Skip to content
Agents tracked: 157 Downloads (7d): 216M up 9.6% GitHub stars: 4.2M VS Code installs: 145M Releases (7d): 233 Agent pull requests (last week): 940K Updated Oct 6, 2026

AI agent release tracker

715 stable releases from tracked agents and frameworks in the last 30 days, newest first, with the headline changes from each set of release notes. Also available as RSS.

Oct 6, 2026

  • feat: outline the back navigation control on settings sub-pages
  • feat(settings): bulk-add provider models as LLM profiles
  • feat: add direct-prompt Model Router settings
  • feat(canvas): retire streaming slots by event id and delete the text-matching reconciler
  • feat(apps): add Update action for installed Canvas Apps

Oct 5, 2026

  • feat(ts): port mcprouter vended tool to TypeScript (#4448) (ec86d614d)
  • feat(bidi): normalize token usage events (#4886) (3973d1cb8)
  • feat(multiagent): migrate agent axis policies to SDKs (#4714) (d87a0718a)
  • feat(stop): use agent.cancel() to stop the event loop (#3506) (5e82809b3)
  • feat(skills): add Strands coding-agent skill (#4739) (8404ebbdb)
  • Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
  • Added agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
  • Added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool
  • Added ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
  • Added to claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Pi
  • Tool patterns and --no-mcp: --tools and --exclude-tools accept patterns, for example --tools read,codemode,'mcpradius' keeps only one MCP server's tools. --tools now keeps MCP tools unless an…
  • Codemode persists images: tools.read() on an image file now gives back an image block that image() can show. See Call tools.
  • Added patterns to --tools and --exclude-tools, for example --tools read,codemode,'mcpradius'
  • Added --no-mcp to disable the built-in MCP support for one run
  • Fixed syntax highlighting losing colors after the first line of multiline strings and comments in fenced code blocks
  • Add copilot config subcommands to list, read, set, and remove settings.
  • Add a pre-conversation Ctrl+E environment picker to switch between local and cloud runs
  • Entra-protected MCP servers can silently renew access-token-only credentials.
  • Legacy HTTP+SSE MCP connections no longer hang indefinitely when a message POST is never acknowledged; the acknowledgement is bounded by the server's configured timeout
  • Voice runtime install errors name why the download from nuget.org failed, not only the fallback feed's 401
  • Preserve SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to retain the Windows executor's startup…
  • #51121: Backport Windows remote MCP environment preservation to 0.160.
AI SDK
  • Updated dependencies [3824c69]
  • Updated dependencies [6e8ec70]
  • @ai-sdk/gateway@3.0.210
  • fix(langgraph): fork before replaying an update checkpoint the thread moved past
  • fix(langgraph): keep an updatestate on an older checkpoint out of its other branches
  • fix(langgraph): keep DeltaChannel counters on every updatestate path
  • release(langgraph): 1.2.13
  • fix(langgraph): don't walk history for a DeltaChannel that was never written
Junie
No release notes published.
  • Load a skill’s tools only when the skill is read.
  • Reset stale encoding when overwriting text.
  • dcba425 release(deepagents): 0.7.22
  • 337f4d0 chore(deps): raise dependency minimums for all
  • 92cd8e7 feat(sdk): load a skill's tools only when the skill is read
Base44
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.27 NPM Tag: latest
Qwen Code
  • fix(serve): preserve session creation failure diagnostics
  • feat(sdk-java): Add managed runtime attestation client
  • feat(web-shell): select a time range on the trajectory overview to narrow the table
  • feat(serve,web-shell): set the Qwen Live endpoint and model from settings
  • feat(channels): separate private and group access policies
Mastra
  • @mastra/playground-ui: anchorTraceId removed from ThreadViewByTrace, TraceThreadPanel, and ThreadTrace; ThreadTrace.LoadMoreSentinel removed. Use pageSize and onLoadOlder on ThreadTrace to control…
  • Added agent.getMessages() to tool execution context in standard and durable agent loops. Tools can read the current conversation, including remembered messages and in-run responses, without…
  • Added group filtering and generation ordering to observational memory history. For example, getObservationalMemoryHistory(threadId, resourceId, 1, { groupId, sortDirection: "ASC" }) finds the…
  • Update provider registry and model documentation with latest models and providers (ac54c46)
  • Fixed chat channel agents ignoring mentions of their current display name after being renamed. For example, a Slack app renamed from acme-bot to helper now responds to @helper in channels, instead…
  • fix(mothership): preserve workflow identity in background confirmations
  • fix(files): retain known lineage through binary exports and extraction
  • fix(code-placeholders): make python bare-placeholder classification and tagged-template edits linear
  • fix(execution): make code placeholder and reference scans linear
  • @icecrasher321
  • API: Let global members grant variable scopes to API keys (#40151) (cc25c71)
  • editor: Show Gateway credits promotions on community nodes (#40109) (a509d92)

Oct 4, 2026

Kortix
  • Fork a conversation. A session's conversation offers a Fork action, so you can branch from any point.
  • Cancel a subscription from the billing pane.
  • One permission per topic. The broad project.customize. permissions are replaced by project.settings.write, project.sandbox.write, and project.model.read/.write. Agent changes use…
  • Sign-in: an existing account opens on the password form, and the email link is one click away. After you enroll in two-factor authentication, sign-in asks for the code. A magic link still…
  • Security settings list the devices that are signed in.
  • Fixed native OpenAI context compaction for sessions containing many screenshots, preventing image-size estimates from incorrectly causing compaction requests to be rejected.
  • Fixed compatibility with Command Code DeepSeek and other DeepSeek-family models by preserving the reasoning context required for warm OpenAI Responses sessions and correctly handling incomplete…
  • Fixed waiting for subagent follow-up messages: responses now appear as background jobs that can be waited on or canceled, and are delivered only once.
  • Improved /switch autocomplete so model and role suggestions use the same relevance ordering as the model picker, including support for @role aliases.
  • Fixed concurrent skill:// searches blocking other filesystem operations and delaying subagent artifact publication.
  • feat(library): Slack AI Agent Security: Permissions, Data, and Audit Guide
  • feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026
  • feat(library): How do you build an AI voice agent with Twilio and Sim?
  • improvement(knip): check entry exports of private packages and delete their dead barrels
  • improvement(tools): stop exporting tool types used only in their own file
  • Sampling by thinking level — samplingParamsByThinkingLevel in models.json sets sampling parameters such as temperature and topp for each thinking level on OpenAI-compatible APIs. See Configure…
  • Added samplingParamsByThinkingLevel to models.json for per-thinking-level sampling parameter overrides on OpenAI-compatible APIs. See Configure sampling by thinking level

Oct 3, 2026

  • Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
  • Fixed the terminal freezing on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions
  • Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink
  • [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent
  • Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
Oh My Pi
  • When a DeepSeek turn ends with raw <|DSML|…> tool-call text that could not be parsed into a real call, and no tool call was made, the broken markup is now removed from the message before it is…
  • Fixed Antigravity chat and image requests sending an outdated client version when the model list came from cache, which could make newer models such as Claude Opus 5.5 unavailable.
  • When a DeepSeek model writes a broken DSML tool call (for example with the opening <|DSML|toolcalls> and <|DSML|invoke> tags missing), its closing tags are now kept in the streamed text instead of…
  • Fixed DeepSeek V4 model IDs and the V4.1 Flash alias lacking version information in model identity and dashboards (#14194).
  • Fixed Antigravity models such as Claude Opus 5.5 and Sonnet 5.5 disappearing after omp models refresh. When the update check failed, omp reported an outdated Antigravity client version (2.8.0), so…
  • Your computer, on the web. Each physical computer appears once, even after you re-pair it. Computer Use runs inside the Kortix desktop app, and it asks for every macOS permission right after you…
  • Edit a queued prompt in place. The prompt queue sits in its own card above the composer.
  • Review Center has its own page. You approve requests in a modal on the approve page.
  • Channel bindings live in one dialog, with one tab per platform and a settings dialog for each binding. Teams bindings read "Team › Channel" and include the thread title.
  • Shared sessions show who sent each message, with an avatar per sender.
  • Nix flake — nix run github:earendil-works/pi/stable runs the latest release, and nix profile add github:earendil-works/pi/stable installs it. See Install pi.
  • Project overrides for MCP servers — .pi/mcp.json and /mcp can enable, disable, or change the exposure of a user-level server for one project. See Configure servers.
  • MCP Client ID Metadata Documents — oauth.clientRegistration: "cimd" lets authorization servers allow pi by its document URL instead of dynamic registration. See Authenticate with OAuth.
  • Tool renderers for any tool — pi.registerToolRenderer() draws calls to tools that are not registered yet, such as MCP tools in resumed sessions. See Tool rendering.
  • Cloudflare Clef classifiers — @cf/cloudflare/clef and @cf/cloudflare/clef-flash are usable from codemode scripts and extensions. See Use classifier models.
Junie
No release notes published.
  • fix(mcp): derive model output schemas from serialization
  • fix(tenki): upgrade sdk and preserve timeout failures
  • chore(deps): bump gitpython from 3.1.59 to 3.1.62
  • fix(skills): check local skill ownership before validating arguments
  • chore(deps): bump pyjwt from 2.14.0 to 2.15.0
Sim
  • feat(forks): compare last synced source deployments
  • feat(youcom): add You.com integration
  • feat(search): browse Lucid folders and Notion pages
  • feat(library): How to Use a Postgres MCP Server With AI Agents: Security, Deployment, and Evaluation
  • feat(powerbi): add Power BI actions
  • Release notes — formatted for people, with expandable sections.
  • Changelog — plain Markdown for AI agents and tools.
  • npm package
  • registry tarball
  • integrity: sha512-G+JkNUhtpDE3cXR4AEi2NyyG9fqI/T2WUSl8ZnR8AATH8Dh1kC3qYFL7wwPoZtgHiP/cszA86PEiE0PDysxb9Q==
  • Handle draft-7 list-form items in JsonSchemaTransformer, TestModel and Mistral streamed output, and make TestModel accept boolean subschemas and cap prefixItems at maxItems
  • Fix ImageGeneration under FallbackModel and dataclasses.replace, and compare Embedder by identity
  • Refuse a second durable execution engine on an agent before either binds
  • Make wrap hooks enclose complete stage lifecycles
  • Re-raise model errors from Temporal model activities with their original type in workflow code

