release: 4.1.0 - #93
stainless-app[bot] wants to merge 140 commits into
Conversation
fix(client): mark some request bodies as optional
Note that we still want to run tests, as these depend on the metadata.
Pin all GitHub Actions referenced in generated workflows (both first-party `actions/*` and third-party) to immutable commit SHAs. Updating pinned actions is now a deliberate codegen-side bump rather than implicit on every workflow run.
…t in workflow templates
| @@ -0,0 +1,27 @@ | |||
| #!/usr/bin/env bash | |||
| set -exuo pipefail | |||
There was a problem hiding this comment.
The artifact uploader enables shell tracing while inserting the GitHub OIDC token into an Authorization header and the signed upload URL into curl. GitHub Actions captures this stderr output, so users with access to the build log can obtain reusable credentials. Disable tracing before handling credentials and avoid verbose output containing signed URLs.
How this was verified: The workflow passes an OIDC token as AUTH, and Bash expands that value and the signed URL into traced commands written to stderr.
Prompt To Fix With AI
This is a comment left during a code review.
Path: scripts/utils/upload-artifact.sh
Line: 2
Comment:
**Credentials Leak Into Logs**
The artifact uploader enables shell tracing while inserting the GitHub OIDC token into an `Authorization` header and the signed upload URL into `curl`. GitHub Actions captures this stderr output, so users with access to the build log can obtain reusable credentials. Disable tracing before handling credentials and avoid verbose output containing signed URLs.
**How this was verified:** The workflow passes an OIDC token as `AUTH`, and Bash expands that value and the signed URL into traced commands written to stderr.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| from .voice_deployment import VoiceDeployment as VoiceDeployment | ||
| from .voice_create_params import VoiceCreateParams as VoiceCreateParams | ||
| from .voice_list_response import VoiceListResponse as VoiceListResponse | ||
| from .voice_update_params import VoiceUpdateParams as VoiceUpdateParams |
There was a problem hiding this comment.
Public Response Imports Removed
This minor release removes the documented VoiceCreateResponse, VoiceRetrieveResponse, and VoiceUpdateResponse exports and their importable modules without compatibility aliases. Applications upgrading from 4.0.0 that retain these public imports will fail during import with ImportError or ModuleNotFoundError. Preserve aliases and modules for the 4.x series, or make this a major release.
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/brainbase/types/workers/deployments/__init__.py
Line: 5-8
Comment:
**Public Response Imports Removed**
This minor release removes the documented `VoiceCreateResponse`, `VoiceRetrieveResponse`, and `VoiceUpdateResponse` exports and their importable modules without compatibility aliases. Applications upgrading from 4.0.0 that retain these public imports will fail during import with `ImportError` or `ModuleNotFoundError`. Preserve aliases and modules for the 4.x series, or make this a major release.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| ] | ||
| requires-python = ">= 3.8" | ||
|
|
||
| requires-python = ">= 3.9" |
There was a problem hiding this comment.
Raising requires-python from 3.8 to 3.9 makes version 4.1.0 uninstallable in an environment supported by 4.0.0. Python 3.8 consumers therefore cannot take an otherwise compatible 4.x upgrade. Retain Python 3.8 support or publish the support removal as a major release.
Prompt To Fix With AI
This is a comment left during a code review.
Path: pyproject.toml
Line: 20
Comment:
**Minor Release Drops Python**
Raising `requires-python` from 3.8 to 3.9 makes version 4.1.0 uninstallable in an environment supported by 4.0.0. Python 3.8 consumers therefore cannot take an otherwise compatible 4.x upgrade. Retain Python 3.8 support or publish the support removal as a major release.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| if origin == dict and is_mapping(data): | ||
| items_type = get_args(stripped_type)[1] | ||
| return {key: _transform_recursive(value, annotation=items_type) for key, value in data.items()} |
There was a problem hiding this comment.
The asynchronous dictionary branch calls _transform_recursive instead of _async_transform_recursive. For dictionary values containing base64-formatted PathLike inputs, this reads files synchronously on the event-loop thread rather than using the existing awaited AnyIO path. Large file transformations can therefore delay unrelated asynchronous work.
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/brainbase/_utils/_transform.py
Line: 348-350
Comment:
**Async Transform Blocks Loop**
The asynchronous dictionary branch calls `_transform_recursive` instead of `_async_transform_recursive`. For dictionary values containing base64-formatted `PathLike` inputs, this reads files synchronously on the event-loop thread rather than using the existing awaited AnyIO path. Large file transformations can therefore delay unrelated asynchronous work.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.|
Auto-closed by PR Janitor after 7 days of inactivity. Reopen anytime if this is still relevant. |
Automated Release PR
4.1.0 (2026-09-14)
Full Changelog: v4.0.0...v4.1.0
Features
NotGivenfor body (#67) (3ad7f25)X-Stainless-Read-Timeoutheader (#63) (a594c75)Bug Fixes
model_dumpandmodel_dump_jsonfor Pydantic v1 (898ca7b)by_aliasunless set (887a8ec)Performance Improvements
Chores
httpx-aiohttpversion to 0.1.9 (7aeb4c8)actions/github-script(bdad5ed)api.mdfiles (034e708)--fixargument to lint script (0b1e68e)test_proxy_environment_variablesmore resilient (f79d30c)test_proxy_environment_variablesmore resilient to env (08e33e4)pyproject.tomlfile (f87b268)actions/checkoutversion (54d6bd9)get_platformtest (ef07d85)Documentation
This pull request is managed by Stainless's GitHub App.
The semver version number is based on included commit messages. Alternatively, you can manually set the version number in the title of this pull request.
For a better experience, it is recommended to use either rebase-merge or squash-merge when merging this pull request.
🔗 Stainless website
📚 Read the docs
🙋 Reach out for help or questions
Greptile Summary
This release updates the generated SDK and core HTTP client, adds aiohttp and binary-body support, revises serialization, parsing, retries, streaming cleanup, and path handling, consolidates voice deployment response models, drops Python 3.8, and modernizes CI and development tooling.
VoiceDeployment.Confidence Score: 1/5
The PR is not safe to merge until credential-bearing CI output is protected and the minor-release compatibility breaks are resolved.
The artifact uploader exposes live authorization material in CI logs, while the 4.1.0 package removes documented response imports and Python 3.8 installability; async dictionary transformation also performs potentially blocking synchronous file reads.
Files Needing Attention: scripts/utils/upload-artifact.sh, src/brainbase/types/workers/deployments/init.py, pyproject.toml, src/brainbase/_utils/_transform.py
Security Review
The new CI artifact-upload path exposes its GitHub OIDC bearer token and signed upload URL through Bash command tracing and verbose request output. Tracing and verbose URL logging must be disabled around credential-bearing commands.
Important Files Changed
VoiceDeploymentwithout compatibility aliases.Flowchart
%%{init: {'theme': 'neutral'}}%% flowchart LR User[SDK caller] --> Resource[Generated resource method] Resource --> Transform[Request transformation] Transform --> Client[Sync or async base client] Client --> Retry[Request and retry loop] Retry --> HTTPX[HTTPX transport] HTTPX --> API[Brainbase API] API --> Parse[Response parsing] Parse --> Model[Pydantic response model] CI[GitHub Actions build] --> Build[Build wheel] Build --> Upload[Artifact upload script] Upload --> Storage[Stainless package storage]Prompt To Fix All With AI
Reviews (1): Last reviewed commit: "release: 4.1.0" | Re-trigger Greptile