Skip to content
CAI
Software that uses CAICheck a score

bytedance/deer-flow

48.0

Weak · 26 September 2026

265k

lines of production code

Python

with TypeScript

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

DeerFlow is an extensible AI agent orchestration platform that manages long-running, multi-step workflows through a modular backend and a React-based web interface. It supports complex agent behaviors via pluggable memory backends, durable subagent batch execution, and a comprehensive tool ecosystem including web search, browser automation, and RAG integrations. The system provides robust enterprise features such as OIDC authentication, fine-grained authorization, and project-scoped workspaces, while allowing third-party extensions to inject custom middleware and capabilities.

Features

Add BoxLite micro-VM sandbox provider

DeerFlow now supports running sandboxes as BoxLite micro-VMs (daemonless, OCI-native VMs with their own kernel) via the optional \deerflow-harness\[boxlite\]\ extra. This provider offers a hardware-isolated alternative to the default Docker sandbox, reducing resource overhead and cold-start latency. Users can enable it by setting \sandbox.use\ to \deerflow.community.boxlite:BoxliteProvider\ in their configuration, with optional tuning for memory, vCPUs, warm-pool replicas, and idle timeouts. Note that this provider requires a Linux host with KVM or a macOS host with Hypervisor.framework.

backend/packages/harness/deerflow/community/boxlite · high confidence

Add Browserless web\_fetch and web\_capture tools with SSRF protection

This change introduces new \web\_fetch\ and \web\_capture\ tools that allow agents to fetch rendered HTML and capture screenshots via a Browserless headless Chrome instance. The implementation includes robust SSRF guards to prevent requests to private or internal IP addresses, ensuring safe operation for self-hosted providers. It also adds configuration support for timeouts, resource rejection patterns, and selector-based waiting, with hardened input coercion to handle invalid or missing config values gracefully.

backend/packages/harness/deerflow/community/browserless · high confidence

Add Chinese documentation for the DeerFlow application

Adds the complete Chinese (zh) documentation set for the DeerFlow application, including the application overview, quick start, deployment guide, configuration, workspace usage, agent and thread management, and operations and troubleshooting. The entry also includes Chinese reference documentation for model provider integration, specifically covering the Volcano Ark (Ark) model service.

frontend/src/content/zh/application · high confidence

Add Crawl4AI web\_fetch provider for self-hosted markdown extraction

Users can now configure a self-hosted Crawl4AI Docker server to fetch web page content as clean markdown. This new provider integrates with the existing web\_fetch tool, allowing users to specify the server's base URL, authentication token, and markdown filter mode (fit, raw, bm25, or llm) via configuration. It includes built-in SSRF protection to prevent fetching from private addresses by default and enforces a 4096-character output limit for the extracted content.

backend/packages/harness/deerflow/community/crawl4ai · high confidence

Add DeerMem scope-isolation benchmark

A new reproducible benchmark has been added to validate DeerMem's long-term memory safety boundaries. It measures two key aspects: semantic model quality (ensuring durable user facts are admitted while rejecting project/thread constraints and temporary instructions) and deterministic identity routing (ensuring writes reach only the correct user/agent bucket). The tool supports offline runs with deterministic fixtures and explicit live runs against configured LLM providers, producing metrics such as durable retention rate, unsafe persistence rate, and cross-agent/user contamination rates.

_backend/scripts/benchmark/deermem\_scope\isolation · high confidence

Add DuckDuckGo web search tool with region and time-range support

Users can now search the web using DuckDuckGo via the new \web\_search\ tool. This feature includes native support for filtering results by recency (time range) and handles Wikipedia region inference based on query language. It also ensures robust configuration handling by coercing \max\_results\ to valid integers and rejecting invalid boolean or fractional values.

_backend/packages/harness/deerflow/community/ddg\search · high confidence

Add E2B cloud sandbox provider for DeerFlow

DeerFlow now supports running agents in isolated cloud sandboxes via the E2B platform. This new provider allows users to configure sandbox instances (including API keys, templates, and idle timeouts) and supports features like file mounts, environment variable injection, and Redis-backed multi-worker ownership and capacity coordination. The implementation includes lifecycle management, resource limits for mount uploads, and safe error handling for remote file operations.

_backend/packages/harness/deerflow/community/e2b\sandbox · high confidence

Add English documentation for DeerFlow App

Adds a new English documentation section for the DeerFlow App, including an overview, quick start, deployment guide, configuration, workspace usage, agents and threads, and operations and troubleshooting pages. This provides users with comprehensive guidance on setting up, configuring, and operating the DeerFlow App.

frontend/src/content/en/application · high confidence

Add English introduction documentation for DeerFlow

Added a new set of English documentation pages under the introduction section, including 'Why DeerFlow', 'Core Concepts', and 'Harness vs App'. These pages explain DeerFlow's architecture as a runtime harness for long-horizon agents, detailing key concepts such as skills, sandboxed execution, subagents, and memory, and clarifying the distinction between the DeerFlow Harness (SDK/runtime) and the DeerFlow App (reference implementation).

frontend/src/content/en/introduction · high confidence

Add English tutorials for DeerFlow usage and deployment

New documentation pages have been added to the English tutorials section, covering the first conversation, creating a programmatic harness, using tools and skills, working with memory, and deploying DeerFlow via Docker Compose. These pages provide step-by-step guides and configuration examples for core user workflows.

frontend/src/content/en/tutorials · high confidence

Add Exa search and web fetch tools

This change introduces two new community tools powered by the Exa SDK: a web search tool that retrieves search results with configurable limits and content length, and a web fetch tool that retrieves the text content of specific URLs. The implementation includes logic to safely coerce configuration values for result limits and character counts into valid integers before passing them to the SDK, ensuring that string-based configuration values do not cause runtime errors.

backend/packages/harness/deerflow/community/exa, backend/packages/harness/deerflow/community/firecrawl, backend/packages/harness/deerflow/community/groundroute · high confidence

Add Lark integration support with credential switching

The frontend now includes a new Lark integration module that enables users to install, configure, and authenticate with Lark (and Feishu) applications. This change introduces the necessary API client functions and React Query hooks to manage the integration lifecycle, including checking status, initiating authorization flows, and completing configuration. A key capability added is the ability to switch Lark app credentials, allowing users to update their app\_id and app\_secret via a dedicated configuration endpoint.

frontend/src/core/integrations · high confidence

Add OpenSandbox community provider for DeerFlow sandboxes

Users can now run DeerFlow sandboxes on the OpenSandbox platform by installing the optional \opensandbox\ SDK (\pip install 'deerflow-harness\[opensandbox\]'\) and configuring the \deerflow.community.opensandbox:OpenSandboxProvider\. This provider implements the full \Sandbox\ and \SandboxProvider\ contracts, supporting command execution, file operations, and search (list\_dir, glob, grep) via the OpenSandbox Python SDK, with configurable timeouts, environment variables, and a warm-pool lifecycle for sandbox reuse.

backend/packages/harness/deerflow/community/opensandbox · high confidence

Add React Query and Next.js theme providers

The frontend now includes dedicated provider components to manage application state and theming. A new QueryClientProvider wraps the app with TanStack React Query for data fetching, while a ThemeProvider integrates next-themes to automatically enforce a dark theme on the root landing page (/) and use the system default elsewhere.

frontend/src/components · high confidence

Add SearXNG web search tool with multi-page result support

Users can now perform web searches via a new SearXNG integration, exposed as the \web\_search\ tool. The implementation handles pagination by walking through result pages to honor \max\_results\ settings that exceed a single page, while also including a fallback to the default result count if the configuration value is unparseable.

backend/packages/harness/deerflow/community/searxng · high confidence

Add Serper web and image search tools

Users can now perform web and image searches using the Serper API. This change introduces two new tools, \web\_search\_tool\ and \image\_search\_tool\, which require a Serper API key configured via the \SERPER\_API\_KEY\ environment variable or in the application config. The implementation includes an SSRF guard to validate URLs and handles malformed responses gracefully.

backend/packages/harness/deerflow/community/brave, backend/packages/harness/deerflow/community/serper · high confidence

Add Serply web search tool

Users can now perform web searches using the Serply API within the Deerflow harness. This new tool supports three verticals—standard search, news, and Google Scholar—allowing research runs to target recent coverage or academic papers by configuring the vertical in config.yaml. An API key is required, which can be provided via the SERPLY\_API\_KEY environment variable or in the tool configuration.

backend/packages/harness/deerflow/community/serply · high confidence

Add Tencent Cloud WSA web search provider

Users can now perform web searches using the Tencent Cloud Web Search API (WSA) as a new community provider. This change introduces a new tool that integrates with the Tencent Cloud WSA endpoint, allowing users to configure the provider via the \TENCENTCLOUD\_WSA\_APIKEY\ environment variable or through tool configuration. The provider supports configurable result limits and result modes, handling API responses and errors gracefully within the existing search framework.

_backend/packages/harness/deerflow/community/tencent\wsa · high confidence

Add Tenki cloud sandbox provider

DeerFlow now supports running sandboxes as isolated microVMs on Tenki cloud, offering a cloud-hosted alternative to the container-based AIO sandbox and the local-virtualization BoxLite backend. This new provider allows users to configure Tenki-specific options such as API keys, base images, CPU/memory limits, and warm-pool settings via the harness configuration. It implements the full Sandbox contract, using Tenki's native filesystem API for file operations and shelling out to standard tools for directory and content search, while managing sandbox lifecycle and warm-pool reuse within the process.

backend/packages/harness/deerflow/community/tenki · high confidence

Add backend .gitignore and test duration tracking

The backend directory now includes a .gitignore file to exclude Python build artifacts, virtual environments, local Claude settings, and the sandbox runtime working directory from version control. Additionally, a .test\_durations file has been added to track pytest execution times, enabling faster test runs by prioritizing or skipping tests based on historical performance data.

backend · high confidence

Add blog post structure and initial content

The blog section now supports a structured layout with post listing and tagging. A new \\_meta.ts\ file defines a 'Weekly' category, and initial content has been added, including a technical post on handling provider safety termination signals in tool-using agents, a release note for DeerFlow 2.0 M1, and the first weekly update.

frontend/src/content/en/posts · high confidence

Add browser notification support with rate limiting and settings integration

Users can now receive browser-based notifications through a new \useNotification\ hook in the core notification module. This feature integrates with local user settings to respect notification enable/disable preferences, checks for browser API support, and implements a 1-second rate limit to prevent notification spam. It also ensures the permission state is kept in sync with the actual browser state when showing notifications.

frontend/src/core/notification · high confidence

Add fastCRW web search and fetch tools with SSRF protection

A new fastCRW provider is introduced for the Deerflow harness, implementing \web\_search\ and \web\_fetch\ tools that utilize the Firecrawl-compatible API. The \web\_fetch\ tool now includes a Server-Side Request Forgery (SSRF) guard by validating URLs against private addresses before fetching, configurable via the \allow\_private\_addresses\ setting. Users can configure the provider using the \CRW\_API\_KEY\ and \CRW\_API\_URL\ environment variables or through tool configuration, defaulting to the managed fastCRW service.

backend/packages/harness/deerflow/community/fastcrw · high confidence

Add internationalization (i18n) support for English and Chinese

The frontend now supports English (en-US) and Chinese (zh-CN) locales. The system detects the user's browser language, persists the selected locale in a cookie, and provides translation dictionaries for both client-side components and server-side rendering. This enables localized content delivery across the application.

frontend/src/core/i18n · high confidence

Add interval scheduling and normalize time handling in scheduler

The scheduler now supports a new 'interval' schedule type, allowing tasks to run repeatedly at fixed second-based intervals in addition to existing 'once' and 'cron' options. Internally, the scheduling logic normalizes all calculated run times to UTC before storage, ensuring consistent execution times regardless of the configured timezone. This change introduces new validation for timezones and cron expressions, and handles naive datetime inputs by assuming they refer to the task's declared timezone.

backend/packages/harness/deerflow/scheduler · high confidence

Add mem0 HTTP memory backend

DeerFlow now supports mem0 as a memory backend, allowing users to store and retrieve agent memories via the mem0 Platform API or a self-hosted server. This backend is fully stateless and safe for multi-worker deployments, with configuration options for API keys, timeouts, injection limits, and failure policies (read/write). It supports both middleware mode (passive memory injection) and tool mode (query-aware search), though fact CRUD operations are not implemented.

backend/packages/harness/deerflow/agents/memory/backends/mem0 · high confidence

New server-side API routes have been added to support serving static demo content for threads. The \/artifacts\ route now proxies file requests for thread artifacts, handling range requests and optional download headers. The \/history\ route fetches and normalizes thread history data from static JSON files, ensuring a consistent array format. The \/search\ route implements paginated and sorted search across all demo threads, allowing clients to filter and order results by creation or update time.

frontend/src/app/mock/api/threads · high confidence

Add opt-in advisory screening for fetched content in DeerFlow extensions

An example extension is added that screens text excerpts from remote tool results (web\_fetch, web\_search, image\_search, web\_capture, and MCP tools) for potential AI-directed instructions. When enabled via configuration, it sends bounded excerpts to a TypeSafe endpoint; if a score meets the threshold, a fixed advisory warning is prepended to the tool result before the model sees it. The feature is opt-in, does not block tool execution, and includes configuration for thresholds, timeouts, and excerpt limits.

examples/deerflow-extension-jev-screening · high confidence

Add persistence layer for personal access tokens

The backend now includes a dedicated persistence module for personal access tokens (PATs), introducing a new database table and ORM model to store token metadata. This change enables programmatic API access by allowing users to create, list, and revoke tokens, with the system storing only the SHA-256 digest of the token for security while tracking scopes, expiration, and usage timestamps.

_backend/packages/harness/deerflow/persistence/personal\_access\tokens · high confidence

Add read-only LightRAG knowledge retrieval tool

DeerFlow now includes a read-only knowledge search tool that queries a LightRAG instance via its /query/data endpoint. The new client, formatting, and tool modules in the lightrag package handle HTTP communication, error handling, and result formatting, allowing agents to retrieve structured chunks and references without generating new content. Users can configure the LightRAG base URL, optional API key, retrieval mode, and result limits through the knowledge\_search tool configuration.

backend/packages/harness/deerflow/community/lightrag · high confidence

Add runtime API route for GitHub star count

A new server-side route at /github-stars has been added to fetch the public star count for the 'bytedance/deer-flow' repository. This endpoint retrieves the data at runtime using the GITHUB\_OAUTH\_TOKEN environment variable, caching the result for one hour via Next.js revalidation, and returns a 204 No Content response if the token is missing or the request fails, allowing the UI to gracefully hide the counter.

frontend/src/app/github-stars · high confidence

Add search time-range filters, URL safety guards, and sandbox warm-pool lifecycle

This update introduces three capabilities to the community harness: native recency filters for web searches (supporting day, week, month, and year ranges via DDGS and Brave providers), SSRF protection for self-hosted fetch services that blocks private, loopback, and cloud metadata addresses, and a warm-pool lifecycle mixin for sandbox providers that manages idle timeouts, replica counts, and background cleanup threads.

backend/packages/harness/deerflow/community · high confidence

Add standalone text classification plugin example (Jev/LLM)

An opt-in Python plugin example is added to the examples directory, providing a \classify\_texts\ tool that labels a list of short texts with user-supplied categories. The plugin supports two backends: Jev (TypeSafe System One) and an OpenAI-compatible chat endpoint, configurable via deployment settings. It registers as a community extension using API 0.2.2, includes a \status\ action for configuration verification, and enforces strict input/output bounds (e.g., max 300 items, 256 KiB payload) and security constraints (credentials from environment variables only).

examples/deerflow-extension-jev-classify · high confidence

Add subagent batch execution and management capabilities

This change introduces the backend service and frontend API layer for unified, durable subagent batch execution. The backend exposes a new \SubagentBatchService\ to handle batch operations, while the frontend adds dedicated API functions and React Query hooks to fetch batch lists and items, control batch states (pause, resume, cancel), and retry individual failed items. Users can now monitor batch progress and manage long-running subagent tasks through these new interfaces.

