0.12.3
A security patch. All six packages move to 0.12.3 together. The spec revision stays 1.0.0-draft.8. Details are in the advisory, GHSA-4pcf-49g3-h325: who is affected, workarounds, and what isn’t covered.
What changed
@silverprotocol/corerequires zod 4.4.0 or later. With an older zod,AgEvent.parse()could give a receivedext.*event a prototype taken from its own__proto__member. Three side effects:- An application that pins an older zod for itself gets a second copy of zod for core.
- An application that combines core’s exported schemas with its own zod should move its own zod to 4.4.0 or later.
overridesorresolutionsthat force zod below 4.4.0 defeat the requirement. Remove them, or decode withingestAgEvent().
- Claude Agent SDK: a model name in the native
modelUsageno longer sets the prototype ofusage.byModelor ofmodelUsageinext.anthropic.result-meta, and asupersedeslist is copied like the other carries. - Vercel AI SDK: an emitted value never holds a member named
__proto__, at any depth, and a step’s stop details inmessage.metadatano longer take their prototype from one; the members beside it are carried as before. - Google ADK: a member named
__proto__in a native is dropped at every depth, and the unparsed-native carry no longer takes its prototype from one. - OpenAI Agents SDK: a host error’s usage reaches
turn.errorcopied, without an own__proto__key; a well-formed usage is unchanged. A host usage that isn’t a valid usage once that key is dropped is no longer put onturn.error; it ridesext.openai.unparsedinstead.
What to do
- Upgrade every
@silverprotocol/*package to 0.12.3, including where another package pins one (check your lockfile). - If your application decodes received events with
AgEvent.parse()oringestAgEvent(), upgrade core now. Versions of core before 0.6.4 are being deprecated on npm. - Review the advisory for what to check in application code that copies values taken from events.