses #747 (partial)\n\n* ci: add smoke test improvements\n\nReplace fixed time.sleep(2) with a polling loop on /api/v0/projects so\nthe smoke test waits only as long as necessary and fails fast if the\nserver process exits unexpectedly.\n\nLaunch the server in its own process group (start_new_session\u003dTrue) and\nsend SIGTERM to the whole group on teardown so uvicorn child processes\nare not orphaned.\n\nAdd GET / check to verify the UI is being served by the installed wheel.\n\nAdd --cleanup / --no-cleanup flag; defaults to cleanup locally but\npreserves the workspace in GITHUB_ACTIONS so artifacts are available\nfor upload on failure.\n\nAdd tests/test_ci_smoke_server.py covering all new testable helpers.\n\nCloses #747 (partial)\n\n* ci: add CI coverage gaps\n\nAdd _wheel_content_hashes and _compare_wheel_contents to\nverify_apache_artifacts.py to compare wheels by file content hashes\nrather than binary equality (zip timestamps make byte-for-byte\ncomparison unreliable). Add compare-wheels subcommand exposing this\nfrom the CLI.\n\nAdd bare-install job: installs the wheel without optional extras and\nimports core symbols to catch accidental leakage of optional\ndependencies into core code.\n\nAdd sdist-wheel-equivalence job: extracts the sdist tarball, rebuilds\nthe wheel from it (including the npm frontend build), and compares\ncontent hashes against the CI-built wheel to catch files missing from\nthe sdist.\n\nPin the Apache RAT JAR download with a SHA256 checksum to guard\nagainst supply-chain tampering.\n\nCloses #747 (partial)\n\n* ci: add hygiene improvements\n\nAdd scripts/check_asf_headers.py: checks that Python, YAML, and shell\nfiles carry the ASF license header. Reads .rat-excludes at runtime so\nknown third-party files are automatically respected without duplicating\nthe exclusion list.\n\nWire the script into .pre-commit-config.yaml as a local hook so missing\nheaders are caught before a commit lands.\n\nAdd weekly cron schedule (Monday 09:00 UTC) to release-validation.yml\nso dependency drift against main is detected between releases.\n\nAdd tests/test_check_asf_headers.py with 15 tests covering all helper\nfunctions and the main entry point.\n\nCloses #747\n\n* style: apply black + fix RAT excludes for wheel dist-info\n\nTwo small fixes on top of t1mato/burr@ci/release-ci-followups so CI goes\ngreen:\n\n* Black formatting on the four new/modified files (auto-fix; contributor\n  can pull this back locally, or maintainers can just squash-in on\n  merge).\n\n* Wheel RAT scan: sdist and src tarball RAT scans pass, but the\n  newly-added wheel scan fails because auto-generated dist-info metadata\n  files (METADATA, WHEEL, RECORD) have no source and no ASF header.\n  Added those three basename globs to .rat-excludes.\n\nVerified locally: black + flake8 + isort clean on the touched files.\nRAT reproduction not possible without the jar, but the failure signature\nin CI matches this class of file exactly and the excludes are the\nminimum-necessary additions.\n\n* ci: exclude bundled UI assets from RAT; apply isort\n\nFollow-up fixes on top of the black + METADATA/WHEEL/RECORD change:\n\n* RAT was still finding 6 unapproved files in the wheel: the bundled\n  tracking-UI static assets (index.html, minified CSS/JS bundles and\n  their source maps). These are generated by the telemetry/ui build\n  and shipped inside the wheel so the tracking server can serve them\n  at runtime; they have no ASF headers, and their sources\n  (telemetry/ui/src/**/*.tsx) carry their own headers checked against\n  the source release. Added burr/tracking/server/build/** to\n  .rat-excludes.\n\n* isort was failing on two files not part of this PR\n  (burr/integrations/persisters/b_mongodb.py and\n  tests/integrations/persisters/test_b_pymongo_driver_info.py) --\n  the current pre-commit config wants the imports collapsed to a\n  single line. Applied.\n\nLocal RAT run against the extracted wheel now shows 0 unapproved\nfiles (the CI wheel will not contain the stale\nexamples/deep-researcher/utils.py that my local one had -- that\nfile was renamed to deep_researcher_utils.py earlier in the PR).\n\n* style: drop unused \u0027import pytest\u0027 in two new test files (flake8 F401)\n\n* fix(release): honor --output-dir in wheel subcommand\n\n_build_wheel_from_current_dir was hardcoded to leave the wheel at\ndist/apache_burr-*.whl regardless of the --output-dir argument\n(flit build always writes to dist/). The Release Validation\nsdist-wheel-equivalence job (added in this PR) discovered this\nby extracting the sdist, cd-ing in, and running\n\n    python scripts/apache_release.py wheel VERSION 0 \\\n      --skip-signing --output-dir /tmp/sdist-wheel\n\nthen comparing that wheel against the release wheel. The wheel was\ncreated but sat in \u003cextracted-sdist\u003e/dist/ instead of /tmp/sdist-wheel,\nso the compare step failed with \u0027Wheel not found: /tmp/sdist-wheel/...\u0027.\n\nAfter flit build writes to dist/, move the wheel to output_dir if\nthe caller specified a different location. No-op for the standard\nin-place build (output_dir defaults to \u0027dist\u0027).\n\n---------\n\nCo-authored-by: Elijah Ben Izzy \u003celijahbenizzy@users.noreply.github.com\u003e"
    },
    {
      "commit": "2e021569e17ef60a06d11be9f222522431e7d316",
      "tree": "a8225f7f88fc122b7afdf8cd383461b657c12db4",
      "parents": [
        "30fa494a278b5e22b978f91ac7ce5612d6da65d6"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sun Jul 12 08:30:54 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 12 08:30:54 2026 -0700"
      },
      "message": "docs: tighten Condition.expr documentation; remove misleading empty globals dict (#819)"
    },
    {
      "commit": "30fa494a278b5e22b978f91ac7ce5612d6da65d6",
      "tree": "bef81f0a9142a86c6564bc77cf652ce122dac87d",
      "parents": [
        "378ba7d1b5fb9d507011b20c7a048517bc00ebe8"
      ],
      "author": {
        "name": "Alex Bevilacqua",
        "email": "alex@alexbevi.com",
        "time": "Fri Jul 10 20:33:22 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 00:33:22 2026 +0000"
      },
      "message": "feat: add MongoDB driver handshake metadata (#821)\n\nIdentify Burr in the MongoDB handshake so server-side telemetry can\ndistinguish Burr traffic. A module-level constant\n_DRIVER_INFO \u003d DriverInfo(name\u003d\"Burr\", version\u003d_VERSION) is defined\nonce in b_pymongo.py and used at every client construction site.\n\nb_pymongo.MongoDBBasePersister has three patterns:\n\n  Pattern A – from_values() constructs MongoClient:\n    mongo_client_kwargs.setdefault(\"driver\", _DRIVER_INFO) guards against\n    overriding a caller-supplied driver value.\n\n  Pattern B – __init__() receives an existing client:\n    if hasattr(client, \"append_metadata\"): client.append_metadata(_DRIVER_INFO)\n    append_metadata is idempotent; the hasattr guard keeps this safe with\n    older pymongo versions that predate the API.\n\n  Pattern A – __setstate__() reconstructs MongoClient after unpickling:\n    driver\u003d_DRIVER_INFO passed directly.\n\nb_mongodb.py is a deprecated shim that constructs its own MongoClient\ninstances in from_values() and __init__(). Both receive the same\nsetdefault guard, importing _DRIVER_INFO from b_pymongo.py.\n\nVersion is read via importlib.metadata(\"apache-burr\") with a try/except\nfallback so it works whether or not the package is pip-installed.\n\nAdds tests/integrations/persisters/test_b_pymongo_driver_info.py\n(no live DB required) verifying all five behaviours:\n- _DRIVER_INFO has name\u003d\"Burr\" and matches the installed version\n- from_values() passes driver\u003d_DRIVER_INFO to MongoClient\n- from_values() does not override a caller-supplied driver\n- __init__() calls append_metadata(_DRIVER_INFO) when the client supports it\n- __init__() does not raise when client lacks append_metadata\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "378ba7d1b5fb9d507011b20c7a048517bc00ebe8",
      "tree": "49321dab002816fcee2a583b6b4c091a93da4659",
      "parents": [
        "3df3b51eb2f10f5f0bbe8f1a29a020f25f297533"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Fri Jul 10 17:23:15 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 10:23:15 2026 +1000"
      },
      "message": "add burr-redirect package for legacy burr PyPI name (#827)\n\nBurr\u0027s PyPI listing under the legacy name \u0027burr\u0027 is at 0.40.2 and was\nsuperseded by \u0027apache-burr\u0027 at the Apache donation. Mirror the Hamilton\nsf-hamilton-redirect/ playbook: ship a thin metadata-only \u0027burr\u0027 wheel\nthat just pins apache-burr\u003d\u003d\u003cversion\u003e (plus every extra), so that users\non pip install burr / pip install burr[start] / etc. keep working and\nget the current apache-burr release transitively.\n\nFiles:\n- burr-redirect/pyproject.toml.template: setuptools-based, name\u003d\u0027burr\u0027,\n  dependencies\u003d[\u0027apache-burr\u003d\u003dVERSION\u0027], all 28 extras mirrored.\n- burr-redirect/build.sh: stamps VERSION into the template, builds wheel\n  + sdist, runs twine check, prints TestPyPI and PyPI upload commands.\n- burr-redirect/README.md: \u0027this package has moved\u0027 note, points users at\n  apache-burr.\n- burr-redirect/.gitignore: ignores generated pyproject.toml, dist/,\n  build/, *.egg-info/.\n\nExcludes:\n- .rat-excludes: adds burr-redirect/** so RAT does not scan the\n  metadata-only redirect package.\n- pyproject.toml: adds burr-redirect/** to [tool.flit.sdist].exclude so\n  the redirect package is NOT bundled into the apache-burr source\n  tarball (the redirect is a non-ASF artifact and must not appear in any\n  IPMC-voted release).\n\nThis PR is infrastructure only -- it does not produce or upload any\nrelease artifacts. The legacy burr 0.42.0 wheel is built and uploaded\nmanually after the apache-burr 0.42.0 wheel is live on PyPI (so the\n\u003d\u003d-pin resolves)."
    },
    {
      "commit": "3df3b51eb2f10f5f0bbe8f1a29a020f25f297533",
      "tree": "004af3561ab3c06f1e47222fa928c6060906f213",
      "parents": [
        "a6bda44e72e1d5047ef2637e58e1073bf751be83"
      ],
      "author": {
        "name": "Adam Munawar Rahman",
        "email": "msrahmanadam@gmail.com",
        "time": "Fri Jul 10 20:13:16 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 00:13:16 2026 +0000"
      },
      "message": "fix: tracking UI graph view freezes on state machines with dense transitions (#834)\n\n* fix: stop smart-edge pathfinding from rerunning on every graph interaction\n\nThe graph view reran A* pathfinding for every edge on every render.\nHighlight state arrives via a context whose value object was rebuilt\ninline, so every click and hover re-rendered all nodes and edges, each\nedge re-running pathfinding over a grid sized to the whole layout.\n\n- memoize the smart-edge path per edge on geometry and node set\n- skip A* above 100 nodes and fall back to bezier so large graphs render\n- memoize the highlight context value\n- key the relayout effect on graph structure instead of object identity,\n  so identity churn without a structural change (focus switches,\n  responses that are not reference-stable) no longer forces a full\n  relayout and fitView\n- create a fresh dagre graph per layout instead of reusing a module-level\n  instance that accumulates stale nodes across applications\n- remove leftover debug edge label\n\nMeasured with production builds: clicks on a 150-action application went\nfrom 11s+ on the 0.40.2 release (the same benchmark hung outright on a\nbuild of this source) to ~31ms; a 300-action application previously never\nfinished its initial render and now renders with ~75ms interactions.\n\nFixes #833\n\n* fix: derive relayout key from the rendered graph; store only labels in node data\n\nThe relayout key now comes from the same conversion the renderer uses\n(node ids and types plus edge source/target/condition), so it matches\nrendering by construction: hidden __-prefixed inputs and non-rendered\nmodel fields can neither trigger nor miss a relayout, and showInputs is\ncovered by the key because input nodes have their own ids. Node data\ncarries only the rendered label instead of the whole ActionModel, so\nreplacing the model object cannot leave stale data in nodes."