_backend/app/subagent\batches, frontend/src/core/subagent-batches · high confidence

Add user feedback persistence layer

A new persistence module has been added to store user feedback (thumbs-up/down ratings and optional comments) associated with specific runs and threads. This includes an SQLAlchemy ORM model for the feedback data and an asynchronous repository that handles creating, retrieving, updating, and deleting feedback records, ensuring that users can only access or modify their own feedback entries.

backend/packages/harness/deerflow/persistence/feedback · high confidence

Add workspace change review UI for agent runs

A new badge and side-panel interface has been added to the frontend to allow users to review file changes made during agent runs. The \WorkspaceChangeBadge\ component displays a count of edited files and a summary of additions/deletions, while clicking it opens a \WorkspaceChangePanel\ that lists individual files with their status (created, deleted, modified), line-level diffs, and links to open the files. This feature is specifically triggered by a \runId\, enabling users to inspect the workspace impact of a specific agent execution.

frontend/src/components/workspace/changes · high confidence

Added API routes for memory import and export

New Next.js API routes have been added at \frontend/src/app/api/memory\ and \frontend/src/app/api/memory/\[...path\]\ to proxy memory-related requests to the backend. These routes support GET, POST, DELETE, and PATCH methods, allowing the frontend to import and export memory data by forwarding requests to the backend service (defaulting to port 8001).

frontend/src/app/api · high confidence

Added Blocking-IO Guard skill for async event loop protection

Introduced a new agent skill that provides a standard operating procedure for identifying and fixing blocking I/O operations that could stall the asyncio event loop. The skill includes a static scanning script to detect candidates in changed code or the full repository, along with reference documentation and a test template for creating 'runtime anchors'—tests that verify blocking calls are properly offloaded. This ensures that backend changes in Python modules are accompanied by verified safeguards against event loop blocking.

.agent/skills/blocking-io-guard · high confidence

Added Chinese introduction documentation for DeerFlow

New Chinese-language documentation pages have been added to the frontend content, covering the introduction section. This includes an index page, a guide on why to choose DeerFlow, a breakdown of core concepts (such as Harness, long-horizon agents, skills, sandboxing, and memory), and a comparison between the DeerFlow Harness and the DeerFlow application. These pages provide Chinese users with the foundational understanding of the framework's architecture and capabilities.

frontend/src/content/zh/harness, frontend/src/content/zh/introduction · high confidence

Added Chinese localization for documentation site navigation and overview

Users can now access the documentation in Chinese, starting with the main overview page (index.mdx) which introduces the DeerFlow framework, its Harness runtime, and application layers. The navigation structure (\_meta.ts) has been translated to include sections for Introduction, Harness, Application, Tutorials, Reference, Blog, Posts, Login, and Setup, enabling Chinese-speaking users to browse and understand the product's capabilities and deployment options.

frontend/src/content/zh · high confidence

Added Chinese-language blog content and navigation structure

This change introduces the Chinese localization for the blog section by adding a meta configuration file that defines the 'Weekly' (周报) section title, and includes new documentation posts: a release note for DeerFlow 2.0 RC, a weekly update for April 6, 2026, and a technical article explaining how tool-based agents should handle safety termination signals from model providers.

frontend/src/content/zh/posts · high confidence

Added Chinese-language tutorials for DeerFlow usage and deployment

New documentation pages have been added to the Chinese (zh) tutorial section, covering the first conversation, creating a Harness, using tools and skills, working with memory, and deploying DeerFlow. These pages provide step-by-step guides for users to interact with the agent, configure tools and skills via the UI or config files, enable and understand the memory system, and deploy the application using Docker Compose.

frontend/src/content/zh/tutorials · high confidence

Added demo thread for generating a static Jiangsu football league website

A new demo thread (5aa47db1...) has been added to the frontend public directory, capturing a conversation where the AI generates a complete static website for the 'Jiangsu City Football League 2025 Season'. The output includes a full set of static assets: an HTML entry point with navigation and hero sections, a comprehensive CSS stylesheet with dark mode support and animations, a JavaScript data file containing league standings and team details, and a main script handling UI interactions like theme toggling and scroll spying. This entry demonstrates the system's capability to produce multi-file static site outputs from a single user request.

frontend/public/demo/threads/5aa47db1-d0cb-4eb9-aea5-3dac1b371c5a · high confidence

Attach previous conversations as context in the composer

Users can now attach references to other conversations when composing a message. A new button in the composer opens a picker to select from recent threads, with a configurable limit on how many can be attached. Selected conversations appear as removable chips in the input and as read-only links in the transcript, allowing users to provide additional context to the AI based on prior discussions.

frontend/src/components/workspace/conversation-references, frontend/src/core/conversation-references · high confidence

Clipboard fallback and static website mode support

The application now includes a robust clipboard utility that ensures copy functionality works even in environments where the standard Clipboard API is unavailable or restricted, by falling back to legacy document.execCommand methods and patching the navigator object when necessary. Additionally, a new static website mode has been introduced, allowing the application to detect and operate in a static-only context based on environment configuration.

frontend/src/core · high confidence

Configurable backend and LangGraph base URLs via environment variables

The frontend now supports externalizing the backend and LangGraph service endpoints through the new environment variables NEXT\_PUBLIC\_BACKEND\_BASE\_URL and NEXT\_PUBLIC\_LANGGRAPH\_BASE\_URL. When these variables are set, the application constructs full URLs relative to the base origin, allowing users to connect to remote or custom service instances instead of relying on the default local development paths. If the variables are not provided, the system falls back to constructing URLs based on the current window origin or specific local defaults (such as localhost:2026 for SSR), ensuring compatibility with existing setups while enabling flexible deployment configurations.

frontend/src/core/config · high confidence

Database-backed storage for custom agents and managed subagents

Custom agent definitions and deployment-level managed subagents can now be persisted in a shared SQL database (SQLite or PostgreSQL) instead of the default local file system. This allows agent and subagent configurations to be synchronized across multiple application nodes in a multi-instance deployment. The change introduces new persistence backends (\SqlAgentStore\, \SqlManagedSubagentStore\) alongside the existing file-based ones, with the database backend selected via the \agent\_storage.backend\ configuration setting.

backend/packages/harness/deerflow/persistence/agents · high confidence

Declarative agent factory and structured runtime features

The agent assembly now uses a new \create\_deerflow\_agent\ SDK entry point that accepts plain Python arguments and a \RuntimeFeatures\ dataclass for declarative feature flags (sandbox, memory, summarization, subagent, vision, auto\_title, guardrail, loop\_detection, token\_budget). This factory supports explicit middleware takeover, custom middleware insertion via \@Next\/\@Prev\ decorators, and optional direct subagent runtime injection for isolated capacity boundaries. Thread state management is enhanced with delta-mode checkpoint channels, configurable snapshot frequency, and specialized reducers for artifacts, viewed images, goals, promoted tools, and a capped delegation ledger. Interaction policies now distinguish interactive, autonomous, webhook, and scheduled modes, controlling clarification tool availability and system prompt guidance. Assembly descriptors provide a comparable identity of the assembled agent by hashing model identity, middleware parameters, and tool schemas without copying payloads.

backend/packages/harness/deerflow/agents · high confidence

Declarative capability catalog and bundled business integrations

The system now uses a declarative capability catalog to manage plugins and integrations. A new \builtin.json\ manifest defines bundled business tools for Lark, DingTalk, WeCom, and HubSpot, including their configuration schemas and authentication methods. The \capabilities\ package provides the runtime logic to load this catalog, validate manifests, and execute the bundled business tools via a secure stdio MCP lifecycle that keeps credentials in environment variables rather than tool arguments. This replaces ad-hoc integration handling with a unified, validated discovery and execution model.

backend/packages/harness/deerflow/config · high confidence

DeerFlow Extension API contract package introduced

A new \deerflow\_extension\_api\ package has been added to define the public contracts for DeerFlow extensions, enabling them to be released independently of the host. This API (version 0.2.4) provides the foundational interfaces and data types required for extension development, including mechanisms for observing agent assembly and task lifecycles, accessing run evidence, invoking models, and contributing middleware. It also establishes the plugin contribution model, allowing extensions to register backend actions, model tools, and browser assets, while enforcing authorization and principal resolution through dedicated auth helpers.

backend/packages/extension-api · high confidence

DeerFlow persistence layer migration infrastructure and durable subagent batch storage

The persistence module now includes a full Alembic migration framework to manage schema evolution, featuring a hybrid bootstrap strategy that handles empty, legacy, and versioned databases while serializing concurrent startup via Postgres advisory locks. This infrastructure introduces idempotent column helpers to prevent drift, filters to exclude LangGraph and extension-owned tables from Alembic's view, and support for custom Postgres schemas. Additionally, the system now persists durable subagent batch execution state, including new \subagent\_batches\ and \subagent\_batch\_items\ tables with lease-based claiming, acceptance criteria tracking, and result storage, enabling reliable multi-worker batch processing.

backend/packages/harness/deerflow/persistence/migrations · high confidence

DeerFlow persistence layer: new schema migrations and bootstrap wiring

The application now uses Alembic for database schema management, bootstrapped via \\deerflow.persistence.bootstrap.bootstrap\_schema\\. This introduces a baseline migration (\\0001\_baseline\\) that defines core tables for users, threads, runs, channel connections, and feedback, followed by a series of migrations adding support for scheduled tasks, run ownership and cancellation, MCP durable tasks, managed subagents, and subagent batch execution. These changes enable durable, multi-worker run coordination, cross-pod webhook deduplication, and persistent storage for agent definitions and task states.

backend/packages/harness/deerflow/persistence/migrations/versions · high confidence

DeerMem backend configuration and initialization structure

The DeerMem memory backend now exposes a dedicated configuration module and package structure. A new \\\_\init\\_.py\\ file initializes the \\deermem\\ package, while \\config.py\\ defines the \\DeerMemConfig\\ and \\DeerMemModelConfig\\ Pydantic models. These models parse the \\backend\_config\\ dictionary passed from the host, allowing users to configure storage paths, retrieval adapters (such as FTS5), fact deduplication gates, relevance-aware ranking, eviction policies, and LLM parameters for memory updates. This change establishes the self-contained configuration layer for the DeerMem backend, separating its private settings from the shared \\MemoryConfig\\.

backend/packages/harness/deerflow/agents/memory/backends/deermem/deermem · high confidence

Deferred skill discovery and request-scoped secrets

The skills system now supports deferred discovery, where the agent sees only skill names in the system prompt and uses the new \describe\_skill\ tool to fetch metadata on demand, keeping prompts compact. Additionally, skills can now declare \required-secrets\ in their frontmatter, allowing callers to pass per-request, short-lived credentials via the run context that are injected into the sandbox environment without entering the prompt, traces, or persisted records.

backend/packages/harness/deerflow/skills · high confidence

First-class Helm chart for DeerFlow Kubernetes deployment

DeerFlow can now be deployed to Kubernetes using a dedicated Helm chart. The chart provisions the full application stack, including the gateway, frontend, nginx ingress, provisioner, and optional bundled PostgreSQL and Redis services. It handles configuration via ConfigMaps, manages secrets for database and provider credentials, and enforces security best practices by running all pods as non-root with dropped capabilities. The deployment supports both in-cluster and external database/Redis backends, configurable ingress with TLS, and persistent storage for user data and sandbox environments.

deploy/helm/deer-flow/templates · high confidence

Frontend skills management and slash-command integration

The frontend now includes a dedicated skills module that enables users to install, enable, and export custom skills. This change introduces API clients for loading the skill catalog, toggling skill states, uploading skill archives, and exporting custom skill packages as version-bound ZIP files. It also adds React Query hooks to manage these operations and a slash-command parser that reserves specific command names (like /context and /agent) while allowing activation of enabled custom skills via /skill-name syntax. Additionally, the system captures and displays skill usage evidence within conversation history, showing which skills were automatically or manually triggered during assistant responses.

frontend/src/core/skills · high confidence

Frontend support for extracting and displaying verifiable RAGFlow source citations

The frontend now includes logic to parse markdown content and extract verifiable source citations (e.g., \\citation: ...\\). This change adds a new module in \frontend/src/core/citations/sources.ts\ that identifies citation links, normalizes their URLs and titles, and aggregates them into a list of unique sources with occurrence counts. It also includes utilities to mask code blocks to prevent false-positive citation extraction, enabling the UI to display a dedicated evidence panel showing the original sources used to generate the response.

frontend/src/core/citations · high confidence

Gateway API documentation and core application structure introduced

The backend gateway now includes a comprehensive AGENTS.md specification detailing the API surface, including new endpoints for managed models, knowledge retrieval, console observability, MCP configuration, skills, subagents, and GitHub integrations, alongside security hardening for artifacts and uploads. The application module structure is established with lazy initialization in \_\init\\_.py and a new app.py entry point that wires up middleware (CORS, CSRF, Auth, Trace), routers, and startup/shutdown lifecycle hooks, including a first-boot setup flow and orphan thread migration for users upgrading from unauthenticated modes.

backend/app/gateway · high confidence

Initial frontend project scaffolding and configuration

The frontend directory has been initialized with a complete Next.js 16 project structure, including environment variable templates, build configurations, and development tooling. This establishes the foundation for the web interface, featuring a Dockerfile for containerized builds, a Makefile for standard operations, and ESLint/Prettier configurations to enforce code quality. The setup also includes Playwright E2E test configurations for both mocked and real-backend scenarios, as well as Rstest for unit testing, ensuring the application is ready for development and testing workflows.

frontend · high confidence

Initial i18n infrastructure and English/Chinese locale files

The frontend now includes a new internationalization structure under \frontend/src/core/i18n/locales\, introducing \en-US.ts\ and \zh-CN.ts\ alongside a shared \types.ts\ definition. This adds the foundational translation keys for the UI, covering common actions (e.g., export, settings), the new Capability Center (plugins, skills, integrations), and extension management states. While the commit history references many features, this specific change establishes the localization scaffolding and initial English/Chinese content required to support those features.

frontend/src/core/i18n/locales · high confidence

Initial landing page and root layout for the web app

The frontend now includes a root layout (\layout.tsx\) that sets up the global theme provider and metadata, and a landing page (\page.tsx\) that serves as the default entry point. This page assembles a full-screen dark-themed interface composed of a header, hero section, case study, skills, sandbox, what's new, community sections, and a footer, establishing the basic structure for the web application.

frontend/src/app · high confidence

Introduce AIO Sandbox community implementation

Adds the \aio\_sandbox\ module to the harness, providing a new sandbox backend that connects to the all-in-one-sandbox Docker container via HTTP. This includes the \AioSandbox\ client for executing commands, an \AioSandboxProvider\ for managing the sandbox lifecycle (including local Docker and remote/K8s backends), and a network proxy sidecar for enforcing egress policies. The implementation supports both local container provisioning and remote provisioner integration, enabling users to run agent skills in isolated sandbox environments.