Oct 2, 2026

  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Cline
  • Existing users get a one-time What's new dialog introducing Connectors, with connector logos, a clickable example prompt, and an Open Connectors button. You can replay it from Settings → About →…
  • Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
  • Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
  • Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images
  • Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call
  • Added --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
  • Resizable Picture-in-Picture window for MCP Apps
  • Fetch model metadata from models.dev live with bundled fallback
  • Quoting action to append selected conversation text to composer
  • Lean ACP-only Goose binary
  • Model discovery API for GDK Provider
Junie
No release notes published.
  • #2451 df9c0ef Thanks @aron-cf! - Update pi-durable and pi-ai to ^1.0.0. See Pi harness docs for details.
Sim
  • improvement(audits): enforce console, helper, render-path, persist, and deployment-flag rules
  • fix(deps): bump mammoth to 1.12.3
  • fix(logging): name the driver cause and redact bound params in logged errors
  • fix(files): resolve chat uploads whose names are not in VFS form
  • fix(search): reuse managed MCP sessions within operations
Oh My Pi
  • Added createAuthGatewayRouter, the auth-gateway's routes without the HTTP listener, and serveAuthGatewayStdio, which serves them as JSON lines ({"id", "path", "body"} in, {"id", "status", "body"}…
  • Added omp auth-gateway stdio: a long-lived inference server for other programs speaking JSON lines on stdin/stdout ({"id", "path": "/v1/chat/completions", "body"} in, {"id", "status", "body"} out)…
  • Reduced CPU use while streaming with several agents active: extension messageupdate handlers are delivered through a lighter queue, and RPC no longer processes subagent events unless a client…
  • Fixed web search stopping at Perplexity's anonymous signup wall instead of falling back to the next configured provider (#12756).
  • Fixed imported Claude Code sessions on Windows reporting the encoded C--… directory name instead of the registered project path when the transcript records no cwd
OpenAI Agents SDK
  • restore release tests and refresh required readiness check (#5278) (730deb4)
  • Review mode: final candidate
  • Intended release: patch, 0.23.1
  • Minimum required release type: patch
  • Versioning verdict: compatible
  • agent-framework-foundry-hosting: Host native workflows over Foundry Responses and Foundry Invocations (#8947,
  • agent-framework-duckdb, agent-framework-sql-server, agent-framework-typesafe: Add DuckDB and SQL Server native vector-store connectors and the TypeSafe AI connector (#8675, #8686,
  • agent-framework, agent-framework-core: Add response-stream gates and buffering, session-scoped file-access isolation, an AgentExecutor checkpoint-state TypedDict, and opt-in…
  • agent-framework-foundry, agent-framework-foundry-hosting, agent-framework-openai: Add native computer-use support to Responses clients and Foundry project embeddings (#8751,
  • agent-framework-azure-ai-search: Support knowledgesourceparams in AzureAISearchContextProvider
OpenClaw
  • GPT-6.1 Sol support: add the current Sol model across OpenAI routing, discovery, reasoning, harness, and Reef guard-model boundaries. (#161400,
  • Safer updates and recovery: preserve plugin settings, prevent duplicate Gateways, handle pnpm package updates without terminal failures, and retain plugin inventory through migration. (#160344,…
  • Reliable agent completion: preserve complete delegated and CLI answers, release suspended child capacity, recover full cron output, and prevent failed requests from consuming steered questions.…
  • Security and ownership hardening: keep secret-store kinds stable during rotation, restore admitted secret-egress execution, and retain explicit cron tool allowlists while repairing stale automatic…
  • Channel and integration reliability: repair Gmail and IMAP watchers, Matrix direct mappings, Telegram progress, remote MCP startup, and managed llama.cpp startup on clean Windows hosts. (#161503,…
  • Live progress & cancellation for page sync: Knowledge.streamsyncpages() / astreamsyncpages() yield typed PageSyncProgress snapshots plus one terminal SyncReport, and syncpages / asyncsyncpages…
  • Page sync reports name failed pages: SyncReport.failedpaths lists the site paths of pages that failed to publish/delete (capped at the first 20, like errors; failed keeps the full count; defaults…
  • Retry transient page-fetch failures with backoff: on large corpora (e.g. docs.agno.com, 3,913 pages) 1–2 random pages failed per run with Connection reset by peer. Each attempt previously consumed…
  • Complete page sync for Mintlify-style sites: large Mintlify sites (e.g. docs.langchain.com) synced as partial even when every page indexed — and a partial result skips pruning, so removed pages…
  • feat: name failed pages and their causes in page sync reports
  • core: Keep the task runner running on an unhandled promise rejection (#40092) (d719c87)
  • GHSA-6fqq-452j-qhrp (high): a streamed request through ConcurrencyLimitedModel or limitmodelconcurrency could keep its concurrency slot when the slot was released on a different task than the one…
  • Add oneOf schema support to TestModel's generated data
  • Make clai2 plugins declarative Plugin subclasses, modeled on AbstractCapability
  • Move session naming into clai2 and deprecate pydanticaiharness.steppersistence.naming
  • Add a built-in posthog plugin to pydantic-clai2 with /keys or browser sign-in
  • Execution cancellation: Pass an abortsignal to Runner, Workflow, and nodes to stop a run gracefully; /runsse now cancels the run when the client disconnects. See the unit guide for more details.…
  • Tool confirmation in workflows: Tool nodes now pause for user approval via RequestInput, the same way an LlmAgent does, instead of passing an error downstream. (ce132b9)
  • ModelConsultTool: Let an agent consult another model mid-task, capped by per-turn and per-session budgets. See the unit guide for more details. (84cc99a)
  • SQLite memory service: Keep agent memory in a local SQLite database, selected with a sqlite:// memory service URI. (9625b06)
  • MCP SDK 2.x: Connect to MCP servers over the modern protocol through a new opt-in path. (e738c26)

Oct 1, 2026

  • feat(smallestai): add TTS continuations protocol support
  • baseten: inline mid-conversation instructions for Qwen/Qwen3.8-27B
  • fix: drain inference STT transcripts before closing
  • feat(azure): Add Azure Voice Live Realtime API support
  • Revert "worker: read agent name from livekit.toml as last fallback (#7295)"
  • Amazon Q for VS Code 2.8.0
Deep Agents
  • Emit a cacheexpiring hook before the prompt cache expires (#6638).
  • Keep the transcript at its current position when opening pickers (#6635).
  • Share cache-expiring notifications with the TUI (#6639).
  • Use listed skill paths instead of inferring their locations (#6711).
  • Correct product and command names in skill guides (#6637).
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Bump version to 1.0.55 (#8758) (d45e60095)
  • SKY-17491: Inline run reliability below analytics (#8753) (4a3ca3abc)
  • Stabilize request principal attribution (#8751) (643d9d049)
  • SKY-17496: Keep run ID copy in the Studio top bar only (#8749) (6c57e35e3)
  • Start the API event-loop lag gauge on the API process and send it to SigNoz only (SKY-17497) (#8748) (5f961fe0e)
Kortix
  • Microsoft Teams is on for every project. There is no feature flag to turn on: connect Teams from the project's Connectors → Channels page. A tenant admin consents once, or the project brings its…
  • What Kortix says to one person in Teams stays with that person. In a channel or group chat, only that person sees
  • the prompt to connect an account or request access, with the connect button right in the thread;
  • command replies;
  • why a message did not run;
  • Browse older tasks in the agent command center with a keyboard-accessible “Show more” action.
  • Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals.
  • Start sessions outside a project with workspace defaults when policy permits, and restore saved permissions when resuming.
  • Added opt-in Guardian review capabilities to retrieve earlier user instructions and include context from agent handoffs. (#49036,
  • Unsent queued messages now resume after reconnection once uncertain submissions are resolved, avoiding duplicate sends.
  • Fullscreen by default — The TUI now runs fullscreen. Set tuiMode to "regular" to keep the terminal's normal scrollback. See Terminal and display.
  • Leaner codemode — About 40% fewer prompt tokens, and errors that tell the model how to recover. See Codemode.
  • Image generation in codemode — Scripts call models.generateImages() with the session's credentials. See Generate images and Use image models.
  • Radius in /login — Sign in with Radius and set up its MCP server in one step. See Radius.
  • Anthropic copy code login — Sign in when the browser runs on another machine. See Authenticate interactively.
AI SDK
  • Updated dependencies [295aadf]
  • @ai-sdk/gateway@3.0.209
  • feat(bidi): graduate bidirectional streaming API (#4707) (8dbc128ea)
  • feat(vended-tools): port a2aclient tool to TypeScript (#4575) (ff114a9bd)
  • feat(bidi): display tool calls in console I/O (#4703) (5a940fbae)
  • feat(bidi): support cancellation from custom tools (#4664) (3e5e89e26)
  • feat(bidi): preserve grouped tool calls through execution and delivery (#4687) (43479b8da)
Junie
  • Added Junie Lite
  • Added Claude Mods: plugins may now modify deeper behavior
  • Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin (for…
  • Added an n:<text> filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match
  • Added prompttext to the OpenTelemetry userprompt event, a copy of prompt for backends that nest dotted keys; drop or mask it wherever you drop or mask prompt (anthropics/claude-code
  • Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry
  • Add copilot sandbox ca commands to check, create, trust, rotate, and remove proxy CA trust, including unattended Windows setup; /sandbox ca install becomes create and trust
  • Session timelines now clear busy status after interrupted turns finish.
  • Sandboxed commands run on Windows versions without filesystem enumeration support, with a warning that PowerShell's current location may be wrong
  • Footer text selection stays on the same visible line when the footer grows or shrinks.
  • Offer sandbox network bypass for Node/npm EACCES socket denials on Windows
  • feat(library): What are the best marketing automation platforms for AI workflows in 2026?
  • feat(library): AI Agent Marketplace vs Building From Scratch: Where Sim Fits
  • improvement(search): run Search retirement as an operator command instead of a deploy step
  • fix(chat): keep mention searches open and align resource menus
  • fix(seo): GEO hygiene — indexing, canonical URLs, llms.txt, docs redirects, library consolidation
Oh My Pi
  • Fixed rejected HTTP 400 requests from consuming unbounded disk space by automatically cleaning up old request logs and enforcing a size limit.
  • Fixed unnecessary credential and session updates that could trigger needless authentication reloads in other running processes.
  • Fixed context-overflow recovery for Strata requests that exceed the model context limit but return no usage information.
  • Fixed model catalog caching so unchanged catalogs refresh without unnecessary rewrites, and offline snapshots for endpoint-less models (such as Azure models) are now handled correctly across startups.
  • Added opt-in stale-session garbage collection with omp gc --stale or gc.stale, removing orphaned session markers and terminal breadcrumbs and expiring old debug reports and collaboration replicas…
  • #14634 34ec938 Thanks @brunoagatao! - Add a copy content button to the Documents viewer toolbar, and expand the document tab context menu with Copy Path, Copy Relative Path, Copy File Name, and…
  • #14630 de285a6 Thanks @brunoagatao! - Add a manual Fetch Models button to the Custom Provider settings dialog.
  • #13589 2d6d0a0 Thanks @sylwester-liljegren! - Suggest files from every folder in a multi-root VS Code workspace when typing @, so folders added through "Add Folder to Workspace..." are mentionable…
  • #14675 5b336a9 - Keep the latest Agent Manager selection when another project finishes loading.
  • #14672 97dda4f - Keep the Agent Manager browser preview visible when you resize its panel.
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.25 NPM Tag: latest
  • be01deccaf3dd7b85e03620145bc1a757c857827 .NET: Add origin pinning to Foundry toolbox MCP client (#8721)
  • 0d6d2bb6b0b58f3aabdf170320ab90fc300d4c99 .NET: fix: declarative workflow http variables (#8797)
  • 2024d4df4c4dd01b904fb9daaf56f5759801654a .NET: Fix workflow topology edge multiplicity comparison (#8656)
  • 37ce872a85fed62cedfd7fffa2e0bd43f7d32b92 .NET: Store created external input messages (#8606)
  • 1370903bd8e6eb8871781cd1fcc74f674c022e0b .NET: [BREAKING] Better support tool changes between runs (#8754)
  • InMemoryDocumentStore.bm25retrieval and InMemoryBM25Retriever with BM25L (the default) or BM25Plus now return only documents that contain at least one query term, with or without scalescore.…
  • TextCleaner.run now raises a clear TypeError when texts is not a list or any element is not a str, instead of failing later or producing unexpected results.
  • Haystack now requires anyio>=4.14.2. anyio is installed transitively through httpx and openai; versions before 4.14.2 are affected by CVE-2026-63374 (GHSA-82r6-8w77-94w6).
  • Fixed BM25 tokenization in InMemoryDocumentStore for Chinese, Japanese and Korean text. The default bm25tokenizationregex now splits CJK characters into one token each, so bare-term queries can…
  • Fix Pipeline.connect() raising TypeError: object of type 'ellipsis' has no len() when one of the sockets is annotated with Callable[..., T]. A Callable[..., T] now matches callables with any…
  • User Management / Authorization (RBAC): a new agno.os.authz package adds role-based access control to AgentOS — a role store, scope policy, audit log, user directory and an admin router, with…
  • AgentOS Filesystem: a new agno.fs filesystem (DbFileSystem) with dedicated /filesystem routes (list/read/manage files) backed by an agnofs table.
  • MCP config / auth updates: refreshed MCP server config and built-in MCP auth handling.
  • AIMLAPITools: new toolkit for image, video, speech and transcription via the AI/ML API.
  • Filesystem table re-key (agnofs): v3.1 keys the filesystem table by (namespace, userid, path), where userid is the user partition ("" for the shared/no-user partition). A table created by an…
  • <!-- This is an auto-generated description by cubic. --> <a href=" target="blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)"…