    },
    {
      "commit": "a6bda44e72e1d5047ef2637e58e1073bf751be83",
      "tree": "7ffbd8dcf08c7579e1acb76618afc30d7cff5944",
      "parents": [
        "ce297d2181493f99e19608113d70d88587bf9915"
      ],
      "author": {
        "name": "Vaquar Khan",
        "email": "vaquar.cna@gmail.com",
        "time": "Mon Jun 22 15:25:09 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 22 20:25:09 2026 +0000"
      },
      "message": "docs: fix docs typos and example issues for issue 725 (#764)\n\nCorrect broken snippets and grammar, fix RST formatting issues, and remove decorative emoji from documentation headers for consistency with project standards.\n\nCo-authored-by: vaquarkhan \u003cvaquarkhan@users.noreply.github.com\u003e"
    },
    {
      "commit": "ce297d2181493f99e19608113d70d88587bf9915",
      "tree": "99d515a340fcefe1a1a76961d28aa3a35e58ce42",
      "parents": [
        "d3278d20e720e7d95ff0f946ef3a64ff70e8263f"
      ],
      "author": {
        "name": "Timothy Lee",
        "email": "tnln3rd@gmail.com",
        "time": "Mon Jun 22 13:05:49 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 23 06:05:49 2026 +1000"
      },
      "message": "docs: restructure Burr UI documentation into dedicated section (#411) (#815)\n\n* docs: add dedicated Burr UI section to documentation (#411)\n\n* Adds docs/ui.rst as a top-level \u0027Burr UI\u0027 entry in the Sphinx sidebar,\n  mirroring how Hamilton surfaces their UI\n* Covers quickstart, data model, notebook/Colab usage, FastAPI embedding,\n  and See Also links to the tracking reference and monitoring deployment guides\n\n* docs: restructure Burr UI documentation into dedicated section for issue 411\n\n* docs: restructure Burr UI documentation into dedicated section (#411)\n\nAdd a dedicated docs/ui/ section covering the Burr UI from installation\nthrough notebook usage and production deployment, with focused pages for\ngetting-started, notebook/Colab, and deployment."
    },
    {
      "commit": "d3278d20e720e7d95ff0f946ef3a64ff70e8263f",
      "tree": "110e302b31a7f9575b43bec5805b8ea4be3fe0cb",
      "parents": [
        "38f49b61d84a71d593d18d2376852f3dfcc9f287"
      ],
      "author": {
        "name": "Rolly Calma",
        "email": "115199279+Ghraven@users.noreply.github.com",
        "time": "Sun Jun 21 04:01:26 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 20 20:01:26 2026 +0000"
      },
      "message": "fix: use aware UTC for S3 log partitions (#811)"
    },
    {
      "commit": "38f49b61d84a71d593d18d2376852f3dfcc9f287",
      "tree": "0269585132cd371048e0e745ba472bbd6afd509f",
      "parents": [
        "2ccf1849a19f040b955d1ad33e378333ee037c6a"
      ],
      "author": {
        "name": "adawang",
        "email": "adawang12101210@gmail.com",
        "time": "Sat Jun 13 14:03:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 13 06:03:13 2026 +0000"
      },
      "message": "fix: #351 make serde errors informative (#806)\n\nPandas serde now raises a clear ValueError explaining the required pandas_kwargs \u0027path\u0027 entry instead of an opaque TypeError/KeyError; State.serialize/deserialize wrap failures with the offending field name; unknown deserializer keys now list registered keys and hint at the missing registration import.\n\nSigned-off-by: adawang \u003cadawang12101210@gmail.com\u003e"
    },
    {
      "commit": "2ccf1849a19f040b955d1ad33e378333ee037c6a",
      "tree": "f14f48171c156d384c6a6c448e2d4d8d74088a58",
      "parents": [
        "c2b752ed53553c0ac8f5bd24f5309cd4a466827e"
      ],
      "author": {
        "name": "Vaquar Khan",
        "email": "vaquar.cna@gmail.com",
        "time": "Sat Jun 06 11:53:03 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 07 02:53:03 2026 +1000"
      },
      "message": "docs: add AWS deployment and Bedrock documentation for issue 724 (#763)\n\n* docs: add AWS deployment and Bedrock documentation for issue 724\n\nDocument S3 tracking deployment patterns and event-driven SQS mode, expand Bedrock integration guidance, and wire new AWS concept/example pages into existing docs navigation.\n\n* docs: fix RST heading lengths in AWS docs\n\nCorrect heading underline lengths in the AWS S3 tracking and Bedrock docs so the documentation builds cleanly without section title warnings.\n\n---------\n\nCo-authored-by: vaquarkhan \u003cvaquarkhan@users.noreply.github.com\u003e"
    },
    {
      "commit": "c2b752ed53553c0ac8f5bd24f5309cd4a466827e",
      "tree": "6080d8c540968516675a2388e2bd3d0e03876ecd",
      "parents": [
        "a3f0563c6ae71b348594d01a9d2917007344f43f"
      ],
      "author": {
        "name": "Shabbir Hussain",
        "email": "72.shabbir@gmail.com",
        "time": "Wed Jun 03 21:11:26 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 04 04:11:26 2026 +0000"
      },
      "message": "feat: add release email generation tooling (#743)\n\n* feat: add release email generation tooling\n\n* fix: handle binding no votes in result email\n\n* fix: make adaptive crag example python 3.10 compatible"
    },
    {
      "commit": "a3f0563c6ae71b348594d01a9d2917007344f43f",
      "tree": "ebb90e86c5f7d93259a486935feb8ce178a85513",
      "parents": [
        "1040e8e8b51ae7edbdc9532f7a49d93bf5359e25"
      ],
      "author": {
        "name": "Hari Charan Panjwani",
        "email": "panjwani.h@husky.neu.edu",
        "time": "Wed Jun 03 20:37:34 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 04 00:37:34 2026 -0300"
      },
      "message": "ci: add RC promotion command (#749)\n\n* ci: add RC promotion command\n\n* ci: preserve KEYS during RC promotion\n\n* ci: apply black formatting to promote command and tests\n\nblack --line-length\u003d100 reformats scripts/apache_release.py and\ntests/test_apache_release.py; the pre-commit black hook was failing.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n* ci: fix RC promotion to additive per-version release layout via svn cp\n\nThe promote command copied artifacts flat into the dist/release project\nroot and svn-rm\u0027d every existing entry (except KEYS). But dist/release\npublishes each release under a per-version subdirectory\n(e.g. dist/release/incubator/burr/0.42.0) and keeps prior releases\nalongside KEYS. The old flow would have dumped artifacts in the wrong\nplace and deleted already-published releases (0.41.0, 0.42.0).\n\nPromote now performs a single server-side \u0027svn cp \u003crc_url\u003e\n\u003crelease\u003e/\u003cversion\u003e\u0027: atomic, no local download of the release tree, and\nadditive. Existing release directories and KEYS are untouched by\nconstruction. The command refuses to run if the target version directory\nalready exists. The local RC checkout is kept only to validate the\nexpected artifacts and their .asc/.sha512 companions before promotion.\n\nDrops the now-unnecessary flat-copy/remove/commit helpers and the dead\nRC-suffix rename (release artifact names never carry the RC number; it\nlives in the dev directory name). README and tests updated to match.\n\nNote: the svn workflow is unit-tested with mocked svn but not verified\nend-to-end against live ASF dist.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n---------\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\nCo-authored-by: André Ahlert \u003candre@aex.partners\u003e"
    },
    {
      "commit": "1040e8e8b51ae7edbdc9532f7a49d93bf5359e25",
      "tree": "5659168a327c2d60c588ffc78237e91ab6874c39",
      "parents": [
        "0624e00027cc931c997520bdeb3691d4cd17699c"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Tue Jun 02 07:04:49 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 14:04:49 2026 +0000"
      },
      "message": "fix(deps): resolve 22 npm security vulnerabilities in website and telemetry/ui (#773)\n\n* fix(deps): resolve npm security vulnerabilities in website and telemetry/ui\n\nRun npm audit fix in both website/ and telemetry/ui/ to address\nDependabot security alerts.\n\nwebsite/ (16 alerts → 2 remaining):\n- hono 4.12.8 → 4.12.18 (11 alerts)\n- @hono/node-server → 1.19.14\n- fast-uri → 3.1.2 (2 HIGH)\n- path-to-regexp → 8.4.2 (2 alerts)\n- ip-address removed\n- postcss inside next cannot be fixed without breaking next downgrade\n\ntelemetry/ui/ (8 alerts → 4 remaining):\n- fast-uri → 3.1.2 (2 HIGH)\n- @babel/plugin-transform-modules-systemjs → 7.29.4 (1 HIGH)\n- lodash, postcss, vite remain unfixed (locked by react-scripts/CRA)\n\nResolves 22 of 26 open Dependabot alerts. The remaining 4 require\nmigrating telemetry/ui from Create React App to a modern bundler.\n\n* style: apply black formatting to collapsed line in graph.py\n\n* fix: align eslint-config-next with next@15.5.18"
    },
    {
      "commit": "0624e00027cc931c997520bdeb3691d4cd17699c",
      "tree": "dceea3771af788ea3db9c931c21830c63d34e249",
      "parents": [
        "d417f9a6acb47a0bc88fdacab4b97c8fb11bb525"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Tue Jun 02 08:30:47 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 08:30:47 2026 -0300"
      },
      "message": "Add optional module allowlist to pydantic serde deserializer (#794)\n\n* fix(packaging): repair developer extra reference and dedupe tests extra\n\nThe \u0027developer\u0027 optional-dependency referenced apache-burr[bloat], but the\n\u0027bloat\u0027 extra was renamed to \u0027examples\u0027 in cd801c88 and the reference was\nnever updated, so \u0027pip install apache-burr[developer]\u0027 failed to resolve.\n\nAlso drop a duplicate apache-burr[hamilton] entry in the \u0027tests\u0027 extra.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n* Add optional module allowlist to pydantic serde deserializer\n\nIntroduces a configurable allowlist for pydantic deserialization to\nprovide stricter control over which modules can be dynamically imported.\nWhen an allowlist is configured, unauthorized modules are rejected with\na clear error message. When no allowlist is set, behavior remains\nbackward-compatible with an added runtime warning to encourage adoption.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n---------\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e"
    },
    {
      "commit": "d417f9a6acb47a0bc88fdacab4b97c8fb11bb525",
      "tree": "b3c41916334fcdf50859628976d3b006e1af540d",
      "parents": [
        "f62e39c8e9777d9932c6d3219fdaaf46a1443197"
      ],
      "author": {
        "name": "Hari Charan Panjwani",
        "email": "panjwani.h@husky.neu.edu",
        "time": "Tue Jun 02 01:20:58 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 08:20:58 2026 +0000"
      },
      "message": "ci: improve artifact verification flow (#741)"
    },
    {
      "commit": "f62e39c8e9777d9932c6d3219fdaaf46a1443197",
      "tree": "a78c14c01ba2b4612c416bd7e01bdb81ae3c94b9",
      "parents": [
        "855bea6a5b64b2d04704a30b0658dfc6bd0ef25a"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Tue Jun 02 03:30:25 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 03:30:25 2026 -0300"
      },
      "message": "ci: skip docs preview deploy steps for PRs from forks (#791)\n\nForks cannot push to gh-pages because PR-from-fork GITHUB_TOKEN is\nread-only regardless of declared workflow permissions, causing the\ndocs job to fail with \"Resource not accessible by integration\" on\nevery fork PR.\n\nGate the three steps that need write access (Comment on PR, Build PR\npreview website, Update comment) on PRs originating from this\nrepository so the docs job still validates the Sphinx build for fork\nPRs without attempting the preview deploy."
    },
    {
      "commit": "855bea6a5b64b2d04704a30b0658dfc6bd0ef25a",
      "tree": "3c7f16f733b07e4cee8beb61a313a11038f5f1a8",
      "parents": [
        "edabb86f85a97c31d6f76e112818b56932921a5b"
      ],
      "author": {
        "name": "Rolly Calma",
        "email": "115199279+Ghraven@users.noreply.github.com",
        "time": "Fri May 29 22:25:19 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 29 11:25:19 2026 -0300"
      },
      "message": "fix: use utf-8 for local tracking text files (#790)\n\n* fix: use utf-8 for local tracking text files\n\n* fix: read local tracking graph as utf-8\n\n* test: cover local backend utf-8 reads\n\n* test: assert utf-8 on local backend text opens\n\nHarden the local-backend UTF-8 regression test so it catches missed\ncall sites independently of the host\u0027s default encoding. A round-trip\nassertion alone passes on a UTF-8 host even if a text open drops\nencoding\u003d\"utf-8\". Wrap the backend\u0027s aiofiles.open and assert every\ntext-mode (non-binary) open is explicitly UTF-8; binary opens (mode\n\"rb\") stay exempt. Also exercise non-ASCII (incl. CJK) content through\nannotations, graph.json and children.jsonl end to end.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n* fix(ci): run local backend utf-8 test with tracking-server deps\n\nThe new regression test imports burr.tracking.server.backend, which\npulls aiofiles (tracking-server extra). The base test job only installed\ntracking-client, so the top-level server import broke collection and\nfailed all test (3.9-3.12) jobs.\n\n- Make the server backend/schema imports lazy and gate the test with\n  pytest.importorskip(\"aiofiles\"), matching the tracking-server-s3 test\n  idiom, so the module still collects with only tracking-client present.\n- Add the tracking-server extra to the base test job so aiofiles is\n  available and the regression test actually runs across the matrix\n  instead of being skipped everywhere.\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n---------\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\nCo-authored-by: André Ahlert \u003candre@aex.partners\u003e"
    },
    {
      "commit": "edabb86f85a97c31d6f76e112818b56932921a5b",
      "tree": "ebb820f1a1f39d760b20197d0101be7efe21e43d",
      "parents": [
        "6ec8ffcb1df655e8fcb75ec5c1c4078cc40ec372"
      ],
      "author": {
        "name": "John Bampton",
        "email": "jbampton@users.noreply.github.com",
        "time": "Thu May 28 18:33:14 2026 +1000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 28 08:33:14 2026 +0000"
      },
      "message": "misc: fix typos in py and tsx files (#623)\n\nGeneral spelling clean up"
    },
    {
      "commit": "6ec8ffcb1df655e8fcb75ec5c1c4078cc40ec372",
      "tree": "f58e54defd8d6771a2d02c4dde5fb9a5244c3934",
      "parents": [
        "eb783107da3d46928edbed9f3561d7395ba45fad"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sat May 16 12:59:53 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 16 12:59:53 2026 -0700"
      },
      "message": "docs: fix stale dagworks-inc/burr URLs and bracketed-extras installs (#777)\n\nTwo follow-up cleanups for the Apache rename:\n\n* 14 example READMEs + 2 notebooks linked `dagworks-inc/burr`\n  Colab URLs (or a commented git URL in the s3 Dockerfile) that\n  404 since the repo moved to `apache/burr`.\n\n* 11 install lines escaped PR #772\u0027s regex (the JSON-escaped\n  `\\\"burr[...]` form in notebook cells, and a `poetry add` form)\n  and still said `pip install \"burr[extras]\"`. PyPI\u0027s `burr` is\n  an unrelated placeholder, so these instructions don\u0027t work.\n\nPure mechanical sweep. No code or behavior changes."