_backend/packages/harness/deerflow/community/aio\sandbox · high confidence

Introduce DeerFlow terminal workbench (TUI)

Adds a new terminal-native UI for DeerFlow, exposed as the \deerflow\ console script. The TUI provides an interactive transcript with slash-command support (including a built-in command registry and skill activation), model and thread selection modals, and transparent terminal background support. It runs agent sessions via \DeerFlowClient\ on a worker thread and includes a persistence layer that writes thread metadata to the shared database so TUI sessions appear in the Web UI sidebar. The implementation includes pure view-state reduction, Rich-based rendering, and a CJK cursor fix for the composer input.

backend/packages/harness/deerflow/tui · high confidence

Introduce GitHub as a webhook-driven channel for custom agents

This change adds a new webhook-driven channel for GitHub, enabling custom agents to react to repository events such as pull requests, issues, and reviews. The implementation includes a dispatcher that fans out verified webhook deliveries to the appropriate agent based on configuration, handling authentication via GitHub App installation tokens and ensuring deterministic thread IDs for consistent conversation history. It also introduces logic to filter out redundant review-comment webhooks, prevent self-triggering loops by the bot itself, and manage concurrency with a per-installation token cache and busy-run buffering to ensure reliable processing of GitHub events.

backend/app/gateway/github · high confidence

Introduce Honcho memory backend for user-model memory

DeerFlow now supports the Honcho backend as a user-model memory provider, enabling long-term user modeling, preferences, and cross-session working representations via a self-hosted or hosted Honcho v3 instance. This backend operates without local LLM calls, using plain HTTP message writes for ingestion, and supports both middleware and tool modes for recall. It enforces strict multi-user isolation through workspace scoping and collision-resistant ID derivation, ensuring users cannot see each other's memory by default. Configuration includes options for timeout, character limits, and failure policies (fail-open or fail-closed), with validation at startup to reject invalid URLs or insecure API key configurations.

backend/packages/harness/deerflow/agents/memory/backends/honcho · high confidence

Introduce IM Channels system with Buzz (Nostr) connector

Adds a new pluggable IM Channels system that bridges external messaging platforms (Feishu, Slack, Telegram, Discord, DingTalk, GitHub, and now Buzz/Nostr) to the DeerFlow agent via Gateway's LangGraph-compatible API. This location introduces the core channel infrastructure—including the message bus, channel manager, and abstract base class—along with the new Buzz connector implementation. The Buzz integration connects to a Nostr relay using NIP-42 authentication, implements channel-scoped subscriptions for chat and membership events, and enforces strict security by verifying NIP-01 signatures on all inbound events and blocking outbound messages that contain hidden model context markers.

backend/app/channels · high confidence

Introduce InfoQuest-based web search, fetch, and image search tools

The InfoQuest harness now provides three new LangChain tools—web\_search, web\_fetch, and image\_search—that replace previous implementations with the BytePlus InfoQuest API. The web\_search tool queries the InfoQuest search endpoint, while web\_fetch retrieves and extracts readable content from specific URLs using the InfoQuest reader service, applying configurable timeouts for connection, fetch, and navigation. A new image\_search tool allows agents to find reference images online before generating visual content. All tools are configured via existing app config sections (web\_search, web\_fetch, image\_search) and require an INFOQUEST\_API\_KEY environment variable for authentication.

backend/packages/harness/deerflow/community/infoquest · high confidence

Introduce Kubernetes Sandbox Provisioner service

Adds a new FastAPI-based Sandbox Provisioner service (docker/provisioner) that dynamically creates, monitors, and destroys isolated sandbox Pods in a Kubernetes cluster. The service exposes a REST API for the backend to manage sandbox lifecycles, supporting both NodePort and ClusterIP service types for sandbox access, configurable container ports, and optional PVC mounts for skills and user data. It also includes support for Lark CLI integration via init containers and sidecar credential brokers, and enforces API key authentication for its endpoints.

docker/provisioner · high confidence

Introduce Lark CLI integration with secure credential broker

Added the first-party Lark CLI integration, which installs official Lark AI-agent skills and manages the CLI binary. To enhance security, a new credential broker (Pattern B) was implemented to run the CLI in a sidecar, ensuring raw credential files never exist in the sandbox filesystem. The integration includes platform-aware runtime validation, private ACL enforcement for credentials on Windows, and logic to preserve app secrets during credential switches.

backend/packages/harness/deerflow/integrations · high confidence

Introduce MCP background task management and dev-server origin configuration

The frontend now supports managing Model Context Protocol (MCP) background tasks directly from the chat interface, allowing users to monitor, cancel, and view results for long-running server operations. This includes new API hooks and types for fetching task lists and details, with automatic polling that adapts to task status. Additionally, the application now allows configuring allowed origins for the Next.js development server via the \DEER\_FLOW\_DEV\_ALLOWED\_ORIGINS\ environment variable, enabling proper hydration when accessing the dev stack from LAN addresses or proxied hostnames. The frontend also exposes the application version on the About page and validates client-side environment variables using Zod schemas.

frontend/src · high confidence

Introduce MCP server configuration management in the frontend

The frontend now includes a dedicated module for managing Model Context Protocol (MCP) server settings. This change adds the core API layer, React Query hooks, and type definitions required to load, create, update, and delete MCP server configurations via the backend. It also introduces utilities for parsing and validating server definition snippets (including copy-paste support) and handling plugin icons, enabling users to configure and toggle MCP servers directly from the application settings.

frontend/src/core/mcp · high confidence

Introduce Next.js App Router layout and page for chat threads

The chat thread view is now structured using the Next.js App Router, with a new layout file that wraps the chat interface in ChatProviders and a page file that renders the ChatPage component. In static website mode, the layout generates static paths for all demo thread IDs to ensure proper routing for pre-rendered content.

_frontend/src/app/workspace/chats/\[thread\id\] · high confidence

Introduce OpenViking memory backend with official LangChain integration

DeerFlow now supports OpenViking as a memory backend, using the official LangChain adapter for transport, batching, and retrieval. The backend enforces strict configuration validation, including mandatory user API keys, secure URL schemes, and defined failure policies for reads and writes. It provides stable session identity and message capture tracking to ensure reliable memory injection and retrieval for agents.

backend/packages/harness/deerflow/agents/memory/backends/openviking · high confidence

Introduce Projects with document management and thread integration

This change introduces the Projects feature, providing a dedicated workspace for organizing conversations and files. Users can now create and manage projects, which include a 'Document Shelf' for uploading and organizing files, and a 'Conversation Files' view that groups files by their source threads. The implementation includes a cross-route handoff mechanism that allows users to attach project documents directly to chat threads, persisting the attachment state across navigation. Projects support active and archived states, with specific UI handling for archived projects that restricts mutation actions while preserving read access.

frontend/src/components/workspace/projects, frontend/src/core/projects · high confidence

Introduce RAGFlow knowledge scope management and verifiable source citations

The frontend now supports selecting specific knowledge bases and documents for agent retrieval via a new scope system (defined in \scope.ts\ and exposed via \scope-api.ts\), allowing users to restrict RAG queries to a curated subset of data. Additionally, the system integrates with RAGFlow to provide verifiable source citations, extracting and displaying provenance details such as document names, dataset names, and page numbers directly from tool artifacts in the conversation history.

frontend/src/core/knowledge · high confidence

Introduce SQL-backed persistence for run metadata

The run persistence layer now uses a SQLAlchemy-backed repository (SQLite or PostgreSQL) to store run metadata, replacing the previous in-memory or ad-hoc storage. This change introduces a dedicated \runs\ table with columns for run status, thread/assistant/user associations, model usage, token counts, and multi-worker lease ownership, ensuring that run state is durable across restarts and consistent across distributed workers.

backend/packages/harness/deerflow/persistence/run · high confidence

Introduce Stream Bridge for decoupled SSE streaming

Added a new stream bridge package that decouples agent workers from SSE endpoints, providing an abstract protocol and default in-memory implementation backed by asyncio.Queue. This enables reliable event streaming with support for Last-Event-ID reconnection, heartbeat intervals, and gap detection. The implementation includes an async provider for lifecycle management and optional Redis-backed streaming for cross-process scenarios.

_backend/packages/harness/deerflow/runtime/stream\bridge · high confidence

Introduce abstract RunStore interface and in-memory implementation

The runs store module now exposes a formal abstract interface (RunStore) for run metadata storage, alongside a concrete in-memory implementation (MemoryRunStore) used for development and testing. This change introduces support for tracking model names, stop reasons, and lease-based ownership (including renewal and cancellation actions) within run records, and adds efficient per-thread indexing to avoid full scans when listing run history.

backend/packages/harness/deerflow/runtime/runs/store · high confidence

Introduce agentic browser automation tools

Added a new set of agentic browser tools (navigate, click, type, screenshot, snapshot, etc.) that maintain a stateful, per-thread browser session backed by Playwright. This enables agents to perform multi-step interactions on JavaScript-heavy or authenticated pages, with actions guided by stable element references in page snapshots rather than fragile CSS selectors. The implementation includes a session manager with capacity limits and idle timeouts, loop-affine execution to handle async event loop constraints, and SSRF protection for all navigated URLs.

_backend/packages/harness/deerflow/community/browser\automation · high confidence

Introduce agentic browser view with live interactive screencast

Adds a new browser-view component area that enables interactive control of a remote browser session. Users can now open a panel to view a live, binary JPEG screencast of a webpage, navigate to URLs, and send mouse and keyboard inputs directly to the remote page via a WebSocket stream. The implementation includes a context provider to manage the panel's open/close state and frame history, a trigger button to toggle visibility, and logic to handle reconnections by seeding the stream with the last known URL to avoid blank screens.

frontend/src/components/workspace/browser-view · high confidence

Introduce built-in general-purpose and bash subagents with sandbox-aware configurations

Deerflow now includes two built-in subagent configurations—general-purpose and bash—registered in the harness. The general-purpose subagent is configured with a 150-turn limit and a system prompt that prohibits the \task\ tool to prevent nesting, while also providing specific guidance on file editing workflows (preferring \str\_replace\ and chunked \write\_file\ calls) to mitigate streaming timeouts on long reports. The bash subagent is limited to sandbox tools (bash, ls, read\_file, write\_file, str\_replace), disallows the \task\ tool, and includes explicit instructions to use workspace-relative paths and respect sandbox mount points (e.g., \/mnt/user-data/workspace\).

backend/packages/harness/deerflow/subagents/builtins · high confidence

Introduce built-in tool package with durable subagent batching and background task management

DeerFlow now exposes a new \builtins\ tool package that consolidates core agent capabilities into a structured module. This update introduces explicit durable batch execution for independent subagent items, allowing users to submit and monitor large sets of tasks with acceptance criteria and concurrency controls. It also adds tools for managing background tasks, including listing and cancelling long-running operations. Additionally, the package includes updated tools for agent setup and review, structured clarification forms for user interaction, and improved file presentation and upload discovery, all organized under a unified \\_\init\\_\ entry point.

backend/packages/harness/deerflow/tools/builtins · high confidence

Introduce core file upload infrastructure with validation and error handling

This change adds the foundational module for file uploads in the frontend, introducing API functions to upload, list, and delete files within a thread, along with React Query hooks to manage this state. It includes client-side validation logic that enforces gateway-defined limits (max file size, max file count, and total size) and specifically blocks unsupported macOS .app bundles. Additionally, it implements robust error handling that parses structured API error details for user-facing feedback and ensures uploaded filenames are correctly encoded during deletion requests.

frontend/src/core/uploads · high confidence

Introduce cross-instance ownership leases for shared sandbox containers

Added a new ownership subsystem (\backend/packages/harness/deerflow/community/aio\_sandbox/ownership\) that manages lease-based ownership of shared sandbox containers across multiple gateway instances. This prevents one instance from accidentally adopting and destroying a container actively used by a peer (fixing issue \#4206). The system supports both in-memory (single-instance) and Redis-backed (multi-instance) stores, with the latter using Lua scripts for atomic lease operations and two-state tracking (\own\/\del\) to safely handle teardown windows. It also includes logic to reject overflowing lease TTLs and enforce deployment-wide capacity limits.

_backend/packages/harness/deerflow/community/aio\sandbox/ownership · high confidence

Introduce dedicated /chats page with pagination, search, and archive management

The new frontend/src/app/workspace/chats/page.tsx component provides a centralized interface for managing chat threads. It supports infinite scrolling with an intersection-observer-based sentinel for active chats, while search mode disables auto-pagination to prevent excessive backend requests, requiring explicit user action to load older results. Users can now filter chats by title, view active versus archived threads via tabs, and restore archived chats directly from the list. The page also includes dynamic i18n titles and handles error states with retry options.

frontend/src/app/workspace/chats · high confidence

Introduce dedicated chat layout and page components for custom agent threads

This change establishes the frontend structure for individual chat threads within custom agents by adding a new layout component that wraps the chat interface with necessary providers, and a new page component that renders the full chat experience. The page component integrates core chat functionalities including message streaming, token usage indicators, knowledge scope selection, and thread management, effectively creating the dedicated UI for interacting with a specific agent's conversation history.

_frontend/src/app/workspace/agents/\[agent\name\] · high confidence

Introduce deterministic skill review gate with CLI and reporting

This change adds a new skill review subsystem under \backend/packages/harness/deerflow/skills/review\ that provides a deterministic, static analysis gate for skill packages. It introduces a CLI entry point (\cli.py\) to analyze local directories or \.skill\ archives, producing structured review facts (via \analyzer.py\) that check for structural validity (e.g., required \SKILL.md\, frontmatter fields), security/safety issues (symlinks, nested archives, hidden files, path escapes), and resource integrity (broken links, orphans). The system also parses eval manifests (\eval\_schema.py\) to count test cases and renders localized Markdown reports (\renderer.py\) indicating readiness (blocked/revise/publish candidate). This location specifically provides the core analysis logic, data models, readers, and report rendering; it does not include the orchestration or integration layers that invoke this gate.

backend/packages/harness/deerflow/skills/review · high confidence

Introduce durable MCP task service for long-running operations

Added a new \McpTaskService\ in the \backend/app/mcp\_tasks\ module to persist and poll long-running MCP tasks outside the main agent loop. This service manages task lifecycles, including submission, polling, and cancellation handling, and exposes a \PermanentNotificationError\ for unrecoverable notification failures. It relies on the \McpTaskDriverRegistry\ and integrates with the existing persistence and runtime cancellation systems to ensure reliable task execution.

_backend/app/mcp\tasks · high confidence

Introduce durable persistence for MCP tasks with thread-incarnation scoping

A new persistence layer for MCP tasks has been added, introducing a dedicated database table and repository to manage the lifecycle of long-running tasks. This change enables durable storage of task state, including results, errors, and notification status, while enforcing strict scoping by thread incarnation to ensure that task operations are correctly associated with the active version of a conversation thread. The implementation includes mechanisms for claim-based locking, polling, and cancellation safety, providing a reliable foundation for task execution and status tracking.

_backend/packages/harness/deerflow/persistence/mcp\tasks · high confidence

Introduce durable, long-running MCP task execution with validation and session scoping

DeerFlow now supports long-running MCP tasks that persist beyond the initial agent run, allowing users to submit work and poll for status asynchronously. This change introduces a protocol-neutral task model (defining statuses like submitted, working, input\_required, completed, failed, and cancelled) and an 'ordinary' driver that maps standard MCP tool contracts to this lifecycle. To ensure reliability, the system validates task inputs (rejecting non-finite poll intervals) and enforces strict configuration rules: durable tasks require a SQL database backend and explicit enabling via \mcp\_tasks.enabled=true\. Additionally, task access and sessions are now scoped by thread incarnation to prevent cross-session interference, and request-scoped secrets are correctly mapped to HTTP/SSE headers during submission.

backend/packages/harness/deerflow/mcp/tasks · high confidence

Introduce local sandbox provider with thread-scoped path mappings and bounded execution

The local sandbox implementation now provides a provider that creates per-thread sandbox instances, mapping virtual paths like /mnt/user-data and /mnt/acp-workspace to thread-specific host directories to enforce isolation. It includes a bounded pipe capture mechanism to limit subprocess output memory usage, enforces a default 600-second timeout on bash commands to prevent hanging turns, and resolves Windows path issues by normalizing backslashes and handling MSYS path conversions. The provider also manages skill mounts with read-only public skills and per-user custom skills, while preventing symlink escapes and ensuring proper file permissions for uploaded content.

backend/packages/harness/deerflow/sandbox/local · high confidence

Introduce managed subagent configuration and management API

This change adds the frontend infrastructure for managing user-defined subagents. It introduces a new API layer (\api.ts\) to create, update, list, and delete managed subagents via backend endpoints, along with React Query hooks (\hooks.ts\) to handle data fetching and mutations. The \types.ts\ file defines the data structures for subagents, including properties like name, model, tools, and source type, enabling users to configure and control specific subagent behaviors.

frontend/src/core/subagents · high confidence

Introduce modular lead agent assembly with configurable middleware and delegation controls

The lead agent logic is now structured into a dedicated module (lead\_agent) that exposes a factory function to build the agent graph. This change introduces explicit support for configuring lead agent middlewares, enforcing subagent delegation limits (concurrency and total count), and applying tool authorization policies. It also implements a background-cached skill loading mechanism to improve prompt generation performance and ensures tracing callbacks are correctly attached at the graph root to prevent duplicate spans in observability tools.

