Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
88 commits
Select commit Hold shift + click to select a range
a27112e
chore: regenerate providers and docs [skip ci]
dane-ai-mastra[bot] Jun 29, 2026
1e04ae3
test(playground): standardize the E2E suite on a lint-enforced BDD st…
mfrachet Jun 29, 2026
9265348
fix(core): fix lint formatting in session.ts (#18597)
intojhanurag Jun 29, 2026
0edf3b2
chore: regenerate providers and docs [skip ci]
dane-ai-mastra[bot] Jun 29, 2026
e05dade
fix(server): include inline skills in Dev Portal agent serialization …
intojhanurag Jun 29, 2026
12af22b
chore(docs): Fix harness redirects (#18595)
LekoArts Jun 29, 2026
f151ca5
fix(playground): allow Studio Metrics tab for PostgresStoreVNext (#18…
intojhanurag Jun 29, 2026
2ac7637
fix(mastracode): expand ${VAR} env references in MCP stdio server env…
VihaanAgarwal Jun 29, 2026
c9530b7
fix(ai-sdk): apply editor stored overrides in chatRoute (#18592)
Sandy-1711 Jun 29, 2026
1b8728a
fix(core): in-memory getWorkflowRunById matches by runId when workflo…
abhay-codes07 Jun 29, 2026
9feeaa0
fix(schema-compat): correct inverted zod v4 date min/max descriptions…
abhay-codes07 Jun 29, 2026
60139c2
fix(core): pass mastra and memory to makeCoreTool for processor-added…
tsushanth Jun 29, 2026
7ae6e6d
fix(mastracode): expand ${VAR} references in MCP HTTP server urls (#1…
VihaanAgarwal Jun 29, 2026
cdd5f93
fix(core): preserve thread metadata written mid-run by processors (#1…
intojhanurag Jun 29, 2026
0969845
fix(railway): stop double-building sandbox templates (#18605)
wardpeet Jun 29, 2026
213feb8
fix(core,schema-compat): resolve TS2589 type instantiation depth erro…
wardpeet Jun 29, 2026
40e5f4f
chore: version packages (alpha) (#18537)
dane-ai-mastra[bot] Jun 29, 2026
bfbbb01
fix(core): preserve custom model gateways and surface real gateway er…
wardpeet Jun 29, 2026
ee7b47a
chore(playground): remove remaining playground-ui root imports (#18511)
damien-schneider Jun 29, 2026
848faa0
chore: regenerate providers and docs [skip ci]
dane-ai-mastra[bot] Jun 29, 2026
e62c108
feat(mastracode): add Amazon Bedrock model provider (#17937)
Sri01728 Jun 29, 2026
705ba98
feat(inngest): InngestAgent parity with DurableAgent (#18615)
taofeeq-deru Jun 29, 2026
00e682c
fix(core): catch async title persistence failures in Agent (#18612)
nemphys Jun 29, 2026
c119ce0
chore(docs): Add missing harness redirects (#18625)
LekoArts Jun 29, 2026
d527fa5
feat(mastracode): add hold-to-talk voice input to the TUI (#18624)
abhiaiyer91 Jun 29, 2026
56ea17e
chore: version packages
dane-ai-mastra[bot] Jun 29, 2026
1917c53
feat(core): scheduled agent heartbeats (core + server + client-js) (#…
CalebBarnes Jun 29, 2026
acb2f5c
chore: regenerate providers and docs [skip ci]
dane-ai-mastra[bot] Jun 29, 2026
cceb068