    },
    {
      "commit": "eb783107da3d46928edbed9f3561d7395ba45fad",
      "tree": "262f02153f8e7b1afa4f20dade7ab0e0c2760bf3",
      "parents": [
        "83f2ea8c289d97cb16be101e446ce905abf9ca1d"
      ],
      "author": {
        "name": "Hemanth Savasere",
        "email": "hemanth.savasere@gmail.com",
        "time": "Sun May 17 01:10:38 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 17 05:40:38 2026 +1000"
      },
      "message": "feat: allow plain dict yields in single-step streaming actions (#779)\n\nIntermediate yields in streaming actions can now be plain dicts\ninstead of requiring (dict, None) tuples. The (dict, None) form\nstill works for backward compatibility.\n\nFixes : #277\n\nSummary\nAllow intermediate yields in _run_single_step_streaming_action and _arun_single_step_streaming_action to be plain dict instead of requiring (dict, None) tuples\nBackward compatible — existing (dict, None) yields still work\nAdded callback tests verifying PostStreamItemHook fires correctly for plain dict yields\nUpdated streaming_action docstring example to show plain dict yield"
    },
    {
      "commit": "83f2ea8c289d97cb16be101e446ce905abf9ca1d",
      "tree": "38cdffa3a3dfea5e2b4bbd9404a2e079ae28d312",
      "parents": [
        "b4f2903be02978e36fea68868e18fe7e3254a3cb"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Mon May 11 14:33:26 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 14:33:26 2026 -0700"
      },
      "message": "docs: rename pip install burr to pip install apache-burr (#772)\n\nThe PyPI package was renamed to apache-burr at the 0.41.0\nrelease, but ~30 files in docs, examples, and a few error\nmessages still tell users to `pip install burr[...]`. That\ndoesn\u0027t work — PyPI\u0027s `burr` is a placeholder.\n\nThis is a pure mechanical sweep that only touches `pip install`\ninvocations. Module imports (`import burr`, `from burr...`),\nthe `burr` CLI command name, and file paths are untouched."
    },
    {
      "commit": "b4f2903be02978e36fea68868e18fe7e3254a3cb",
      "tree": "1e1260a2f5fca022af88509c2fdccd390d3950c7",
      "parents": [
        "56dcfd4735f8d39555aa9259818b0cb7e0207e8a"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Mon May 11 13:33:06 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 20:33:06 2026 +0000"
      },
      "message": "website: add Downloads page per ASF release policy (#771)\n\n* website: add Downloads page per ASF release policy\n\nAdds a /downloads route covering the 0.42.0-incubating and 0.41.0-incubating\nreleases with mirror-selection links for tarballs, direct HTTPS links for\nsignatures and checksums, GPG/SHA-512 verification instructions, and the\nstandard incubator disclaimer. Adds a \"Download\" entry to the navbar.\n\nAddresses the IPMC vote feedback that burr.apache.org needs a public\ndownload page per https://www.apache.org/legal/release-policy.html#publication.\n\nThe repo-root .gitignore has a `downloads/` rule (Python packaging), which\nshadows the new Next.js app-router directory; a negation rule is added in\nwebsite/.gitignore to re-include it.\n\n* website: restructure downloads page for end users\n\nLead with install + UI launch + quick links, then ASF source\nreleases, then verification. Apache compliance content is still\npresent but no longer the first thing a Python dev sees.\n\nAlso: flag 0.41.0 PyPI packaging issues with a note on its release\ncard, and render version headings as \"X.Y.Z (incubating)\" rather\nthan \"X.Y.Z-incubating\"."
    },
    {
      "commit": "56dcfd4735f8d39555aa9259818b0cb7e0207e8a",
      "tree": "7dc758ed3c5e726df88bb526e61cbc3a1bbe2784",
      "parents": [
        "7b2049209cbc81ec2ba764e5b2aae9f21e0bd7f9"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Mon May 11 13:19:52 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 13:19:52 2026 -0700"
      },
      "message": "ci: gate merging on a single Release Validation summary job (#775)\n\n* ci: gate merging on a single Release Validation summary job\n\nAdds a \"summary\" job to release-validation.yml that depends on\ncheck-paths, build-artifacts, and install-and-smoke and runs\nwith if: always(). It translates the upstream conclusions into\na single binary verdict — success/skipped → pass, failure or\ncancelled → fail — so the required check has a stable name and\na definite state regardless of whether upstream jobs ran or\nwere path-filtered out.\n\nIn .asf.yaml the required contexts drop from two matrix-suffixed\nnames (\"Release Validation / build-artifacts\", \"Release Validation\n/ install-and-smoke (3.12)\") to one: \"Release Validation / summary\".\n\nWhy this is needed:\n- PRs that only touch docs/ or website/ trigger check-paths to\n  set should_run\u003dfalse, which skips the heavy jobs.\n- GitHub treats SKIPPED jobs as non-passing for required-status-\n  checks, so those PRs were stuck in BLOCKED state forever\n  (see commit a655edf2 for the previous attempt that didn\u0027t\n  work for this exact reason).\n- The summary job sidesteps the SKIPPED ambiguity because it\n  always runs and always produces a definite SUCCESS or FAILURE.\n\nReal code PRs are unaffected: if any release-validation job\nfails, the summary fails, and merging is blocked.\n\n* style: run black on burr/core/graph.py\n\nDrive-by fix — `f7a1750d` (rename shadowed `format` builtin)\nleft this file black-non-compliant for line-length\u003d100. Caught\nby pre-commit on this branch."
    },
    {
      "commit": "7b2049209cbc81ec2ba764e5b2aae9f21e0bd7f9",
      "tree": "bc8feadc2a7f7900f5d73a2eb02cb9b8fae84b32",
      "parents": [
        "0e883bbb091250b441539a2413f6c186eed51c1a"
      ],
      "author": {
        "name": "Cao Hanzhe",
        "email": "dashitongzhi@users.noreply.github.com",
        "time": "Thu May 07 22:04:59 2026 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sun May 10 22:06:30 2026 -0700"
      },
      "message": "fix: use module logger instead of root logger in b_aiosqlite.py\n\nAll other persister modules in burr/integrations/persisters/ use\nlogging.getLogger(__name__) to create a properly scoped logger.\nb_aiosqlite.py was using logging.getLogger() (no arguments), which\nreturns the root logger.\n\nUsing the root logger is bad practice because:\n- It causes log messages to bypass the module\u0027s namespace, making it\n  harder to filter or configure logging for this specific module.\n- It can lead to unexpected log output appearing in the root logger\u0027s\n  handlers even when the module\u0027s logging is intended to be suppressed.\n\nThis one-line fix changes it to logging.getLogger(__name__) for\nconsistency with all other persister implementations.\n"
    },
    {
      "commit": "0e883bbb091250b441539a2413f6c186eed51c1a",
      "tree": "cc0d9d1c4bd8a87f868c4aab48d1457b11b1df5b",
      "parents": [
        "f7a1750d04db49d250cabbe14f2dee447904f313"
      ],
      "author": {
        "name": "Cao Hanzhe",
        "email": "dashitongzhi@users.noreply.github.com",
        "time": "Thu May 07 22:07:02 2026 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sun May 10 22:05:15 2026 -0700"
      },
      "message": "fix: correct validate_inputs error message when both missing and additional inputs exist\n\nIn burr/core/action.py, the validate_inputs() method had a bug in its\nerror message construction due to operator precedence in a nested ternary\nexpression.\n\nThe original code:\n    raise ValueError(\n        f\"Inputs to function {self} are invalid. \"\n        + f\"Missing the following inputs: ...\"\n        if missing_inputs\n        else (...)\n    )\n\nDue to Python operator precedence, the ternary \u0027if\u0027 binds lower than \u0027+\u0027,\nso the whole expression is evaluated as:\n    (str1 + str2) if missing_inputs else (str3 if additional_inputs else \"\")\n\nThis means when BOTH missing_inputs and additional_inputs are non-empty,\nthe error message only reports the missing inputs and silently drops info\nabout the additional inputs. Similarly, when only additional_inputs exist,\nthe \u0027Inputs to function ... are invalid\u0027 prefix is omitted.\n\nFixed by building error message parts independently:\n- Always include the \u0027Inputs to function ... are invalid\u0027 prefix\n- Conditionally append missing inputs info\n- Conditionally append additional inputs info\n- Join all parts with spaces\n\nThis ensures all relevant validation errors are reported regardless of\nwhich combination of issues exist.\n"
    },
    {
      "commit": "f7a1750d04db49d250cabbe14f2dee447904f313",
      "tree": "e4be45a350439f603a5ee7af8209cc5f570c25cb",
      "parents": [
        "07ad9a007b45928a39dcb51c5d1d98245d33b2ae"
      ],
      "author": {
        "name": "Cao Hanzhe",
        "email": "dashitongzhi@users.noreply.github.com",
        "time": "Thu May 07 22:05:56 2026 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sun May 10 22:03:40 2026 -0700"
      },
      "message": "fix: rename shadowed \u0027format\u0027 builtin in _render_graphviz\n\nIn burr/core/graph.py, the function _render_graphviz() used \u0027format\u0027 as\na local variable name, which shadows Python\u0027s built-in format() function.\nRenamed it to \u0027fmt\u0027 to avoid the shadowing while preserving all existing\nbehavior.\n\nThe variable is used only within the function scope and the rename is\nconsistent and self-documenting.\n"
    },
    {
      "commit": "07ad9a007b45928a39dcb51c5d1d98245d33b2ae",
      "tree": "f8e6c723be16577d35032e9088236e91e8b1569a",
      "parents": [
        "30c9b3a82398fa461e88270a1825545edd912a76"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sun May 10 09:16:40 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 10 09:16:40 2026 -0700"
      },
      "message": "chore: bump version to 0.42.0 for RC3 release (#770)"
    },
    {
      "commit": "30c9b3a82398fa461e88270a1825545edd912a76",
      "tree": "ad13cfd283237f2aa87c1310c8d3ada74f1f24b8",
      "parents": [
        "a7e44890d735a9ddfe45e49836543fae4e29e745"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Sat May 09 21:59:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 09 21:59:08 2026 +0200"
      },
      "message": "Emit standard sha512sum format in release checksums (#769)\n\nSurfaced during 0.42.0-incubating RC3 verification: the .sha512 files\nshipped on dist.apache.org contain only the bare hex digest, so the\nstandard \u0027sha512sum -c file.sha512\u0027 recipe returns \u0027no properly\nformatted checksum lines found\u0027. Voters either have to work around it\nwith \u0027echo \"$(cat ${F}.sha512)  ${F}\" | sha512sum -c -\u0027 (as the\nREADME currently does) or compare digests by hand.\n\nSwitch _checksum_artifact() to emit the standard \u0027\u003cdigest\u003e  \u003cfilename\u003e\u0027\nlayout that sha512sum -c and shasum -c both expect, and simplify the\nverification recipe in scripts/README.md to plain\n\u0027sha512sum -c \u003cfile\u003e.sha512\u0027.\n\nBoth checksum readers in the repo (scripts/verify_apache_artifacts.py\nand scripts/apache_release.py::_verify_artifact_checksum) already use\n\u0027.read().strip().split()[0]\u0027, so they accept both the old and the new\nformat -- verification of existing RCs on dist.apache.org keeps working\nunchanged.\n\nVote thread:\nhttps://lists.apache.org/thread/bhcwnjpbx7vhnql48z7vc3njpgrx9qmj"
    },
    {
      "commit": "a7e44890d735a9ddfe45e49836543fae4e29e745",
      "tree": "3bbc5f03c911e217a7b90b1d878a5ba73c57104e",
      "parents": [
        "a655edf2b834390e065d47dafb4377360ba69f52"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun May 03 03:29:35 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 03 03:29:35 2026 +0000"
      },
      "message": "chore(deps): bump follow-redirects in /telemetry/ui (#739)\n\nBumps [follow-redirects](https://github.com/follow-redirects/follow-redirects) from 1.15.5 to 1.16.0.\n- [Release notes](https://github.com/follow-redirects/follow-redirects/releases)\n- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.15.5...v1.16.0)\n\n---\nupdated-dependencies:\n- dependency-name: follow-redirects\n  dependency-version: 1.16.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a655edf2b834390e065d47dafb4377360ba69f52",
      "tree": "387ce562671cba69a0c7e72f51b9961c968a3094",
      "parents": [
        "b707b1d8efc588e9104978d18f2933460b44ef70"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Sat May 02 18:52:47 2026 -0700"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sat May 02 20:24:35 2026 -0700"
      },
      "message": "ci: fix required checks blocking Dependabot PRs\n\nRemove paths-ignore from release-validation workflow and add a\ncheck-paths job that detects whether the full validation should run.\nWhen only docs/ or website/ files change, the build-artifacts and\ninstall-and-smoke jobs are skipped rather than never triggered, which\nsatisfies branch protection required check requirements.\n"
    },
    {
      "commit": "b707b1d8efc588e9104978d18f2933460b44ef70",
      "tree": "0c4c10eaf1c7bb22990bccb598eb2c507efb9415",
      "parents": [
        "ff76817be5b1f7893f68b9659b47f6752f00e662"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sat Apr 25 21:07:07 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 26 04:07:07 2026 +0000"
      },
      "message": "fix: remove stray newline from burr/examples symlink target (#748)\n\n* fix: remove stray newline from burr/examples symlink target\n\nThe burr/examples symlink was committed with target \u0027../examples\\n\u0027\n(12 bytes) instead of \u0027../examples\u0027 (11 bytes). Most tools tolerate\nthe trailing newline, but stricter consumers (Java\u0027s FileReader via\nApache RAT, some Linux extractors of the source tarball) treat\n\u0027../examples\\n\u0027 as a literal nonexistent target and fail.\n\nManifested in CI as a RAT crash on the source tarball produced by\ngit-archive: the symlink in the tarball points to \u0027../examples\\n\u0027,\nwhich doesn\u0027t resolve, and RAT raises FileNotFoundException trying\nto read it as a file.\n\nRecreate the symlink via \u0027rm burr/examples \u0026\u0026 ln -s ../examples\nburr/examples\u0027 to write the correct 11-byte target.\n\n* fix: fail license verification when Apache RAT exits non-zero\n\nPreviously, if RAT crashed partway through scanning (e.g. on the\nbroken burr/examples symlink that motivated this PR), the verify\nscript would print a warning, parse the truncated XML report, find\nzero unapproved licenses in whatever RAT managed to scan before the\ncrash, and report success.\n\nThat false green is what hid the symlink corruption when PR #745\nmerged into main, even though our release-validation workflow\ntechnically ran on main. The CI run scanned 14 files (out of ~700),\nsaw RAT exit code 1, swallowed it, and called the build green.\n\nTreat any nonzero exit from RAT as a hard failure of license\nverification. Print the last 25 lines of RAT stderr so the next\ndebug session has the trace immediately.\n\n* fix: exclude burr/examples symlink from end-of-file-fixer pre-commit hook\n\nend-of-file-fixer mistreats the symlink as a regular text file and\nappends \u0027\\n\u0027 to the link target, turning \u0027../examples\u0027 (11 bytes) into\n\u0027../examples\\n\u0027 (12 bytes). Strict consumers (Apache RAT, Linux tar\nextractors) then fail to resolve the symlink. This is exactly the bug\nthat motivated PR #748 — without this exclude, the next pre-commit run\non a maintainer\u0027s machine would silently re-corrupt the symlink.\n\nAlso exclude trailing-whitespace defensively for the same reason."