_backend/packages/harness/deerflow/agents/lead\agent · high confidence

Introduce new Agents workspace UI with per-agent configuration and capability selection

The Agents workspace now features a dedicated gallery view for browsing and managing custom agents, including a new settings dialog that allows users to configure per-agent model selection, temperature, max tokens, thinking/reasoning effort, and knowledge scopes. Users can also select specific MCP plugins and skills for each agent via a new capability selection component, and agent cards now intelligently truncate long labels with tooltips to prevent layout overflow.

frontend/src/components/workspace/agents · high confidence

Introduce new chat workspace UI components and state management

This change introduces the core frontend components for the chat workspace, including \ChatPage\, \ChatBox\, and \ChatProviders\, along with hooks for managing thread state (\useThreadChat\) and specific chat modes (\useSpecificChatMode\). The new \ChatBox\ component implements a resizable panel layout that dynamically switches between sidecar, artifacts, browser, and message details views, while \ChatPage\ handles thread lifecycle, knowledge scope selection, and permission-based UI gating. The \useThreadChat\ hook manages thread identity, new-chat state, and project scoping, ensuring stable thread IDs during navigation and preventing stale history requests.

frontend/src/components/workspace/chats · high confidence

Introduce new run lifecycle management and execution runtime

The \backend/packages/harness/deerflow/runtime/runs\ directory now contains the core implementation for managing agent run lifecycles. This includes a \RunManager\ for handling run registration, persistence, and lease-based ownership, schemas defining run statuses and disconnect modes, and a \worker\ module that executes agent graphs asynchronously. The new code also introduces stream cleanup logic to ensure proper resource teardown and naming helpers for tracing, effectively replacing or refactoring the previous run handling logic in this location.

backend/packages/harness/deerflow/runtime/runs · high confidence

Introduce pre-execution tool authorization and risk gating

DeerFlow now intercepts tool calls before they execute, evaluating them against a pluggable authorization provider. A built-in allowlist provider enforces explicit allow/deny lists, with a critical fix ensuring that an empty allowlist correctly denies all tools rather than failing open. Additionally, a TypeSafe (Jev) provider is available to gate calls based on a risk probability threshold, preventing potentially irreversible or out-of-scope side effects. All authorization decisions are persisted as run events for auditability.

backend/packages/harness/deerflow/guardrails · high confidence

Introduce project workspaces with scoped chats, document shelves, and instructions

Users can now organize their work into projects, which act as scoped containers for chats and documents. The backend provides persistence for project metadata (name, instructions, status) and a recoverable document shelf with trash/recovery capabilities, while the frontend exposes a dedicated workspace page with tabs for threads, documents, instructions, and settings. This enables users to group related conversations and reference uploaded files within a specific project context.

backend/packages/harness/deerflow/persistence/projects, frontend/src/app/workspace/projects · high confidence

Introduce scheduled task persistence layer

Added the initial database schema and repository for scheduled tasks, including the \ScheduledTaskRow\ model and \ScheduledTaskRepository\ implementation. This enables storing task metadata (such as schedule specifications, timezones, and status) and managing task lifecycle operations like creation, retrieval, and pausing with queue cancellation.

_backend/packages/harness/deerflow/persistence/scheduled\tasks · high confidence

Introduce scheduled task run persistence and concurrency controls

Adds the \ScheduledTaskRunRepository\ and associated database model (\scheduled\_task\_runs\ table) to persist and manage the lifecycle of scheduled task executions. This includes enforcing concurrency limits via a unique index on active runs (queued, launching, running) to prevent duplicate dispatches, handling lease-based claims for multi-instance safety, and tracking run history with occurrence sequencing and launch accounting. The implementation supports both SQLite and PostgreSQL, with specific logic to serialize access and reconcile task states upon run completion.

_backend/packages/harness/deerflow/persistence/scheduled\_task\runs · high confidence

Introduce scheduled task service with concurrency controls and recovery logic

Adds a new ScheduledTaskService in the backend scheduler module to manage the lifecycle of scheduled tasks. The service enforces a global concurrent-run budget for manual triggers, handles busy scheduled task runs by queuing them, and supports safe multi-instance recovery to resolve duplicate dispatch races. It also includes logic to reconcile stuck once-only tasks from committed run outcomes and retains launched runs even if post-launch bookkeeping fails, ensuring robust state management for scheduled executions.

backend/app/scheduler · high confidence

Introduce scheduled tasks management interface

Users can now create, edit, and manage scheduled tasks directly from the workspace. The new page allows configuring task titles, prompts, and schedules (including cron and interval types), selecting specific agents to run the tasks, and filtering or searching through existing tasks. It also provides visibility into task status and run history.

frontend/src/app/workspace/scheduled-tasks · high confidence

Introduce scheduled tasks with interval scheduling and run history

The frontend now includes the core infrastructure for scheduled tasks, adding support for a new 'interval' schedule type alongside existing 'once' and 'cron' options. This update introduces a paginated run history view to track task execution status and errors, as well as a search feature to filter tasks by title and prompt. The implementation provides the necessary API clients, React Query hooks, and type definitions to manage task creation, updates, and lifecycle.

frontend/src/core/scheduled-tasks · high confidence

Introduce sidecar panel for quoted follow-ups and text selection

This change adds a new sidecar panel component to the workspace, enabling users to initiate threaded conversations based on quoted text or selected fragments from the main chat. The implementation includes a context provider to manage sidecar state (such as active references and thread IDs), a trigger button to open/close the panel, and a panel UI that supports sending messages with attached context. It also introduces a reference attachment summary component to display and clear selected text fragments, effectively adding a new interaction mode for follow-up discussions within the workspace.

frontend/src/components/workspace/sidecar · high confidence

Introduce structured memory management with import, export, and fact editing

The frontend now includes a dedicated memory subsystem that allows users to import and export their memory data, as well as manually add, edit, and delete individual memory facts. This change introduces a new \UserMemory\ data model that structures memory into user context (including work, personal, top-of-mind, and cognitive style) and history sections, alongside a list of facts with confidence scores. The implementation provides React Query hooks for loading, clearing, and mutating memory state, along with robust normalization logic to handle legacy or malformed import payloads gracefully.

frontend/src/core/memory · high confidence

Introduce unified run event store with memory, database, and JSONL backends

A new event store module has been added to the runtime to centralize run event persistence. It provides a unified \\RunEventStore\\ interface with three concrete implementations: an in-memory store for development and testing, a SQLAlchemy-backed database store for production use, and a JSONL file-based store for local debugging. The module includes a factory function that selects the backend based on configuration, ensuring that event streams for runs and threads are consistently stored and retrieved across the application.

backend/packages/harness/deerflow/runtime/events/store · high confidence

Introduce unified store persistence layer with async and sync providers

DeerFlow now provides a dedicated store persistence layer that supports memory, SQLite, and PostgreSQL backends. The new \runtime/store\ package exposes an async factory (\make\_store\) for long-running servers and a sync singleton/context manager (\get\_store\, \store\_context\) for CLI tools and embedded clients. The store respects the unified \database\ configuration section (falling back to the legacy \checkpointer\ section if present) and ensures PostgreSQL schemas are created before table setup. SQLite paths are automatically resolved and parent directories are created, while missing backend packages raise clear installation hints.

backend/packages/harness/deerflow/runtime/store · high confidence

Introduce unified thread metadata persistence with SQL and memory backends

The thread metadata persistence layer has been replaced with a new unified implementation that supports both SQL (SQLite/PostgreSQL via SQLAlchemy) and in-memory (LangGraph BaseStore) backends. This change introduces a structured ORM model for thread metadata, including fields for project association, pinning, and archiving, and enforces strict ownership checks and atomic operations for thread creation and updates. Users benefit from consistent thread metadata handling across environments, with the SQL backend providing robust transactional integrity and the memory backend offering a lightweight fallback for development or testing.

_backend/packages/harness/deerflow/persistence/thread\meta · high confidence

Introduce workspace change review for agent runs

Adds a new capability to fetch and display workspace changes resulting from agent runs. This includes a new API client to retrieve change summaries and file-level details (including diffs, symlink status, and binary/sensitive flags), React Query hooks for data fetching, and utility functions to classify diff lines and sort changes by status (created, modified, deleted, or symlink\_created).

frontend/src/core/workspace-changes · high confidence

Introduce workspace change tracking and review for agent runs

A new \workspace\_changes\ module has been added to the backend to capture and report file-level changes within agent sandbox workspaces. This feature enables a review interface by scanning workspace and output roots, comparing file snapshots to detect created, modified, deleted, or symlinked files, and generating unified diffs. The implementation includes an API endpoint to retrieve these changes, configurable limits on scanned files and diff sizes, and specific exclusions for internal temporary files, browser frames, and externalized tool outputs to ensure only relevant user deliverables are tracked.

_backend/packages/harness/deerflow/workspace\changes · high confidence

Introduces opt-in task notes and compacted history recall for agent continuity

DeerFlow now supports opt-in task notes and compacted history recall, allowing agents to maintain context across long conversations by storing and retrieving historical data. This feature includes a new \task\_continuity\ module with tools like \history\_search\, \history\_read\, and \task\_note\, enabling agents to save working notes and search through compacted history. The implementation uses a local SQLite archive for efficient storage and retrieval, ensuring that only relevant text and tool-call arguments are preserved. This enhancement improves the agent's ability to handle complex, multi-turn tasks by providing a mechanism to recall and reference past interactions without overwhelming the current context window.

backend/packages/harness/deerflow · high confidence

Introduction of DeerMem as the default self-contained memory backend

The system now includes a new, self-contained memory backend named DeerMem, which serves as the default implementation for the pluggable MemoryManager interface. This backend encapsulates the core memory machinery—including storage, queue management, fact updating, prompt formatting, and message processing—within the \deermem\ package. It provides file-backed fact storage with debounced LLM extraction, supports tool-mode retrieval via case-insensitive substring search, and handles configuration through a dedicated \DeerMemConfig\ class. This change establishes the foundational architecture for backend onboarding while maintaining existing memory behaviors such as filter validation, correction detection, and injection formatting.

backend/packages/harness/deerflow/agents/memory/backends/deermem · high confidence

Introduction of global CSS theme and animation definitions

The frontend now includes a centralized \globals.css\ file that establishes the core visual design system. This file imports Tailwind CSS and defines custom CSS variables for the theme (including dark mode support via \@custom-variant dark\) and a suite of keyframe animations such as \fade-in\, \loading-bar\, \skeleton-entrance\, and \suggestion-in\. It also sets up specific styling rules for content elements like streaming list markers and configures inline source patterns to ensure Tailwind generates utility classes for text, spacing, and color variants used throughout the application.

frontend/src/styles · high confidence

MCP integration foundation and runtime configuration

This change introduces the core Model Context Protocol (MCP) integration layer for the DeerFlow harness, establishing the runtime boundary for tool discovery, caching, and server configuration. It provides the \MultiServerMCPClient\ management via \langchain-mcp-adapters\, implementing a robust cache invalidation strategy that tracks config file path, size, and SHA-256 content signatures to detect changes even when modification times are unreliable. The module adds support for stdio, SSE, and HTTP transports, including secure credential injection through OAuth, per-user authentication, and per-request context headers, with strict validation to prevent illegal header values from leaking into model-visible errors. It also defines the configuration normalization rules and client parameter builders that ensure consistent server setup and secure header handling across the MCP ecosystem.

backend/packages/harness/deerflow/mcp · high confidence

Native deterministic security scanner for DeerFlow skills

DeerFlow now includes a built-in static security scanner (SkillScan) that analyzes skill packages before installation. The scanner enforces strict policies on archive structure (blocking absolute paths, NTFS alternate data stream smuggling via colons, and oversized files) and inspects code for dangerous patterns such as shell execution, dynamic imports, hardcoded secrets, and sensitive data exfiltration. Skills containing critical-severity findings are blocked from installation, while other issues are logged as warnings.

backend/packages/harness/deerflow/skills/skillscan · high confidence

New AI UI component library for chat and workflow visualization

A new set of React components has been added to the frontend to support AI-driven chat interfaces and visual workflow builders. This includes a comprehensive chat system with message branching, context usage indicators, and code block rendering, as well as a node-based canvas for visualizing AI plans and chains of thought. These components provide the building blocks for richer, more interactive AI conversations and structured task planning.

frontend/src/components/ai-elements · high confidence

New Checkpoints documentation manual added

A comprehensive ten-chapter manual on checkpoint storage and management has been added to the documentation site in both English and Chinese. The new content covers core concepts such as Channel Modes (full vs. delta), Snapshot Cadence configuration, the History Cache implementation, and operational guidance for retention and troubleshooting.

frontend/src/content/en/harness/checkpoints, frontend/src/content/zh/harness/checkpoints · high confidence

New DeerFlow extension example demonstrating all five contribution types

A new standalone Python package at examples/deerflow-extension-example demonstrates how to build DeerFlow extensions by implementing all five contribution kinds: middleware (counting tool calls), task lifecycle hooks (scoping stats per task), system-model observation (tracking model calls and failures), service binding (accessing runtime dependencies), and router registration (exposing a /api/extension-example/stats endpoint). The example includes comprehensive tests verifying registration, disabled-state behavior, and runtime stats aggregation, and provides clear instructions for installing, enabling, and managing the extension via the DeerFlow extension manager.

examples/deerflow-extension-example · high confidence

New DeerFlow smoke-test skill for end-to-end deployment verification

A new agent skill has been added to guide users through a full end-to-end smoke test of the DeerFlow deployment. The skill supports both local and Docker deployment modes, automatically selecting the best option based on user preference or network conditions. It orchestrates a six-phase workflow: pulling the latest code, checking environment dependencies (Node.js 22+, pnpm, uv, nginx for local; Docker and Compose for Docker), preparing configuration files, executing the deployment, and performing health checks on the frontend, API Gateway, and LangGraph-compatible API. A key feature is the \frontend\_check.sh\ script, which automatically detects if authentication is enabled and logs in a smoke-test user to verify protected routes rather than just the login page. The skill concludes by generating a structured test report using mode-specific templates.