fix(mastracode): wire getNotificationStreamOptions to agent notificat…
devin-ai-integration[bot] Jun 29, 2026
07bf909
Revert notification streamOptions fixes (#18549, #18636) (#18637)
CalebBarnes Jun 29, 2026
58e287b
feat(core): storage-backed suspended-run discovery for HITL approvals…
roaminro Jun 29, 2026
c607ece
feat(memory): expose providerMetadata on observational memory hooks (…
brennanmceachran Jun 29, 2026
142ed7e
chore: regenerate providers and docs [skip ci]
dane-ai-mastra[bot] Jun 30, 2026
65bad83
chore: version packages
dane-ai-mastra[bot] Jun 30, 2026
3227b58
fix(mastracode): restore sandbox grants per thread (#18657)
TylerBarnes Jun 30, 2026
6751821
MastraCode web chat: render via standard Mastra message parts (#18620)
mfrachet Jun 30, 2026
1009f77
feat(core): add processor agent context (#18651)
TylerBarnes Jun 30, 2026
3703bef
Default Agent Builder observational memory to OpenAI gpt-5.4-mini (#1…
YujohnNattrass Jun 30, 2026
b33c77d
Rename AgentController interval background-task API (#18665)
abhiaiyer91 Jun 30, 2026
994b259
fix(evals): extract user message from subscription/signal scorer inpu…
YujohnNattrass Jun 30, 2026
2866f04
fix(core): honor model supportedUrls in durable agent execution (#18649)
rodrigo-rodrigues-pc Jun 30, 2026
cb421de
chore: Fine-tune agent model ID instructions (#18668)
LekoArts Jun 30, 2026
ec80e8d
fix(vercel)!: Rename public API (#18667)
LekoArts Jun 30, 2026
0368766
fix(core): sort in-memory scores listScoresByScorerId by createdAt DE…
abhay-codes07 Jun 30, 2026
6a4a466
fix(client-js): send page/perPage in logs queries when they are 0 (#1…
abhay-codes07 Jun 30, 2026
191b792
Add Latitude to the OpenTelemetry exporter docs (#18621)
guillemwilly Jun 30, 2026
f1c35e8
feat(mastracode): multi-provider voice STT with macOS native engine (…
abhiaiyer91 Jun 30, 2026
9e76ed9
fix(deployer): preserve $ in env values when updating an existing key…
abhay-codes07 Jun 30, 2026
65a66db
fix(mcp): lazily call createRequire to prevent Cloudflare Workers cra…
intojhanurag Jun 30, 2026
d0702ee
fix(schema-compat): preserve unrecognized zod v4 string_format checks…
abhay-codes07 Jun 30, 2026
23c31de
fix(core): honor startExclusive/endExclusive in in-memory listTraces …
abhay-codes07 Jun 30, 2026
bd1fc23
fix(playground): clear setTimeout on unmount in WorkflowNestedGraph (…
devin-ai-integration[bot] Jun 30, 2026
24dac57
chore: version packages (alpha) (#18611)
dane-ai-mastra[bot] Jun 30, 2026
90aeb8b
feat(mastracode): WorkOS auth and GitHub App repo projects for the we…
abhiaiyer91 Jun 30, 2026
ee14cae
File-based agents: config, tools, skills, workspace seeding, and suba…
abhiaiyer91 Jun 30, 2026
345eecc
feat(mastracode): programmatic headless API (runMC) (#18680)
abhiaiyer91 Jun 30, 2026
8be63b0
fix(core): close DurableAgent ↔ Agent parity gaps (phase 1 of 5) (#18…
taofeeq-deru Jun 30, 2026