    },
    {
      "commit": "ff76817be5b1f7893f68b9659b47f6752f00e662",
      "tree": "5d6706c620837ff2c96f9035c92369cbcaf73b27",
      "parents": [
        "0bf59dc8470a1104b5c45f797d3e017e08f58726"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Fri Apr 24 16:18:02 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 24 16:18:02 2026 -0700"
      },
      "message": "fix: address RC2 vote feedback (#745)\n\n* fix: add __init__.py to tests/ so pytest discovery works\n\n* fix: add ASF license header to tutorial.md\n\n* fix: update .rat-excludes for RC2 feedback\n\n- Fix patterns for burr/examples/ symlink duplicates (use .* prefix)\n- Add .github/ templates (YAML/MD with frontmatter)\n- Add image file extensions (.png, .gif, .ico, .jpg)\n\n* fix: include hello-world-counter in release artifacts\n\nThe tracking server imports burr.examples.hello-world-counter.server\n(added in #675) but the release config still had it in the exclude\nlist. Move it from exclude to include so the wheel ships with the\nmodule the server needs, preventing ModuleNotFoundError when running\nburr from a fresh install.\n\nAlso bumps REQUIRED_EXAMPLES in scripts/apache_release.py and updates\ntests/test_release_config.py accordingly.\n\n* fix: use sys.executable for uvicorn subprocess to fix venv isolation\n\nThe CLI spawned uvicorn as a bare command, which resolves via PATH.\nFor users with pyenv installed, ~/.pyenv/shims/ is in PATH ahead of\nany venv\u0027s bin/, so bare `uvicorn` always hits a pyenv shim that\nroutes to a pyenv environment — never the venv the user is running\nburr from. This means a fresh `pip install` into a non-pyenv venv\nfails to start the server.\n\nUsing sys.executable -m uvicorn ensures uvicorn runs under the same\nPython interpreter that is running burr, regardless of PATH.\n\n* chore: add --skip-signing flag and CI smoke-test helper\n\nPreparation for the release-validation CI workflow.\n\napache_release.py:\n- Add --skip-signing to archive/sdist/wheel/all subcommands\n- Split _sign_artifact into checksum (always) and GPG sign (skippable)\n- Drop gpg from required tools when --skip-signing is set\n\nci_smoke_server.py:\n- Installs a built wheel into a fresh venv outside the source tree\n- Imports burr.tracking.server.run (catches missing-example bugs like #675)\n- Starts the burr server on a free port with a dedicated data dir\n- Runs a tracked app, verifies the server observes the project\n\n* ci: drop svn requirement from \u0027all\u0027 command when --no-upload is set\n\nCI runners don\u0027t have svn installed. The \u0027all\u0027 subcommand listed svn as\na required tool unconditionally, but svn is only used during the upload\nstep. Skip the requirement when --no-upload is passed.\n\n* ci: add release validation workflow\n\nBuild the full release pipeline on every PR, plus RAT license check\nand an end-to-end smoke install of the wheel outside the source tree.\nThis catches the failure modes that have broken recent RCs:\n\n- build-artifacts: runs apache_release.py all --skip-signing --no-upload,\n  verifies the 3 artifacts exist, runs Apache RAT without --report-only\n  so license violations fail the job.\n- install-and-smoke: on 3.10/3.11/3.12, installs the wheel into a fresh\n  venv and runs scripts/ci_smoke_server.py. That helper imports the\n  server module, boots the server, runs a tracked app, and asserts the\n  server sees the project — so a missing example (like PR #675\u0027s\n  hello-world-counter) would fail here.\n\nOnly \"build-artifacts\" and \"install-and-smoke (3.12)\" are required\nchecks in .asf.yaml; 3.10 and 3.11 are informational.\n\n* fix: rewrite .rat-excludes with basename patterns that actually work\n\nRAT\u0027s -E regex doesn\u0027t reliably match through path separators or\nsymlinked directories. The previous patterns like\n\u0027examples/deep-researcher/prompts.py\u0027 never excluded anything because\nRAT effectively matches against basenames. We never noticed because\nall prior RAT runs used --report-only mode.\n\nSwitch to basename patterns. The .tsx files are uniquely named, so\nbasename matching is precise. prompts.py only exists once. utils.py\nmatches 5 different files (all our own ASF code with headers); the\npractical risk of skipping their checks is low.\n\nUpdate the leading comment in .rat-excludes to document the constraint\nso future authors don\u0027t repeat the mistake.\n\n* chore: add .claude/ to .gitignore\n\n* fix: address review feedback (paths-ignore, basename collisions, count)\n\n- Workflow: drop \u0027**/*.md\u0027 from paths-ignore. It would suppress runs\n  whenever a bundled .md file (like the deployment tutorial.md) changes\n  — exactly the case that triggered RC2 feedback.\n- .rat-excludes: document the basename collisions for utils.py and\n  button.tsx so the next maintainer doesn\u0027t think they\u0027re unique.\n- test_release_config.py: fix \u00274 examples\u0027 string that should have been\n  bumped to 5 when hello-world-counter was added.\n\n* fix: use os.path.lexists in _prepare_wheel_contents to handle broken symlinks\n\nOn CI runners, burr/examples is a relative symlink (\u0027../examples\u0027) that\nmay not resolve from the process\u0027s working directory — os.path.exists\nreturns False for a broken link while the link itself is still present\non disk. That made _prepare_wheel_contents skip the removal branch and\nthen fail on os.makedirs with \u0027File exists: burr/examples\u0027.\n\nSwitch to os.path.lexists, which returns True for any directory entry\nincluding broken symlinks, so the cleanup branch always runs when the\nlink is present."