.agent/skills/smoke-test · high confidence

New Docker-based development environment and production deployment stack

DeerFlow now ships with a complete Docker Compose setup for both development and production use. The development environment (docker-compose-dev.yaml) includes a new dev entrypoint script that handles dependency resolution, validation, and self-healing for the Python virtual environment before starting the gateway. The production stack (docker-compose.yaml) introduces a Redis-backed stream bridge for cross-worker SSE delivery, a Kubernetes sandbox provisioner service, and a readiness health probe for the gateway. Security is improved by defaulting the gateway to a single worker, binding the published port to loopback only, and keeping host CLI auth directories and the Docker socket unmounted by default (available via opt-in overlays).

docker · high confidence

New English documentation structure and navigation

The English documentation site now features a structured navigation menu defined in \_meta.ts, organizing content into distinct sections for Overview, Introduction, Harness, App, Tutorials, Reference, Workspace, Blog, Posts, Login, and Setup. The new index page provides a clear entry point, guiding users to the appropriate documentation path based on their goals: understanding the framework, building with the Harness SDK, or deploying the DeerFlow App.

frontend/src/content/en · high confidence

New Extensions documentation manual

Added a comprehensive, ten-page developer manual for the Extensions system, covering the runtime model, middleware contributions, lifecycle observers, services, routes, full-stack plugins, and operational procedures for installing and managing extensions.

frontend/src/content/en/harness/extensions, frontend/src/content/zh/harness/extensions · high confidence

New Gateway API router structure and custom agent management endpoints

The backend gateway now exposes a modular router structure under \backend/app/gateway/routers\, introducing dedicated endpoints for custom agent CRUD operations (including per-agent model overrides, tool group whitelists, and knowledge scopes), artifact editing with atomic saves and SHA-256 validation, and a LangGraph Platform-compatible assistants API stub. This change also adds new routes for browser automation, capability plugin installation, and IM channel connection management, while consolidating authentication and console observability endpoints into the new routing layer.

backend/app/gateway/routers · high confidence

New Harness documentation section added

A new documentation section for the DeerFlow Harness has been added to the frontend, establishing the site structure and providing initial content for key concepts. The \\_meta.ts\ file defines the navigation hierarchy, including pages for Install, Quick Start, Design Principles, Lead Agent, Middlewares, Configuration, Memory, Tools, Skills, Sandbox, Subagents, Checkpoints, MCP Integration, Extensions, Customization, and an Integration Guide. The accompanying MDX files introduce the Harness as a Python SDK and runtime foundation, explain its design philosophy (middleware chains, skills, sandboxing, config-driven behavior), and provide code examples for embedding the \DeerFlowClient\ in external applications.

frontend/src/content/en/harness · high confidence

New Settings dialog with dedicated pages for account, appearance, memory, channels, models, subagents, and notifications

The workspace settings have been reorganized into a unified, single-instance dialog that can be opened from multiple entry points (navigation menu, command palette, deep links) via a shared state store. This dialog includes dedicated pages for Account (profile display, password change for non-SSO users, sign-out), Appearance (theme selection with system/light/dark options and language switching), Channels (connecting and managing external integrations like WeChat), Memory (viewing, editing, importing, and exporting user memory facts and summaries), Models (admin-only management of shared models), Subagents (admin-only creation and configuration of managed subagents), Notifications (browser notification permissions and testing), and About (product information and acknowledgments).

frontend/src/components/workspace/settings · high confidence

New Titanic ADA demo thread added

A new demo thread has been added to the frontend public demos, featuring a conversation where a user asks for interesting findings from the Titanic dataset. The thread includes a system message listing the uploaded \titanic.csv\ file and an AI response that initiates analysis by calling the \read\_file\ tool to examine the dataset structure.

frontend/public/demo/threads/ad76c455-5bf9-4335-8517-fc03834ab828 · high confidence

New UI component library added

The frontend now includes a comprehensive set of new UI components in the \frontend/src/components/ui\ directory, providing a standardized foundation for the user interface. This addition introduces core layout and display elements such as \Alert\, \Badge\, \Breadcrumb\, \Button\, \Card\, \Dialog\, \DropdownMenu\, and \Input\, alongside specialized interactive widgets like \Carousel\, \Command\ (command palette), \ConfettiButton\, \Galaxy\ (visual effect), and \FlickeringGrid\. These components are built using Radix UI primitives and Tailwind CSS, ensuring consistent styling, accessibility, and behavior across the application.

frontend/src/components/ui · high confidence

New agent creation flow with improved error handling and bootstrap chat

The new-agent page now implements a two-step creation process: first validating the agent name (including specific error messages for API disabled, network issues, and backend validation failures), then initiating a bootstrap chat session. It includes retry logic for fetching the newly created agent, prevents form submission during IME composition, and displays a one-time save hint to users.

frontend/src/app/workspace/agents/new · high confidence

New artifact preview, editing, and download capabilities

The frontend now supports inline editing of text artifacts, previewing CSV and TSV files as bounded tables, and downloading run files as a ZIP archive. Artifact content is loaded via a new API layer that handles SHA-256 verification (using ETag headers for non-secure contexts) and range requests for previews. A dedicated viewer route allows markdown and tabular artifacts to be opened in a new window with the app's renderer, while HTML and XML artifacts are served as downloads to prevent script execution. Delimited file parsing is offloaded to a Web Worker to maintain UI responsiveness.

frontend/src/core/artifacts · high confidence

New backend scripts for database migration, safety testing, and e2e replay tooling

This change introduces a suite of new backend scripts to support recent architectural shifts. Operators can now migrate legacy file-based custom agents and managed subagents into the new database-backed storage using \\migrate\_agents\_to\_db.py\\, and migrate legacy global JSON memory facts into per-user Markdown files via \\migrate\_memory\_markdown.py\\. A comprehensive \\migrate\_user\_isolation.py\\ script handles the one-time migration of legacy thread, agent, and skill directories into the new per-user filesystem layout. To support the new TypeSafe risk gate, \\eval\_typesafe\_risk\_gate.py\\ provides a pre-enablement evaluation tool against the real endpoint. For testing and debugging, \\e2e\_safety\_termination\_demo.py\\ demonstrates the safety middleware's behavior, while \\\_autogen\_revision.py\\ simplifies Alembic migration generation by using ephemeral databases. Finally, \\record\_gateway.py\\ and \\run\_replay\_gateway.py\\ provide the infrastructure for deterministic record-and-replay e2e testing.

backend/scripts · high confidence

New blog section with post listing, tagging, and localization

The frontend now includes a dedicated blog area that displays a list of all posts, filters posts by tag, and supports multiple languages. The implementation uses Next.js App Router files to handle dynamic routes for individual posts, the main post list, and tag-based filtering, while leveraging Nextra for MDX rendering and layout. Users can now navigate to the blog, view posts organized by tags, and see content localized according to their preferred language.

frontend/src/app/blog · high confidence

New capabilities catalog and installation management infrastructure

This change introduces the foundational frontend infrastructure for managing plugins and skills, including a new JSON-based catalog (builtin.demo.json) defining integrations like Lark, DingTalk, WeCom, Tencent Docs, and Notion, alongside TypeScript types, React Query hooks for fetching the catalog and installation status, and a static adapter for demo/mock data. Users will benefit from a unified system to view, configure, and select which MCP plugins and skills an agent can use, with support for localized labels and connection validation logic.

frontend/src/core/capabilities · high confidence

New channel connection management and WeChat QR login support

The frontend now includes a dedicated core module for managing external channel integrations (such as Telegram, Slack, and Discord) and specifically supports WeChat QR code login. This change introduces the API layer, React Query hooks, and polling logic required to list available providers, initiate and configure connections, and handle the WeChat QR authentication flow (including session polling and cancellation). Users can now connect and disconnect these channels directly from the web interface, with the system handling the necessary backend API calls and state synchronization.

frontend/src/core/channels · high confidence

New checkpoint benchmark suite for storage and production performance

Added a new set of benchmark scripts in \backend/scripts/benchmark/checkpoint\ to evaluate checkpoint storage growth and production latency. The suite includes \bench\_channels.py\ for measuring full vs. delta checkpoint storage metrics (SQLite, Postgres, memory) with configurable snapshot frequencies, \bench\_production.py\ for measuring end-to-end latency on the production agent graph, and \bench\_tool\_result\_probe.py\ to verify that oversized tool results are correctly externalized rather than stored in checkpoint state. Supporting scripts \checkpoint\_bench\_common.py\, \summarize\_channels.py\, and \summarize\_production.py\ provide shared utilities and result summarization capabilities.

backend/scripts/benchmark/checkpoint · high confidence

New checkpoint history cache with memory and Redis backends

A new checkpoint delta-history cache has been introduced to store and retrieve append-only checkpoint lineage data. The system provides a process-local LRU memory backend for embedded or single-process use, and a shared Redis backend for multi-worker deployments, selected via configuration. Entries are immutable once written, eliminating the need for complex invalidation logic, while thread-scoped deletion ensures data lifecycle compliance (e.g., GDPR erasure) by purging cached history when source checkpoints are removed.

_backend/packages/harness/deerflow/runtime/checkpoint\cache · high confidence

New conversation bookmarks example plugin and frontend extension infrastructure

This change introduces a complete example plugin for saving and managing conversation bookmarks, alongside the frontend host infrastructure required to load and render it. The \examples/deerflow-extension-bookmarks\ package provides a Python backend that persists user-specific bookmarks to a configurable SQLite database and exposes a read-only \search\_bookmarks\ model tool for agents. On the frontend, new modules in \frontend/src/core/extensions\ implement the plugin contract: they fetch extension metadata, dynamically load browser assets (JavaScript modules and CSS) via a credentialed asset importer, and render plugin-defined surfaces (pages) and conversation actions (menus) within the host application. Users can now install this example to save the last visible assistant answer, search and manage their personal bookmarks in a dedicated sidebar page, and allow agents to retrieve saved excerpts.

examples/deerflow-extension-bookmarks, frontend/src/core/extensions · high confidence

New database models for run events, webhook deduplication, and unified persistence registration

The persistence layer now includes explicit ORM models for run events (RunEventRow) and shared inbound webhook deduplication (WebhookDeliveryRow), enabling durable tracking of event sequences and preventing duplicate processing of inbound webhooks across multiple pods. A new central registration module (\_\init\\_.py) imports and exposes all ORM entities—including agents, channels, feedback, subagents, projects, scheduled tasks, and personal access tokens—to ensure Alembic detects every table for schema management.

backend/packages/harness/deerflow/persistence/models · high confidence

New demo thread for DeerFlow deep research

Added a new demo thread that showcases a multi-agent deep research workflow on the bytedance/deer-flow GitHub repository. The entry includes the conversation history (thread.json) where the AI agent uses a 'github-deep-research' skill to perform a four-round investigation, and the resulting outputs: a structured Markdown report (research\_deerflow\_20260201.md) and a styled HTML report (index.html) featuring executive summaries, timelines, and comparative analysis.

frontend/public/demo/threads/fe3f7974-1bcb-4a01-a950-79673baafefd · high confidence

New demo thread for kimi-k2.5 frontend design generation

A new demo thread (c02bb4d5) has been added to showcase the kimi-k2.5 model's ability to generate production-grade frontend interfaces. The thread includes a complete conversation history and the resulting output files (HTML, CSS, and JavaScript) for a 'Pride and Prejudice' landing page, demonstrating the model's use of the 'frontend-design' skill to create a Regency-era themed site with interactive elements.

frontend/public/demo/threads/c02bb4d5-4202-490e-ae8f-ff4864fc0d2e · high confidence

A new demo conversation thread has been added to the frontend public demos, featuring an AI agent researching 'trends and opportunities in 2026'. The thread includes tool calls for web searching and fetching articles, and generates a complete, interactive HTML report titled '2026 Horizons: Trends & Opportunities' with dark mode support and scroll animations.

frontend/public/demo/threads/7cfa5f8f-a2f8-47ad-acbd-da7137baf990 · high confidence

New demo thread showcasing AI-generated skincare landing page

A new demo thread has been added that demonstrates the system's ability to generate a complete, production-grade frontend interface. The example features a minimalist landing page for a fictional skincare brand named "Caren," including the underlying conversation log (thread.json) where the AI agent plans the design, generates structured prompts for image creation, and writes the final HTML/CSS output (index.html). This entry illustrates the end-to-end workflow of combining frontend design skills with image generation capabilities to deliver a polished, responsive web page.

frontend/public/demo/threads/b83fbb2a-4e36-4d82-9de0-7b2a02c2092a · high confidence

New demo: Interactive 3D liquid-glass weather forecast

A new demo thread has been added that showcases the Kimi K2.5 model generating a production-grade, liquid-glass-style weather forecast interface. The demo includes a single HTML file featuring a 3D-tilting weather card, animated background effects for sunny/rainy/snowy states, and interactive controls to switch between weather conditions, demonstrating the model's ability to create distinctive, high-quality frontend designs with complex CSS and JavaScript.

frontend/public/demo/threads/f4125791-0128-402a-8ca9-50e0947557e4 · high confidence

New extension system with plugin management and middleware injection

DeerFlow now supports a Python-based extension system that allows third-party packages to register as plugins. Operators can install, upgrade, enable, disable, and remove extensions via a new CLI (\deerflow extensions\) or Gateway APIs, with changes persisted in \config.yaml\ and managed through \uv\ dependency groups. Extensions can contribute middleware that is injected into the agent's execution stack at semantic positions (e.g., before/after model calls), with failures isolated to prevent disrupting user runs. The system also supports full-stack plugins with static browser assets, agent assembly observation, and request-scoped run evidence access, all loaded at startup.

backend/packages/harness/deerflow/extensions · high confidence

New feature flag system for frontend capabilities

The frontend now includes a centralized feature flag system that dynamically fetches and exposes the availability of several backend capabilities, including agentic browser control, MCP task notifications, subagent batch execution, conversation references, and per-message RAGFlow retrieval scope. This allows the UI to conditionally enable or disable these features based on the current server configuration.

frontend/src/core/features · high confidence

New file-based artifact management and preview system

The workspace now features a dedicated artifact system for managing and previewing generated files. Users can view a list of artifacts with file icons and extension details, and open them in a detailed view that supports inline editing for text/code files, HTML previews, and bounded table previews for CSV/TSV files. The system includes a trigger button to open the artifact panel, persists panel state (open/closed, selected file) across navigation using session storage, and allows downloading individual files or archives of multiple artifacts. It also supports installing .skill files for admin users and handles citation source extraction for markdown previews.

frontend/src/components/workspace/artifacts · high confidence

New frontend development and build tooling scripts

The frontend now includes a set of new Node.js scripts in the \scripts\ directory to manage development, builds, and demo content. \dev.mjs\ starts the Next.js development server, defaulting to Webpack to avoid PostCSS worker leaks on macOS while allowing an override via the \DEER\_FLOW\_DEV\_BUNDLER\ environment variable. \measure-route-assets.mjs\ measures and validates the size of JavaScript, CSS, and HTML assets for specific routes against defined budgets, supporting both normal and static website build modes. \save-demo.js\ fetches chat thread history from the backend API and saves it as static JSON files for demo purposes, including associated user data and uploads. \sync-capability-catalog.mjs\ copies and formats the backend's capability catalog into the frontend's demo configuration, ensuring the frontend stays in sync with backend-defined capabilities.

frontend/scripts · high confidence

New frontend hooks for global keyboard shortcuts and mobile detection

Added two new React hooks to the frontend: \useGlobalShortcuts\ enables registering global keyboard shortcuts that are suppressed when focus is inside input fields (with an exception for the 'k' key to support command palettes), and \useIsMobile\ provides a reactive boolean indicating whether the viewport width is below 768px using \useSyncExternalStore\.

frontend/src/hooks · high confidence

New image search tool with advanced filtering and safe configuration

A new image search capability has been added to the harness, exposing a tool that searches DuckDuckGo for reference images. This tool supports advanced filters including color, image type, layout, and license, allowing users to refine search results for specific visual needs. To ensure stability, the maximum result count is safely coerced from configuration values to prevent invalid inputs, and the search operation is offloaded to a background thread to avoid blocking the main application loop.