Sep 30, 2026

Cline
  • Custom providers added with Add Provider now work when you run a task. They showed up in the provider and model pickers but failed with Unknown or disabled provider
  • New chats remember whether you last used Cloud or Local, and which Cloud model you picked, instead of always going back to Local. Switching a thread from Local to Cloud also opens on your…
  • Saving provider credentials no longer fails when the provider's model list can't be fetched, and the model list refreshes when you change a provider's API key or endpoint
  • MCP settings always use the same file. With CLINEMCPSETTINGSPATH, CLINEDATADIR, or CLINEDIR set, reading and saving servers, MCP OAuth sign-in, and Open MCP settings now all use that path, where…
  • Tool diffs now follow the app's font size setting instead of a fixed 13px
Open Interpreter
  • Fix offline model listing for configured non-OpenAI providers. When an endpoint has no matching catalog identity, the app server now retains that provider's own bundled model choices rather than…
  • Eligible local sessions signed in with ChatGPT can now show optional reminders to complete account security setup.
  • #49744 [0.159] Backport account security setup reminders for 0.159.3 @andrewgu-oai
AI SDK
  • 4f3d236: fix: clear tool approvals when addToolOutput runs
  • Send namespaced session and parent-session identity headers with model requests.
  • Re-sign locally compiled macOS binaries so they run reliably on macOS 27+. (@ryangamerdev)
  • Sign macOS CLI release binaries with a Developer ID.
  • docs(web): correct GPT 6.1 Sol cache pricing
  • @metal-huang
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Add support for GPT-6.1 Sol in model selection
  • Add --mcp-github-auth to scope GitHub account auth to approved MCP server origins
  • Add session-scoped read-only directory approvals to path access prompts
  • Permission prompts remain answerable after resuming interrupted sessions.
  • Auto-approval now takes into account messages you type while the agent is working, as it already did for prompts sent while it was idle
  • Updated bundled Claude CLI to version 2.1.286
  • CI: pinned the model for issue triage to fix failures caused by the CLI's new default model
  • MCP servers stay out of the way: servers with the default codemode exposure are no longer listed in the codemode description and no longer block the first prompt. They appear in a short system…
  • More MCP authentication options: oauth.clientName for servers that only accept known OAuth clients, and "auth": { "provider": "<provider>" } to authenticate HTTP servers with a provider's /login…
  • Anthropic workload identity federation from the Anthropic SDK environment variables. See Use an API key from the environment.
  • /reload enables tools newly added to the defaultTools setting. See Tools.
  • Added a description field for MCP servers (pi mcp add --description), shown with the server in the system prompt and used to rank its tools in tool search, and a describeNamespace(name) codemode…
  • FilesystemMiddleware can now store blobs on the backend (#6550).
  • 4394bcd release(deepagents): 0.7.21
  • e38e6c9 feat(sdk): allow FilesystemMiddleware to store blobs on backend
  • c2da83e build(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/deepagents
  • c9b2ce1 chore(deps): raise dependency minimums for all
Junie
No release notes published.
  • Added a count such as "2 of 5" to the permission prompt when several permission requests stack up
  • Added mouse support for the "N more" rows of lists in fullscreen mode: click one to jump to that end of the list, with hover and pressed states
  • Fixed several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire
  • Fixed claude --resume and --continue sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed
  • Fixed API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions
  • Added Factory Droid OAuth, HTTP streaming across Anthropic, OpenAI and Gemini protocols, and pool-aware usage reporting
  • AuthStorage.keys.setConfig(provider, value, { fallback: true }) registers a key that is used only when no stored OAuth or /login credential exists, instead of overriding them;…
  • Cursor turns now fall back to Cursor's HTTP/1 streaming transport when HTTP/2 is unavailable, surface Cursor's structured service errors, and resume from the last safe server checkpoint after a…
  • Auth gateway checks for configured bearer tokens in URLs or forwarded/logged headers only after authentication; unauthorized requests use socket peers and redact unknown paths. Authenticated…
  • Codex sessions no longer keep spending an account's credits after its plan limit is reached while another logged-in account still has plan usage left; new and ongoing sessions switch to that…
  • Added an optional model parameter to spawnagent to choose a model for that spawn instead of using the configured subagent model or inheriting the parent model, with the active model shown in its…
  • Added BYOK support for GPT-6.1 Sol with an OpenAI API key. (#64968; thanks ktKongTong)
  • Added Grok 4.7 to the SuperGrok and xAI providers and made it their recommended default. (#64567; thanks raphaelluethy)
  • Added the agent.threadssidebar.autoopen setting to control whether opening a folder in an existing window also opens the Threads Sidebar. (#64259, #64395; thanks jackhwalters and joshkent94)
  • Added support for "..." in editpredictions.disabledglobs and editpredictionsdisabledin so settings can extend inherited edit prediction exclusions and scopes. (#64540, #64546; thanks porada)
Kortix
  • Computers are connector accounts like any other: the same row, the same Share dialog (people, groups or everyone), and one registration per machine.
  • The audit trail shows Via for each event: the credential the API authenticated (browser session, personal access token, connected app, session token, API key, service account or SCIM token), never…
  • Slack and Teams connector reads stay inside the calling project's own conversations.
  • Stopping a session no longer fails with a database deadlock when a wake runs at the same moment.
  • A malformed member id returns 400 instead of 500.
  • fix(engine): remove per-sandbox piece LRU (#15786) @amrdb
  • session.respondToToolApproval(...) now requires toolCallId (id-less approval responses are rejected); related approval APIs now key gates per thread/run and update grant scoping.
  • @mastra/playground-ui removed/renamed multiple UI APIs (notably ScrollArea props, PageHeader props, ToolCall → Activity component renames, and significant color token API changes).
  • Added maxRetries and failurePolicy options to the observational memory observation and reflection settings. When failurePolicy is 'continue', an Observer or Reflector model failure no longer ends…
  • Added support for resolving channel providers dynamically. The channels option on the Mastra constructor now also accepts a resolver function, so channel connections added on the Mastra platform…
  • Fence background task execution with a persisted, expiring ownership lease. (#24841)
n8n
  • Pin cjs-module-lexer 2.2.0 to address review finding (76e467d)
  • Release notes — formatted for people, with expandable sections.
  • Changelog — plain Markdown for AI agents and tools.
  • npm package
  • registry tarball
  • integrity: sha512-/8N2LnfTFQPvnZizi8qKSFfnLQaPvSG3Cb4xo1YV7b4JhYiUc43ZNRpXJ01bWghLK0Ezk3HVeo/DGHcIRQwRWA==
Pydantic AI
  • GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local webfetch tool could consume excessive CPU and memory. Provider-native web fetching is…
  • Cap genai-prices below 0.1 to keep token usage extraction and limits working

Sep 29, 2026

OpenAI Codex
  • Suppressed console windows flashing on Windows when Codex launches background processes and sandboxed commands.
  • #49385 [0.159] Backport Windows console suppression for 0.159.2 @andrewgu-oai
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • fix(a2a-server): add early return on unsupported store in tasks metadata endpoint
  • Changelog for v0.61.0-preview.0
  • Changelog for v0.60.0
  • fix(core,acp): format MCP tool call titles as structured signatures and segregate explanations
  • chore(release): bump version to 0.62.0-nightly.20260915.gae28844fb
  • BedrockConfig(session=...) takes an aiobotocore.session.AioSession. A boto3.Session fails on the first call with AttributeError: 'Session' object has no attribute 'createclient'.
  • The bedrock extra installs aiobotocore>=3.9.1,<4 instead of boto3. If your application also installs boto3, pick a version whose botocore fits aiobotocore's pin.
  • Explicit keys and regionname passed together with session= now apply. They used to be silently ignored.
  • Pipes, redirects, chaining, globs, ~ and variables are not available in restricted mode. Shell syntax is refused with a clear error, and globs reach the program literally.
  • readonly=True only allows commands that cannot write files or run other programs. find, file, sort, uniq and git … are no longer in the built-in set; list the ones you need in allowed.
  • fix: reject mixed blocked DNS answers with IP allowlists
  • fix(agent): compute recursionlimit accounting for middleware graph nodes
  • fix(ci): keep PR filenames out of shell scripts
  • fix(twelvelabs): confine Split Video file reads
  • fix(auth): replace Passlib with bcrypt on release-1.12.4
  • Updated bundled Claude CLI to version 2.1.285
Junie
  • GPT 6.1 Sol support
Kortix
  • Local mode: connect your computer from the desktop app. Each computer is a connector account with access approval, and the tunnel keeps running in the background while the app is closed.
  • Microsoft Teams reaches Slack parity: direct messages, a connected note, a home tab, message actions, edit and delete, /unbind, /status buttons, /sessions, the full agent picker, review cards, and…
  • Saved session history is always on, and a reload shows the newer saved copy.
  • Mobile: an empty session opens on its composer, messages queue while the computer wakes, and sub-agents show their saved steps.
  • A redesigned Create a project page. New accounts get their name during onboarding, not from the email address.
Oh My Pi
  • Added Agent.replaceQueue() to replace one pending queue without changing the other queue
  • Added queued-message grouping so owned companion records and their user prompt are dequeued together in one-at-a-time mode
  • Added Agent.onQueueChange(), a listener called whenever a steering/follow-up queue mutator (enqueue, dequeue on delivery, clear, or restore) runs, so hosts can observe queue changes without polling
  • Fixed GPT models on Amazon Bedrock's OpenAI routes (bedrock-runtime and bedrock-mantle /openai/...) falling back to a local summary instead of OpenAI's native remote compaction; set…
  • Fixed native compaction on Amazon Bedrock's OpenAI routes skipping the provider's request setup, which sent Bedrock Mantle compaction to an unresolved {region} host and skipped configured headers…
  • Added CLAUDECODEDISABLEWEBFETCH environment variable to turn off the WebFetch tool
  • Added claude --desktop to open the Claude desktop app on the current directory, or on a session with --continue / --resume <id>
  • Added claude plugin configure <plugin> to show a plugin's options and which are unset, or save new values read from stdin with --values-stdin
  • Added <server>.<key>=<value> to claude plugin install --config, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without visiting /plugin → Configure
  • Added allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud…
Sim
  • feat(library): Best ChatGPT alternatives for building AI agents and automating workflows
  • feat(library): Best AI Workflow Builders for Small Teams in 2026
  • feat(forks): opt-in fork sync for new workflows
  • improvement(search): accept several same-kind native queries per account and cap oversized read limits
  • refactor: remove dead code and enforce code quality gates
Pi
  • GPT-6.1 Sol — Available on OpenAI, Azure OpenAI, and OpenAI Codex, and now the default OpenAI Codex model. See Select a model.
  • Added GPT-6.1 Sol (gpt-6.1-sol) to the OpenAI, Azure OpenAI Responses, and OpenAI Codex providers.
  • Changed the default OpenAI Codex model to GPT-6.1 Sol (gpt-6.1-sol).
  • Fixed /login with OpenAI failing in the bundled release with a missing openai-chatgpt.js module error.
Deep Agents
  • MCP tool calls now use configurable timeouts to prevent them from hanging indefinitely (#6625).
  • Stdio MCP servers now start in the session directory (#6626).
  • JavaScript subagent costs are preserved when resuming a session (#6433).
  • Thread switching now completes its preflight faster and shows progress sooner (#6607).
  • The /effort setting is now constrained for between-tools thinking (#6630).
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
Crush
  • f2d66d286950109082c102d780013df84f741e55: fix: remove the powerline symbol (@andrinoff)
Base44
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.24 NPM Tag: latest
  • The hub now starts reliably on Windows machines with a system proxy. Bun's fetch sends loopback requests through HTTP(S)PROXY with no localhost bypass, so on machines that export those variables…
  • The hub daemon log now records one line per socket close with the close code and reason, whether the heartbeat sweep dropped it for a missed pong, and whether the server was already shutting down.…
  • Token usage no longer counts reasoning tokens twice. Providers report reasoning tokens as a subset of outputTokens, but normalizeUsage() returned the raw total alongside reasoningTokenCount, so…
  • Gateway models on providers that mix endpoints keep their per-model apiProtocol (responses, messages, gemini, or chat/completions). Configured models replace catalog entries and dropped the field,…
  • Bedrock fixes. Bare OpenAI GPT-6 and GPT-5.6 ids now route through inference profiles like Claude, Nova, and DeepSeek already did, since Bedrock only serves them that way; gpt-oss stays on-demand,…
  • Current flagship models: add Meta Muse Spark 1.3, Anthropic Fable 5.1, OpenAI GPT-6 Astra, and OpenAI/fal GPT Image 2.5 support to the extended-stable line. (#135638, #136553, #137550, #143068,
  • Complete GPT-5.6 family support: preserve Sol, Terra, and Luna catalog, routing, migration, image, vision, and thinking behavior, including Ultra reasoning across model-runtime boundaries and…
  • Extended-stable security rollup: reconcile all repository advisories that affect 2026.8.2, harden Prometheus metrics authorization and Discord asset/voice ownership, and clear the production…
  • Extended-stable release preparation: normalize OpenClaw, all publishable plugins, and native version metadata to 2026.8.33 while retaining the release-line-compatible publication workflows from…
  • Anthropic reasoning continuity: preserve Fable 5.1 reasoning through model switches and runtime events.