ed3e42f
Auto-provision per-tenant Turso databases in deployed environments (#…
abhiaiyer91 Jun 30, 2026
7331245
fix(deployer): write file-based agents wrapper after bundler.prepare(…
abhiaiyer91 Jun 30, 2026
1c3f396
fix(mongodb): hardening and data-modeling improvements of storage and…
caseyclements Jun 30, 2026
971decc
feat(inngest): forward FGA actor signal through execution engine (#18…
tiffanybalc Jun 30, 2026
0eed066
fix: remove stray code fence from rag changeset (#18697)
devin-ai-integration[bot] Jun 30, 2026
52415e8
chore: version packages (alpha) (#18684)
dane-ai-mastra[bot] Jun 30, 2026
b4df252
chore(docs): Improve internal agent hints for linting (#18700)
LekoArts Jun 30, 2026
c2f0b7f
Fix background task metadata updates overwriting tool results (#18556)
panliji Jun 30, 2026
0ac14ce
feat(core): reusable createCodingAgent factory and buildBasePrompt (#…
abhiaiyer91 Jun 30, 2026
af17a30
File-based agents: memory.ts convention (#18701)
abhiaiyer91 Jun 30, 2026
cb8153a
chore: version packages
dane-ai-mastra[bot] Jun 30, 2026
e84e791
feat(memory): support inline json prompt injection (#18652)
TylerBarnes Jun 30, 2026
b9d5a7c
chore: regenerate providers and docs [skip ci]
dane-ai-mastra[bot] Jun 30, 2026
d229d13
chore: version packages (alpha) (#18702)
dane-ai-mastra[bot] Jun 30, 2026
6f578ac
feat(memory): add observational memory extractors (#18653)
TylerBarnes Jun 30, 2026
6c86bda
feat: add Mastra Code plugin system (#18658)
TylerBarnes Jun 30, 2026
c83081d
feat: show Mastra Code work and idle timing (#18656)
TylerBarnes Jun 30, 2026
c01012f
feat(memory): add OM-managed working memory (#18654)
TylerBarnes Jun 30, 2026
6df3084
feat(mesa): add workspace filesystem provider
warrenbhw Jun 29, 2026
348cda4
remove MESA_INTEGRATION_PLAN.md
warrenbhw Jun 29, 2026
c5b8d2e
fix(mesa): preserve errors from exists checks
warrenbhw Jun 29, 2026
83abb33
fix(mesa): require repos in provider schema
warrenbhw Jun 29, 2026
f9f7d4b
fix(mesa): surface integration cleanup failures
warrenbhw Jun 29, 2026
6146a09
fix(mesa): align cloud conformance behavior
warrenbhw Jun 30, 2026
c29da2c
fix(mesa): avoid synthetic conformance timestamps
warrenbhw Jun 30, 2026
b910e82
tweak filesystem.mdx
warrenbhw Jun 30, 2026
86357e1
fix(mesa): clean conformance root explicitly
warrenbhw Jun 30, 2026
a81b80c
fix(mesa): use recursive conformance cleanup
warrenbhw Jun 30, 2026
71ec20f
fix(mesa): rely on repo cleanup for cloud tests
warrenbhw Jun 30, 2026
4897570
fix(mesa): skip cloud tests without api key
warrenbhw Jun 30, 2026
66036b2
chore: repair lockfile after rebase
warrenbhw Jun 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
26 changes: 26 additions & 0 deletions .changeset/big-dogs-change.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
'@mastra/core': minor
'mastracode': patch
---