_backend/packages/harness/deerflow/community/image\search · high confidence

This change introduces a new citation rendering system in the workspace. Users will now see inline citation badges that link to external sources or open a dialog showing the specific RAGFlow knowledge source excerpt (document name, dataset, and text). Additionally, a new 'Citation Sources' panel appears at the bottom of responses, listing all referenced sources with their titles, domains, and citation counts, and allowing users to copy a formatted markdown reference for each source.

frontend/src/components/workspace/citations · high confidence

New landing page sections for DeerFlow 2.0

The landing page now includes dedicated sections to showcase DeerFlow 2.0 capabilities: a Case Studies section displaying public demo threads, a Community section with a GitHub contribution link, a Sandbox section highlighting the AIO Sandbox environment, a Skills section with progressive animations, and a What's New section featuring a bento-grid layout of key features like memory, planning, and multi-model support.

frontend/src/components/landing/sections · high confidence

New landing page with hero, navigation, and blog components

The landing page area now includes a complete set of UI components: a responsive header with navigation links and a GitHub star counter, a hero section featuring animated text and background effects, a mobile navigation drawer, a footer with licensing info, a reusable section component, and a blog post list with metadata and tags. These components collectively form the visual structure of the new landing page.

frontend/src/components/landing · high confidence

New lark-cli-broker Docker image for secure credential handling

Added a new Docker image (\docker/lark-cli-broker\) that implements 'Pattern B' for Lark CLI integration. This image runs a sidecar process holding the \lark-cli\ binary and per-user credentials, exposing only a loopback HTTP API to the sandbox. This ensures plaintext secrets and OAuth tokens are never mounted into the sandbox container, mitigating exfiltration risks from compromised agents. The image supports two modes: \serve\ (the sidecar HTTP server) and \install-shim\ (an init container action to stage a launcher in the sandbox's PATH).

docker/lark-cli-broker · high confidence

New lark-cli-init Docker image for sandbox runtime provisioning

A new Docker image (\docker/lark-cli-init\) has been added to provision the Lark CLI runtime into Kubernetes sandbox pods via an init container and shared emptyDir volume. This image downloads and SHA-256-verifies the official \larksuite/cli\ Linux binaries (amd64 and arm64) at build time, staging them in a layout that matches the existing Gateway writer output. At runtime, the init container copies these binaries to the shared mount point (\/mnt/integrations/lark-cli/runtime\), allowing the sandbox container to access the \lark-cli\ executable without relying on hostPath mounts or downloading binaries at install time. This change is opt-in and controlled by the \LARK\_CLI\_INIT\_IMAGE\ environment variable on the provisioner service.

docker/lark-cli-init · high confidence

New mock API endpoint for available skills

A new mock API route at \/mock/api/skills\ has been added to the frontend application, providing a static list of available skills. This endpoint returns metadata for eleven distinct capabilities, including deep research, frontend design, image and video generation, music and podcast creation, presentation generation, and deployment tools, allowing the client to discover and configure these features.

frontend/src/app/mock/api/skills · high confidence

New model infrastructure with declarative reasoning contracts and OAuth provider support

The models package has been restructured to introduce a declarative reasoning capability contract, allowing profiles to define thinking requirements, effort levels, and payload dialects via a structured \reasoning\ mapping instead of legacy booleans. This new factory normalizes thinking and effort settings across providers, preventing duplicate keyword argument errors and ensuring consistent payload construction. The update adds native support for Claude Code and Codex CLI as LLM providers, handling OAuth token authentication, billing headers, and credential loading from file descriptors or local JSON files. It also introduces a vLLM provider with cumulative stream usage tracking, a MindIE adapter that sanitizes tool calls and escapes content to prevent breakout vulnerabilities, and a patched DeepSeek provider that preserves \reasoning\_content\ in multi-turn conversations. Additionally, a shared model management system allows administrators to persist and manage trusted local provider endpoints, while request admission controls enforce FIFO ordering and rate limiting at the factory level.

backend/packages/harness/deerflow/models · high confidence

New modular authentication system with OIDC SSO, Personal Access Tokens, and hardened credential handling

DeerFlow introduces a comprehensive, modular authentication framework in the gateway layer. Users can now log in via OpenID Connect (OIDC) SSO with support for PKCE, stateless cookie-based state management, and domain/email restrictions. Programmatic access is enabled through Personal Access Tokens (PATs) scoped to specific thread, run, and project routes. The system persists JWT secrets to survive restarts, replaces insecure log-based admin credential output with a restricted 0600 file, and enforces atomic first-admin creation to prevent race conditions. Password hashing has been upgraded to a versioned format (v2) to bypass bcrypt's 72-byte truncation limit, ensuring full password entropy is used.

backend/app/gateway/auth · high confidence

New public skills for academic review, agent onboarding, and data visualization

Users can now leverage three new public skills: the academic-paper-review skill for generating structured, peer-review-style analyses of research papers; the bootstrap skill for conducting a conversational onboarding to generate a personalized SOUL.md defining the AI partner's identity and behavior; and the chart-visualization skill for transforming data into various visual charts (including line, bar, map, and network graphs) via a Node.js script.

skills · high confidence

New scripts for dependency checking, version bumping, and Helm chart validation

The scripts directory now includes a suite of new tooling: \check.py\ and \check.sh\ provide cross-platform dependency verification for Node.js, pnpm, uv, and nginx; \bump\_version.sh\ synchronizes version numbers across \pyproject.toml\, \package.json\, and Helm charts; and several \check\chart\\*.sh\ scripts validate Helm chart rendering for sandbox service types, storage paths, and ingress policies. Additionally, \AGENTS.md\ documents the contracts for these scripts, including shell invocation and static analysis targets.

scripts · high confidence

New standalone Jev context pruning plugin example

An opt-in Python plugin example has been added to the examples directory that uses the Jev API to shorten obsolete read-only tool results (read\_file, grep, glob, ls) before DeerFlow's normal summarization. It registers via the extension API 0.2.2, runs on the lead agent, and replaces result contents in the persisted graph state with a lossy summary (preserving 300 characters at each end) when the Jev keep probability is below 0.2 and estimated context reduction reaches 10%. The plugin is disabled by default and requires setting the TYPESAFE\_API\_KEY environment variable and enabling it in the deployment configuration. It includes a smoke test script to verify behavior with synthetic data and a package verification script to ensure correct installation and entry points.

examples/deerflow-extension-jev-context · high confidence

New tool assembly, provenance, and management capabilities in the harness

The \backend/packages/harness/deerflow/tools\ package introduces a centralized tool assembly system (\get\_available\_tools\) that unifies config-defined, MCP, built-in, and subagent tools. It adds a \read\_conversation\ tool for host-authorized, paginated conversation history reads with cut-message continuation, and a \skill\_manage\_tool\ for creating, editing, and patching custom skills with security scanning. Tool provenance is now tracked via \ToolProvenance\ (distinguishing MCP, plugin, and builtin sources), and MCP tools are tagged with metadata for deferred loading. A \make\_sync\_tool\_wrapper\ utility ensures async tools work in synchronous agent paths, and a \Runtime\ type alias resolves Pydantic serialization warnings.

backend/packages/harness/deerflow/tools · high confidence

New trash management interface for workspace documents

Users can now access a dedicated trash view at /workspace/trash to manage deleted documents. This new feature allows users to view a paginated list of trashed items, including their origin project and remaining retention period. Users can restore individual documents back to their original project (with conflict handling for missing content) or permanently delete them. An 'Empty trash' option is also available to permanently remove all trashed documents at once, bypassing the retention window. The interface is hidden in static demo mode and includes proper error handling and loading states.

frontend/src/app/workspace/trash, frontend/src/components/workspace/trash, frontend/src/core/trash · high confidence

New utility modules for datetime, file handling, JSON, markdown, and UUIDs

This change introduces a set of new helper modules in the frontend core utilities to standardize common operations. The datetime module provides a locale-aware 'time ago' formatter that safely handles invalid timestamps. The file utilities module adds functions to extract file names and extensions, and maps file extensions to language identifiers for syntax highlighting, alongside a list of extensions supported for browser preview. A new markdown utility robustly extracts titles from markdown content, correctly handling leading blank lines and indented headings. Additionally, a JSON utility offers a safe parsing wrapper using best-effort parsing, and a UUID module exposes the v4 UUID generator.

frontend/src/core/utils · high confidence

New workspace capabilities center for unified plugin, skill, and extension management

A new workspace capabilities center has been introduced, consolidating the management of plugins, skills, and extensions into a single interface. This update replaces the previous scattered settings approach with a dedicated gallery view featuring tabs for each capability type, search filtering, and category grouping. Users can now browse available plugins and skills, view installation statuses, and manage configurations (including specific integrations like Lark and MCP servers) directly from this hub, streamlining the discovery and setup of workspace tools.

frontend/src/components/workspace/capabilities · high confidence

Persist user account preferences across browsers and sessions

The application now stores user settings (such as notification preferences, default model, conversation mode, and reasoning effort) in a dedicated \user\_preferences\ table, allowing changes made in one browser to be visible in others. This is implemented via a new \UserPreferencesRepository\ that supports atomic PATCH upserts, ensuring that disjoint edits from concurrent clients do not conflict and that only explicitly supplied keys are updated.

backend/packages/harness/deerflow/persistence/user · high confidence

Persist user-owned IM channel connections with race-safe ownership

The persistence layer for instant messaging channel connections has been implemented to support user-owned connections. This introduces database models and a repository for storing connection metadata, encrypted credentials, OAuth states, and conversation mappings. A key behavioral improvement is the enforcement of single-active-owner semantics at the database level using partial unique indexes, which prevents race conditions during concurrent connection attempts by automatically revoking conflicting active owners. The system also includes bounded retries for upsert operations to handle contention gracefully.

_backend/packages/harness/deerflow/persistence/channel\connections · high confidence

Pluggable fine-grained authorization for tools, plugins, and sandboxes

DeerFlow now enforces role-based and pluggable resource-level authorization across the platform. At assembly time, tools are filtered so that agents only see capabilities permitted for the user's role. At runtime, a guardrail adapter intercepts tool calls to enforce dynamic restrictions, while sandbox execution, plugin backend actions, plugin pages, and plugin management routes are all gated by the same authorization provider. A built-in RBAC provider is included, and the system supports custom providers via a pluggable protocol, with fail-closed semantics ensuring that missing or misconfigured policies deny access rather than allowing it.

backend/packages/harness/deerflow/authz · high confidence

Pluggable memory backend architecture with OpenViking and Honcho support

The memory system now supports pluggable backends, allowing users to swap the underlying memory provider by changing a single configuration line in \config.yaml\ without modifying core code. This change introduces two new optional remote backends: OpenViking (using the official \langchain-openviking\ package) and Honcho (an HTTP-based user-model memory provider with workspace-per-user isolation). The default backend remains DeerMem, and a \noop\ template is provided to help developers create custom backends. Users can now choose between local structured storage, remote OpenViking middleware, or remote Honcho services based on their deployment needs.

backend/packages/harness/deerflow/agents/memory/backends · high confidence

Pluggable memory backend architecture with configurable storage and tool-driven interaction

The memory system has been refactored to support pluggable backends via a new \MemoryManager\ interface, allowing users to swap the default local storage (DeerMem) for other providers like Mem0 or Honcho by simply changing the configuration. This change introduces a new \memory.mode\ setting: the default \middleware\ mode continues passive, automatic memory capture, while the new \tool\ mode exposes explicit \memory\_search\, \memory\_add\, \memory\_update\, and \memory\_delete\ tools to the agent, giving the model direct control over memory persistence and retrieval. Additionally, custom agents can now opt out of memory entirely by setting \memory\_enabled: false\ in their configuration.

backend/packages/harness/deerflow/agents/memory · high confidence

Project document shelf with read tools and trash lifecycle

Users can now upload documents to a project shelf, which are stored immutably and optionally converted to Markdown. Agents can list shelf contents and read document text via new tools, with live data reflecting the current state. The shelf includes a trash tier: documents can be restored to an active project or purged, and a retention sweep automatically removes expired trashed items and cleans up orphaned staging files.

backend/packages/harness/deerflow/projects · high confidence

Public case study routes for static demo threads

Users can now access specific showcase case studies via public URLs (e.g., /showcase/\[thread\_id\]). This change introduces a dedicated layout and page component that renders the chat interface for pre-defined demo threads, ensuring proper internationalization and authentication context while returning a 404 for any thread ID not in the static demo list.

frontend/src/app/showcase · high confidence

Read-only RAGFlow retrieval with verifiable source citations

DeerFlow now supports read-only retrieval from RAGFlow knowledge bases via the \knowledge\_search\ tool. Users can configure dataset and document scopes, and the tool returns compact, cited text with bounded, immutable source snapshots (\knowledge\_sources\) that allow verifiable traceability to the original RAGFlow chunks. The implementation includes a dedicated async HTTP client, credential-redacted error handling, and strict output budgeting to ensure evidence entries and their source records are retained together or omitted atomically when limits are exceeded.

backend/packages/harness/deerflow/community/ragflow · high confidence

Redesigned message list with structured conversation navigation and enhanced rendering

The message list component has been rebuilt to support a richer, more structured chat experience. Users can now navigate long conversations using a new conversation outline sidebar that displays chapter-based navigation ticks. Message rendering has been upgraded with a new MarkdownContent component that features smooth, animated streaming text reveals and improved code block handling. The UI now includes dedicated components for displaying human input forms, subtask progress cards with step timelines, and knowledge scope summaries. Additionally, a new markdown-link component enforces a strict protocol allowlist to block unsafe link schemes, and the list supports persistent run duration tracking and token usage summaries.

frontend/src/components/workspace/messages · high confidence

Reproducible benchmark for DeerMem hybrid-v1 capacity eviction policy

A new deterministic evaluation suite has been added to \backend/scripts/benchmark/deermem\_eviction\ to reproduce and verify the DeerMem \hybrid-v1\ capacity eviction policy against the baseline \confidence\ policy. This tool allows for a controlled, offline comparison using a pinned version of the LongMemEval dataset and a blind, versioned grading script (\deterministic-overlap-v1\). It supports running the production \select\_facts\_for\_capacity\ selector at specific capacities (5, 7, and 9) and can execute live QA calls against an OpenAI-compatible provider to measure answer accuracy. The suite ensures reproducibility by validating dataset hashes, config contracts, and prompt versions, and it outputs public, metadata-only reports including paired statistical tests (McNemar) to compare the two policies.

_backend/scripts/benchmark/deermem\eviction · high confidence

Runtime module introduces dual-mode checkpointing and robust cancellation handling

The runtime package now supports a dual-mode checkpoint system (full vs. delta) to optimize storage growth, with a fail-closed compatibility gate to prevent data corruption during migration. It also introduces a \CheckpointStateAccessor\ to centralize state access and mutation, ensuring safe rollback and context compaction. Additionally, the module adds robust cancellation handling for async context managers and JSONL event stores, preventing data loss or detachment during stream teardown.

backend/packages/harness/deerflow/runtime · high confidence

Sandbox subsystem restructured with hardened security and new isolation features

The sandbox subsystem has been reorganized into a modular package with a new AGENTS.md documentation file and dedicated modules for environment policy, acquire serialization, and exceptions. Environment variables are now scrubbed of secrets (keys, tokens, passwords, DSNs) before being passed to sandbox subprocesses to prevent credential leakage. A new authorization gate enforces sandbox execution permissions before reuse. Acquire operations are serialized using a bounded lock-table to prevent concurrency issues. The subsystem now supports cross-instance ownership stores (memory/Redis) for container lifecycle management, and includes new tools for grep and glob operations with bounded results. File operations include read-before-write gates and improved error handling for binary files and truncation.

backend/packages/harness/deerflow/sandbox · high confidence

Standardize development environment with pre-commit hooks and Docker context isolation

The repository now enforces consistent code quality and cross-platform compatibility through a new pre-commit configuration that runs ruff for Python linting/formatting, and ESLint/Prettier for the frontend. To prevent build failures and bloated Docker images, a .dockerignore file explicitly excludes runtime data (such as .deer-flow/ and backend/sandbox/), local virtual environments, and build artifacts from the Docker build context, while ensuring extension sources are included. Additionally, .gitattributes standardizes line endings to LF for text files across the project to resolve Windows-specific shell script issues.