Sep 28, 2026

  • Ask isolated side questions with /btw (#6434).
  • Offer to summarize threads and switch when the cache expires (#6477).
  • Persist project MCP startup denials (#6597).
  • Show 100 recent threads by default (#6604).
  • Restore console input after piped prompts on Windows (#6572).
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Add support for native Gemini 3.8 Flash
  • Implement evaluation of the last traced run through AMP in crewai eval
  • Record the last traced run for crewai eval instead of printing it
  • Improve platform integration setup UX
  • Prioritize popular platform integrations
  • Changes since langchain==1.4.2
  • release(langchain): 1.4.3 (#40888) fix(langchain): sanitize cache settings for fallback models (#40886) feat(langchain): support Bedrock Mantle chat models in initchatmodel (#40837)…
  • Left-clicking supported askuser and elicitation form inputs focuses them and places the cursor at the clicked position
  • Add support for Claude Code rule files in .claude/rules as custom instructions
  • Sessions in the sidebar show a blue dot when they finished a turn you have not opened yet
  • Auto suggests a routing tier and lets you switch with a shortcut or click
  • Auto shows a quick feedback prompt after switching away to a manually selected model
  • Updated bundled Claude CLI to version 2.1.284
BeeAI Framework
  • tools: generate typed schemas for keyword-only parameters (#1721)
  • propagate Python stream errors and cancellation (#1711)
  • adapters: preserve LangChain image content (#1715)
  • adapters: apply LiteLLM proxy response cost reported via hiddenparams (#1699)
  • tools: preserve cache and middleware when cloning file and shell tools (#1706)
  • Added Claude Sonnet 5.5 (claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads
  • Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones
  • Added dollar amounts to the Claude apps gateway spend limit in /usage and the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status…
  • Added effortSlider:decreaseEffort, increaseEffort and toggleUltracode keybinding actions, so the /effort slider's arrow and Tab keys can be rebound in keybindings.json
  • Added /rate-limit-options to /help and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find
Junie
No release notes published.
Oh My Pi
  • Added toolexecutionend events that fire as each tool call settles for live UI updates
  • Emitted tool result messages in the order of tool calls, preserving call order regardless of completion order
  • Reduced repeated token-counting work with a bounded, model-scoped cache of exact text and short-message fragment counts.
  • Fixed an issue where streaming tool call arguments could be incorrectly modified in-place
  • Fixed successful Cursor agent turns being treated as context overflows, which ran overflow compaction and showed "Compaction freed too little context to make progress" while /context read well…
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.22 NPM Tag: latest
  • feat(chat): add shared find menu
  • feat(search): expand live providers and discussion reads
  • feat(snowflake): add Cortex Analyst operations to the Snowflake block
  • feat(databricks): add Genie agent operations to the Databricks block
  • refactor(db): require a transaction for advisory lock helpers
  • Configure copy-on-select and right-click paste in the fullscreen TUI. Copied transcript selections now preserve Markdown formatting. (#47639, #47896, #48118)
  • Connect to MCP servers that require pre-registered OAuth client secrets, including through codex mcp add --oauth-client-secret. (#47891)
  • Secure direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server. (#47601, #47648)
  • Image generation and editing can explicitly request transparent backgrounds, and edits now accept file-backed conversation images. (#47484, #47956)
  • Terminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews. (#47799, #48073)
  • Cloudflare AI Gateway models now honor provider response and stream timeouts. (@danlapid)
  • MCP browser launch failures are now reported when the launcher exits immediately.
  • Debug configuration output now redacts credentials and sensitive headers.
  • Gemini thinking defaults and effort options now match the supported controls across model generations. (@markmcd)
  • docs(web): add Claude Opus 5.5, GPT 6 Sol, and GPT 6 Luna to Zen (#50708)
  • A session whose sandbox name was still held by an old archived sandbox could never get a new sandbox. It now provisions under a fresh name.
  • Opening a session repairs a stale runtime immediately instead of waiting for the background check.
  • A prompt parked while the sandbox restarts keeps its sandbox deadline through every retry.
  • A Firefox browser-extension error no longer reaches error reporting.
  • fix(sandbox): extend a parked prompt's box deadline through the retry ladder
  • #1423 316538a Thanks @jiangjiang248! - Allow custom workspace sandboxes to receive the original executecommand command and args by disabling toolkit command normalization. Fixes #1422.

Sep 27, 2026

Junie
No release notes published.
Kortix
  • Opening a session shows its saved history immediately from cache while the live transcript loads, in one request instead of several.
  • Turns start faster: configuration, model catalog and ingress checks run in parallel.
  • Sessions retry transient model errors inside the turn and continue through short provider outages instead of stopping.
  • A session whose runtime was lost resumes automatically when it was running unattended.
  • The sandbox model catalog stays current across boot, wake, restart and every turn.
Oh My Pi
  • Removed the stream-level Anthropic prompt-cache keep-alive: StreamOptions.anthropicCacheRefresh, StreamOptions.anthropicCacheRefreshRequest, and the zero-output refresh request path. Prompt-cache…
  • Added the openai web-search grounding for OpenAI API models that support Responses web search (gpt-5.5, gpt-5.6-luna, gpt-6-astra, gpt-6-luna)
  • Added Model.promptCache, per-retention-tier prompt-cache entry lifetimes in seconds (short / long), declared per provider through the prompt-cache KDL rule (bundled: direct Anthropic, 5 min / 1…
  • Added API-key-billed OpenAI Responses web search (openai/gpt-6-luna, then openai/gpt-5.6-luna), tried after every Codex entry in the default search fallback chain so ChatGPT-subscription search is…
  • Added prompt-cache warming, ported from earendil-works/pi: shortly before a prompt-cache entry expires, the main agent loop replays its last request and cuts the replay off at the first generated…
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.21 NPM Tag: latest

Sep 26, 2026

  • Grouped outputs. When the agent shows several results in a row, such as two screenshots, the session renders one tabbed card instead of a card per result.
  • Managed model routes. Each Kortix-managed model routes through its own provider route, and the model picker shows the price for each route.
  • Wake failures are explained. When a sandbox fails to wake, the session page shows the failure and when it retries.
  • A live session's transcript recovers when a turn ends even if the working signal was missed.
  • A session idle for more than a day wakes again, and a failed start is recovered instead of reported lost.
Sim
  • fix(search): read Confluence pages through the v2 API the Search grant allows
  • fix(tabs): preserve readable labels in crowded tab strips
  • fix(search): align landing layout and history rows with Home
  • docs(library): update best-ai-agent-platforms-for-enterprise-teams-2026
  • docs(library): update byok-multi-model-ai-agent-builder
  • chore: refine pii review instructions
  • bithuman: resolve the SDK on Python 3.10 and 3.14 again
  • add pid to log lines from parent process
  • fix(tts): forward inner frames as-is in FallbackAdapter and StreamAdapter
  • bithuman: type-check against bithuman 2.11
  • Settings has a new About page. It shows your version and channel, has Check for updates and Restart to update buttons, and lists the release notes for recent versions with links to each GitHub…
  • After an update, a one-time What's new dialog now catches you up on recent features. The first one covers SSH remotes, worktrees, pull request status in the composer, and parallel sub-agents. To…
  • On macOS, Help → Export Diagnostics… now opens the diagnostics export directly, so you don't have to find it in Settings
  • On Amazon Bedrock, OpenAI models reached through inference profiles (us.openai.…, global.openai.…) no longer fail with "Unknown parameter: 'reasoningConfig'" when reasoning effort is set
  • TTS sentence aggregation follows Settings.language, defaulting to English when unspecified. Language updates apply with TTS settings.
  • Added TTSService.pronunciationtransformipa(), which builds a text transform from a word-to-IPA mapping so a voice says names and terms it would otherwise guess from spelling. Each matched word is…
  • Added client-mode reconnect to MOQTransport: when the relay session drops, the transport redials with backoff for as long as MOQParams.connectiontimeout allows the client to be missing, keeps its…
  • Added MOQRunnerArguments.relayurl for dialing a relay by its full URL, query string included. host and port are optional when it is set, and createtransport passes it through to…
  • Added interruptible to every frame: True by default and False by default for UninterruptibleFrame subclasses, and what the frame queue, the processor's interruption handling and the speculation…
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
  • Release highlights could not be determined: the supplied PR index is empty, and the GitHub tag comparison returned 404.
  • Fixed tool calls that put their payload in the intent field i (for example a file body in write) silently running with the leftover arguments; they now fail with an error telling the model to…
  • Fixed the Anthropic compaction failure log omitting why no compaction block came back; it now names the stop reason
  • Fixed capped Anthropic and Bedrock Claude requests with thinking enabled, including on-demand compaction, ending at maxtokens with no answer; every capped request now gets its effort's thinking…
  • Added ctx.agent to the extension context, reporting whether the session is the top-level agent or a subagent, plus its registry id, agent definition name, task depth and parent id, so handlers…
  • Added tracking of Anthropic's usage-limit wrap-up allowance for Claude subscription accounts: after the 5-hour or weekly limit is reached, the status line and /slow status show limit reached ·…

Sep 25, 2026

  • Your own keys and ChatGPT everywhere. Models you reach through your own API keys, keys shared with you, project keys, and ChatGPT subscriptions are available in Teams, Slack and the CLI, not only…
  • Members bring their own ChatGPT subscription, without needing permission to manage project secrets.
  • Saved sessions open on their conversation. Opening an existing session shows skeleton rows shaped like that session while it loads, instead of the full-screen boot screen.
  • Command palette. ⌘K opens instantly at a fixed position, and search can copy your account, project and session IDs.
  • Connect cards name the app they connect, and render as cards even when an agent writes them in a table.
Pydantic AI
  • Match dated gemini-3.8-live ids, reject googleaffectivedialog on Gemini 3.1 Flash Live and 3.8 Live at connect, and raise RealtimeError for Gemini Live close codes
  • Raise a UserError for a realtime toolchoice that forces a tool call on OpenAI, Azure OpenAI, and xAI
  • Add OpenAI GPT-Live support with OpenAILiveModel
  • Expose contextwindowused on realtime sessions, from GPT-Live's reported ratio or response usage
  • Reduce RunContext copying overhead in capability hooks
  • Fixed follow-up turns failing after background subagents: When using query() with hooks, canusetool, or SDK MCP servers, stdin was closed too early if a subagent finished just before the turn's…
  • Aligned docstrings with the code and fixed docstring formatting
  • Updated bundled Claude CLI to version 2.1.283
  • CI: skip wheels over PyPI's per-file limit instead of failing the release
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDECODEGATEWAYHINTHEADERS=1
  • Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed
  • Added deniedModels managed setting to block specific models, even when availableModels allows them
  • Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTELLOGTOOLCONTENT=1
  • Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models
Strands Agents
  • feat(cli): add strands update and polish compact, skills, rename, and setup flows (#4612) (923a5ac2e)
  • feat(bidi): support grouped content messages (#4609) (4342e12b1)
  • feat(bidi): add snapshot capture and restore (#4584) (b8a2e5c00)
  • fix(py): update model id in cancellation integ tests (#4611) (6da3f483b)
  • fix(session): rewrite all stored copies of a message when guardrail redacts it (#4606) (69a465e55)
Kilo Code
  • Add Checkpoints settings for snapshots and automatic session cleanup, including manual cleanup controls and the latest cleanup result.
  • Install companion skills when adding MCP servers from the marketplace.
  • Publish CycloneDX software bills of materials alongside JetBrains release artifacts.
  • Support MCP servers that use client ID metadata documents for OAuth registration.
  • Avoid a crash when reloading or unloading the JetBrains plugin while editor history still references Kilo virtual files.
  • Skills: Control resource usage and tool persistence dynamically using new ephemeral lifecycles and active skill limits (experimental; enable with ADKENABLESKILLLIFECYCLE=1). (43b73e4)
  • Database Integrations: Perform high-performance vector and hybrid searches seamlessly within your agent flows with the new MongoDB toolset. (0961ced)
  • Evaluation: Optimize agent execution costs and latency with new evaluation metrics for tracking duration, token consumption, and model call counts. (2d428ea)
  • Model Support: Integrate OpenAI reasoning models more effectively with automated request parameter adaptation and precise reasoning token reporting. (52a2f0f)
  • BigQuery protected write mode now runs a non-SELECT statement only when the dry run places it in the session's anonymous dataset, so multi-statement scripts, CALL, EXPORT DATA and other statements…
  • feat: toggle all workspace folders from the Conversations header
  • feat: scope OpenAI subscription caches by backend
  • feat(home): reframe splash copy around day-to-day engineering work
  • feat(conversation): open shared automation conversations read-only on cloud
  • fix: cap conversation Skills/Hooks/Tools dialogs at 90vw
Mastra
  • @mastra/playground-ui TaskList API: title, TaskListHeader, and hideWhenEmpty are removed.
  • Added per-endpoint discovery features that observability storage can declare from getFeatures(): entity-type-discovery, entity-name-discovery, service-name-discovery, environment-discovery,…
  • Added planTraceAggregate(). It checks a parsed aggregateTraces() request and returns a TrustedTraceAggregatePlan that any storage backend can execute without re-validating the request. (#24868)
  • timeRange and where are validated exactly like queryTraces().
  • groupBy accepts only supported dimensions.
  • fix(browser): composite background agent tabs, actionable refusals, timed pointer paths
  • fix(ci): build the ARM64 app image on a 16 vCPU runner
  • fix(ci): build the ARM64 app image on a 16 vCPU runner
  • @waleedlatif1
  • The app now starts on machines that set a system HTTP(S) proxy, such as Clash, v2ray, or a corporate proxy. Before, the backend sent its local connection checks through the proxy, so it couldn't…
  • On small or scaled displays, the main window now fits on screen. A 1080p laptop at 150% scaling used to open the window larger than the screen, which pushed the settings and account controls out…
  • Plugin slash commands like /goal no longer vanish from the slash menu the first time you use them. Plugin commands now load as soon as a workspace opens instead of on your first /. If that first…
  • The Providers settings (renamed from API Providers) now keep the model list inside the panel. Long model lists scroll in place, and the model controls stay reachable in short windows
  • In SSH settings, Save is disabled until you change a saved host, and the button for a new host now says Add
n8n
  • core: Propagate project span attributes to node spans (#39457) (59fccb6)
  • Added live steering support for Codex WebSocket transports, allowing users to provide input while a response is in progress.
  • Added passive tool-call context support, allowing hooks and tools to supply additional context for subsequent model processing.
  • Improved context-window handling by automatically adjusting output-token limits and supporting models that truncate output at the context-window limit.
  • Improved prompt token counting for requests with anchored prefixes by using provider-reported usage and limiting local estimation to new message content.
  • Added live steering support for GPT-6 models, allowing queued user messages to be delivered during an active streaming response.
  • Public OpenAI-style lm(messages=[...]) calls, including SDK message objects. Use explicit requests as above.
  • Custom BaseLM.forward() and aforward() integrations. Implement the engine interface.
  • LegacyEngine, AsyncLegacyEngine, and custom completelegacy() shortcuts. These are transition tools, not permanent escape hatches.
  • Native n answers use separate sequential requests, potentially billing input tokens more than once. Use engine="litellm" for that backend's native n behavior.
  • Custom engine objects own their connection. Put apikey, apibase, timeout, and related client settings on the engine itself; DSPy rejects them on LM construction, copying, and calls with custom…
  • Added GPT-6 Sol and Luna, including Amazon Bedrock support and migration prompts for older models. (#47332,
  • Enabled fullscreen transcripts by default and added Shift-click to extend text selections. (#47178,
  • Enabled automatic background-server startup for eligible interactive sessions, with recovery choices when server settings are incompatible. (#47179,
  • Added an f shortcut to fork conversations open in another app, preserving drafts and queued prompts.
  • Made /import available in remote sessions and local background-server sessions.