    },
    {
      "commit": "0bf59dc8470a1104b5c45f797d3e017e08f58726",
      "tree": "8045a64eb9b84d69ef8bcf581b92f9e53e5e1b65",
      "parents": [
        "ab2fb903e3b0a16e1160a4632b62e5832cd7f6c2"
      ],
      "author": {
        "name": "Vaquar Khan",
        "email": "vaquar.cna@gmail.com",
        "time": "Mon Apr 20 23:41:46 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 14:41:46 2026 +1000"
      },
      "message": "Bedrock integration backup (#677)\n\n## Bedrock integration for Burr\n\nAdds first-class support for Amazon Bedrock\u0027s Converse API to Burr, so users can build state machines and agents on top of Bedrock models (Claude, Titan, Llama, etc.) without writing boto3 plumbing themselves.\n\n### Architecture\nThe integration is structured in three layers: a pure \"core\" that knows how to talk to Bedrock, a thin mixin that adapts it to Burr\u0027s action interface, and two concrete action classes that plug into Burr\u0027s state machine.\n\nLayer 1  _BedrockCore (transport + request building). This is a plain Python class with no knowledge of Burr actions. It holds the configuration (model id, region, guardrail, inference config, retry count, optional injected client) and exposes two things: get_client(), which returns the bedrock-runtime boto3 client (either the one injected at construction time, or a new one built lazily with a Config(retries\u003d...) on first use), and build_converse_request(state), which calls the user\u0027s input_mapper(state) and assembles the kwargs dict passed to converse() / converse_stream() — modelId, messages, inferenceConfig, and the optional system and guardrailConfig blocks. Guardrail validation lives here: if guardrail_id is set without an explicit guardrail_version, the constructor raises ValueError so nobody accidentally ships against an unpublished DRAFT.\n\nLayer 2 - _BedrockBase (Burr adapter mixin). A small mixin that holds a _BedrockCore instance and exposes the three properties Burr actions need: reads, writes, and name. It exists purely to avoid duplicating constructor wiring and property boilerplate between the sync and streaming classes.\n\nLayer 3 - concrete actions.\n\nBedrockAction inherits from _BedrockBase and Burr\u0027s SingleStepAction. Its run_and_update() builds the Converse request, calls converse(), runs the response through _text_from_content_blocks() (which joins every text block in the response, so multi-block replies and mixed text/tool-use messages aren\u0027t silently truncated), and then uses _model_result_for_writes() to map the model output to whichever keys the user declared in writes — \"response\" gets the joined text, \"usage\" gets the token counts, \"stop_reason\" gets the Bedrock stop reason, and any other custom key also gets the joined text.\nBedrockStreamingAction inherits from _BedrockBase and Burr\u0027s StreamingAction. Its stream_run() is a generator that iterates the Bedrock event stream, collecting text chunks into a list[str] (joined once at the end — not concatenated in a loop), and yields one dict per contentBlockDelta event plus a final complete: True payload. Its update() runs only on the final chunk and reuses the same _model_result_for_writes() helper, so streaming and non-streaming actions write state using identical logic.\n\nHelper functions. Two pure functions sit at module scope and are shared by both actions: _text_from_content_blocks(blocks) tolerates non-text blocks (e.g. toolUse) and returns the joined text, and _model_result_for_writes(text, usage, stop_reason, writes) centralises the \"which result goes into which state key\" logic so the sync and streaming paths can\u0027t drift out of sync.\n\n#### Cross-cutting concerns.\n\nboto3 is imported inside a try/except that calls require_plugin(...) on failure, so installing Burr without the [bedrock] extra doesn\u0027t break anything until a user actually touches the module.\nThe BedrockAction / BedrockStreamingAction symbols are exposed via a __getattr__ in \n__init__.py\n, giving callers the ergonomic from burr.integrations import BedrockAction without importing boto3 for every Burr user.\nErrors from boto3 (ClientError) are logged at ERROR level and re-raised unchanged, so Burr\u0027s own retry/lifecycle hooks can handle them at the application level.\nState machine shape. Both actions are drop-in nodes in a Burr graph. A typical chatbot wiring is human_input → bedrock_call → save_response → human_input, where bedrock_call is one of these two actions reading chat_history and writing response. For agents, bedrock_call is followed by a conditional transition into a tool-executor action and back again — the integration itself stays stateless across calls; all conversation and tool state lives in Burr\u0027s State.\n\n## Changes\n\n- `burr/integrations/bedrock.py`\n  - `BedrockAction` — single-step action wrapping Bedrock `converse()`. Handles lazy client creation, retries, guardrails, inference config, and maps model output into state.\n  - `BedrockStreamingAction` — streaming variant using `converse_stream()`, yields chunks incrementally and merges final text into state on completion.\n  - Shared `_BedrockBase` + `_BedrockCore` to avoid duplication across the two classes.\n  - Helpers `_text_from_content_blocks` (joins all text blocks, tolerates tool-use blocks) and `_model_result_for_writes` (dynamically maps user\u0027s `writes` keys to response fields).\n- `burr/integrations/__init__.py` — lazy exports for `BedrockAction` / `BedrockStreamingAction` so `boto3` is only imported when the classes are actually used.\n- `pyproject.toml` — adds `[bedrock]` optional extra (`boto3`).\n- `docs/reference/integrations/bedrock.rst` — Sphinx reference docs with install and IAM setup notes.\n- `docs/getting_started/install.rst` — adds Bedrock to the install matrix.\n- `examples/integrations/bedrock/` — runnable example with `application()` (sync) and `streaming_application()` (streaming) functions, plus README and requirements.\n- `.github/workflows/python-package.yml` — dedicated `test-bedrock` job so AWS deps stay out of the default test matrix.\n- `tests/integrations/test_bip0042_bedrock.py` — 23 unit tests covering imports, guardrail validation, sync/streaming interfaces, multi-block responses, custom `writes` keys, and error propagation.\n\n## Design notes\n\n- **No `boto3` import at module load** — guarded by `require_plugin`, so installs without the `[bedrock]` extra still work.\n- **Client injection** — both actions accept a pre-built `bedrock-runtime` client for tests and distributed execution; otherwise the client is created lazily on first use.\n- **Guardrail safety** — setting `guardrail_id` without an explicit `guardrail_version` raises `ValueError` rather than silently defaulting to `DRAFT`.\n- **Empty vs. default inference config** — `inference_config\u003d{}` is respected; `None` falls back to `{\"maxTokens\": 4096}`.\n- **Custom `writes` keys** — both sync and streaming actions map the model\u0027s text output to whichever `writes` key the user declares (e.g. `writes\u003d[\"answer\"]`), with `\"response\"` kept for backwards compatibility.\n\n## How I tested this\n\n- Ran the full unit suite: 23/23 bedrock tests pass, broader Burr suite unchanged.\n- Ran the example against real Bedrock (Claude 3 Haiku, `us-east-1`) — both sync and streaming return valid output.\n- Exercised end-to-end scenarios: multi-turn chat with state-managed history, custom `writes` keys, multi-content-block responses, guardrail validation paths, and `ClientError` propagation.\n\n## Notes\n\n- Follow-ups I\u0027d suggest as separate PRs:\n  - Async variants (`AsyncBedrockAction` / `AsyncBedrockStreamingAction`) on top of `AsyncStreamingAction`.\n  - Native `toolConfig` support in `BedrockAction` for building agents without going around the abstraction.\n  - `stream_result` with typed state via `pydantic` integration.\n\n## Checklist\n\n- [x] PR has an informative and human-readable title\n- [x] Changes are limited to a single goal (Bedrock integration only — tracking/SQS work split out per earlier review)\n- [x] Code passed pre-commit\n- [x] New functionality is tested (23 unit tests + real-API smoke)\n- [x] New functions are documented (docstrings + Sphinx reference)\n- [x] Project documentation updated (`docs/reference/integrations/bedrock.rst`, `docs/getting_started/install.rst`, example README)\n\n\n--- Commits\n* Add Bedrock integration, tests, docs, and CI\n\n* fix(bedrock): streaming writes parity, multi-block text, list join for stream\n\n* style: black-format bedrock integration\n\n* Format Bedrock integration; add runnable Bedrock example\n\nApply Black formatting to burr/integrations/bedrock.py for CI.\n\nAdd examples/integrations/bedrock with BedrockAction and BedrockStreamingAction, requirements and README, and list it in examples/README.\n\n* chore: fix burr/examples newline for pre-commit\n\nend-of-file-fixer expects a trailing newline on burr/examples so\npre-commit run --all-files passes.\n\n* fix bedrock converse content blocks and set_user_input return\n\nMade-with: Cursor\n\n* fixed review comments\n\nMade-with: Cursor\n\n* Fix Bedrock test imports for isort compatibility\n\n---------\n\nCo-authored-by: vaquarkhan \u003cvaquarkhan@users.noreply.github.com\u003e"
    },
    {
      "commit": "ab2fb903e3b0a16e1160a4632b62e5832cd7f6c2",
      "tree": "b76be80cee766c7ebde5533bb1e3bb65576ab257",
      "parents": [
        "c73b24cede7cb742ea021ef7c8dce1d0f6ed9ff5"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Fri Apr 10 08:51:50 2026 -0700"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sat Apr 11 11:40:02 2026 -0700"
      },
      "message": "Fixes pre-commit\n"
    },
    {
      "commit": "c73b24cede7cb742ea021ef7c8dce1d0f6ed9ff5",
      "tree": "705711f2b8bce13bf84afc1d225c60162c1a6e4c",
      "parents": [
        "182d46247ddd6706bd541804c70bd45cb78cdffc"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Apr 09 10:28:05 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Apr 09 22:12:01 2026 -0700"
      },
      "message": "fix: update deprecated OpenAI models in example notebooks\n\nReplaces gpt-3.5-turbo with gpt-4o-mini and gpt-4-turbo-preview with\ngpt-4o in 5 example notebooks. Skips parallelism/notebook.ipynb which\nintentionally uses multiple models to demonstrate parallel execution.\n"
    },
    {
      "commit": "182d46247ddd6706bd541804c70bd45cb78cdffc",
      "tree": "574aeca0e334b0458ef25e45c062f0a81fcbe9ed",
      "parents": [
        "c86901dee25a4e8866edc1efc4d751c1cc776ddd"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Apr 09 09:48:00 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Apr 09 22:12:01 2026 -0700"
      },
      "message": "fix: use gpt-4o for routing actions, gpt-4o-mini for generation\n\nchoose_mode uses gpt-4o (replaces gpt-4) to preserve the intentional\ntwo-tier model design. chat_response uses gpt-4o-mini (replaces gpt-3.5-turbo).\n"
    },
    {
      "commit": "c86901dee25a4e8866edc1efc4d751c1cc776ddd",
      "tree": "c1f4f06482efcd6f2888c9eb5c8666975332e9c6",
      "parents": [
        "30d74e91e39a7ff3c4b76f1c3e6f4a50f9428002"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Apr 09 09:30:18 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Apr 09 22:12:01 2026 -0700"
      },
      "message": "fix: update deprecated OpenAI models to gpt-4o-mini in examples\n\nReplaces gpt-3.5-turbo and gpt-4 references with gpt-4o-mini across\n8 example files. Closes #521.\n"
    },
    {
      "commit": "30d74e91e39a7ff3c4b76f1c3e6f4a50f9428002",
      "tree": "472246ed6f0460dc5aef9ed4b099c0078526b812",
      "parents": [
        "618d2e8d2a3b65f16aca26d0dbff1e7f1afae350"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Fri Apr 10 02:09:40 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 10 15:09:40 2026 +1000"
      },
      "message": "ci: repo governance workflows and assignment policy (#713)\n\n* ci: add stale PR lifecycle workflow\n\nWeekly cron job (Mondays 09:00 UTC) that enforces the PR\nlifecycle policy defined in #690:\n\n- 14 days after review with no author response: label pr/stale\n  and convert to draft\n- 90 days with no activity: close with comment\n- Skip PRs with lifecycle/frozen, pr/do-not-merge, or from\n  dependabot\n\nCloses #695\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n* ci: add auto-labeling for new issues and PRs\n\n- New issues automatically get `status/needs-triage`\n- PRs get `area/*` labels based on changed files via actions/labeler\n- PRs get `pr/needs-rebase` when they have merge conflicts (auto-removed\n  when resolved)\n\nLabeler config maps repo paths to area labels: core, ui, storage,\nstreaming, hooks, tracking, integrations, visualization, website,\nci, examples, typing.\n\nCloses #696\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n* ci: add issue assignment policy and stale assignment workflow\n\nDocuments the assignment policy in CONTRIBUTING.rst:\n- Assignee \u003d actively working\n- 14 days without activity: warning comment\n- 21 days total: unassign + add help wanted\n- lifecycle/frozen issues are exempt\n\nAdds weekly workflow (Wednesdays 09:00 UTC) to enforce it\nautomatically.\n\nCloses #709\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e\n\n---------\n\nSigned-off-by: André Ahlert \u003candre@aex.partners\u003e"
    },
    {
      "commit": "618d2e8d2a3b65f16aca26d0dbff1e7f1afae350",
      "tree": "36bc894d26d483fdb909b6ce377478e79d2b18de",
      "parents": [
        "a7b856ea845c413428c91ad1343ef3b538268f16"
      ],
      "author": {
        "name": "Vaquar Khan",
        "email": "vaquar.cna@gmail.com",
        "time": "Fri Apr 10 00:08:19 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Apr 10 15:08:19 2026 +1000"
      },