Renamed the AgentController interval API. `heartbeatHandlers` is now `intervalHandlers`, the `HeartbeatHandler` type is now `IntervalHandler`, and the `removeHeartbeat()`/`stopHeartbeats()` methods are now `removeInterval()`/`stopIntervals()`. This better reflects that these are fixed-interval background tasks, not liveness pings, and is distinct from the unrelated `mastra.heartbeats` scheduled-agent feature.

**Before**

```ts
const { controller } = await createMastraCode({
heartbeatHandlers: [{ id: 'sync', intervalMs: 60_000, handler: async () => {} }],
});
await controller.removeHeartbeat({ id: 'sync' });
await controller.stopHeartbeats();
```

**After**

```ts
const { controller } = await createMastraCode({
intervalHandlers: [{ id: 'sync', intervalMs: 60_000, handler: async () => {} }],
});
await controller.removeInterval({ id: 'sync' });
await controller.stopIntervals();
```
5 changes: 5 additions & 0 deletions .changeset/calm-spiders-give.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/core': patch
---

Fixed thread metadata being lost when a processor or working memory writes to it during an agent run. The thread is re-saved when the run finishes, and it was using a stale in-memory snapshot that overwrote any metadata written mid-run via updateThread. The agent now re-reads the latest persisted thread before that save, so mid-run metadata is preserved. Affects all storage backends (Postgres, LibSQL, and others). Fixes #16216.
5 changes: 5 additions & 0 deletions .changeset/chatty-clowns-push.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/rag': minor
---

Added MongoDBConfig to DatabaseConfig, exposing numCandidates for MongoDB Atlas Vector Search queries via the RAG tool layer.
27 changes: 27 additions & 0 deletions .changeset/cold-tigers-move.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
'@mastra/core': minor
---

Added `createCodingAgent` factory and a reusable `buildBasePrompt` so other projects can build a coding agent on top of the same defaults MastraCode uses.

The factory wires sensible, portable defaults that you can override per field:

- **Workspace** — a local filesystem + sandbox rooted at `process.cwd()` (set `basePath`, pass your own `workspace`, or pass `workspace: undefined` to opt out entirely).
- **Task signals** — `TaskSignalProvider` so a task list persists across turns.
- **Error handling** — retries on `ECONNRESET` and bad-request errors, plus prefill and provider-history compatibility processors.
- **Goal judging** — the default goal judge prompt.

`buildBasePrompt` is parameterized with `productName`, `coAuthorName` (both default to "Mastra Code"), and `coAuthorEmail` (defaults to "noreply@mastra.ai"), so you can brand the system prompt and commit trailer without forking it.

```ts
import { createCodingAgent } from '@mastra/core/coding-agent';

const agent = createCodingAgent({
id: 'my-coding-agent',
name: 'My Coding Agent',
model: 'openai/gpt-5',
instructions: 'You help with my project.',
tools: {},
basePath: '/path/to/repo',
});
```
36 changes: 36 additions & 0 deletions .changeset/crisp-geckos-do.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
---
'mastracode': minor
---

Improved push-to-talk voice input in the MastraCode TUI. Enable it with `/voice`, hold the spacebar to dictate, and release to finish — your speech streams into the input box in real time.

**Choose how you dictate**

`/voice` is now an interactive settings menu. You can toggle voice on/off, pick a transcription engine, and (for cloud transcription) pick a provider and model. Run `/voice status` to see the current engine, provider/model, and whether it's ready to use. The quick toggles `/voice on` and `/voice off` still work.

**On-device transcription on macOS**

On macOS, voice now defaults to a native on-device engine (Apple's `SFSpeechRecognizer`). It's free, works offline, and streams words into the input box with low latency — no API key required.

When you turn voice on, the TUI checks the macOS Microphone and Speech Recognition permissions for you and guides you through whatever is needed: if access is blocked it offers to open the exact Privacy & Security pane (and tells you to enable "MastraCode Voice" there); if macOS simply hasn't asked yet, it explains that the first time you hold space it will prompt and you should click Allow. The same guidance appears in `/voice status` and, if dictation ever fails on a permission problem, alongside the error — so you're never left guessing what to do.

**Multiple cloud providers, not just OpenAI**

Cloud transcription is no longer locked to OpenAI Whisper. You can pick from several providers — OpenAI, Groq and other OpenAI-compatible Whisper hosts, plus Deepgram via its own SDK — and choose a model for each. Set the matching API key via the provider's environment variable or `/api-keys`; if a key is missing, `/voice` points you to `/api-keys`.

You still need a local audio recorder on your `PATH` for the cloud engine — `rec`/`sox` (recommended) or `ffmpeg` on macOS, and `pw-record`/`parecord`/`arecord`/`sox` on Linux. Non-macOS systems default to the cloud engine.

