## MervinPraison/PraisonAI — v4.7.6…v4.7.7

_238+ commits._

### Features
- **feat: add LSP call-hierarchy and go-to-implementation navigation tools (fixes #5027)** (b73d4e9)
- **feat(ts): a team's autonomy reaches members that declared none** (1b740dc)
- **feat(ts): a team-wide toolsRunOn places every member in ONE sandbox** (5e3db52)
- **feat(ts): human sign-off on a task's output** (84747ad)
- **feat(ts): compute providers become toolsRunOn places** (0fbf07f)
- **feat(workflows): typed workflow state** (463ae56)
- **feat(eval): load task sets from JSONL and export passing runs as SFT data** (d12a37a)
- **feat(ts): compute providers — where an agent's tools run** (9ed7a83)
- **feat(agents): a team can resume instead of restarting** (d25a188)
- **feat(workflows): N-agent discussion loop** (88405e7)
- **feat(knowledge): load sources from S3, GCS and Azure blob storage** (7dd1b44)
- **feat(tools): provider-hosted tools work on any Agent** (d9ac52f)
- **feat(session): encrypt transcripts at rest** (fbe4ca7)
- **feat(eval): fingerprint the setup a run was scored under** (d51ce39)
- **feat: render a workflow's definition as a mermaid diagram** (0993e07)
- **feat: close two capability gaps found by reading seven competitor frameworks (#4933)** (f4a6acd)