      "message": "Issue 664 cloud native aws (#666)\n\n* feat: BIP-0042 Cloud-Native Architecture for Apache Burr on AWS (#664)\n\n- Event-driven SQS telemetry: S3 notifications to SQS, near-instant updates\n- Buffered S3 persistence: SpooledTemporaryFile fixes seek errors on large files\n- Native BedrockAction and BedrockStreamingAction for Bedrock integration\n- Terraform module: S3, SQS, IAM with dev/prod tfvars and tutorial\n\n* feat: BIP-0042 Cloud-Native Architecture for Apache Burr on AWS (#664)\n\n* feat: BIP-0042 Cloud-Native Architecture for Apache Burr on AWS (#664)\n\n* BIP-0042 Cloud-Native Architecture for Apache Burr on AWS (#664) fixed build error\n\n* chore: move Bedrock integration to separate PR and review comments fixed\n\n* feat: add Bedrock integration (BIP-0042) as separate PR\n\n* Revert \"feat: add Bedrock integration (BIP-0042) as separate PR\"\n\nThis reverts commit 61673cdfbc79f0c6bcc444594173042de186fab1.\n\n* fix: add tracking-server-s3 to CI deps, remove Bedrock (in separate PR), fix typo\n\n* fix: lint S3/run.py, SQS multi-record parse, BIP-0042 tests and CI job\n\n---------\n\nCo-authored-by: vaquarkhan \u003cvaquarkhan@users.noreply.github.com\u003e"
    },
    {
      "commit": "a7b856ea845c413428c91ad1343ef3b538268f16",
      "tree": "151eb832a390a18e8126f45895c104e49456bfd6",
      "parents": [
        "c57ce3c6b9c984f6faeb78211038546ce235bcee"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Tue Apr 07 20:38:34 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 07 20:38:34 2026 -0700"
      },
      "message": "fix: update .rat-excludes for third-party MIT files and SVGs (#729)\n\n- Add deep-researcher prompts.py/utils.py (MIT, attributed in LICENSE)\n- Add website/src/components/ui/*.tsx (Magic UI/shadcn, MIT, attributed in LICENSE)\n- Add blanket *.svg exclude (third-party logos, same approach as Apache Airflow)"
    },
    {
      "commit": "c57ce3c6b9c984f6faeb78211038546ce235bcee",
      "tree": "87eea78e897bb57153eaa4c2cef5c1752d9ac46a",
      "parents": [
        "8571806e8b8d0584e5a192ffc79e8343e63208fb"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sun Apr 05 21:12:25 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 05 21:12:25 2026 -0700"
      },
      "message": "fix: remove .DS_Store and add ASF license headers to website source files (#727)\n\n* fix: remove .DS_Store and add ASF license headers to website source files\n\n- Remove examples/multi-modal-chatbot/.DS_Store from repo\n- Fix .DS_Store case sensitivity in .gitignore\n- Add ASF license headers to all 26 .ts/.tsx files in website/src/\n\n* fix: add ASF headers to remaining website config files and update .rat-excludes\n\n- Add ASF license headers to next.config.js, globals.css, postcss.config.mjs\n- Add *.json to .rat-excludes (JSON files cannot contain comments)\n\n* fix: replace ASF headers with MIT attribution on third-party UI components\n\nThe website/src/components/ui/ files are copied from Magic UI and\nshadcn/ui (both MIT licensed). Replace incorrectly added ASF headers\nwith proper MIT attribution and add license notices to LICENSE file.\n\n- 11 files from Magic UI: animated-beam, animated-shiny-text, blur-fade,\n  border-beam, dot-pattern, icon-cloud, magic-card, marquee,\n  number-ticker, safari, shimmer-button\n- 1 file from shadcn/ui: button"
    },
    {
      "commit": "8571806e8b8d0584e5a192ffc79e8343e63208fb",
      "tree": "0aa2af673bda0ae9d408a46922c925fb2357aca5",
      "parents": [
        "c3ab9942df96567621621ecc4254797cf8a621c7"
      ],
      "author": {
        "name": "hkr",
        "email": "104939283+harishkesavarao@users.noreply.github.com",
        "time": "Sun Apr 05 10:44:24 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 05 15:14:24 2026 +1000"
      },
      "message": "Ecosystem page for Apache Burr (#661)\n\n* Ecosystem page for Apache Burr\n\n* Removed broken links, this is a work in progress\n\n* more integrations, examples, docs\n\n* remove extra file\n\n* add ecosystem to the index"
    },
    {
      "commit": "c3ab9942df96567621621ecc4254797cf8a621c7",
      "tree": "e85c75aabbc8b2b745f85ca78c543ca5da982691",
      "parents": [
        "8baae125793db37736e463d36158b7520b2439b3"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sat Apr 04 12:19:17 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Apr 04 12:19:17 2026 -0700"
      },
      "message": "fix: add MIT license notice to LICENSE-wheel for deep-researcher examples (#726)\n\nThe wheel distribution includes examples/deep-researcher/prompts.py and\nutils.py which are MIT-licensed, but LICENSE-wheel only contained the\nApache 2.0 text. Syncs LICENSE-wheel with the main LICENSE file.\n\nFixes #712\n\nCo-authored-by: Claude Opus 4.6 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "8baae125793db37736e463d36158b7520b2439b3",
      "tree": "ec6b304af061a754d93196bd711045bae99b31e4",
      "parents": [
        "558de8adec01075567ca2243df9f60834bc343f5"
      ],
      "author": {
        "name": "Vaibhav Singh",
        "email": "95634443+vbhavh@users.noreply.github.com",
        "time": "Sat Apr 04 09:48:42 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Apr 04 15:18:42 2026 +1100"
      },
      "message": "fix/#652 (#668) fixes pydantic warnings and minimum pins to pydantic \u003e\u003d2.0\n\n* type(model).model_fields accesses the attribute on the class, which is the correct way per Pydantic v2.11+.\n\n* all instances use type(model).model_fields correctly.\n\n* Update pydantic version constraint to \u003e\u003d2.11\n\n* Update pydantic version to \u003e\u003d2.11 in pyproject.toml\n\n* Added test_pydantic_version that ensures correct pydantic version to handle model_fields.\n\n* made all the structural changes.\n\n* Fixed some pre-commit linting errors.\n\n---------\n\nCo-authored-by: vaibhavsingh-materialplus \u003cVaibhav.Singh@materialplus.io\u003e"
    },
    {
      "commit": "558de8adec01075567ca2243df9f60834bc343f5",
      "tree": "92d72c19d6165bada073e8a5c0ec959462fefe61",
      "parents": [
        "2c5abdb0e3829228bb1397c8063eff7d9b85c6ae"
      ],
      "author": {
        "name": "PJ Fanning",
        "email": "pjfanning@users.noreply.github.com",
        "time": "Sun Mar 29 21:56:39 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 29 12:56:39 2026 -0700"
      },
      "message": "Update licensing information in prompts.py and utils.py (#711)"
    },
    {
      "commit": "2c5abdb0e3829228bb1397c8063eff7d9b85c6ae",
      "tree": "17d1beec7aeece92020e6e7892c49b7be8f87a85",
      "parents": [
        "f884adff8d5b0afd0e813f2c46b6196c060a9649"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Mar 28 16:24:33 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 29 06:24:33 2026 +1100"
      },
      "message": "fix: graceful stream shutdown on exceptions in streaming actions (#680)\n\n* fix: allow streaming actions to gracefully handle raised exceptions\n\nWhen a streaming action catches an exception and yields a final state\nin a try/except/finally block, the stream now completes gracefully\ninstead of propagating the exception and killing the connection.\n\nIf the generator yields a valid state_update before the exception\npropagates, the exception is suppressed and the stream terminates\nnormally. If no state was yielded, the exception propagates as before.\n\nCloses #581\n\n* fix: add logging for suppressed exceptions and tests for streaming graceful shutdown\n\n- Add logger.warning with exc_info in all 4 streaming except blocks\n- Remove dead caught_exc variable in multi-step functions\n- Fix count increment asymmetry between sync and async single-step\n- Add 8 tests covering graceful exception handling and propagation\n\n* style: apply black formatting\n\n* style: apply pre-commit formatting (black 23.11.0, isort 5.12.0)"
    },
    {
      "commit": "f884adff8d5b0afd0e813f2c46b6196c060a9649",
      "tree": "0c39312dd493fec44fc8b4c8eab7c839681703e7",
      "parents": [
        "e6f03974a5db50f1d790610b5ee5020b913c03df"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Mar 28 16:16:44 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 29 06:16:44 2026 +1100"
      },
      "message": "core: add flexible_api decorator to fix mypy override errors (#683)\n\n* core: add flexible_api decorator to fix mypy override errors on class-based actions\n\nAdds a `flexible_api` decorator that users can apply to `run`,\n`stream_run`, or `run_and_update` overrides that use explicit\nparameters instead of `**run_kwargs`. This prevents mypy [override]\nerrors caused by narrowing the base-class signature.\n\nCloses #457\n\n* style: apply black formatting\n\n* Rename flexible_api to type_eraser and fix async support\n\nAddress review feedback: rename decorator per maintainer suggestion.\nFix critical bug where @wraps on async/generator functions broke\nis_async() detection. Add tests for all function types."
    },
    {
      "commit": "e6f03974a5db50f1d790610b5ee5020b913c03df",
      "tree": "86c861b456fff9ba9f08d23cdc14332811fed682",
      "parents": [
        "ecb55337f3e6dc32a9d889d3905cd9c7ddab796c"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Mar 28 16:13:24 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 29 06:13:24 2026 +1100"
      },
      "message": "fix: support `async with` on async persister factory methods (#681)\n\n* fix: support `async with` on async persister factory methods\n\n`AsyncSQLitePersister.from_values()` and `AsyncPostgreSQLPersister.from_values()`\nwere async classmethods returning coroutines, which cannot be used directly\nwith `async with`. This wraps them in `_AsyncPersisterContextManager` that\nsupports both `await` (backwards compatible) and `async with` protocols.\n\nCloses #546\n\n* refactor: move _AsyncPersisterContextManager to burr/common/async_utils.py and add tests\n\nAddress review feedback:\n- Move _AsyncPersisterContextManager from b_aiosqlite.py to\n  burr/common/async_utils.py to avoid cross-dependency between\n  unrelated integrations\n- Add type annotation to coro parameter\n- Add tests for async with pattern on from_values and from_config\n\n* fix: guard against __aexit__ crash and double consumption in context manager wrapper\n\n- __aexit__ now returns False when __aenter__ failed (persister is None),\n  preventing AttributeError that would mask the original exception\n- Add _consumed flag to prevent silent coroutine reuse, raising\n  RuntimeError with clear message on second await/async with\n- Add tests for both edge cases\n\n* docs: fix async persister examples and remove redundant test helpers\n\n- Add missing `await` to from_values() calls in parallelism.rst docs\n- Remove AsyncSQLiteContextManager helper class from both test files,\n  now that from_values() natively supports async with\n- Replace deprecated .close() calls with .cleanup() in test fixtures\n\n* style: fix black formatting and isort import order\n\n* style: reformat with black 23.11.0 (project version)\n\n* ci: trigger workflow rerun"
    },
    {
      "commit": "ecb55337f3e6dc32a9d889d3905cd9c7ddab796c",
      "tree": "2760a29bb8d6c9d4cee05f7242e10e1f6f5b159e",
      "parents": [
        "62b61c94688c2fbfcb813b367465a5c85dce5760"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Mar 28 15:52:35 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sat Mar 28 11:59:56 2026 -0700"
      },
      "message": "fix: pin sphinx\u003c9 to fix docs build\n\nsphinx-toolbox 4.1.2 imports sphinx.ext.autodoc.logger which was\nremoved in Sphinx 9.x. Pin until sphinx-toolbox releases a fix.\n\nCloses #707\n"
    },
    {
      "commit": "62b61c94688c2fbfcb813b367465a5c85dce5760",
      "tree": "fc311cf3d0b1f60972a6000ff39426408bdb90dd",
      "parents": [
        "98dadec7e01377cfe0f910d8bd082c4eb7bbd7b1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Mar 29 05:19:29 2026 +1100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 29 05:19:29 2026 +1100"
      },
      "message": "Bump brace-expansion in /telemetry/ui (#702)\n\nBumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.\n\nUpdates `brace-expansion` from 1.1.11 to 1.1.13\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.13)\n\nUpdates `brace-expansion` from 2.0.1 to 2.0.3\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.13)\n\n---\nupdated-dependencies:\n- dependency-name: brace-expansion\n  dependency-version: 1.1.13\n  dependency-type: indirect\n- dependency-name: brace-expansion\n  dependency-version: 2.0.3\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "98dadec7e01377cfe0f910d8bd082c4eb7bbd7b1",
      "tree": "cd073ccd69ccc135027f6ce6c9e3d568e731c82f",
      "parents": [
        "3402fa961c119724d05c9205641bd153c959f159"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Mar 29 05:19:06 2026 +1100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 29 05:19:06 2026 +1100"
      },
      "message": "Bump node-forge from 1.3.1 to 1.4.0 in /telemetry/ui (#700)\n\nBumps [node-forge](https://github.com/digitalbazaar/forge) from 1.3.1 to 1.4.0.\n- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.1...v1.4.0)\n\n---\nupdated-dependencies:\n- dependency-name: node-forge\n  dependency-version: 1.4.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "3402fa961c119724d05c9205641bd153c959f159",
      "tree": "63225ab8506d79a88bacaed57fcac872843fb607",
      "parents": [
        "cb7febfb4cbf723e3007f68447cf432c085a92ba"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:38:43 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:38:43 2026 -0700"
      },