Sep 24, 2026

  • An audit log you can read. Every entry shows a readable title instead of a
  • More outcomes are audited: sandbox-provider transitions, App deployments,
  • Agents act as their own principal by default. An agent has its own
  • Apps are a per-agent resource in both the editor and the CLI.
  • Reply to several passages at once with inline quote blocks.
  • MessageEnqueued — ConversationContext.enqueue() now announces a transient event after appending to an agent's inbox, so a live session can react between model responses. The calling API is unchanged.
  • MCP errors follow the spec. Prompts with required arguments are validated before rendering, and protocol-level failures return the prescribed JSON-RPC codes instead of a generic error or a tool…
  • A shared event descriptor could retarget under concurrency, leaving a tool awaiting a result that never matched. Seen as intermittent worker-thread hangs on Windows CI.
  • Provider payloads are built from the SDKs' own param types, with the remaining mappers under strict mypy. SDK drift — a renamed, removed or narrowed field — now fails in CI rather than arriving as…
  • fix(mcp): validate required prompt arguments before rendering
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Strands Agents
  • feat(cli): replace setup Q&A with Quickstart, Customize, and Export, and add /tools (#4581) (9b7657f13)
  • feat(py): add a2aclient vended tool (#4304) (9746df634)
  • fix(a2a): extract content from task.status.message when artifacts are absent (#4511) (7f2b0c5ea)
  • fix(mcp-server): migrate off removed mcp.server.fastmcp for mcp 2.x compat (#4547) (18becd79d)
  • refactor(bidi): use barge-in terminology (#4566) (e83c0488f)
Activepieces
  • fix: cherry-pick subflow retry and connection-reference fixes into 0.91.1 (#15689) @abuaboud, @hazemadelkhalel, @Louai-Zokerburg, @majewskibartosz
  • fix: cherry-pick subflow retry and connection-reference fixes into 0.91.1 (#15689) @abuaboud, @hazemadelkhalel, @Louai-Zokerburg, @majewskibartosz
  • fix(build): unblock the release — MinIO moved off Docker Hub, and drop the source maps the image build deletes (#15691) @abuaboud
  • fix: cherry-pick subflow retry and connection-reference fixes into 0.91.1 (#15689) @abuaboud, @hazemadelkhalel, @Louai-Zokerburg, @majewskibartosz
Deep Agents
  • Preview remote plugin contents before installation.
  • Report mis-encoded config.toml files created by older config writers.
  • Show how to cancel MCP browser login and handle Escape.
  • Make workspace configuration warnings actionable.
  • Hide prompt search hints when search is unavailable.
  • Added a maxProseWidth setting that caps the width of Claude's prose in wide terminals while tables and code blocks keep the full width
  • Added a startup notice, and /status and claude doctor entries, listing telemetry variables in a project's settings files that were ignored or that turned telemetry off
  • Added the allowClaudeInChromeWithManagedMcp managed setting to let claude --chrome run alongside an exclusive managed-mcp.json; the error shown when Chrome is blocked now names it
  • Added store.readinessgraceseconds to the Claude apps gateway so /readyz can stay ready through a short Postgres outage such as a database failover
  • Added a scrollbar to the /feedback drafts list in fullscreen mode; it appears while the mouse is over the list
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
Cline
  • New provider: ai&, an OpenAI-compatible endpoint serving open-weight models from Japan.
  • Refreshed the model catalog to 6,386 models across 209 providers. The resolved default model changes for 19 providers that do not pin one, 11 of them to Claude Opus 5.5 (including GitHub Copilot…
  • Raised the minimum js-yaml version to 4.3.2 to pick up a security fix in the parser used to read rule and skill frontmatter.
  • Long replies on local models (llama.cpp, Ollama, LM Studio) that hit the output-token limit now compact the conversation and retry once instead of ending the task. These servers cap generation at…
  • Reopening a task that failed now shows the error with the retry option, instead of presenting it as a completed task.
Base44
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.20 NPM Tag: latest
  • Serialized OutputAdapter and ConditionalRouter components containing Jinja customfilters must now be loaded with Pipeline.load(..., unsafe=True) (or the equivalent Pipeline.loads /…
  • The toolresultoffloaded meta key that the hook sets on an offloaded message now always holds a list of store references rather than a single reference string, since a result can span several…
  • The + operator for combining Toolsets has been removed. Pass Toolsets as a list wherever tools are accepted instead: Agent(..., tools=[toolseta, toolsetb]). Pipelines serialized with a +-combined…
  • Toolset.add() now only accepts a single Tool, not another Toolset. To combine Toolsets, pass them as a list: Agent(..., tools=[toolseta, toolsetb]).
  • Add Pipeline.addcomponents() to add a mapping of component names to component instances in one call. Re-adding the same component instance under the same name with Pipeline.addcomponent() or…
  • Trace ids are unconditional — every Gateway HTTP response carries an
  • /mnt/skills is reserved for managed enabled-only skill projections.
  • sandbox.replicas is enforced for E2B as a capacity limit; the default
  • A SKILL.md directory is a runtime package boundary — nested SKILL.md
  • Memory is pluggable (memory.managerclass): DeerMem-private settings
  • hermes update (git installs), or re-run the installer one-liner.
  • Docker / Hermes Cloud: images build from this tag (nousresearch/hermes-agent:v2026.9.24).
  • core: Keep OpenTelemetry export working after a restart when Sentry is enabled (#39368) (7720a02)
  • core: Retry instance reports that cross the UTC midnight boundary (#39434) (5e09a78)
  • core: Authenticate instance reports with the license certificate (#39381) (f0ab4ea)
  • #4013 929403b Thanks @7Sageer! - Roll back some of the overly defensive changes in 2.1.0
  • #4015 c7dd841 Thanks @sailist! - Revert filesystem watchers for config and workspace files to on by default. Set [watch] enabled to false or KIMICODEWATCH=0 to keep them off.
  • @mastra/playground-ui: removed @mastra/playground-ui/lib/springs; FluidHoverHighlight API changed to accept only hover and className.
  • @mastra/playground-ui: PageLayout/shell APIs reworked (removed PageLayoutRoot, MainContentLayout, MainContentContent, and multiple AppShell header-related props/contexts); migrate to the new…
  • Trace grouping deprecations (Core/Server/Client): grouped results in queryTraces() / trace-query group are deprecated; migrate to thread query (queryTraceThreads() / queryThreads contract).
  • Added classifier registration on Mastra. (#24738)
  • Added configured classifiers as typed workflow steps with fluent and dynamic graph support. Classifier steps expose complete typed answers and token usage for existing branch and conditional…
  • Add GitHubCopilotOAuthFlow for device authorization
  • Add BoolCriteria to say what a bool field's yes and no mean, and let a True/False Enum do the same
  • Use what the user wrote about None as the "none of these" option in TypeSafeModel
  • Offer whole numbers that are not a rubric as a Choice in TypeSafeModel
  • Add RealtimeSession.waitforreply()
  • Added support for documenting agent tools on demand through the new AgentTool.docTopics method.
  • Added TOOLINTERRUPTABORTREASON so interruptible tools can distinguish queued steering, peer messages, or background completions from a full run abort.
  • Improved interrupt handling so tools respect wait mode and can be interrupted when appropriate.
  • Updated Anthropic compaction compatibility with signature verification.
  • Added support for Anthropic User Profiles, including schema-validated API responses.

Sep 23, 2026

  • Changelog for v0.60.0-preview.0
  • chore(release): bump version to 0.61.0-nightly.20260908.gc647533d6
  • Changelog for v0.59.0
  • fix(core): preserve explicit versioned Flash model IDs
  • fix(core): prevent indirect prompt injection via build file modifications and untrusted flags
  • Release notes — formatted for people, with expandable sections.
  • Changelog — plain Markdown for AI agents and tools.
  • npm package
  • registry tarball
  • integrity: sha512-Ie0kyQSCVfFqixsgVg39vevUDq01Ch5u3+7Yu5Y3qARczmdAe+lzp8bVnO9925rHiW/+CFp70zfORCyPmCH31g==
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • feat(mcp-ts)!: swap to @modelcontextprotocol/client 2.0 (#4093) (ab8ff46f1)
  • feat(bidi): require explicit model IDs for providers (#4525) (8732c7c90)
  • feat(agent): add Agent.shutdown() for scope-based cleanup (#4519) (fec042766)
  • fix: simplify and clarify CLI UX; fix bugs (#4548) (43b15b723)
  • fix(hitl): reject non-boolean classifier decisions (#4538) (08f5bdd3a)
Claude Agent SDK
  • Updated bundled Claude CLI to version 2.1.281
  • Pinned default model for e2e tests to claude-opus-5 to work around CI failures with the CLI's new default model
  • Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode
  • Added assumerole on Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer
  • Added guardrail: {id, version} on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)
  • Added telemetry.resourceattributes to the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and /login sessions
  • Added "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions
Sim
  • feat(mcp): support OAuth on workflow MCP servers
  • fix(copilot): clarify knowledge connector authentication
  • @waleedlatif1
  • feat(desktop): universal macOS DMG with per-arch bundled runtimes
  • feat: Support Light+ and Solarized Light theme
  • feat: tag Agent Canvas telemetry by deployment kind (OSS-13530)
  • fix: refresh Canvas image packages
  • fix(chat): restore 11px mode label on the change-agent button
Kilo Code
  • Fold and unfold large pasted text blocks directly from the prompt input and transcript.
  • Add a Marketplace page to JetBrains settings for browsing, installing, and removing marketplace agents, MCP servers, and skills without leaving the IDE.
  • Install Marketplace plugins from npm packages or from a git repository (for example git:github.com/owner/repo@v1.2.3#subdir).
  • Add Kilo Swarm support to JetBrains, including an Agent Behavior toggle, readable board tool cards, and a board viewer for session collaboration.
  • Add a cleanup flow for leftover Agent Manager worktree folders, with size reporting, git-checkout warnings, and safe removal from JetBrains.
Deep Agents
  • Lazy MCP caches now warm without blocking the event loop.
  • Token and cost breakdowns now refresh while the view is open.
  • c526854 release(deepagents-code): 0.1.75
  • 460feb6 chore(deps): raise dependency minimums for all
  • 95b338e chore(deps): bump genai-prices in deepagents-code to 0.1.8
  • fix(flows): stop template imports from failing when the v23 upgrade has no stored flow- #15736 #15736 > 📌 Upgrading a self-hosted instance? Review the Breaking Changes page for any actions…
  • Added SuperGrok sign-in so SuperGrok subscribers can use Grok models in the Agent Panel. (#63248; thanks thibaudgg)
  • Added the agent.preventidlesleep setting, enabled by default, to prevent idle system sleep while agent threads are running. (#53130; thanks cppcoffee)
  • Added support for DeepSeek Flash 4.1. (#64014; thanks cppcoffee)
  • Added the agent.threadssidebardefaultwidth setting to configure the width of the Threads Sidebar. (#62883; thanks porada)
  • Added the agent: rename selected thread action for renaming the active Terminal Thread from the Agent Panel. (#63660; thanks mauriciord)
  • Rust CLI: support for configuring Vibe Code remote projects
  • Clean up managed worktrees after archiving local sessions
  • Archive local sessions so they can be hidden from active session lists
  • Vibe Desktop now shows unseen indicators for local Code sessions that need attention or finish a turn
  • Rust CLI: the live todo plan pins above the input, and Cmd+\ opens the full plan in a right sidebar.
  • Live voice conversations in the desktop app
  • Decisions provider crate with OpenRouter and Jev implementations
  • Z.AI Coding Plan provider with streaming tool calls
  • Recipe parameter limits enforcement (max 32 params, 200 select options, 128 KiB)
  • OpenAI provider custom base URL support in SDK
  • Knowledge Retrieval Pipeline: Knowledge.search() now runs a knowledge level retrieval pipeline that can widen the candidate pool before a reranker reorders it, so rerankers no longer need to be…
  • MMR Reranker: Added MMRReranker (Maximal Marginal Relevance) as a retrieval strategy that balances relevance against diversity so near-duplicate chunks do not crowd out the result set.
  • Page Source Relocation: Added Knowledge.inspectpagesource / ainspectpagesource and guarded migratepagesource / amigratepagesource to move an indexed documentation source to a new hostname.…
  • Recency Reranker: Added RecencyReranker, which blends the search score with an exponential decay on a timestamp so newer revisions outrank superseded ones. Built on the knowledge level pipeline,…
  • Typed Page Tool Results: Added PageCommandResult and PageFileSystem.runcommandresult / aruncommandresult with explicit error, completeness and truncation metadata.…
  • Agents act as their own principal. An agent session now acts as the agent, on behalf of the person who started it, and every audit event records both. The kortixcli permission scope is now…
  • Microsoft Teams is complete. Agent questions, images, and the remaining Teams flows now work like Slack.
  • Saved history works while the sandbox is off. Session transcripts and their attachments load on web, SDK, and CLI without waking the sandbox.
  • Mermaid previews. .mmd and .mermaid files render as diagrams in the file viewer.
  • Mobile app revamp. New primitives, a project stack, and session chat parity with web. Session logic is now shared through @kortix/sdk.
  • #3990 32000d0 Thanks @Grapedge! - In fullscreen, click a folded block to open or close it.
  • #4004 e17ff67 Thanks @Grapedge! - Add a TUI mode setting to /settings with an experimental fullscreen layout; switching modes takes effect after restarting Kimi Code. You can also set tuimode in…
  • #3964 6451f1e Thanks @7Sageer! - Block file tools from accessing files outside the working directory through symlinks.
  • #3975 bb96d80 Thanks @RealKai42! - Reduce the CLI's startup time and memory usage.
  • #3957 6a214b8 Thanks @huangzheng2016! - Fix a "Maximum call stack size exceeded" error when opening large sessions.
Base44
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.18 NPM Tag: latest
  • Agent Controller stream message events changed: one full messagestart, then ID-addressed messageupdate deltas; messageend now contains only the message ID (store by ID and apply updates).
  • @mastra/mcp@2.0.0 is a major rewrite: MCP 2026-07-28 only (legacy handshake removed), suspend/resume replaces elicitation APIs, and several server/client transport and protocol surfaces were…
  • Make the workspace grep text-extension whitelist extensible. Added .sas, .log, and .jsonl to the built-in text extensions and MIME type map so they are searchable by default. Added an optional…
  • Added consistent, resumable prune() execution for storage adapters, including bounded work, pause intervals, and cancellation. (#23466)
  • Added list-compatible page pagination to advanced trace queries while preserving keyset cursors. (#24061)
  • Fixed background job completions interrupting foreground Bash and eval calls, which could cause those calls to be repeatedly moved into the background.
  • Fixed Claude Opus 5.5 not applying a mid-session switch to high-effort reasoning when the session started without an explicit effort setting.
  • Fixed Alibaba Token Plan monthly quotas not appearing in usage reports or the status line.
  • Added built-in StepFun provider support for the step-5-preview model, including live model discovery.
  • Fixed cost estimation for OpenAI Codex GPT-6 Sol and Luna models across standard and worker routes.
  • Support genai-prices 0.1.7 and new OpenAI audio models
  • Add OpenAI gpt-6-sol and gpt-6-luna model support
  • Add Claude Opus 5.5 (claude-opus-5-5) support
  • Preserve UIMessage.id across Vercel AI loadmessages and dumpmessages
  • Preserve AG-UI Message.id across AGUIAdapter.loadmessages and dumpmessages