### Fixes
- **Merge pull request #4981 from MervinPraison/fix/typed-workflow-state** (9497a37)
- **Merge pull request #4969 from MervinPraison/fix/breaker-double-count-and-trust-fail-open** (e7f92ee)
- **fix: address plugin-tool wiring review findings (#5018)** (31e24df)
- **fix: robust LSP navigation — location-link normalization, all call-hierarchy items, graceful capability degradation** (c72b932)
- **fix: resolve archived-recall gaps in session search (Issue #5031)** (409ee5f)
- **fix: harden memory consolidation loss guard + runtime type hints** (6835246)
- **fix: wire plugin-provided tools into agent toolset (fixes #5018)** (67cd813)
- **fix: consolidate sync→async dispatch scaffolding into one bridge helper (fixes #5026)** (e5bd0aa)
- **fix: treat reply-to-bot as implicit mention in mention_only groups (fixes #5029)** (f03af1b)
- **fix: add control-trust provenance primitive to gateway inbound contract (fixes #5019)** (158991c)
- **fix: add MemoryConsolidation protocol + loss-guard contract (fixes #5030)** (07e2663)
- **fix: make session_search recall compacted (archived) history (fixes #5031)** (8f45715)
- **fix: remove dead config constants in _config.py (fixes #5024)** (4366680)
- **fix: record tool timeouts on breaker; refresh stale root pin; isolate trust test** (97ff8c7)
- **fix: circuit breaker counted every outcome twice; trust lookup failed open** (225dae3)
- **Merge pull request #4966 from MervinPraison/fix/spider-ssrf-octal** (1efaf04)
- **Merge pull request #5009 from MervinPraison/fix/ts-team-autonomy** (d711bf6)
- **fix(ts): propagated autonomy builds its gate; sandbox host-fallback is not silent** (ee3be74)
- **Merge pull request #5004 from MervinPraison/fix/ts-task-human-review** (7e9e1c7)
- **Merge pull request #5007 from MervinPraison/fix/ts-toolsrunon-wiring** (7da2488)
- **fix(ts): review full task output and reject non-boolean verdicts** (5c5583d)
- **Merge pull request #5000 from MervinPraison/fix/eval-jsonl-and-sft** (a1d4ac0)
- **fix(ts): close three toolsRunOn gaps found in review** (704c825)
- **Merge pull request #5003 from MervinPraison/fix/ts-compute-providers** (e75d270)
- **Merge pull request #5002 from MervinPraison/fix/team-checkpoint-resume** (b9d5319)
- **Merge pull request #5001 from MervinPraison/fix/n-agent-discussion** (c2468ac)
- **Merge pull request #4977 from MervinPraison/fix/cloud-knowledge-sources** (f6713fb)
- **Merge pull request #4976 from MervinPraison/fix/hosted-tools-on-any-agent** (124706a)
- **Merge pull request #4973 from MervinPraison/fix/encrypted-session-store** (3fac82f)
- **fix(eval): report physical JSONL line, export dataset helpers, correct docs** (48c4ae2)
- **Merge pull request #4971 from MervinPraison/fix/eval-run-fingerprint** (385649b)
- **Merge pull request #4970 from MervinPraison/fix/workflow-definition-diagram** (68cfb8d)
- **Merge pull request #4960 from MervinPraison/fix/test-isolation-continue** (ebc89c8)
- **fix(ts): enforce Docker timeout in-container and fail loudly on cleanup** (3ab158b)
- **fix(agents): harden team checkpoint restore against silent corruption** (7982ee3)
- **fix(workflows): propagate Discussion stop, nested dispatch, exports** (a633c7b)
- **fix(hooks): no HookEvent member can silently swallow a registration (#4998)** (f887a50)
- **fix(bot): Windows autostart wrote a %APPDATA% directory into the repo (#4996)** (0afc522)
- **fix(hooks): emit SCHEDULE_ADD and SCHEDULE_REMOVE from the schedule store (#4993)** (bd66080)
- **fix(hooks): the 7 declared-but-never-emitted lifecycle events now fire (#4994)** (b2050e1)
- **fix(knowledge): clear reported success when nothing was cleared (#4991)** (e359e89)
- **fix(mcp): CLI printed literal [bold] tags instead of formatted text (#4989)** (17bc20a)
- **Merge remote-tracking branch 'origin/fix/spider-ssrf-octal' into fix/spider-ssrf-octal** (2662261)
- **Merge remote-tracking branch 'origin/main' into fix/spider-ssrf-octal** (81cf6d1)
- **fix(core): make four accepted-and-ignored config knobs real (#4975)** (be1961a)
- **Merge pull request #4963 from MervinPraison/fix/project-identity-pin** (0b2db6f)
- **fix(knowledge): bind Azure account, stream blobs, decode keys, fix cloud citations & cleanup** (9d3d6d3)
- **fix(tools): hosted tools survive default Agent path, cache-key config, shape validation** (b84ebc5)
- **fix(session): encrypt runtime turns and tool_calls, guard legacy metadata** (8d9f6d3)
- **fix(code): a shell that does not lie, real OS containment, and four unreachable capabilities (#4965)** (f9c7043)
- **fix(tools): the SDK shell executor reported success for work it never did (#4968)** (39d6a7f)
- **fix(ts): five paths returned fabricated results and reported success (#4967)** (2d145ab)
- **fix(eval): export fingerprint API and drop duplicate lazy entries** (1cd329d)
- **Merge pull request #4962 from MervinPraison/fix/mcp-cli-defects** (b4c2007)
- **Merge pull request #4961 from MervinPraison/fix/green-the-agents-suite** (22e70cb)
- **fix: connect nested controls, dedupe Route default, expand Include in diagram** (b201386)
- **Merge pull request #4957 from MervinPraison/fix/openapi-composed-bodies** (be29268)
- **fix(identity): repair stale root-commit pin; make SSRF tests hermetic** (86cc439)
- **fix(security): octal-encoded loopback bypassed the spider SSRF guard** (35bada3)
- **fix(mcp): make todo tools interoperate with the runtime store, and drop unmatchable recipe source labels** (3c23ced)
- **fix(identity): heal a stale root-commit pin instead of only distrusting it** (bb30be5)
- **fix(identity): creating an orphan branch could reassign the project id** (a0bebea)
- **fix(mcp): list-recipes never worked, and the todo tools read a store nothing writes** (30e53d6)
- **fix: green the two pre-existing praisonai-agents failures** (c1ddaea)
- **fix(openapi): honour additionalProperties:false as a closed empty body** (8912e1c)
- **fix(openapi): a body schema without top-level properties sent an empty body** (9af9edc)
- **Merge pull request #4955 from MervinPraison/fix/openapi-origin-pin** (51fc94d)
- **fix(openapi): reject same-host scheme downgrades in origin pin** (30474ba)
- **fix(openapi): pin credentialed requests to the configured origin** (5bfb7d0)
- **fix: harden AgentApproval reviewer against prompt injection (#4954)** (394a92f)
- **fix: bridge remote-sandbox agent media into outbound delivery (fixes #4951) (#4953)** (09c891a)
- **fix: enforce ApprovalRequest.liveness so stale approvals fail closed (#4950)** (3f1788e)
- **fix(code): six commands that reported success for work they did not do (#4943)** (e7acc60)
- **fix: a broken knowledge base no longer looks like an empty one — plus the reason nobody noticed (#4939)** (592e1c3)
- **fix: guard concurrent handoffs, AgentTeam re-entrancy, and approval scope leak (#4938)** (836cd71)
- **Merge pull request #4944 from MervinPraison/fix/rust-placeholders-fail-loud** (a037b0c)
- **fix(cli): workflow exit codes, .praisonai path drift, dropped CLI options (#4946)** (8a1dd56)
- **fix(workflows): loop body output_variable results were silently discarded (#4947)** (857e351)
- **fix: copy-on-write observability run stack + lazy-cache cooldown tests** (c8738a3)
- **fix: async completion persistence, per-task observability, lazy-cache cool-down (fixes #4945)** (348e494)
- **fix(bot): declared platform wins, slack can start, bots stay up, failures exit non-zero (#4942)** (1b122d0)
- **Merge pull request #4940 from MervinPraison/fix/async-path-compensation** (e90dc88)
- **fix(ts): stop 13 observability adapters claiming to send telemetry they discard (#4941)** (0e8aceb)
- **fix(rust): stop RAG::query and Judge::judge fabricating results** (1f38643)
- **fix(llm): the async path silently lost tool calls emitted as text** (71e7e06)
- **fix: remove dead ManifestStorage module in standardise (fixes #4934)** (37571d3)
- **fix(ci): use GitHub MCP get_* tool names in merge gate assess (#4926)** (f625d4b)
- **fix(workflows): parallel branch output_variable results were silently discarded (#4932)** (a1cb756)
- **fix: make google-adk extra resolvable (#4931)** (e4b2678)