(repo-wide) · high confidence

Subagent execution, acceptance, and batch capabilities

The subagent subsystem now includes a comprehensive acceptance-checking framework that validates file existence, non-emptiness, and test execution results against deterministic criteria, ensuring that subagent outputs meet specific requirements before being considered successful. Additionally, a durable batch execution service has been introduced, allowing for the submission and processing of multiple subagent tasks with individual acceptance checks, sandbox authorization, and lease-based management. The system also features enhanced context isolation, step capture, and persistence, along with improved error handling and reporting for subagent runs, including support for deferred MCP tool loading and model overrides per subagent.

backend/packages/harness/deerflow/subagents · high confidence

Subtask cards now persist and display full step history, model, and token usage

Subtask cards now show a complete, ordered timeline of the subagent's assistant turns and tool outputs instead of just the latest message, ensuring the full history survives page reloads. The cards also display the effective model name and cumulative token usage for each subtask. Additionally, guardrail caps (token, turn, or loop limits) are surfaced via a structured \stopReason\ field, allowing the UI to distinguish capped runs from standard completions or failures.

frontend/src/core/tasks · high confidence

Thread management and conversation history overhaul

The frontend's thread handling has been restructured into a dedicated core module, introducing a comprehensive set of capabilities for conversation management. Users can now archive and restore threads, branch conversations from specific assistant turns to create side conversations, and export chat history as Markdown or JSON. The system also supports per-thread composer drafts, allowing users to recover their input if a session is interrupted. Under the hood, message ordering and deduplication have been rewritten to ensure chronological integrity during streaming and context compaction, while a new thread list model and search query builder improve sidebar performance and pagination.

frontend/src/core/threads · high confidence

Unified checkpointer provider with async support and delta-history caching

The checkpointer module now provides a unified factory for both synchronous and asynchronous runtimes, supporting memory, SQLite, and PostgreSQL backends. For PostgreSQL, the async provider uses an AsyncConnectionPool with TCP keepalive to prevent stale connection errors, and both providers support custom PostgreSQL schemas. A new CachedHistorySaver wrapper implements a read-through delta-history cache, significantly improving checkpoint retrieval performance by caching channel writes and composing history from warm ancestors rather than walking the full chain.

backend/packages/harness/deerflow/runtime/checkpointer · high confidence

Unified persistence layer with schema-aware PostgreSQL support and robust bootstrap

DeerFlow introduces a dedicated persistence layer for application data (runs, threads, users, agents) that is fully decoupled from LangGraph's checkpointer. The layer now supports custom PostgreSQL schemas via the \database.postgres\_schema\ configuration, ensuring both async ORM and synchronous agent connections use the correct \search\_path\. Database initialization has been hardened with a hybrid Alembic/\create\_all\ bootstrap strategy that safely handles legacy databases, enforces cross-process serialization via advisory locks, and drains all background workers (Alembic migrations, schema creation) across host cancellation to prevent stale connections and 504 errors. Additionally, the engine now enforces connection recycling and command timeouts for PostgreSQL, and offloads SQLite directory creation to a background thread to prevent blocking the event loop.

backend/packages/harness/deerflow/persistence · high confidence

Unified, per-user isolated skill storage with safe singleton lifecycle

The skills storage layer has been refactored into a unified, reflection-based factory that manages a global singleton for public skills and a thread-safe, LRU-cached pool of per-user storage instances for custom skills. This change ensures that custom skills are strictly isolated per user (stored under \\{base\_dir}/users/{user\_id}/skills/custom/\\) while public skills remain globally read-only. The new implementation includes robust lifecycle management: it synchronizes the singleton with configuration reloads, prevents blocking the event loop during archive installations by offloading filesystem work to worker threads, and provides explicit reset functions for hot-reload and testing scenarios. Additionally, legacy global custom skills are now surfaced as read-only \\LEGACY\\ entries for users who have not yet created their own custom skills, ensuring backward compatibility without exposing mutable access to shared resources.

backend/packages/harness/deerflow/skills/storage · high confidence

View loaded skill snapshots in message details

Users can now inspect the exact skill snapshots used during a conversation. A new message details panel and menu system allow users to click on skill usage entries to view the full SKILL.md content, including metadata like name, description, and source category (built-in, custom, or integration). The snapshot view safely renders markdown content, preserving external links and images while neutralizing relative paths that lack backing resources, and includes a copy action to export the raw skill content.

frontend/src/components/workspace/message-details, frontend/src/components/workspace/skill-usage · high confidence

WeChat QR login and provider icons added to workspace channels

The workspace channels sidebar now supports WeChat QR login, allowing users to authenticate via a QR code displayed in the browser or by binding an existing WeChat connection. This is accompanied by new, branded SVG icons for WeChat and several other providers (Buzz, Telegram, Slack, Discord, Feishu, DingTalk, WeCom) to improve visual identification in the channel list.

frontend/src/components/workspace/channels · high confidence

Workspace UI overhaul with new components and features

The workspace interface has been significantly updated with a suite of new components and features. A new command palette (Cmd+K) has been added for quick navigation and actions. Users can now export conversations as Markdown or JSON. A code editor with syntax highlighting and theme support is available for code-related tasks. The UI now displays context usage percentages and goal status with continuation counters. Agent welcome screens provide better context for custom agents. Gateway offline banners and model load error banners improve error handling and user feedback. Additional features include a flip display animation, copy buttons, and knowledge scope selectors for RAG.

frontend/src/components/workspace · high confidence

Removals

Removal of JSON repair utility functions

The \src/utils\ module has been removed, specifically deleting \src/utils/\_\init\\_.py\ and \src/utils/json\_utils.py\. This eliminates the \repair\_json\_output\ function that previously handled JSON normalization, including stripping markdown code block wrappers (such as \\\json or \\\ts) and using the \json\_repair\ library to fix malformed JSON strings. Users relying on this utility for post-processing LLM outputs will need to implement alternative JSON repair logic or use a different library.

src/utils · high confidence

Removal of legacy LLM module and cached model instances

The legacy \src/llms/llm.py\ module has been removed, eliminating the previous mechanism that cached and instantiated \ChatOpenAI\ models for reasoning, basic, and vision tasks via \conf.yaml\. This change removes the global \reasoning\_llm\, \basic\_llm\, and \vl\_llm\ instances, indicating a shift in how LLM providers are initialized and managed within the application.

src/llms · high confidence

Removal of legacy agent factory and exports

The \src/agents\ module has been removed, deleting the \research\_agent\ and \coder\_agent\ exports and the \create\_agent\ factory function that previously relied on the deprecated \langgraph.prebuilt.create\_react\_agent\. This cleanup eliminates the old agent instantiation logic, aligning with the migration to the newer \langchain.agents.create\_agent\ API used elsewhere in the codebase.

src/agents · high confidence

Removal of legacy configuration module

The \src/config\ package has been completely removed, eliminating the previous static configuration system. This deletes the YAML-based loader, the hardcoded team member definitions (researcher, coder), the agent-to-LLM type mapping, and the \Configuration\ dataclass used for runtime settings. Users relying on these specific configuration structures or environment variable overrides defined in this module will need to adopt the new configuration approach.

src/config · high confidence

Removal of legacy crawler implementation

The legacy crawler module in src/crawler has been completely removed. This deletion eliminates the Jina-based web scraping client, the Readability content extractor, and the Article data model that previously handled HTML-to-markdown conversion and message formatting for LLM consumption.

src/crawler · high confidence

Removal of legacy graph implementation files

The \src/graph\ directory has been cleared of its previous implementation files (\\_\init\\_.py\, \builder.py\, \nodes.py\, and \types.py\). This removes the specific graph construction logic, node definitions (such as coordinator, planner, and reporter), and state types that were previously exported from this module, indicating a structural change to how the agent workflow is defined or integrated.

src/graph · high confidence

Removal of legacy prompt templates and template engine

The \src/prompts\ directory has been completely removed, deleting the Jinja2-based template engine (\template.py\, \\_\init\\_.py\) and all associated Markdown prompt files (\coder.md\, \coordinator.md\, \planner.md\, \reporter.md\, \researcher.md\). This eliminates the previous system for rendering agent instructions via variable substitution, indicating a migration to a different prompt management approach.

src/prompts · high confidence

Removal of legacy tool implementations and module structure

The \src/tools\ directory has been completely removed, eliminating the previous module structure that included \\_\init\\_.py\, \bash\_tool.py\, \crawl.py\, \decorators.py\, \python\_repl.py\, and \search.py\. This change removes the built-in Bash execution, Python REPL, web crawling, and Tavily search capabilities, along with the logging decorators and factory functions that supported them, from this location.

src/tools · high confidence

Removal of standalone workflow runner script

The standalone \src/workflow.py\ module, which previously provided a direct entry point for running the agent workflow with configurable debug logging and iteration limits, has been removed. This change eliminates the ability to execute the workflow directly via this specific script file, likely as part of a broader refactoring to consolidate execution logic or migrate to a different orchestration pattern.

src · high confidence

Behavioural changes

Account-scoped preferences sync and per-thread model overrides

Settings are now persisted per account and synced across browsers via a backend API, replacing the previous single-user local storage approach. Users will see their notification preferences, display modes, and model selections synchronized across devices. Additionally, model selection is now remembered independently for each chat thread, allowing different models to be used in different conversations without affecting the global default.

frontend/src/core/settings · high confidence

Agents UI is now gated by the agents\_api feature flag

The Agents workspace page now checks the \agents\_api\ feature flag before rendering. If the feature is disabled or still loading, users see a dedicated "feature disabled" message or a loading state instead of the Agent Gallery. This ensures the Agents UI is only accessible when the underlying API support is enabled.

frontend/src/app/workspace/agents · high confidence

DeerMem memory backend core logic and configuration externalized

The DeerMem memory backend now includes a self-contained core implementation with pluggable storage, deterministic fact eviction, and externalized prompt templates. Users benefit from a hybrid eviction policy that scores facts by confidence, confirmation freshness, and access heat to manage memory capacity, and an opt-in Markdown storage mode that tolerates corrupt or hand-edited memory files by quarantining them instead of crashing. Message processing logic has been moved to YAML pattern files for corrections, decisions, goals, identity, preferences, and trivial acknowledgments, allowing signal detection rules to be updated without code changes. Prompt templates for fact extraction, consolidation, and staleness review are now loaded from external YAML files, enabling per-agent customization. The backend also introduces its own LLM construction and path resolution, decoupling memory storage locations from the host application's default paths.

backend/packages/harness/deerflow/agents/memory/backends/deermem/deermem/core · high confidence

Enforce deployment-wide E2B sandbox capacity limits via Redis

The E2B sandbox capacity management has been refactored to use a Redis-backed ledger, ensuring that the total number of active sandbox reservations is tracked and enforced across the entire deployment rather than per-instance. This change introduces a new capacity module that utilizes atomic Redis operations to manage hard limits, preventing the system from exceeding configured capacity thresholds even under concurrent load. Users will benefit from more reliable resource management and consistent capacity enforcement across all sandbox instances.

_backend/packages/harness/deerflow/community/e2b\sandbox/capacity · high confidence

The frontend library now includes utilities to correctly handle Input Method Editor (IME) composition states, preventing premature submission or action during text composition (specifically addressing Enter key behavior in Safari and other browsers). Additionally, shared utility functions for CSS class merging and specific styling classes for external links (with and without underlines) have been added to standardize link appearance across the application.

frontend/src/lib · high confidence

Interactive first-boot setup replaces automatic admin creation

The setup page now requires users to manually create the initial administrator account during first boot, replacing the previous behavior where an admin account was created automatically. This new interactive flow handles both the initial admin creation and subsequent password changes for authenticated users who need setup, while also improving resilience against service timeouts by allowing retries when the system status is unavailable.

frontend/src/app/(auth)/setup · high confidence

Introduce agents API client, React Query hooks, and feature-gate caching

The frontend now includes a dedicated API layer for managing agents (CRUD operations and name availability checks) along with React Query hooks to consume them. To prevent UI instability when the backend feature flag endpoint is unavailable, a local storage cache is introduced to persist the last known state of the \agents\_api\ feature flag, ensuring the agents interface remains hidden during outages rather than failing open.

frontend/src/core/agents · high confidence

Introduce backend-driven suggestions configuration and placeholder detection

The frontend now fetches a suggestions configuration from the backend to determine whether suggestions are enabled and how many follow-up suggestions to display, falling back to a default of 3 if the backend endpoint is unavailable. A new React Query hook manages this configuration state, and a utility function has been added to detect unreplaced placeholders in suggestion template strings, supporting the localization of prompt templates.

frontend/src/core/suggestions · high confidence

Introduce model favorites and refined reasoning capabilities

Users can now mark specific models as favorites, which are persisted in local storage and displayed prominently in the model selection list. The model selection interface also benefits from improved reasoning support, allowing the system to correctly map and resolve reasoning effort levels (such as minimal, low, medium, high) based on the specific model's capabilities and provider contracts. Additionally, the model loading process has been stabilized to provide clearer feedback when gateway errors occur, and the system now supports a static website demo mode that gracefully handles model loading without a backend.

frontend/src/core/models · high confidence

Introduces abstract user repository interface and case-insensitive email handling

This change adds a new abstract base class for user data storage operations, defining the contract for user repository implementations. It also introduces case-insensitive email handling by normalizing emails to lowercase during creation and lookup, ensuring that accounts are uniquely identified regardless of case variations. Additionally, the first admin creation process is made atomic to prevent race conditions during initial setup.

backend/app/gateway/auth/repositories · high confidence

Introduces structured event catalog and stable message identity for run history

This change establishes the foundational structure for persisting and displaying run events. It adds a canonical event catalog (\catalog.py\) that defines specific event types (such as \run.start\, \llm.ai.response\, and \subagent.step\) and categories, ensuring a consistent JSON contract between the backend and frontend. Additionally, it implements stable message identity logic (\message\_identity.py\) and sequence stamping (\message\_seq.py\) to ensure that messages in the thread feed and checkpoints are correctly aligned, preventing issues where early user messages might vanish or jump positions during pagination and context compaction.

backend/packages/harness/deerflow/runtime/events · high confidence

Migrate Tavily tools to async client with domain filtering and credential handling

The Tavily search and web-fetch tools have been rewritten to use the asynchronous \AsyncTavilyClient\, ensuring proper connection lifecycle management by closing clients after each use. Search results can now be restricted to specific sources using \include\_domains\ and \exclude\_domains\ configuration options, with inclusion explicitly set to filter mode. Additionally, the web-fetch tool now correctly uses \web\_fetch\ credentials for extraction and safely handles responses that may lack a page title by falling back to the URL.

backend/packages/harness/deerflow/community/tavily · high confidence

New centralized API client with CSRF protection and robust stream reconnection

The frontend now uses a new \api-client.ts\ module to manage communication with the backend. This client automatically injects CSRF tokens for state-changing requests and handles authentication redirects. It introduces resilient stream reconnection logic that detects gaps in the event stream, recovers durable state, and restores user input to prevent UI hangs. Additionally, it sanitizes unsupported LangGraph stream modes to ensure compatibility and provides a static-response layer for read-only demo environments.