Sep 22, 2026

  • Fixed stream finalization when a provider ends without emitting a completion or error event, ensuring the final assistant message is preserved and corresponding message lifecycle events are emitted.
  • Fixed tool execution being incorrectly skipped when host steering callbacks reject during a tool batch.
  • Fixed stream hangs and preserved the original error when host aside-commit or discard callbacks fail.
  • Added Claude saved-reset discovery and redemption, including session-only resets, grant eligibility, expiry, and safe retry handling.
  • Fixed custom OpenAI-compatible extension streamers failing when no compatibility configuration was provided.
  • Bump version to 1.0.54 (#8632) (2352506b5)
  • Preserve onboarding example attribution (#SKY-16818) (#8633) (0e6274ff8)
  • Stop syncing devscripts to the open source repo and inline the invisible hCaptcha test fixture (#8631) (b6749ea20)
  • Remove the fake captcha test site and inline the invisible hCaptcha fixture into its test (#8626) (9a3ee5e44)
  • Rename CodeBlock redaction test constant so OSS CodeQL stops flagging it (SKY-16595) (#8624) (e93325e95)
Strands Agents
  • fix(cli): align @strands-agents/sdk range with harness (fixes interventions instanceof crash) (#4530) (d13c21486)
  • fix(cli): improve onboarding and terminal responsiveness (#4518) (2db407431)
  • fix(bidi): remove retired Nova Sonic 1 from integration tests (#4512) (d29c36e1f)
  • fix(cli): install provider SDKs with the CLI (#4508) (91a44787a)
  • fix(sandbox): preserve UTF-8 across stream chunk boundaries (#4157) (20231cb1e)
Sim
  • feat(jev): add TypeSafe evaluation models to Agent
  • feat(models): add GPT-6 Sol and Luna
  • feat(providers): add Claude Opus 5.5
  • improvement(settings): consolidate access requests in settings
  • refactor(ui): narrow local style forwarding and preview geometry
  • feat(assistant): slash command menu and 100-step budget
  • feat(agui): let callers opt out of graph state on the stream
  • fix(frontend): keep assistant reopenable mid-run
  • fix(mcp): 404 for missing servers on GET and PATCH
  • fix(frontend): report deleted MCP servers on edit
Cline
  • Composio connectors now load all their tools, not just the first 20. Google Calendar, for example, showed only 20 of its 47 tools, and the Installed view wrongly said "20/20." The full list is now…
  • You can now connect to a Mac as an SSH remote from a Mac. Picking a Mac host used to fail with "Remote target darwin/arm64 is unsupported in SSH" even though Test passed on the same profile. The…
  • Session errors now stay in the transcript when you leave a session or open it in another client. Before, a failed run's error disappeared once you went away and came back, or opened the session in…
  • Stopping a run while it waits to retry an empty model response now takes effect right away, instead of after the backoff finishes
  • Add optional OSC 777 terminal notifications for direct Ghostty and WezTerm sessions.
  • Text selection now works in bottom-anchored dialogs, including login device codes
  • Preserve /allow-all during managed-settings refresh failures, and remember exact session approvals for missing paths without granting their parent directory; exact grants are visible in /list-dirs…
  • Sandboxed network denials from proxy tunnel failures now show bypass guidance
  • Custom-agent startup now distinguishes model-list load failures from an empty catalog, preventing false unavailable warnings and silent required-agent deselection
  • Latest frontier models — Use Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna through supported providers, including GitHub Copilot. See Choose a Model.
  • Grok 4.7 by default for xAI — New xAI sessions now default to Grok 4.7. See Provider Authentication.
  • Added inherited Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna support for GitHub Copilot.
  • Added inherited GPT-6 Sol and GPT-6 Luna support for OpenAI API keys and OpenAI Codex subscriptions.
  • Added inherited Claude Opus 5.5 support for Anthropic with adaptive thinking and a 1M context window.
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Added Claude Opus 5.5 (claude-opus-5-5), now the default Opus model — 1M context, $4/$20 per Mtok with $0.20/Mtok cache reads
  • Added mouse support to more lists in fullscreen mode: the wheel scrolls the /skills list, and a skill's state options in /plugin can be clicked
  • Added CLAUDECODEMAXMCPDESCRIPTIONLENGTH to change the 2,048-character cap on MCP tool descriptions and server instructions for every MCP server in the session
  • Added hook output sizes and the number of oversized outputs saved to a file to the hookexecutioncomplete OpenTelemetry event
  • Fixed writes through a symlinked path being judged by their in-tree spelling: the prompt names where the write lands, and acceptEdits, allow rules and auto mode no longer approve one landing outside
Kortix
  • Let owners and admins open every session. An owner can turn on an account
  • See who owns each session. The Sessions page shows each session's owner and
  • Sending from the project home sends the message instead of freezing the input,
  • A session that wakes fills in its saved history.
  • The waiting indicator stops while a turn is waiting on you.
OpenHands
  • feat: test remote MCP servers on cloud backends via the app server
  • feat: open Git Sync to org admins on cloud backends
  • feat(i18n): translate recently added Turkish UI strings
  • fix: show the add automation menu to org members
  • fix(canvas): keep the base path on links that leave the app
Qwen Code
  • fix(review): keep unplanned chunks out of coverage, and read the denominator from the plan
  • feat(review): record what a plan was computed from, and report drift
  • fix(core): accept nullable pagination when reading notebooks
  • fix(cli): clean up stale session debug logs
  • feat(java): Add managed tool execution state
  • Allow /teleport with Vibe and workspace API keys, including free accounts, without an internal feature gate.
  • Explain which API keys to use when teleport rejects a Codestral key.
  • Warn when managed configuration contains removed Vibe Code settings.
  • On Windows, opening a session that is already open in another process reports 'Session is already open' instead of a raw permission error.
  • On Windows, idle-session cleanup no longer mistakes a session held by another process for an idle one.
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.16 NPM Tag: latest
  • Adopt OpenCode v1.18.14 through v1.18.15 improvements, including message ordering fixes, compaction serialization, locale coverage, and TUI enhancements.
  • Adopt OpenCode v1.18.16 through v1.18.18 improvements, including conversation-aware compaction, expanded reasoning effort support, provider compatibility fixes, and retry handling.
  • #14360 675ed4b - Retry transient connection drops when approving permissions so auto-approve and manual approvals no longer leave agents waiting.
  • Adopt OpenCode v1.18.14 through v1.18.15 improvements, including message ordering fixes, compaction serialization, locale coverage, and TUI enhancements.
  • Adopt OpenCode v1.18.16 through v1.18.18 improvements, including conversation-aware compaction, expanded reasoning effort support, provider compatibility fixes, and retry handling.
Deep Agents
  • Added cache bust timer to the footer.
  • Added a durable Debug Console cost breakdown.
  • Added support for copying the highlighted thread ID with Ctrl+C.
  • Improved cost-warning behavior by showing session cost warnings in a modal and suppressing historical cost warnings when resuming. (#6393,
  • Made thread browsing and resume flows more resilient with recoverable thread-picker resume failures, loading labels for thread details, and a clearer thread message count header. (#6476, #6430,
  • Name a None output route None rather than NoneType
  • Raise when UserPromptPart.content is not a str or a sequence, instead of silently sending a dict's keys
  • Ask three more field types TypeSafeModel can already answer
  • Refuse a tuple output field and a self-contained model instead of crashing
  • Refuse a rubric with more levels than Jev scores against