### Backend
- **Release v4.7.7** (c136fe4)
- **Merge pull request #5035 from MervinPraison/claude/issue-5019-20260910-1654** (27ec92d)
- **Merge pull request #5036 from MervinPraison/claude/issue-5029-20260910-1654** (b7ca09a)
- **Merge pull request #5033 from MervinPraison/claude/issue-5031-20260910-1654** (e53c11a)
- **Merge pull request #5034 from MervinPraison/claude/issue-5030-20260910-1654** (96e9a70)
- **Merge pull request #5041 from MervinPraison/claude/issue-5018-20260910-1655** (f6dfafe)
- **Merge pull request #5038 from MervinPraison/claude/issue-5026-20260910-1654** (c464113)
- **Merge pull request #5037 from MervinPraison/claude/issue-5027-20260910-1654** (d17cd7b)
- **Merge pull request #5032 from MervinPraison/claude/issue-5024-20260910-1654** (8d2b4cd)
- **Merge pull request #4948 from MervinPraison/claude/issue-4945-20260908-0825** (d9650d5)
- **Merge pull request #4935 from MervinPraison/claude/issue-4934-20260907-1617** (172cd3c)

### Tests
- **test: add Telegram adapter reply-to-bot admission coverage (#5029)** (4c5a850)
- **test: cover dispatch_maybe_awaitable branches (addresses Qodo #227433)** (7c99f4c)
- **test(chat): assert --continue prefers the project store over the unified fallback** (364f1d2)
- **test: move test_botos_integration.py out of tests/unit** (5699b68)
- **test(chat): --continue tests read the developer's real session store** (e0ccc0c)

### Docs
- **docs: auto-update api.md [skip ci]** (e8cb8b8)
- **docs: auto-update documentation parity trackers [skip ci]** (923daca)
- **docs: auto-update documentation parity trackers [skip ci]** (9c2ee01)
- **docs: auto-update feature parity trackers [skip ci]** (ecc67a9)
- **docs: auto-update documentation parity trackers [skip ci]** (b6c2498)
- **docs: auto-update documentation parity trackers [skip ci]** (c2eeba5)
- **docs: auto-update documentation parity trackers [skip ci]** (0bde2ec)
- **docs: auto-update api.md [skip ci]** (768cd0c)
- **docs: auto-update documentation parity trackers [skip ci]** (e23965d)
- **docs: auto-update api.md [skip ci]** (aed4df0)
- **docs: auto-update documentation parity trackers [skip ci]** (855fae2)
- **docs: auto-update documentation parity trackers [skip ci]** (5b68f33)
- **docs: auto-update feature parity trackers [skip ci]** (f3d10e7)
- **docs: auto-update api.md [skip ci]** (1e978c1)
- **docs: auto-update documentation parity trackers [skip ci]** (4149cf4)
- **docs: auto-update api.md [skip ci]** (7579cc3)
- **docs: auto-update feature parity trackers [skip ci]** (23ba30f)
- **docs: auto-update api.md [skip ci]** (bab7390)
- **docs: auto-update documentation parity trackers [skip ci]** (3fe0789)
- **docs: auto-update documentation parity trackers [skip ci]** (f8ce1e2)
- **docs: auto-update documentation parity trackers [skip ci]** (5552f26)
- **docs: auto-update feature parity trackers [skip ci]** (4b807be)
- **docs: auto-update documentation parity trackers [skip ci]** (a28a65b)
- **docs: auto-update documentation parity trackers [skip ci]** (2a89369)
- **docs: auto-update feature parity trackers [skip ci]** (5a3473c)
- **docs: auto-update documentation parity trackers [skip ci]** (bbe586c)
- **docs: auto-update documentation parity trackers [skip ci]** (a2cd71e)
- **docs: auto-update api.md [skip ci]** (ee64c29)

### Chore
- **refactor: drop unused internal flag, keep control-trust primitive minimal** (7583f55)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/MervinPraison/PraisonAI?utm_source=github-action)._