frontend/src/core/api · high confidence

New message grouping, token usage, and UI stability logic in the frontend

The \frontend/src/core/messages\ module has been restructured into dedicated files to improve how the chat UI processes and displays messages. \utils.ts\ now defines the \MessageGroup\ types and grouping logic, ensuring orphan tool messages are kept visible and reasoning content is not rendered twice. \derived-state.ts\ introduces stable message group derivation to prevent unnecessary UI re-renders during streaming. \usage.ts\ and \usage-model.ts\ handle token usage extraction, accumulation, and attribution for debug and per-turn views. \run-duration.ts\ calculates and formats run durations, while \artifact-archive.ts\ and \workspace-change-anchor.ts\ correctly anchor run-specific UI elements to the last relevant group. \human-input.ts\ adds support for structured human input forms, and \tool-detail-preview.ts\ provides bounded serialization for tool details.

frontend/src/core/messages · high confidence

Redesigned login and authentication callback flows with SSO and session persistence

The login experience has been rebuilt to support multiple authentication methods and improved security. Users can now sign in via OIDC SSO providers, which are dynamically fetched and displayed alongside traditional email/password forms. A new 'Keep me signed in' option allows users to persist their session across browser restarts. The login page also handles initial system setup states, preventing registration until an admin completes the first-boot setup. Additionally, a new authentication callback page securely validates the post-login redirect path to prevent open-redirect vulnerabilities, ensuring users are sent to a safe destination after SSO or local authentication.

frontend/src/app/(auth)/login · high confidence

Restructured subagent documentation into an eleven-chapter user manual

The subagent documentation has been reorganized into a comprehensive, eleven-chapter user manual to improve clarity and navigation. The new structure includes dedicated sections for the Subagent Catalog (detailing built-in agents, definition sources, and external ACP agents), Delegating Work (covering task parameters, context modes, and durable batches), Limits and Capacity, Sandbox and Isolation, Observability, Troubleshooting, and Developers and Integration. This restructure provides users with a more logical flow from quick starts to advanced configuration and integration guides.

frontend/src/content/en/harness/subagents, frontend/src/content/zh/harness/subagents · high confidence

Unified Nginx proxy configuration for Docker and local development

The Docker Nginx setup now uses a single, unified configuration structure that supports both containerized and local development environments. The new \nginx.conf\ is optimized for Docker, resolving upstream service names at request time to handle container restarts and using \/tmp\ for the PID file to avoid permission issues. The \nginx.local.conf\ mirrors this for local \make dev\ runs, binding to \127.0.0.1\ and using local log paths. Both configurations enforce 600-second timeouts for long-running API requests (such as chat prompts and skill installations), disable buffering for streaming responses, and correctly preserve the \X-Forwarded-Proto\ header to ensure authentication and CORS checks work correctly when the proxy is behind another TLS-terminating reverse proxy.

docker/nginx · high confidence

Unified authentication context and hardened session handling

The frontend now uses a centralized \AuthProvider\ to manage user state, replacing previous scattered logic with a single source of truth for authentication. This change introduces a robust logout mechanism that performs a hard navigation to clear all client-side state when the backend is unreachable, preventing stale sessions. It also adds a "Keep me signed in" feature that persists login preferences in local storage, and implements strict validation for the post-login redirect path to prevent open-redirect vulnerabilities. Additionally, the system now supports an "auth-disabled" mode for local development and static website demos, automatically injecting a default admin user when authentication is bypassed.

frontend/src/core/auth · high confidence

Updated mock model list and added MCP configuration endpoint

The mock API now serves an updated list of available models, including DeepSeek V4, GPT-5, Gemini 3 Pro, and Doubao Seed 1.8, replacing previous entries. Additionally, a new mock endpoint for MCP (Model Context Protocol) server configuration has been introduced, providing predefined settings for servers like 'mcp-github-trending', 'context-7', and 'feishu-importer'.

frontend/src/app/mock/api/models · high confidence

Workspace layout and sidebar state persistence

The workspace now persists the sidebar's open/closed state across page navigations by reading it from a cookie, and introduces a global command palette accessible via keyboard shortcuts. Additionally, the layout ensures that gateway offline and model loading errors are surfaced as banners within the workspace content area.

frontend/src/app/workspace · high confidence

Fixes

Async web fetch tool with proxy support and improved error handling

The web\_fetch tool now uses an asynchronous HTTP client (httpx) to fetch web pages, allowing it to run without blocking the event loop. Users can now configure a proxy server and adjust the request timeout via tool configuration, which is useful for restricted network environments. The implementation also includes better error handling by logging transient failures as warnings instead of tracebacks and supports relative URL resolution in extracted Markdown content.

_backend/packages/harness/deerflow/community/jina\ai · high confidence

Centralized and secured upload management logic

The upload handling logic has been extracted into a shared, framework-agnostic module (\backend/packages/harness/deerflow/uploads/manager.py\) that both the Gateway and Client delegate to. This change introduces strict security validations, including path traversal detection, rejection of symlinked upload destinations, and enforcement of the 255-byte filename limit. It also adds Windows support for safe symlink-protected uploads, ensures unique filenames are generated without exceeding length limits, and provides utilities to clean up stale staging files left by crashes.

backend/packages/harness/deerflow/uploads · high confidence

Hardened markdown rendering with security sanitization and crash prevention

The Streamdown rendering pipeline now includes robust safeguards against rendering crashes and security vulnerabilities. It prevents stack-overflow crashes caused by deeply nested lists and blockquotes by capping their indentation levels, and ensures math rendering works correctly by normalizing LaTeX delimiters. Additionally, the pipeline enforces strict HTML sanitization to block malicious scripts and DOM clobbering attacks, while correctly handling fenced code blocks and Mermaid diagrams to preserve content integrity.

frontend/src/core/streamdown · high confidence

Stabilizes document conversion, message handling, and assembly offloading

This update introduces several reliability and performance improvements across the DeerFlow backend. Uploaded document conversion now uses a two-converter strategy (pymupdf4llm with MarkItDown fallback) and offloads large file processing to a thread pool to prevent event-loop blocking. Document outline extraction has been hardened to correctly parse split-bold and fenced-code headings, while UTF-8 BOMs are now handled to prevent preview corruption. Message text extraction now safely returns empty strings for content-less messages, and agent/tool assembly is offloaded to a dedicated worker pool to avoid starving the main event loop during MCP discovery. Additionally, custom stream events are now properly exposed to async event consumers, and active content MIME types are unified to prevent security bypasses.

backend/packages/harness/deerflow/utils · high confidence

Test coverage

Added E2E tests for artifact viewer access and auth setup recovery; Added Playwright E2E test infrastructure with shared mock API utilities; Added Playwright end-to-end tests for real-backend and record workflows; Added benchmark script for skill export performance; Added multi-process concurrency benchmark for Postgres claim validation; Added strict event-loop blocking I/O regression tests; Added tests for Unicode agent display names, model settings validation, and capability selection isolation; Added tests for artifact preview, download, and table rendering components; Added tests for legacy memory import and normalization compatibility; Added trace-based behavioural tests for DeerFlow using Monocle Test Tools; Added unit and DOM tests for frontend runtime and UI features; Added unit tests for ChannelProviderIcon collision safety; Added unit tests for Lark integration API client; Added unit tests for MCP configuration API, hooks, icon handling, and definition parsing; Added unit tests for MiniMax-powered media generation skills; Added unit tests for Project Documents and Threads sections; Added unit tests for Streamdown markdown processing; Added unit tests for WeChat QR login and channel connection flows; Added unit tests for agent API, feature flags, and background tasks; Added unit tests for artifact core logic; Added unit tests for citation link rendering and source evidence panels; Added unit tests for citation source extraction and formatting; Added unit tests for clipboard fallback, reasoning trigger, and streamdown sanitization; Added unit tests for code highlighting, animation scheduling, and render activity; Added unit tests for conversation reference metadata and feature capability APIs; Added unit tests for core message handling and sidecar conversation logic; Added unit tests for documentation content integrity; Added unit tests for frontend API client and streaming logic; Added unit tests for frontend authentication core modules; Added unit tests for frontend build scripts and dependency security; Added unit tests for frontend plugin extension system; Added unit tests for global shortcuts and mobile viewport hooks; Added unit tests for i18n context and translation loading; Added unit tests for knowledge scope management and RAGFlow citation provenance; Added unit tests for markdown title extraction utility; Added unit tests for model API, favorites, and reasoning capabilities; Added unit tests for project document and trash management features; Added unit tests for scheduled tasks core logic; Added unit tests for settings persistence, synchronization, and SSR hydration; Added unit tests for skill usage inspection and message details menu interactions; Added unit tests for subagent batch API and type utilities; Added unit tests for subtask lifecycle, rendering, and API logic; Added unit tests for suggestion template placeholder detection; Added unit tests for the RememberSessionOption component; Added unit tests for the notification hook; Added unit tests for the skills module; Added unit tests for thread core logic; Added unit tests for upload API, validation, and file handling; Added unit tests for voice input speech recognition helpers; Added unit tests for workspace capabilities components; Added unit tests for workspace changes API and summary logic; Added unit tests for workspace message components; Added unit tests for workspace settings components and utilities; Expanded test coverage for backend components; Playwright E2E test suite for agents, artifacts, and settings.

Dependencies

DeerFlow 2.2.0-dev: New modular backend architecture and dependency updates

The backend is restructured into a modular workspace with a new \deerflow-harness\ package (version 2.1.0) and a \deerflow-extension-api\ (version 0.2.4) to support a plugin-based extension system. This update upgrades core dependencies to LangGraph 1.x and LangChain 1.x, and introduces optional extras for sandbox providers (E2B, Tenki, OpenSandbox), observability (Monocle), and browser control. The frontend is upgraded to Next.js 16.3.3 and React 19, while the legacy \lite-deep-researcher\ project is removed.

(dependencies) · high confidence

Housekeeping

Documented agent middleware chain and architecture

Added AGENTS.md to document the complete middleware chain, assembly order, and behavioral invariants for the agent harness. The documentation details the sequence of middlewares (from InputSanitization through LoopDetection and TokenBudget), explains message provenance stamping, and clarifies how specific middlewares like ClarificationMiddleware, DurableContextMiddleware, and ToolReceiptMiddleware handle state, errors, and user interactions.

backend/packages/harness/deerflow/agents/middlewares · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 39 → 48 (+9.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 59 → 73 (+14.5)
  • Architecture 93 (new)
  • Maturity 91 → 80 (-10.8)
  • Readiness 17 → 31 (+14.3)
  • Security 52 → 68 (+15.9)
  • Domain Modelling 100 (new)
  • Accessibility 48 (new)

Resolved (124)

  • Boundary-crossing change coupling: page.tsx ↔ artifact-file-list.tsx (frontend/src/app/workspace/chats/[thread_id]/page.tsx)
  • Change coupling: artifact-file-detail.tsx ↔ hooks.ts (frontend/src/components/workspace/artifacts/artifact-file-detail.tsx)
  • Change coupling: en-US.ts ↔ hooks.ts (frontend/src/core/i18n/locales/en-US.ts)
  • Change coupling: en-US.ts ↔ zh-CN.ts (frontend/src/core/i18n/locales/en-US.ts)
  • Change coupling: hero.tsx ↔ whats-new-section.tsx (frontend/src/components/landing/hero.tsx)
  • Change coupling: hooks.ts ↔ hooks.ts (frontend/src/core/notification/hooks.ts)
  • Change coupling: page.tsx ↔ page.tsx (frontend/src/app/workspace/agents/[agent_name]/chats/[thread_id]/page.tsx)
  • Change coupling: types.ts ↔ hooks.ts (frontend/src/core/i18n/locales/types.ts)
  • Change coupling: zh-CN.ts ↔ hooks.ts (frontend/src/core/i18n/locales/zh-CN.ts)
  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • FileTooLong: js/main.js (frontend/public/demo/threads/5aa47db1-d0cb-4eb9-aea5-3dac1b371c5a/user-data/outputs/jiangsu-football/js/main.js)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
  • …and 104 more

New (1818)

  • AioSandbox._render_shell_output (cognitive 16) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox._run_bash_exec (cognitive 63) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox._run_bash_exec (cyclomatic 29) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.close (cognitive 17) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.execute_command (cognitive 23) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.execute_command (cyclomatic 17) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.execute_command_in_scope (cognitive 27) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.execute_command_in_scope (cyclomatic 21) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.glob (cognitive 21) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.grep (cognitive 18) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandbox.list_dir (cognitive 17) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox.py)
  • AioSandboxProvider._load_config (cognitive 20) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox_provider.py)
  • AioSandboxProvider._load_config (cyclomatic 16) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox_provider.py)
  • AioSandboxProvider._reconcile_orphans (cognitive 21) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox_provider.py)
  • AioSandboxProvider._reuse_in_process_sandbox (cyclomatic 17) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox_provider.py)
  • AioSandboxProvider.release (cognitive 16) (backend/packages/harness/deerflow/community/aio_sandbox/aio_sandbox_provider.py)
  • AnchorRule.resolve (cognitive 28) (backend/packages/harness/deerflow/extensions/anchors.py)
  • ArchivePackageReader.read (cognitive 20) (backend/packages/harness/deerflow/skills/review/readers.py)
  • AuthMiddleware.dispatch (cognitive 20) (backend/app/gateway/auth_middleware.py)
  • AuthMiddleware.dispatch (cyclomatic 16) (backend/app/gateway/auth_middleware.py)
  • …and 1798 more

Changes since last survey

  • 300 commits — 85 feature/other, 215 fixes

By area

  • backend/packages — 130 commits
  • (root) — 41 commits
  • frontend/src — 41 commits
  • backend/app — 38 commits
  • backend/tests — 36 commits
  • backend/docs — 4 commits
  • .github/workflows — 2 commits
  • frontend/tests — 2 commits
  • backend/scripts — 1 commit
  • backend/uv.lock — 1 commit
  • examples/deerflow-extension-bookmarks — 1 commit
  • examples/deerflow-extension-jev-classify — 1 commit
  • examples/deerflow-extension-jev-context — 1 commit
  • skills/public — 1 commit

Notable commits

  • fix: Fix backend-unit-tests failure by bringing gateway AGENTS.md under hard size budget (#5725)
  • fix: chore(discord): best-effort flush thread mappings on stop() + restart regression tests (#5461)
  • fix: fix(agent): align unattended prompt with tool policy (#4919)
  • fix: fix(agents): close delegations a stopped run left in progress (#5507)
  • fix: fix(agents): distinguish undeclared and empty skill allowed-tools (#5669)
  • fix: fix(agents): keep queued guard warnings when a model call is retried (#5433)
  • fix: fix(agents): keep settings dialog within the viewport (#5458)
  • fix: fix(agents): keep the token budget across goal continuations of a run (#5410)
  • fix: fix(agents): keep token budget signals for runs without a run_id (#5436)
  • fix: fix(agents): key read_file loop detection on its exact line window (#5486)
  • fix: fix(agents): make create_deerflow_agent's subagent limit, summarization and token_budget features take effect (#5488)
  • fix: fix(agents): remove provider tool-call blocks when guards strip calls (#5447)
  • fix: fix(artifacts): preserve literal percent sequences in file names (#5817)
  • fix: fix(auth): claim the first admin atomically instead of counting first (#5776)
  • fix: fix(auth): enforce write permission for Live Browser WebSockets (#5621)
  • fix: fix(authz): cover create/run/memory/agent routes with permission checks; scope USER.md per user (#4989)
  • fix: fix(backend): validate assistant search pagination (#5506)
  • fix: fix(browser): keep session teardown alive across caller cancellation (#5444)
  • fix: fix(browserless): read reject_resource_types / reject_request_pattern from config (#5719)
  • fix: fix(browserless): read web_fetch wait timeouts like web_capture (#5702)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bytedance/deer-flow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 41e8e75f5650bbb7b783dbb2b69180b48c133a57 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-09659c52afae.