Sep 21, 2026

Strands Agents
  • feat(defaults): opus 5 and high thinking by default (#4460) (c3fc5ff81)
  • feat(site): launch the redesigned Strands website (#4446) (1fd2ad684)
  • fix(cli): depend on the published harness in exported projects (#4478) (8ecf1ebc1)
  • fix(harness): align Node requirement and default model docs (#4469) (1f08ea61c)
  • fix(context-ts): accept a ContextManager instance in Agent contextManager (#4459) (9248cab36)
  • Fixed Bedrock image attachments so they are only hoisted for Claude, Nova, and Llama 4 models.
  • Fixed Together AI streaming usage reporting.
  • docs: add DeepSeek V4.1 Flash to Zen
  • feat: add Grok 4.7 to Zen and Go
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Sim
  • feat(organizations): expose organization and permission group administration
  • chore(trigger): upgrade Trigger.dev to 4.5.16 so deploy images build without deleting nodemodules
  • chore(ci): give the Trigger.dev upload job room for a slow image push
  • @waleedlatif1
  • fix(mcp): decode resource template URI variables
  • feat(mcp): let a served agent own its HTTP transport settings
  • feat(tealtiger): add ratelimit governance policy
  • feat(skills): render a MemorySkill body per read
  • fix(a2a): require only the chosen transport's SDK extra
  • fix: cherry-pick subflow retry and connection-reference fixes into 0.91.1 (#15689) @abuaboud, @hazemadelkhalel, @Louai-Zokerburg, @majewskibartosz
  • fix: cherry-pick subflow retry and connection-reference fixes into 0.91.1 (#15689) @abuaboud, @hazemadelkhalel, @Louai-Zokerburg, @majewskibartosz
  • fix(build): unblock the release — MinIO moved off Docker Hub, and drop the source maps the image build deletes (#15691) @abuaboud
  • fix: cherry-pick subflow retry and connection-reference fixes into 0.91.1 (#15689) @abuaboud, @hazemadelkhalel, @Louai-Zokerburg, @majewskibartosz
  • Canonical session context and extension boundaries — Edit model context without rewriting history and add actionable lifecycle hooks. See ContextEditEntry and extension events.
  • Full-transcript context extensions — Use contextwithsystem for per-request system-message transformations. See contextwithsystem.
  • Per-model image input limits — Configure cache-safe image resizing per model for attachments, read, and tool-result images. See Image Input Limits.
  • Removed the inherited shouldStopAfterTurn agent option. Use finishTurn and return { action: "end" } instead. finishTurn runs before turnend but applies the decision afterward, and it also receives…
  • Added ContextEditEntry to the exported SessionEntry union. TypeScript consumers with exhaustive entry switches must handle contextedit; use replacement: null for omission and a content replacement…
  • hermes update (git installs), or re-run the installer one-liner.
  • Docker / Hermes Cloud: images build from this tag (nousresearch/hermes-agent:v2026.9.21).
Kortix
  • Edit a person's account role from a group's member list. You no longer
  • A new API key or ChatGPT account is private by default. The Add dialog
  • One place to pick provider keys for a session, and the choice saves.
  • Sessions stay usable after the project's repository changes.
  • Every role assignment is checked against the owner ceiling, so an assignment
Oh My Pi
  • Added support for text embeddings, document reranking, video generation, image generation across multiple providers, audio speech synthesis, and audio transcription services.
  • Added support for the System One judgment API, including configurable request headers for proxy routing and custom authentication.
  • Updated API response cost reporting to use aggregate usage totals.
  • Model list responses now optionally include a model kind.
  • Fixed detection of Claude usage-limit errors.
Qwen Code
  • fix(cli): scope the ACP permission queue to the session
  • feat(channels): add shared output modes with DingTalk support
  • feat(web-shell): slide the active pill between tabs
  • refactor(goal): delete the first-generation Stop-hook Goal implementation
  • fix(ci): separate autofix runner labels from queued reviews
  • fix: resolve a ton of security alerts
  • fix: resolve a ton of security alerts
  • fix: resolve a ton of security alerts
  • fix: resolve a ton of security alerts
  • fix: resolve a ton of security alerts
Crush
  • 56abdfa7f1fa2cbe1e073f553bc10b06598046f9: themes: prefix diff theme keys with diff (@meowgorithm)
  • a88b5735ff056b52eee8d30121b85c8a8ca79601: themes: small adjustments to the key names in the theme API (@meowgorithm)
  • Add user and managed startup defaults for the Auto routing tier, including strict and user-overridable organization policy
  • Consecutive steering prompts in the same mode combine into one pending message. Press Up in an empty chat input to take it back for editing, including pasted text and attachments. The recall hint…
  • A worktreePathTemplate setting decides where /worktree, /move, /new and --worktree create worktrees. Set for example ~/src/worktrees/{repo}/{branch}; {repoPath}, {repo}, {branch} and {branchSlug}…
  • Number-key selection in the question dialog works for choices 10 and beyond
  • Sandbox proxies work on Windows, and a proxy with a username and password works on every platform
  • release(langgraph): 1.2.12
  • chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph
  • feat(langgraph): add responseschema to interrupt()
  • fix(langgraph): type undeclared v3 stream projections
  • chore(langgraph): bump mistune to 3.3.4
n8n
  • Limit declarative routing during base URL ownership checks (#39146) (164b3f3)
Deep Agents
  • Reload skills when skillsmetadata is reset to None (#6364).
  • Reject parallel edits to the same file to prevent conflicting changes (#6446).
  • 0114a3f release(deepagents): 0.7.16
  • f173a01 chore(deps): raise dependency minimums for all
  • 2e2ee91 fix(sdk): reject parallel same-file edits
  • Doctor plugin registry: preserve the complete bundled plugin inventory when Doctor creates or repairs registry state, so default Browser, Canvas, pairing, file-transfer, phone-control, Talk voice,…
  • Security and credential safety: harden command parsing, browser origin checks, plugin Git installs, diagnostics, service credentials, and webhook logging across Gateway and official plugins.
  • Message and session integrity: preserve queued, imported, streamed, and tool-result messages across retries, hooks, recovery, and channel lifecycle transitions.
  • Gateway reliability: close failed HTTP and Responses streams, bound expensive reads and history queries, and settle shutdown work before reporting completion. Thanks @RomneyDa.
  • Channel delivery: repair Discord, Matrix, Telegram, Slack, WhatsApp, LINE, Feishu, Zalo, and meeting-plugin edge cases that could lose, corrupt, or stall messages.
  • #14054 3b6746c Thanks @vkeerthivikram! - Reintroduce automatic session cleanup in Settings > Checkpoints. Keep it off by default and apply the configured retention period across all projects and…
  • #14301 f03ebe3 - Create new Git projects and clone repositories directly from Agent Manager. Choose where projects are stored and attach them without changing the VS Code workspace. Adding a…
  • #14282 d0475a6 - Label prompts that Kilo sends on your behalf, such as worktree updates from base, expanded slash commands, and editor or terminal code actions, with a "Sent by Kilo" header. Long…
  • #14344 83d276a - Load older chats on demand in the session history with a "Load more" control instead of stopping at the 100 most recent. Paging works across the workspace and every worktree…
  • #14346 65702ab - Preview session display settings with an automatic sample conversation that streams reasoning, tool progress, and an answer beside the controls.

Sep 20, 2026

  • feat(web-shell): restore remote workspace add flow
  • feat(web-shell): expose assistant turn settlement lifecycle
  • Adds an internal bwrap-based Linux sandbox execution foundation with structured process launching, supervision, and confined worker support.
  • feat(web-shell): choose the Live Voice model and voice from the setup card
  • feat(web-shell): expose slash-command exports as artifacts
  • Meta Muse provider — Sign in with Meta using /login meta or use METAAPIKEY to access Muse Spark models. See Meta (Muse subscription).
  • Added Meta (Muse subscription) login via /login meta with automatic Model API key refresh, plus METAAPIKEY support
  • Enabled Node's persistent compile cache before loading the bundled CLI runtime, reducing repeat launch time.
  • Fixed /bug descriptions dropping line breaks from pasted diagnostics.
  • Fixed /bug hints appearing for user cancellations and retryable provider failures such as service unavailability.
  • DeepSeek now offers DeepSeek Flash and DeepSeek V4 Pro as easy provider
  • DeepSeek Flash supports image input and a 1M-token context window.
  • Fixed the provider model picker loading state so available choices load
  • Inherited GPT-6 and GPT-5.6 models remain available, as does the existing
  • Merged the Terminus UTF-8 boundary fix from PR #1911.

Sep 19, 2026

  • Prompt cache warming — Keep valuable prompt caches alive during long tool runs and optionally while idle using cost-aware refreshes. See Cache Warming.
  • Bug reporting — Report problems with /bug using redacted diagnostics, optional transcripts, or exported ZIP archives. See Reporting Bugs.
  • Transcript-aware prompt and tool updates — Preserve instruction and tool changes across resume and branch navigation while retaining cached prefixes. See beforeagentstart.
  • Offline Radius model catalog — Select Radius models immediately, with cached and live catalogs overlaid when available. See Radius.
  • Per-model compaction budgets — Configure reserved and recent-token budgets by model. See Per-model overrides.
  • #3922 9df7a9c Thanks @sailist! - Fix new messages occasionally landing at an old position in the conversation after resuming a session.
  • #3911 88a7d93 Thanks @Grapedge! - Fix compaction failing after switching to a model with a smaller context window.
  • #3929 6ffdf0d Thanks @7Hanrui! - The agent no longer assumes the current working directory is the project root.
  • #3933 9721259 Thanks @liruifengv! - Fix a message sent while the agent was running sometimes appearing twice in the chat.
  • #3934 2e605b1 Thanks @liruifengv! - web: Improved interactions and fixed known bugs.
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
  • Let TypeSafeModel fill a tool's arguments when Jev can express them
  • Add RealtimeSession.waitforplayback() and let the docs examples finish the reply before closing
  • Add supportstextoutput to ModelProfile, and run LLMJudge and GEval on a model without it
  • Add typesafebooleanthreshold for what a yes/no has to be before it is True
  • Let TypeSafeModel fill a union of output types by choosing the type first
  • Changed auto mode for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry and gateways, to default to the server-side classifier, which does not charge for classifier overhead…
  • Added an Auto mode server row to /status showing whether this session's auto mode classifier runs on the server
  • feat(library): Best AI Agent Builders with MCP Support
  • feat(workflows): add model fallbacks to Agent, Evaluator, and Router
  • feat(mcp): Sim MCP server for the full Sim API
  • feat(access-requests): remove rollout flag and move feature into ee
  • improvement(knowledge): rank inside the permitted set for organization search
  • Release notes — formatted for people, with expandable sections.
  • Changelog — plain Markdown for AI agents and tools.
  • npm package
  • registry tarball
  • integrity: sha512-TCO/ImVLh5HkF4tdfo7iriIa7kT6iYkIr/jR5ZOkePGFGhUx5Oe7DE716Y1DzzG2teRAVDdCjgJDu1A24Yta7w==

Sep 18, 2026

  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Deep Agents
  • Scoped cancel() requests to the requested session.
  • dfed90c release(deepagents-acp): 0.0.12
  • fc6df1f chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/acp
  • 0f5a2b5 release(deepagents): 0.7.15
  • 96236d2 fix(acp): scope cancel() to the requested session
Sim
  • improvement(knowledge): match keyword chunks before authorizing them
  • fix(file-search): isolate and queue concurrent searches
  • @icecrasher321
  • @waleedlatif1
  • .NET: fix: race concdition in workflow formula state
  • .NET: update remaining dependencies
  • .NET: fix: inspect for delemiter value before adding headers
  • docs: fix 'availble' typo in ADR 0001
  • .NET: docs: use 'a FunctionApprovalRequestContent' in ADR 0006
  • Fixed Anthropic prompt-cache head re-baselining on every memory recall refresh: the system breakpoint now anchors on the last stable segment instead of the volatile recall suffix, and the…
  • Fixed auth-broker client config resolution failing silently on Windows when reading the token file or config.yml; reads now use node:fs instead of Bun.file.
  • Fixed clipboard paste stalling on an empty clipboard; image and text clipboard reads now run concurrently so the empty-clipboard status surfaces after the slower read instead of the sum of both.
  • Fixed memory recall blocks carrying a minute-resolution Current time stamp that dirtied the cached system prompt on every refresh; recall rows already carry dates, so the stamp is removed.
  • Fixed omp auth-broker token and omp auth-gateway token exiting silently without creating a token on Windows when no token file exists yet; token and config reads now use node:fs instead of Bun.file.
  • Telemetry: OpenTelemetry event names are now preserved on platforms outside of Agent Engine, ensuring more accurate and consistent tracking. (9110770)
  • telemetry: only drop the OTel event name on Agent Engine (9110770)
Claude Code
  • Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under "Project instructions" in /config (not yet on Bedrock, Vertex or Foundry)
  • Added CLAUDEGATEWAYPROXYISEGRESSBOUNDARY=1 for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally
  • Added an optional headers: map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider
  • Added a line saying a background task's update is waiting when it finishes while a panel such as /tasks is open
  • Fixed claude -p and Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1
  • Changes since langchain==1.4.1
  • release(langchain): 1.4.2 (#40621) fix(langchain): preserve model-generated tool calls in HITL tool call edits and add notice to ToolMessage
  • #3878 f233f9d Thanks @7Sageer! - Stop listing unavailable media tools in subagent menus and clarify Read errors for images and videos.
  • #3762 c5ad17f Thanks @7Sageer! - Providers can read their API key from a named environment variable (apikeyenv in config.toml or the provider API).
  • #3896 73ebe9a Thanks @sailist! - Keep follow-up messages sent during a turn from appearing twice after a session reload.
  • #3889 5108cad Thanks @huangzheng2016! - Compact the session index on startup when many entries point to deleted sessions.
  • #3889 5108cad Thanks @huangzheng2016! - Start the CLI faster by removing a duplicate skills directory scan.
  • #2249 ebab868 Thanks @mattzcarey! - WebSockets speaks the Agent protocol for plain hosts, and gains a Cap'n Web transport.
  • A plain Durable Object composed with WebSockets now works with useAgent and AgentClient: the capability sends the identity frame on connect (protocol: false leaves the connect sequence to the…
  • useAgent({ transport }) and AgentClient({ transport }) pick the wire. "cf-websocket" (default) is the hibernating socket; call()/stub send JSON rpc frames. "capnweb" runs one Cap'n Web session…
  • @callable() decorators remain the JSON-wire interface of Agent; an Agent wanting native calls passes callables.
  • The experimental ?agentsrpc=capnweb endpoint from 0.23.0 is removed.
Kilo Code
  • #14251 b3ef153 - Add @model, @past-chats, and @worktrees mentions to the Agent Manager New Worktree prompt. Past chats and worktrees are sent as attachments to the new session, and model…
  • #14249 d73b514 - Run worktree-independent slash commands from the Agent Manager New Worktree prompt. Custom commands, skills, MCP prompts, and /goal now appear in the prompt menu and execute when…
  • #14274 d162846 - Keep the Agent Manager .kilo directory out of git in subdirectory workspaces and avoid creating it in folders that are not git repositories.
  • #14277 d8eaefd - Recover permission approval dialogs that stall instead of leaving the approval buttons disabled.
  • #14280 815a81b - Fix a memory leak that made Agent Manager session switching slower the longer the window stayed open. Tool card fade animations kept unmounted transcript rows alive.
  • Subagent conversation history is readable through the owning parent session
  • Configurable live subagent status and read-only transcript switching from the interactive prompt
  • experimental-harness sessions can track todos, shown as a pinned line under the input and in full on /todo, and keep a per-session scratchpad whose notes are re-stated to the agent after the…
  • Turn an installed skill on or off from the /skills browser without removing it.
  • Skill authors can mark skills as explicit-only, keeping slash invocation available while preventing model-initiated loading.
  • core: Repair data-encryption keys stored as the raw instance key (#38911) (954f6d8)
  • core: Sweep parents parked on a finished sub-execution (#38949) (496b7cb)
  • editor: Fix blank workflow previews in AI Assistant (#38915) (058bb8a)
  • A second agent harness, behind a flag. pi (pi-agent-core) now runs in-process in the sandbox alongside OpenCode, selected per project by the piharness feature flag. It implements abort-after-tool…
  • The piharness setting reads correctly in all nine languages.
  • Internal: the sandbox daemon's timing budgets now tolerate a slow machine during a process respawn, so a correct restart is no longer reported as a failure.
  • Restored the load-balancer response-time alarms required by the Drata DCF-86 control.
  • feat(kortixd): pi harness — pi-agent-core in-process as a second HarnessDefinition
  • Add TypeSafeModel for TypeSafe's Jev
  • Pass xhigh effort through on Bedrock when the model profile supports it
  • Allow gpt-5.6-sol, gpt-5.6-luna, and gpt-5.6-terra on Bedrock Converse
  • Resolve a DynamicToolset once per durable run instead of inside every durable unit
  • Hold one MCP server session per durable run instead of one per durable unit
  • Added BaseAudioResampler.flush() and BaseAudioResampler.reset(), so callers can mark stream boundaries themselves rather than relying on SOXRStreamAudioResampler's inactivity timeout. flush()…
  • Scripted eval expectations on functioncall accept an eval:: each matched call is judged by name and arguments, under a judge prompt of its own, so a scenario can check what args: cannot match…
  • AWSTranscribeSTTService.Settings gained partialresultsstability, which selects AWS Transcribe's "high", "medium" or "low" interim-result stability. It still defaults to "high".
  • Added an effect setting to AzureTTSService and AzureHttpTTSService, which passes Azure's <voice effect> audio effect processor (eqcar, eqtelecomhp8k) through to the synthesis request.
  • Added a reasoningeffort field to GroqLLMService.Settings, which passes Groq's reasoning effort control through to the completion request. Accepted values vary by model: "low", "medium" and "high"…
  • Updated bundled Claude CLI to version 2.1.276
  • Cline starts again after updating. In 0.0.31 the app could fail at launch with "desktop backend exited before publishing its endpoint" and never reach the workspace picker. Cline runs its own copy…
  • Captain assignment, scenario and tool controls, and improved playground testing. [Enterprise]
  • Guided WhatsApp setup and clearer account health.
  • WhatsApp campaigns and calls for BSUID-only contacts.
  • Per-inbox call recording and transcription settings. [Enterprise]
  • Additional conditions for delayed automations.