**Reliability fixes**

macOS native engine:

- It now triggers the permission prompt and works end-to-end. The on-device recognizer ships as a proper `.app` bundle — `Contents/MacOS/<binary>` plus a generated `Contents/Info.plist` with the Speech Recognition and Microphone usage descriptions — that is ad-hoc signed (`codesign -f -s -`) so the plist binds into the signature.
- The bundle is launched through macOS LaunchServices (`open`), the only launch path that makes macOS show the permission dialogs. A bare command-line executable — even one with an embedded, signed Info.plist — never fires `SFSpeechRecognizer.requestAuthorization`, so the Allow prompt never appeared and the recognizer was silently denied.
- Because a LaunchServices-launched app has no stdin/stdout pipe back to the CLI, the recognizer talks to the TUI over files: it appends newline-delimited JSON events to an events file the engine tails, and the engine asks it to flush a final result and quit by writing a stop sentinel file the recognizer polls for. The engine buffers partial lines so an event split across reads is never dropped, and it lets the recognizer see the stop sentinel before tearing the process down.
- `/voice status` does a real readiness check: it verifies the Swift toolchain and probes the actual Speech Recognition and Microphone permission state, naming exactly which one to enable in System Settings (and explaining the first-run prompt when permission hasn't been requested yet). The probe runs through the same `.app` bundle so it reads authorization under the bundle's TCC identity — probing the loose binary would query a different identity and wrongly report "not granted".
- If the recognizer exits before it can start (suppressed prompt or TCC kill), the engine surfaces a clear, actionable error with its captured output. A not-yet-determined permission state is no longer dressed up as the cause of a real crash, so you no longer see a misleading "macOS will prompt next time" message in red. The recognizer's Swift source and plist ship with the built CLI so the bundle can be built on first use.

Cloud engine:

- The live-partial loop is more robust: non-overlapping ticks and de-duplicated partials, and the terminal callback always fires on stop (final transcript, empty result, or error).
- First-dictation latency is reduced: the provider client is built once per dictation and reused across ticks so its HTTP connection stays warm (keep-alive), removing the DNS + TLS handshake cost that made the first dictation lag. The loop also polls at a short cadence until the recorder produces usable audio, so the opening partial fires as soon as there's something to transcribe.
9 changes: 9 additions & 0 deletions .changeset/durable-agent-parity-phase-1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
'@mastra/core': patch
---

`DurableAgent` now matches `Agent` behavior in three places where the durable loop previously diverged:

- `isTaskComplete` scorers receive `requestContext` as `customContext`, so the same scorer code works on both agents. Only JSON-serializable entries from `requestContext` are forwarded; non-serializable values are dropped. Do not store secrets in `RequestContext` if you persist durable agent snapshots.
- Provider-defined tools (e.g. OpenAI `web_search`) resolve and execute when invoked by the model, instead of surfacing as `ToolNotFoundError`.
- Each iteration of a multi-step durable run produces a distinct assistant `messageId`, matching the non-durable loop and unblocking downstream consumers (signal drains, audit logs, replay) that key off message identity.
18 changes: 18 additions & 0 deletions .changeset/early-spoons-joke.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
'@mastra/inngest': minor
---

Added support for the fine-grained authorization (FGA) `actor` signal on the Inngest execution engine.

Workflows running on the Inngest engine can now pass a trusted `actor` through `run.start()`, `startAsync()`, `resume()`, `stream()`, and `timeTravel()`. The signal is re-threaded across durable step and nested-workflow boundaries, so every nested agent, tool, and memory FGA check sees the same actor. Previously `actor` was only threaded through the default engine, so trusted background workflows on Inngest lost the membership bypass at each step re-entry.

**Usage**

```ts
const run = await workflow.createRun();
await run.start({
inputData,
requestContext, // includes organizationId / tenant scope
actor: { actorKind: 'system', sourceWorkflow: 'nightly-sync' },
});
```
5 changes: 5 additions & 0 deletions .changeset/eighty-points-sneeze.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/core': patch
---

add agent reference to processor execution context
18 changes: 18 additions & 0 deletions .changeset/few-planets-invite.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
'@mastra/mesa': minor
---