      "message": "Bump yaml and lint-staged in /telemetry/ui (#697)\n\nBumps [yaml](https://github.com/eemeli/yaml) to 2.8.3 and updates ancestor dependencies [yaml](https://github.com/eemeli/yaml) and [lint-staged](https://github.com/lint-staged/lint-staged). These dependencies need to be updated together.\n\n\nUpdates `yaml` from 2.5.1 to 2.8.3\n- [Release notes](https://github.com/eemeli/yaml/releases)\n- [Commits](https://github.com/eemeli/yaml/compare/v2.5.1...v2.8.3)\n\nUpdates `yaml` from 1.10.2 to 1.10.3\n- [Release notes](https://github.com/eemeli/yaml/releases)\n- [Commits](https://github.com/eemeli/yaml/compare/v2.5.1...v2.8.3)\n\nUpdates `yaml` from 2.3.4 to 2.8.3\n- [Release notes](https://github.com/eemeli/yaml/releases)\n- [Commits](https://github.com/eemeli/yaml/compare/v2.5.1...v2.8.3)\n\nUpdates `lint-staged` from 15.2.2 to 15.5.2\n- [Release notes](https://github.com/lint-staged/lint-staged/releases)\n- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/lint-staged/lint-staged/compare/v15.2.2...v15.5.2)\n\n---\nupdated-dependencies:\n- dependency-name: yaml\n  dependency-version: 2.8.3\n  dependency-type: indirect\n- dependency-name: yaml\n  dependency-version: 1.10.3\n  dependency-type: indirect\n- dependency-name: yaml\n  dependency-version: 2.8.3\n  dependency-type: indirect\n- dependency-name: lint-staged\n  dependency-version: 15.5.2\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "cb7febfb4cbf723e3007f68447cf432c085a92ba",
      "tree": "5efbab3253bd2ffa76436fa7e06306902b7a2e92",
      "parents": [
        "4f1046e54dae445883954cea06e741439a242910"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:38:40 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:38:40 2026 -0700"
      },
      "message": "Bump handlebars from 4.7.8 to 4.7.9 in /telemetry/ui (#699)\n\nBumps [handlebars](https://github.com/handlebars-lang/handlebars.js) from 4.7.8 to 4.7.9.\n- [Release notes](https://github.com/handlebars-lang/handlebars.js/releases)\n- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md)\n- [Commits](https://github.com/handlebars-lang/handlebars.js/compare/v4.7.8...v4.7.9)\n\n---\nupdated-dependencies:\n- dependency-name: handlebars\n  dependency-version: 4.7.9\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "4f1046e54dae445883954cea06e741439a242910",
      "tree": "feca6b1b1f85d5000603ea3d45a757efeee16ba3",
      "parents": [
        "d1b78898d61e1216e5b0306072ddfcbba8f16ae8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:38:35 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:38:35 2026 -0700"
      },
      "message": "Bump path-to-regexp and express in /telemetry/ui (#703)\n\nBumps [path-to-regexp](https://github.com/pillarjs/path-to-regexp) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.\n\nUpdates `path-to-regexp` from 0.1.12 to 0.1.13\n- [Release notes](https://github.com/pillarjs/path-to-regexp/releases)\n- [Changelog](https://github.com/pillarjs/path-to-regexp/blob/v.0.1.13/History.md)\n- [Commits](https://github.com/pillarjs/path-to-regexp/compare/v0.1.12...v.0.1.13)\n\nUpdates `express` from 4.21.2 to 4.22.1\n- [Release notes](https://github.com/expressjs/express/releases)\n- [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md)\n- [Commits](https://github.com/expressjs/express/compare/4.21.2...v4.22.1)\n\n---\nupdated-dependencies:\n- dependency-name: path-to-regexp\n  dependency-version: 0.1.13\n  dependency-type: indirect\n- dependency-name: express\n  dependency-version: 4.22.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d1b78898d61e1216e5b0306072ddfcbba8f16ae8",
      "tree": "e668d7283b9e500b4b5291d8f2c5495bb0b2e98f",
      "parents": [
        "3b2ca2ad9a8f41ddc9bce28c763cd3101d1e2740"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:38:32 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:38:32 2026 -0700"
      },
      "message": "Bump picomatch from 2.3.1 to 2.3.2 in /telemetry/ui (#704)\n\nBumps [picomatch](https://github.com/micromatch/picomatch) from 2.3.1 to 2.3.2.\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/picomatch/compare/2.3.1...2.3.2)\n\n---\nupdated-dependencies:\n- dependency-name: picomatch\n  dependency-version: 2.3.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "3b2ca2ad9a8f41ddc9bce28c763cd3101d1e2740",
      "tree": "193fda5e07c9aff5f4f1209e3ac0f80301a3b690",
      "parents": [
        "40da4a95eb883e04f8c11584f865bc11ed69fe24"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:38:07 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:38:07 2026 -0700"
      },
      "message": "Bump webpack from 5.90.2 to 5.105.2 in /telemetry/ui (#660)\n\nBumps [webpack](https://github.com/webpack/webpack) from 5.90.2 to 5.105.2.\n- [Release notes](https://github.com/webpack/webpack/releases)\n- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/webpack/webpack/compare/v5.90.2...v5.105.2)\n\n---\nupdated-dependencies:\n- dependency-name: webpack\n  dependency-version: 5.105.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "40da4a95eb883e04f8c11584f865bc11ed69fe24",
      "tree": "4c8a40c0c36797144f7d56ef67ca75480ec75763",
      "parents": [
        "c22141f8f37023b2d395cf021614478dbcc860ea"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 23:38:05 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 23:38:05 2026 -0700"
      },
      "message": "Bump picomatch in /website (#698)\n\nBumps  and [picomatch](https://github.com/micromatch/picomatch). These dependencies needed to be updated together.\n\nUpdates `picomatch` from 4.0.3 to 4.0.4\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/picomatch/compare/4.0.3...4.0.4)\n\nUpdates `picomatch` from 2.3.1 to 2.3.2\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/picomatch/compare/4.0.3...4.0.4)\n\n---\nupdated-dependencies:\n- dependency-name: picomatch\n  dependency-version: 4.0.4\n  dependency-type: indirect\n- dependency-name: picomatch\n  dependency-version: 2.3.2\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c22141f8f37023b2d395cf021614478dbcc860ea",
      "tree": "a353d9c35149af1d94f1691e21baa58478f06d01",
      "parents": [
        "df3a281ad2e08ce59272fa21ccb207cc8f649ffe"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Mar 28 03:34:05 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Mar 28 17:34:05 2026 +1100"
      },
      "message": "website: replace placeholder testimonials with real quotes (#688)\n\n* website: replace placeholder testimonials with real quotes\n\nSwap placeholder testimonials with real user quotes from the\noriginal Burr docs. Add company logos to the trusted-by section.\nRemove inactive Twitter/X links from Community and Footer.\n\n* website: restore Twitter/X links with updated URL\n\nRe-add Twitter/X links to Community and Footer sections that were\nremoved in the previous commit. Update the URL to the correct\nhandle (x.com/burr_framework).\n\n---------\n\nCo-authored-by: Stefan Krawczyk \u003cstefank@cs.stanford.edu\u003e"
    },
    {
      "commit": "df3a281ad2e08ce59272fa21ccb207cc8f649ffe",
      "tree": "1ca4db9da6ea54f80adf2802d691f23a64937a88",
      "parents": [
        "44f7dc6a59ae31fdbbf4979f854710be65559e19"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Mar 27 14:43:09 2026 +0000"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Mar 27 22:50:28 2026 -0700"
      },
      "message": "Bump brace-expansion in /website\n\nBumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.\n\nUpdates `brace-expansion` from 5.0.4 to 5.0.5\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.4...v5.0.5)\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.13\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.4...v5.0.5)\n\n---\nupdated-dependencies:\n- dependency-name: brace-expansion\n  dependency-version: 5.0.5\n  dependency-type: indirect\n- dependency-name: brace-expansion\n  dependency-version: 1.1.13\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "44f7dc6a59ae31fdbbf4979f854710be65559e19",
      "tree": "07c553019939611ab8571520fe9377f3160dd43f",
      "parents": [
        "04d172ff53558f5277033df8339652d5963c7128"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Wed Mar 25 00:33:33 2026 -0700"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Wed Mar 25 11:14:02 2026 -0700"
      },
      "message": "Adds andreahlert as collaborator\n"
    },
    {
      "commit": "04d172ff53558f5277033df8339652d5963c7128",
      "tree": "05f5cb2758074ad540720c21bf7ac5f33112cbf7",
      "parents": [
        "f61d30f5291a586f43a4c880917d2eef6e7fd054"
      ],
      "author": {
        "name": "Smita D Ambiger",
        "email": "75329912+Smitaambiger@users.noreply.github.com",
        "time": "Sun Mar 22 10:46:34 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 22 16:16:34 2026 +1100"
      },
      "message": "Enable Burr UI to be added to existing FastAPI app (#671)\n\n* Add create_burr_ui_app factory and mount_burr_ui helper to embed Burr UI into existing FastAPI apps\n\n* Add FastAPI mount example and documentation for Burr UI embedding\n\n* feat: enable Burr UI mounting as sub-app with dynamic base path support\n\nRefactor run.py to use a factory pattern (create_burr_ui_app) so all routes\nare registered on the sub-app instance, not at module level. Add mount_burr_ui()\nhelper for embedding the Burr UI into an existing FastAPI application.\n\nWhen mounted at a sub-path (e.g. /burr), the server rewrites CRA\u0027s hardcoded\nabsolute paths in index.html and injects window.__BURR_BASE_PATH__ so the\nReact app can prefix all API calls and client-side routes at runtime.\n\nReact-side changes:\n- OpenAPI.ts reads __BURR_BASE_PATH__ for API client BASE\n- App.tsx uses it as Router basename\n- appcontainer.tsx prefixes logo image paths\n- StreamingChatbot.tsx prefixes direct fetch calls\n\n* fix: resolve pre-commit and eslint CI failures\n\n- Add Window.__BURR_BASE_PATH__ type declaration to avoid no-explicit-any\n- Apply prettier formatting to TS files\n- Apply black formatting to test_local_tracking_client.py\n\n---------\n\nCo-authored-by: Smita Ambiger \u003csmitaambiger@gmail.com\u003e\nCo-authored-by: Stefan Krawczyk \u003cstefank@cs.stanford.edu\u003e"
    },
    {
      "commit": "f61d30f5291a586f43a4c880917d2eef6e7fd054",
      "tree": "965f891d9387e25165fee1b158643581cb9d451d",
      "parents": [
        "62535d0399a30ae53fb217ec2a4ec931750aa01e"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Wed Mar 18 11:09:42 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Mar 20 22:28:09 2026 -0700"
      },
      "message": "fix: pass partition_key to child PointerModel in fork/spawn relationships\n\nThe _log_child_relationships function was hardcoding partition_key\u003dNone\nwhen creating child PointerModels in children.jsonl. This caused the UI\nto generate broken links for forked/spawned apps that use partition keys,\nsince the route includes the partition_key segment.\n\nCloses #518\n"
    },
    {
      "commit": "62535d0399a30ae53fb217ec2a4ec931750aa01e",
      "tree": "9f954f763160641d07dfab44473b24fa56222f2f",
      "parents": [
        "a3e253ac093574e4609dd6c82684b2e5501c58d3"
      ],
      "author": {
        "name": "hkr",
        "email": "104939283+harishkesavarao@users.noreply.github.com",
        "time": "Sat Mar 21 10:50:01 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Mar 21 16:20:01 2026 +1100"
      },
      "message": "Update project references to Apache Burr and remove DAGWorks attributions (#659)\n\n* Update project references to Apache Burr and remove DAGWorks attributions\n\n- Update GitHub URLs from dagworks-inc and DAGWorks-Inc to apache.\n- Update documentation links from burr.dagworks.io to burr.apache.org.\n- Update package references dagWorks-Inc/hamilton to apache/hamilton.\n- Remove by DAGWorks Inc. attributions from documentation and examples.\n- Standardize project URLs across READMEs, examples, and backend code.\n\n* Add write permissions to docs.yml\n\n* Apply suggestion from @skrawcz\n\nupdate wording on readme about hamilton connection\n\n* Changing more references to DAGWorks\n\n* Changed more dagworks references in examples and telemetry\n\n* typos and removed write permissions for pull request triggers\n\n* Update examples/conversational-rag/graph_db_example/ingest_notebook.ipynb\n\nCo-authored-by: André Ahlert \u003candre@aex.partners\u003e\n\n---------\n\nCo-authored-by: Elijah ben Izzy \u003celijahbenizzy@users.noreply.github.com\u003e\nCo-authored-by: Stefan Krawczyk \u003cstefan@dagworks.io\u003e\nCo-authored-by: André Ahlert \u003candre@aex.partners\u003e"
    },
    {
      "commit": "a3e253ac093574e4609dd6c82684b2e5501c58d3",
      "tree": "eb3e962f481e94ec11c3640eb741d3493c8027a2",
      "parents": [
        "9da8f2949ace716933451381e0be614fba238c0b"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Sat Mar 21 01:56:24 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Mar 21 15:56:24 2026 +1100"
      },
      "message": "fix: instantiate instrumentor class before calling instrument() (#684)\n\n_init_instrument was accessing is_instrumented_by_opentelemetry and\ncalling instrument() on the class instead of an instance. The property\ndescriptor on the class is always truthy, causing instrumentation to\nbe silently skipped.\n\nCloses #408"
    },
    {
      "commit": "9da8f2949ace716933451381e0be614fba238c0b",
      "tree": "c3ce3b6d62faa3710bfba2a8a92e54d7b77ee4d7",
      "parents": [
        "5ff9f44cae534d8e922ca7b09953de5a6a0a274b"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Mar 19 03:32:09 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 17:32:09 2026 +1100"
      },
      "message": "fix: deploy .htaccess and add HTML redirect fallbacks for old doc paths (#686)\n\nThe deploy step used `cp -r ... /*` which skips dotfiles, so .htaccess\nwas never copied to the asf-site branch. Add `shopt -s dotglob` to fix.\n\nAlso generate static HTML redirect pages by scanning the Sphinx build\noutput at build time, as fallback in case ASF infra does not process\n.htaccess. See PR #679 for context."
