With no new Claude Code, ADK or OpenAI Agents SDK releases since this digest last checked, the week's useful changes came from three other frameworks. All three releases deal with cost, failure handling and trust boundaries – the problems teams hit after an agent is already in production.
Pydantic AI 2.55 – October 9
The largest theme is prompt caching, which matters because agent loops resend the same instructions and tool definitions on every turn.
- One cache setting across providers. A unified
cachesetting andCachingcapability add "cross-provider prompt caching"; with Anthropic's automatic caching,cache=Truenow covers "the instructions and tool definitions too." - Cache health as telemetry. The release records "prompt cache diagnostics in
provider_details" (on by default for OpenAI Responses, opt-in for Anthropic) and reports "prompt-cache health per conversation viapydantic_ai.cache.*span attributes." - Caching on by default for coding. The harness
Codernow turns prompt caching on by default. - Fallback accounting. Each failed
FallbackModelattempt is now recorded "with its model, timing, error and usage," and rejected responses count inRunUsage, so a run that silently fell back to a second model no longer looks cheaper than it was. - Durable runs. Default
run_idandconversation_idvalues stay stable when a durable run is re-executed, and a newConversationobject carries history between runs. - Breaking. Every package now requires Python 3.11 or newer; Python 3.10 installs resolve to 2.54.0 and earlier.
Microsoft Agent Framework for Python 1.21 – October 8
The most interesting change fixes a side effect of an earlier security fix. In version 1.19 the framework's label-tracking middleware made per-item security labels restrict-only, so a tool could not promote web content or other runtime bytes to trusted. The pull request for 1.21 explains the cost: that "removed the only channel a tool had to provide explanatory context about its own hidden output. A hidden failed compile and a hidden clean compile look identical to the model." Integrators had resorted to "unsafe workarounds," including declaring a whole tool trusted.
The fix lets a tool declare standing_guidance – fixed sentences such as "A result you cannot read is not a clean validation." The middleware itself attaches them as trusted content, and because the text "is fixed at declaration time and never passes through the tool body," an attacker controlling the tool's inputs cannot change it.
Two other changes: when an agent is invoked as a tool by another agent, provider-owned session state is now isolated per delegated call, failing closed when a custom loop cannot establish ownership of a shared session; and the Purview integration can evaluate policy on the full buffered text of a streamed response rather than on fragments.
LangChain 1.4.4 – October 8
A smaller but familiar failure: SummarizationMiddleware, which compresses long histories, could itself overflow the context window. "If the summarization step overflows, we retry with some conservative trimming," the fix says, and non-retryable errors are now skipped.
What remains uncertain. How much the cache diagnostics change real bills depends on whether teams act on them; and Microsoft's standing guidance is only as good as the sentences tool authors write.
Analysis: the pattern across all three is that production agent work is shifting from capabilities to accounting – knowing what was cached, which model actually answered, which state belongs to which sub-agent, and what the model is allowed to trust. Teams evaluating frameworks should weight these features as heavily as new integrations.
Pydantic AI 2.55 adds cross-provider prompt caching with per-conversation cache telemetry and honest fallback accounting; Microsoft Agent Framework 1.21 lets tools attach fixed, trusted guidance to results the model cannot read and isolates sub-agent session state; LangChain 1.4.4 stops summarization overflowing the context it protects.
Sources
- Release v2.55.0 (pydantic/pydantic-ai, GitHub)
- Release python-1.21.0 (microsoft/agent-framework, GitHub)
- Allow tools to declare standing guidance appended to results (microsoft/agent-framework PR #8784)
- Isolate provider-owned state in agent tools (microsoft/agent-framework PR #8853)
- SummarizationMiddleware: retry summary step on context overflow (langchain-ai/langchain PR #41159)