Added a Mesa filesystem provider for Mastra workspaces.

```ts
import { Workspace } from '@mastra/core/workspace';
import { MesaFilesystem } from '@mastra/mesa';

const workspace = new Workspace({
filesystem: new MesaFilesystem({
apiKey: process.env.MESA_API_KEY,
org: 'acme',
repos: [{ name: 'docs', bookmark: 'main' }],
}),
});
```
5 changes: 5 additions & 0 deletions .changeset/fix-client-js-logs-pagination-zero.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/client-js': patch
---

Fix `listLogs` and `getLogForRun` dropping the `page` and `perPage` query parameters when they are `0`. Requesting the first page with `page: 0` (or `perPage: 0`) now sends those values instead of falling back to the server defaults. Closes #18631.
5 changes: 5 additions & 0 deletions .changeset/fix-deployer-env-dollar-corruption.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/deployer': patch
---

Fix `FileEnvService.setEnvValue` corrupting env values that contain `$` when updating an existing key. Values such as database URLs and passwords that include `$&`, `$$`, or `$1` are now written exactly as provided instead of being mangled by `String.prototype.replace` special patterns. Closes #18633.
12 changes: 12 additions & 0 deletions .changeset/fix-fs-agents-dev-entry-write-order.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
---
'@mastra/deployer': patch
'mastra': patch
---

Fix `ENOENT: .mastra-fs-agents-entry.mjs` when running `mastra dev`/`mastra build` in a project that uses file-based agents. The generated fs-agents wrapper entry was written before `bundler.prepare()` emptied the output directory, so it was wiped before the bundler could read it. Wrapper generation is now split: `prepareFsAgentsEntry` returns the generated source without writing, and the new `writeFsAgentsEntry` writes it after `prepare()` runs.

```ts
const fsAgents = await prepareFsAgentsEntry({ entryFile, mastraDir, outputDirectory });
await bundler.prepare(outputDirectory); // empties output dir
await writeFsAgentsEntry(fsAgents); // wrapper now survives for the bundler
```
5 changes: 5 additions & 0 deletions .changeset/fix-inmemory-getworkflowrunbyid-optional-name.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/core': patch
---

Fix in-memory workflow storage `getWorkflowRunById` returning `null` when `workflowName` is omitted. `workflowName` is optional in the storage contract and the pg/libsql adapters match by `runId` alone when it is not provided, but the in-memory store always compared `workflow_name === workflowName`, which never matched for an undefined name. It now matches by `runId`, only filters by `workflowName` when provided, and returns the most recent run for parity with the persistent adapters. Closes #18585.
5 changes: 5 additions & 0 deletions .changeset/fix-inmemory-observability-exclusive-bounds.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/core': patch
---

Fix in-memory observability `listTraces` ignoring the `startExclusive` and `endExclusive` flags on `startedAt`/`endedAt` filters. Exclusive date-range bounds now drop a trace that sits exactly on the boundary, matching the pg/libsql adapters (and the in-memory log/metric filters). Closes #18635.
5 changes: 5 additions & 0 deletions .changeset/fix-inmemory-scores-scorerid-sort.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/core': patch
---

Fix in-memory scores store `listScoresByScorerId` returning scores in insertion order instead of newest first. The pg and libsql adapters order by `createdAt DESC`, and the sibling `listScoresBySpan` already does, so the in-memory store now sorts the same way before paginating. Closes #18618.
5 changes: 5 additions & 0 deletions .changeset/fix-schema-compat-v4-string-format-drop.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/schema-compat': patch
---

Fix the Zod v4 string handler silently dropping unrecognized `string_format` checks. Formats without a textual description (such as `ipv4`, `ipv6`, `datetime`, `date`, `time`, `base64`, `cuid2`, `ulid`, `nanoid`, `jwt`) are now preserved as validation instead of being removed, so schemas using them keep rejecting invalid input. Closes #18634.
5 changes: 5 additions & 0 deletions .changeset/fix-zod-v4-date-constraint-descriptions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/schema-compat': patch
---