    },
    {
      "commit": "5ff9f44cae534d8e922ca7b09953de5a6a0a274b",
      "tree": "a540d974073adb88b4367168fbd10666c91c033b",
      "parents": [
        "226288fdb7438943a989c815641acb9ec322019f"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Mar 19 02:17:51 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 16:17:51 2026 +1100"
      },
      "message": "website: add Next.js landing page for burr.apache.org (#679)\n\n* website: add Next.js landing page for burr.apache.org\n\nAdd a modern landing page built with Next.js 15, Tailwind CSS and\nMagic UI that will serve as the homepage for burr.apache.org.\nSphinx docs move from / to /docs/ so both coexist.\n\nLanding page sections:\n- Hero with animated stats (GitHub stars, PyPI downloads)\n- Interactive code terminal with syntax-highlighted examples\n- Feature highlights (state management, observability, HITL, etc.)\n- Integration marquee with real SVG logos\n- Testimonial carousel with existing quotes\n- Community links (Discord, GitHub, Twitter)\n- ASF-compliant footer (License, Thanks, Security, Sponsorship,\n  Privacy Policy, Incubator link, trademark attribution,\n  incubation disclaimer)\n\nBuild \u0026 deploy changes:\n- New unified workflow (build-site.yml) that builds both Next.js\n  and Sphinx, then merges outputs into asf-site branch\n- Landing page at / and Sphinx docs at /docs/\n- sphinx-docs.yml retains build + artifact for PR review only\n  (deploy removed to avoid conflicts)\n- Sphinx html_baseurl updated to include /docs/ prefix\n\nTech stack: Next.js 15 (App Router), Tailwind CSS v4, shadcn/ui,\nMagic UI (Marquee, NumberTicker, ShimmerButton, BlurFade,\nBorderBeam, MagicCard, DotPattern, AnimatedShinyText), shiki\nfor syntax highlighting. Static export for Apache infra compat.\n\n* add .htaccess redirects for old Sphinx paths and fix trailing newline\n\nRedirect old root-level Sphinx URLs (concepts/, getting_started/, etc.)\nto /docs/ with 301s so existing links and search results keep working\nafter the landing page migration. Also fix missing newline at end of\nglobals.css that was failing the pre-commit end-of-file-fixer hook.\n\n* docs: add logo and landing page link to Sphinx sidebar, add missing website constants\n\n- Add Burr logo to Sphinx docs sidebar, displayed inline with the title\n- Sidebar brand link points to / (landing page) instead of docs root\n- Add missing website/src/lib/constants.ts and utils.ts needed by Next.js\n- Gitignore built Sphinx docs in website/public/docs/\n\n---------\n\nCo-authored-by: Stefan Krawczyk \u003cstefank@cs.stanford.edu\u003e"
    },
    {
      "commit": "226288fdb7438943a989c815641acb9ec322019f",
      "tree": "6a3a2cc499d6c108b2e95ac466cac5435b460173",
      "parents": [
        "241d6ee0c7467841ab27f905dc26d93f2b9976c2"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Mon Mar 16 02:35:51 2026 -0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 16 16:35:51 2026 +1100"
      },
      "message": "feat: implement counter app demo in Burr UI (#675)\n\n* feat: implement counter app demo in Burr UI (#69)\n\nAdd a fully functional counter demo integrated with the Burr tracking\nUI, replacing the previous WIP placeholder.\n\nBackend:\n- Add FastAPI server for the counter example with /count, /state and\n  /create endpoints\n- Register counter router in the main Burr tracking server\n\nFrontend:\n- Implement Counter React component with increment button and live\n  telemetry view\n- Add CounterState model and API service methods\n\n* Fixes pre-commit issue"
    },
    {
      "commit": "241d6ee0c7467841ab27f905dc26d93f2b9976c2",
      "tree": "8a4a0b6e05d480e76fa55a25f5405baee4e18d71",
      "parents": [
        "af1a6e416392a5de0737c0f04e77b796dfec98b2"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Sun Mar 15 22:10:39 2026 -0700"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sun Mar 15 22:20:12 2026 -0700"
      },
      "message": "Add is/isnot identity operators to when() conditions\n\nAdds __is and __isnot operators for identity checks, useful for\nNone/True/False comparisons (e.g. when(value__is\u003dNone)).\n"
    },
    {
      "commit": "af1a6e416392a5de0737c0f04e77b796dfec98b2",
      "tree": "0f177cd798f2df1ad42441f74954c581b80046b6",
      "parents": [
        "5d7267c5314ba0b562fc7b91c4771b73d9d4566e"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Sun Mar 15 22:02:59 2026 -0700"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sun Mar 15 22:20:12 2026 -0700"
      },
      "message": "Add comparison operators to when() conditions\n\nExtend Condition.when() to support Django-style lookup operators via\ndouble-underscore suffixes (e.g. when(age__gte\u003d18), when(status__in\u003d[...])).\n\nSupported operators: eq, ne, gt, gte, lt, lte, in, notin, contains.\nPlain key\u003dvalue usage remains fully backward compatible.\n\nIncludes 43 new parametrized tests and updated transition docs.\n"
    },
    {
      "commit": "5d7267c5314ba0b562fc7b91c4771b73d9d4566e",
      "tree": "5f323f52030b619dcd3b5b623f9da7a719851632",
      "parents": [
        "b6b511d019e04f7d943b3f36755cb3303ccff07e"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Sun Mar 08 09:04:28 2026 -0700"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Mar 12 12:50:41 2026 -0700"
      },
      "message": "chore: add deprecation warnings to telemetry stub functions\n"
    },
    {
      "commit": "b6b511d019e04f7d943b3f36755cb3303ccff07e",
      "tree": "f705de9d6c5885e4ed2fa4e77881e16b1e2ed05b",
      "parents": [
        "a1fd33840e327b66d6587bd39251fe1293d227e1"
      ],
      "author": {
        "name": "Stefan Krawczyk",
        "email": "stefank@cs.stanford.edu",
        "time": "Sat Mar 07 22:45:29 2026 -0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Mar 12 12:50:41 2026 -0700"
      },
      "message": "chore: remove phone-home telemetry per ASF policy\n\nRemove PostHog usage analytics that collected anonymous data on\napplication builds, execution calls, and CLI commands. ASF projects\nshould not phone home. The burr.telemetry module is kept as a no-op\nstub (disable_telemetry, is_telemetry_enabled) so existing user code\nthat disables telemetry will not break.\n"
    },
    {
      "commit": "a1fd33840e327b66d6587bd39251fe1293d227e1",
      "tree": "f54e5113f1865c7f479473f85db0946beb1685a4",
      "parents": [
        "d2214d9dec4e781cf692a2fb8ba4e6ee742062e0"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Mar 12 03:42:53 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Mar 12 12:49:30 2026 -0700"
      },
      "message": "fix: wheel LICENSE should not reference examples-only MIT files (#641)\n\nKeep source LICENSE intact (Apache 2.0 + MIT attribution for\nexamples/deep-researcher) and create a separate LICENSE-wheel\n(Apache-only) that Flit injects into the .whl via license-files.\nThe sdist continues to ship the full LICENSE as before.\n"
    },
    {
      "commit": "d2214d9dec4e781cf692a2fb8ba4e6ee742062e0",
      "tree": "02d5f5e59f09faf3749fa1d7e10a29164b2aaf89",
      "parents": [
        "8a975b02f8fd76097917de25ae5217ddee4272f5"
      ],
      "author": {
        "name": "André Ahlert",
        "email": "andre@aex.partners",
        "time": "Thu Mar 12 05:51:51 2026 -0300"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Thu Mar 12 12:46:51 2026 -0700"
      },
      "message": "chore: add ASF license headers to requirements.txt and .gitignore files\n\nAdd missing Apache 2.0 license headers to 25 requirements.txt and\n3 .gitignore files, completing the work started in #651.\n\nCloses #639\n"
    },
    {
      "commit": "8a975b02f8fd76097917de25ae5217ddee4272f5",
      "tree": "78b465f64b780a467433dcb9793a3c3ade5ae522",
      "parents": [
        "9237df20159dadf97e6ee88fdc7a878dad810bf1"
      ],
      "author": {
        "name": "Smita D Ambiger",
        "email": "75329912+Smitaambiger@users.noreply.github.com",
        "time": "Sun Mar 01 13:05:12 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Mar 01 18:35:12 2026 +1100"
      },
      "message": "core: add AST-based linter for undeclared state reads in function-bas… (#656)\n\n* core: add AST-based linter for undeclared state reads in function-based actions\n\n* core: cleanup duplicate originating_fn assignment\n\n* fix: address review feedback and add regression tests\n\n---------\n\nCo-authored-by: Smita Ambiger \u003csmitaambiger@gmail.com\u003e"
    },
    {
      "commit": "9237df20159dadf97e6ee88fdc7a878dad810bf1",
      "tree": "b566927a60e76abef7534d072d084e15d353d16e",
      "parents": [
        "a2d10a6fc5ab8343066f67dcf38363b0ae068ad2"
      ],
      "author": {
        "name": "Smita Ambiger",
        "email": "smitaambiger@gmail.com",
        "time": "Wed Feb 04 00:26:10 2026 +0530"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Sat Feb 28 23:31:02 2026 -0800"
      },
      "message": "ui: add toggle to show/hide input nodes in graph view\n"
    },
    {
      "commit": "a2d10a6fc5ab8343066f67dcf38363b0ae068ad2",
      "tree": "ee81fb79612f9f6e4d92789cb4a680d976e6f8eb",
      "parents": [
        "45c0538f3318973f57dd40dbc80b2652d992c122"
      ],
      "author": {
        "name": "Elijah ben Izzy",
        "email": "elijahbenizzy@users.noreply.github.com",
        "time": "Sun Feb 15 11:41:02 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Feb 15 11:41:02 2026 -0800"
      },
      "message": "Burr 0.42.0 release prep (#651)\n\n* Replace non-standard license headers in 6 notebooks\n\nReplace \"Copyright YEAR Apache Software Foundation\" format with the\nApache-recommended \"Licensed to the Apache Software Foundation\" format.\nThe copyright year format is not standard for ASF projects.\n\n* Add Apache license headers to 33 notebooks\n\nAdd standard Apache license headers as first code cell to all notebooks\nthat were missing them. Apache releases require proper license headers\nin all distributed files for IP compliance.\n\n* Add twine verification to wheel build process\n\nAdd twine check to validate wheel metadata before signing and release.\nThis catches packaging issues like malformed metadata, missing long\ndescriptions, or invalid entry points early in the release process.\n\n* Document twine requirement in release process\n\nAdd twine to prerequisites and update build documentation to reflect\nthe new metadata validation step. Release managers need to know about\nthis dependency before attempting a release.\n\n* Add twine-check command for voter verification\n\nAdd twine-check subcommand to allow voters to independently verify wheel\nmetadata during release voting. This gives voters an additional tool to\nvalidate package quality beyond signature and license checks.\n\n* Truncate pyproject.toml description to single line\n\n* Improve twine validation error messages\n\nShow actual twine output when wheel metadata validation fails. This\nhelps release managers quickly diagnose and fix packaging issues\nwithout needing to manually re-run twine.\n\n* Bump version to 0.42.0\n\n* Replace copyright headers in config files with Apache standard\n\nReplace \"Copyright YEAR\" format with the Apache-recommended\n\"Licensed to the Apache Software Foundation\" format in all\nconfiguration and requirements files. The copyright year format\nis not standard for ASF projects.\n\n* Add -src suffix to source release archive name\n\nRename git archive from apache-burr-{version}-incubating.tar.gz to\napache-burr-{version}-incubating-src.tar.gz to clearly distinguish\nthe source archive from other artifacts in the release.\n\n* removes pyproject.toml update for merge\n\n* fixes pandas 3 compatibility test\n\n* Pre-commit on everything\n\n---------\n\nCo-authored-by: Elijah ben Izzy \u003cebenizzy@salesforce.com\u003e"
    },
    {
      "commit": "45c0538f3318973f57dd40dbc80b2652d992c122",
      "tree": "fc7542499772e0b22f612a226acd3f9517b9b073",
      "parents": [
        "f2ee19394e61b3c81c539bbdc8283b6fc92c5936"
      ],
      "author": {
        "name": "echonesis",
        "email": "echonesis@gmail.com",
        "time": "Wed Dec 03 14:36:52 2025 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Feb 06 13:44:42 2026 -0800"
      },
      "message": "fix: add ASF license section\n"
    },
    {
      "commit": "f2ee19394e61b3c81c539bbdc8283b6fc92c5936",
      "tree": "8c0f45401ea08ae684e9385dcd14e1f9b574d212",
      "parents": [
        "2c0ccb088a958cf6db3ae5483ca5ad312d5efa00"
      ],
      "author": {
        "name": "echonesis",
        "email": "echonesis@gmail.com",
        "time": "Mon Dec 01 14:39:18 2025 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Feb 06 13:44:42 2026 -0800"
      },
      "message": "chore: remove additional line\n"
    },
    {
      "commit": "2c0ccb088a958cf6db3ae5483ca5ad312d5efa00",
      "tree": "43a43086cb60b20437d4000aae9ece12747ad63b",
      "parents": [
        "374aa8fb5b9aaf74d29c4ea2923e5ae4702bb5b1"
      ],
      "author": {
        "name": "echonesis",
        "email": "echonesis@gmail.com",
        "time": "Mon Dec 01 14:38:06 2025 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Feb 06 13:44:42 2026 -0800"
      },
      "message": "chore: add EOL\n"
    },
    {
      "commit": "374aa8fb5b9aaf74d29c4ea2923e5ae4702bb5b1",
      "tree": "cd82f20e65b155dc55cb46306ff72d8baad1a655",
      "parents": [
        "00901a6075a48d3b6aa4faba7ff40e572b945a8a"
      ],
      "author": {
        "name": "echonesis",
        "email": "echonesis@gmail.com",
        "time": "Mon Dec 01 14:34:01 2025 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Feb 06 13:44:42 2026 -0800"
      },
      "message": "chore: remove test settings\n"
    },
    {
      "commit": "00901a6075a48d3b6aa4faba7ff40e572b945a8a",
      "tree": "cc04d5f6f6ae4995f63fce8808037b117c9fb472",
      "parents": [
        "bc2237802ccbdadfaad689d244dd7078210a2d4f"
      ],
      "author": {
        "name": "echonesis",
        "email": "echonesis@gmail.com",
        "time": "Mon Dec 01 14:31:58 2025 +0800"
      },
      "committer": {
        "name": "Stefan Krawczyk",
        "email": "stefan@dagworks.io",
        "time": "Fri Feb 06 13:44:42 2026 -0800"
      },
      "message": "feat: deploy Burr in Vercel\n"
    }
  ],
  "next": "bc2237802ccbdadfaad689d244dd7078210a2d4f"
}
