From c6debbfbc1dad52c66b6f6b7ccf1f4bd0c098545 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 16:53:16 +0000 Subject: [PATCH] Version Packages --- .changeset/model-type-extrabody.md | 44 ------------------------------ CHANGELOG.md | 44 ++++++++++++++++++++++++++++++ package.json | 2 +- src/version.ts | 2 +- 4 files changed, 46 insertions(+), 46 deletions(-) delete mode 100644 .changeset/model-type-extrabody.md diff --git a/.changeset/model-type-extrabody.md b/.changeset/model-type-extrabody.md deleted file mode 100644 index 2fcbb89..0000000 --- a/.changeset/model-type-extrabody.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -'smart-decisions': minor ---- - -**Breaking (pre-1.0):** the provider settings on `Question` moved into a new `Model` type. - -- `apiBaseUrl`, `apiKey` and `model` no longer sit flat on `Question`; they are now - `question.model.{apiBaseUrl, apiKey, model}`. This groups everything about how the - model is reached and served into one reusable object to pass to every `choice()`. -- `Model` gains `extraBody`: extra fields forwarded verbatim into the chat completions - request body for engine- or model-specific settings (i.e. `chat_template_kwargs` - thinking toggles on llama.cpp/vLLM/SGLang, `reasoning_effort` on OpenAI/OpenRouter/ - Ollama, Ollama's native `think`). Reserved request keys the library's single-token - trick depends on (`model`, `messages`, `stream`, `logprobs`, `top_logprobs`, - `max_tokens`, `temperature`) cannot be overridden through it; `chat_template_kwargs` - merges one level deep with user keys winning per key. -- System 1's request now asks for `top_logprobs: 20` instead of 50: 20 is the highest - portable window (OpenAI and OpenRouter cap it at 20, vLLM's server default - `--max-logprobs` is 20). On llama.cpp (accepts up to 50) the smaller window is - enough for realistic option counts. -- New `Model` type exported from the package root; `generateText` accepts extra - top-level body fields via `ChatCompletionRequest`'s index signature. - -### Hardening - -- The transport no longer follows redirects (`redirect: 'error'`): the Bearer token - stays off unexpected paths, and a misconfigured base URL fails loudly. -- Response bodies are read under a 10 MB safety cap instead of being buffered - unconditionally; an over-cap body fails fast and is not retried. A declared - `Content-Length` over the cap is refused before reading anything. -- Non-finite `maxRetries` (i.e. `NaN`) no longer causes an infinite retry loop: it - falls back to the default, negatives clamp to 0 and fractions to whole attempts. -- `extraBody` ignores `__proto__` and `constructor` keys, so prototype-smuggled - config can never re-parent the request object. -- Malformed entries inside `top_logprobs` (missing/null token) are skipped instead - of crashing mid-read. -- Error messages strip query strings from the request URL, so providers that take - credentials as query parameters cannot leak them into logs. -- The endpoint path is joined through the URL API, preserving a query string in - `apiBaseUrl` instead of swallowing it, and an invalid base URL throws a clear - `Invalid model.apiBaseUrl` error. -- CI actions are pinned by commit SHA; the release script spawns every subprocess - as an argv array (no shell), so interpolated values can never be re-parsed as - shell syntax. diff --git a/CHANGELOG.md b/CHANGELOG.md index 072da5b..caef3e0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,49 @@ # smart-decisions +## 0.3.0 + +### Minor Changes + +- [#12](https://github.com/expilu/smart-decisions/pull/12) [`87127d5`](https://github.com/expilu/smart-decisions/commit/87127d58d79a06c086945782aea9f5b848a39149) Thanks [@expilu](https://github.com/expilu)! - **Breaking (pre-1.0):** the provider settings on `Question` moved into a new `Model` type. + + - `apiBaseUrl`, `apiKey` and `model` no longer sit flat on `Question`; they are now + `question.model.{apiBaseUrl, apiKey, model}`. This groups everything about how the + model is reached and served into one reusable object to pass to every `choice()`. + - `Model` gains `extraBody`: extra fields forwarded verbatim into the chat completions + request body for engine- or model-specific settings (i.e. `chat_template_kwargs` + thinking toggles on llama.cpp/vLLM/SGLang, `reasoning_effort` on OpenAI/OpenRouter/ + Ollama, Ollama's native `think`). Reserved request keys the library's single-token + trick depends on (`model`, `messages`, `stream`, `logprobs`, `top_logprobs`, + `max_tokens`, `temperature`) cannot be overridden through it; `chat_template_kwargs` + merges one level deep with user keys winning per key. + - System 1's request now asks for `top_logprobs: 20` instead of 50: 20 is the highest + portable window (OpenAI and OpenRouter cap it at 20, vLLM's server default + `--max-logprobs` is 20). On llama.cpp (accepts up to 50) the smaller window is + enough for realistic option counts. + - New `Model` type exported from the package root; `generateText` accepts extra + top-level body fields via `ChatCompletionRequest`'s index signature. + + ### Hardening + - The transport no longer follows redirects (`redirect: 'error'`): the Bearer token + stays off unexpected paths, and a misconfigured base URL fails loudly. + - Response bodies are read under a 10 MB safety cap instead of being buffered + unconditionally; an over-cap body fails fast and is not retried. A declared + `Content-Length` over the cap is refused before reading anything. + - Non-finite `maxRetries` (i.e. `NaN`) no longer causes an infinite retry loop: it + falls back to the default, negatives clamp to 0 and fractions to whole attempts. + - `extraBody` ignores `__proto__` and `constructor` keys, so prototype-smuggled + config can never re-parent the request object. + - Malformed entries inside `top_logprobs` (missing/null token) are skipped instead + of crashing mid-read. + - Error messages strip query strings from the request URL, so providers that take + credentials as query parameters cannot leak them into logs. + - The endpoint path is joined through the URL API, preserving a query string in + `apiBaseUrl` instead of swallowing it, and an invalid base URL throws a clear + `Invalid model.apiBaseUrl` error. + - CI actions are pinned by commit SHA; the release script spawns every subprocess + as an argv array (no shell), so interpolated values can never be re-parsed as + shell syntax. + ## 0.2.0 ### Minor Changes diff --git a/package.json b/package.json index 1c748a3..6ac3082 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "smart-decisions", - "version": "0.2.0", + "version": "0.3.0", "description": "A TypeScript library that returns choices from System 1 (logit-based) or System 2 (LLM structured output) intelligence.", "type": "module", "scripts": { diff --git a/src/version.ts b/src/version.ts index 3901953..cf853e9 100644 --- a/src/version.ts +++ b/src/version.ts @@ -4,4 +4,4 @@ * Shown to servers in the `User-Agent` header of every request. Kept in sync * with package.json by `test/version.test.ts`; bump both on release. */ -export const VERSION = '0.2.0'; +export const VERSION = '0.3.0';