Fix inverted date constraint descriptions in the Zod v4 schema handler. `z.date().min()` and `z.date().max()` were described with their bounds swapped (a lower bound was labelled "older than" and an upper bound "newer than"), so the schema sent to the model stated the opposite and impossible constraint. The handler now matches Zod semantics and the existing v3 handler. Closes #18581.
5 changes: 5 additions & 0 deletions .changeset/floppy-towns-notice.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/railway': patch
---

Fixed Railway sandbox templates so they are built once during sandbox creation.
13 changes: 13 additions & 0 deletions .changeset/forty-carpets-unite.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@mastra/memory': minor
'@mastra/core': patch
---

add observational memory extractors

Introduces a public Extractor API for Observational Memory
with inline XML extraction and structured follow-up modes.
Includes built-in extractors for current task, suggested
response, and thread title. Persists extracted values into
thread OM metadata with key-level merging and carry-forward
into future observer/reflector prompts.
16 changes: 16 additions & 0 deletions .changeset/fs-agents-cli.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
'mastra': minor
---

`mastra dev` and `mastra build` now pick up file-based agents defined under `src/mastra/agents/<name>/`. Agents created this way appear in Studio and respond just like agents registered in code, and the two styles can be mixed in one project. Files committed under `agents/<name>/workspace/` are mirrored into the agent's workspace so it starts with them on disk. Agents can also declare subagents under `agents/<name>/subagents/<childId>/`, which the agent can delegate to as a tool named after the directory.

```text
src/mastra/agents/weather/
config.ts # export default agentConfig({ model: 'openai/gpt-4o' })
instructions.md
tools/get_weather.ts
```

```bash
mastra dev # discovers and registers src/mastra/agents/weather automatically
```
14 changes: 14 additions & 0 deletions .changeset/fs-agents-deployer.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
'@mastra/deployer': minor
---

You can now define agents by file convention instead of registering each one in code: drop a directory under `src/mastra/agents/<name>/`, run a Mastra build/dev, and the agent is bundled and registered onto your Mastra instance automatically. A directory becomes an agent when it has a `config.ts` or `instructions.md`; `tools/*.ts` add tools, `skills/` add skills (a `createSkill()` module, a packaged `SKILL.md` with its `references/`, or a flat `<skill>.md`), a `memory.ts` default export supplies the agent's `memory`, and `subagents/<childId>/` (one level deep) add delegatable subagents. Each agent gets a default workspace unless `workspace.ts` / `config.workspace` overrides it, and files committed under `agents/<name>/workspace/` are mirrored into the bundle to seed that workspace at runtime. Projects with no file-based agents are unaffected — the original entry is used unchanged.

```text
src/mastra/agents/weather/
config.ts # export default agentConfig({ model: 'openai/gpt-4o' })
instructions.md
memory.ts # export default new Memory()
tools/get_weather.ts
workspace/cities.json # mirrored into the agent's workspace
```
12 changes: 12 additions & 0 deletions .changeset/fs-agents-server-source.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
---
'@mastra/server': patch
---

Allow `'fs'` as an agent/scorer definition source in the server handlers and response schemas. File-based agents are registered with `source: 'fs'`, and the scorer/agent list endpoints now surface and validate that value instead of failing schema validation.

```ts
// GET /api/agents now returns file-based agents alongside code/stored ones:
{
"weather": { "name": "weather", "source": "fs" /* was rejected before */ }
}
```
5 changes: 5 additions & 0 deletions .changeset/full-numbers-occur.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/server': patch
---

Fixed inline skills (created via createSkill()) not appearing in the Dev Portal. The server now uses agent.listSkills() and agent.getSkill() which return both inline and workspace skills, instead of only querying workspace skills.
5 changes: 5 additions & 0 deletions .changeset/gateway-redos-fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@mastra/core': patch
---

Fix a polynomial ReDoS in the model gateway error matcher. The `Missing .+ environment variable` pattern used to classify expected missing-auth errors could backtrack catastrophically on adversarial error messages; it now uses `Missing [^ ]+ environment variable`, which matches the same real messages without the ambiguous overlap.
Loading