0.12.1

Security patch: Google ADK stops carrying an A2A relay's forwarded request

A security patch. All six packages move to 0.12.1 together, and only @silverprotocol/google-adk changes. The spec revision stays 1.0.0-draft.8. Details are in the advisory, GHSA-685v-3m98-6f7p.

What changed

  • Google ADK no longer carries an A2A relay’s bookkeeping. When a run relays a conversation through @google/adk’s RemoteA2AAgent, ADK records its exchange with the remote agent in the customMetadata of the events it relays, under a2a:request, a2a:response, a2a:task_id and a2a:context_id. The forwarded request can hold the host’s A2A push-notification token and credentials, request metadata, local ids and the conversation it forwards. Before 0.12.1, the normalizer copied customMetadata unchanged into provider-raw blocks, and a relayed event it couldn’t map reached an ext.google.unparsed event with its native copy intact.
  • 0.12.1 drops those four entries from each event’s customMetadata, and from the native copy in an ext.google.unparsed event under either spelling of the field (customMetadata or custom_metadata). Every other entry still rides, and no customMetadata member is emitted when none remains. The package’s README documents this exception to draft.8’s carry of unmapped ADK event fields.
  • No recorded stream carries these entries, so none changes.

Who is affected

An application on @silverprotocol/google-adk 0.3.0 to 0.12.0 (the versions before 0.12.1 that declare @google/adk as a peer) that either runs an agent tree containing a RemoteA2AAgent, or feeds the normalizer ADK events serialized from ADK-Python’s relay. An application that doesn’t relay to a remote A2A agent isn’t affected.

What to do

  1. Upgrade every @silverprotocol/* package to 0.12.1, including where another package pins one (check your lockfile), and rebuild any image that bundles the normalizer.
  2. If AgJSON events from an affected version were forwarded or persisted while your application relayed through a RemoteA2AAgent, rotate the credentials the advisory lists, starting with the A2A push-notification token and credentials.
  3. Purge stored provider-raw blocks, and ext.google.unparsed events whose native carries a2a:* entries in customMetadata or custom_metadata.

Not covered

These are unchanged in every version, 0.12.1 included:

  • other customMetadata entries, which 0.12.1 still carries;
  • copies of ADK’s native events that your application reads, stores or forwards itself;
  • copies ADK keeps or forwards itself;
  • a remote agent that repeats the forwarded message in its reply, which @google/adk yields as the relay’s own output. Upgrading doesn’t stop this. The advisory describes a RemoteA2AAgent afterRequestCallbacks entry that removes the repeated message from a response in the submitted state, and what to rotate and purge for it. ADK’s own copies and the repeated message have been reported to Google. For the repeated message in the events this package emits, 0.12.2 addresses it; see its release note.