Sep 17, 2026

Kortix
  • Choose which account a connector runs as, per call. A connection now carries the accounts you may run it as, and the account is chosen when the connector is called rather than pinned to the whole…
  • An ambiguous connector call is refused, not guessed. When several accounts are reachable and none is named or pinned as default, the call is denied with accountrequired instead of silently picking…
  • Choosing a connector account is discoverable in the CLI rather than a dead end.
  • A connector you have your own accounts for reads as connected, not "needs setup", and the admin connector list now agrees with what each caller can actually reach.
  • Connector accounts are per connection instead of a connector-level strategy, and connections the old strategy flag made unreachable are revoked.
Oh My Pi
  • Improved agent performance by reducing redundant tool-schema processing during repeated model calls and optimizing streamed tool-call argument parsing.
  • Added support for templating and custom base and authentication URLs in OAuth flows.
  • Fixed Anthropic prompt-cache breakpoints stalling when conversations include mid-conversation tool changes, preventing growing message tails from being unnecessarily re-billed as uncached input.
  • Added the stencil authentication provider for omp stream, supporting OAuth code + PKCE sign-in with auth.stencil.so, configurable via STENCILAPIKEY, STENCILAUTHURL, and STENCILBASEURL. This is an…
  • Corrected Yolo-Auto metadata for Qwen Flash: qwen3.8-flash and the paid yolo route now report the documented 256K context window and use the Qwen chat-template reasoning dialect, with…
  • Custom agents can opt into repository instruction files (AGENTS.md, copilot-instructions.md, CLAUDE.md) by setting include-custom-instructions: true in their frontmatter.
  • Resuming an active session without plugin-directory, discovery, or working-directory overrides preserves marketplace plugins and skills after reload. Configuration read or validation failures no…
  • /sandbox policy now reports local-network access using your configured setting
  • The status row now says it is waiting for background shells, instead of "Working", when a turn ends while an attached background shell such as a dev server is still running.
  • Resume sessions even when transcript files contain recoverable corruption
Claude Agent SDK
  • Updated bundled Claude CLI to version 2.1.275
Claude Code
  • Added the signed-in account to Claude apps gateway sign-in: when the gateway names it, you confirm it before the credential is saved, and /status shows it
  • Added a send-now key (ctrl+enter, or ctrl+x ctrl+s) that interrupts the current turn and sends all queued messages at once; sent and queued messages show in gray until the model receives them
  • Added a startup warning when a configured otelHeadersHelper fails, so sessions that silently export no telemetry are noticed
  • Added syncing of the skills and plugins enabled on your claude.ai account to terminal sessions signed in with it; opt out with syncClaudeAiSkills: false or syncClaudeAiPlugins: false
  • Added /plugin install <plugin> --marketplace <source>, which offers to add the marketplace before installing the plugin
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • fix(core): align conditional approvals with validated tool arguments
  • fix(core): deliver tool-not-found output on server-managed resume
  • fix(sandbox): keep command paths POSIX on a Windows host
  • fix(sessions): handle concurrent async SQLite startup
  • fix(sessions): do not forward session limit as Conversations page size
Cline
  • Cline can now work on a remote machine over SSH, with the app itself staying local. Add and test a host under Settings → Remote, then pick it from the environment selector beside the workspace…
  • Sub-agents spawned in the same step now run at the same time instead of one after another, so delegating three independent pieces of work takes as long as the slowest one rather than the sum of…
  • Route Desktop to state-machine loop via ACP prompt meta
  • EUrouter as a declarative provider
  • Connect external backend ACP socket to redirect-resolved backend URL
  • GPT-live API support
  • Operator allowlist for gateway pairing
  • #14209 3eaf47b - Remove KiloClaw: the VS Code chat panel and sidebar button, the /kiloclaw TUI command and chat view, the Kilo Chat client and token handling, and the kilo.claw.status and…
  • #14204 d202c80 - Animate the Kilo logo on the welcome screen: hover the mark to see it turn and play the yellow slot-machine animation.
  • #13519 9e61d68 - Show ChatGPT Codex quota alongside other provider usage in the CLI and VS Code.
  • #14170 36771e6 - Show large pasted text in the prompt input as an expandable [Pasted ~N lines] block that restores the full text when expanded, copied, or sent.
  • #14137 91040bc - Report worktree problems accurately and repair them: stale entries are cleaned up on their own, a deleted worktree can be restored from its branch or removed while keeping its…
Sim
  • feat(library): AI-Native Workflow Automation vs Traditional Automation Platforms
  • feat(library): AI Agent Examples by Department and Industry: A Practical Roundup
  • feat(coda): add permission-aware knowledge connector
  • improvement(insights): default to the last 30 days
  • fix(knowledge): preserve permission notices and fixture isolation
n8n
  • core: Allow a domain-restricted credential to work in its own node (#38786) (7e98622)
  • core: Update undici to 7.29.1 (#38849) (3357ecc)
  • core: Update vm2 to 3.12.2 (#38846) (b3b77aa)
  • Snowflake Node: Update the Snowflake SDK to 3.3.0 (#38831) (1281ee6)
  • feat(agent-profiles): select secrets available to a profile
  • feat: forward Docker conversation runtime settings
  • feat(automations): select saved agent profiles
  • test: isolate Mock-LLM profiles from ambient secrets
  • chore: bump released agent runtime dependencies
  • #3849 34ec5d2 Thanks @wbxl2000! - Add the /desktop slash command (alias /install-desktop) and the kimi install-app subcommand to open the Kimi Code desktop app page in the browser.
  • #3851 faec32c Thanks @Grapedge! - Render mermaid code blocks as diagrams in the terminal; turn it off under /settings → Mermaid diagrams, or set mermaid = "off" in the [markdown] section of tui.toml.
  • #3838 f4e5822 Thanks @sailist! - Fix an occasional crash when a running turn is canceled.
  • #3802 c72a202 Thanks @Grapedge! - Highlight diff code blocks.
  • #3844 0cf413f Thanks @Grapedge! - Fix a steered message appearing twice after interrupting the turn.
  • Fixed payment errors from non-Zed model providers incorrectly prompting users to upgrade to Zed Pro instead of displaying the original provider error message. (#64354)
  • Fixed different snippet extensions for the same language cancel each other (#64314)
  • fix(cli): scope the ACP permission queue to the session
  • feat(channels): add shared output modes with DingTalk support
  • feat(web-shell): slide the active pill between tabs
  • refactor(goal): delete the first-generation Stop-hook Goal implementation
  • fix(ci): separate autofix runner labels from queued reviews
Pydantic AI
  • GHSA-vmxc-h2x2-jmf3 (moderate): the cloud-metadata and private-IP blocklists could be bypassed with an IPv6 zone identifier on a URL opted into local network access, via…
  • GHSA-fpf4-vwcp-v4hp (moderate): webfetch processed responses in superlinear time on the event loop, in both the HTML conversion and the charset decode, so a single attacker-chosen page could stall…
  • GHSA-22h6-qm39-v87j (low): webfetchtool's domain lists were compared as written rather than in the form the resolver uses, so a blocked domain could be reached under another spelling. (#8407,
  • GHSA-4x9p-g9wm-8q7f (low): with InstrumentationSettings(includecontent=False), spans still carried exceptions, error statuses, instructions and the output template. Reported
  • Make RunContext.enqueue() safe from worker threads

Sep 16, 2026

  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Support aliases as connection identifiers
  • Record reasons for deployment creation failures
  • Collect human feedback and pause events in tracing
  • Add llmoverlay context variable to route agent roles to models
  • Carry taskprompt and output in agent execution payloads
Deep Agents
  • Fixed prompt clipboard word deletion behavior.
  • Clarified unknown model effort in footer.
  • Prevented duplicate clicks in the footer model and effort pickers.
  • Delayed hook status display in the footer to reduce UI noise.
  • 229ffef release(deepagents-code): 0.1.70
Kortix
  • Projects with thousands of sessions no longer slow the app down. The session list now loads one page at a time — 50 sessions, with a Load more control — instead of returning every session on every…
  • Opening, sharing, stopping, restarting or renaming a session now works however old the session is. These controls used to look the session up in the full list, so once a project grew past the…
  • Date grouping (Today, This week, Older), filters and search work as before, applied to the sessions you have loaded.
  • A new database index serves the paged list, so a request no longer sorts every session in the project.
  • The pagination cursor is encrypted and tied to both the project and the person viewing it. It cannot reveal a session they are not allowed to open, and it cannot be reused by anyone else.
  • feat: scope an agent profile to specific MCP servers
  • feat: add GPT-6 Astra model support
  • feat: track authenticated Canvas arrivals
  • feat: surface automation disablement reason in the UI
  • fix: recognize Azure DevOps SSH remotes
  • Azure OpenAI Responses: Added AzureOpenAIResponses to use the Responses API with Azure OpenAI deployments. See cookbook.
  • Elasticsearch: Added Elasticsearch vector database with vector, keyword and hybrid search. See cookbook.
  • DocumentationMarkdown: Added a transform for Knowledge.syncpages that converts Mintlify and Fumadocs components into plain Markdown. See cookbook.
  • MCPConfig: Added roothost, path and pathaliases to serve MCP on a dedicated hostname or a custom endpoint path.
  • MCP Server Card: /mcp/server-card now returns pretty-printed JSON.
  • Queued messages can now be sent into the running turn with Enter. While the agent is working, pressing Enter with an empty composer steers the first message in the queue, so it is picked up at the…
  • The macOS Dock icon now has the standard margin other apps use. The bundled icon and the selectable runtime icons (Classic, Chip, Hologram, Midnight) were edge-to-edge, so Cline rendered visibly…
  • The session sidebar's sort toggle now shows the mode a click switches to, not the one already active — a folder icon while sorted by time, a clock while grouped by project
  • Changes since langchain==1.4.0
  • release(langchain): 1.4.1 (#40498) fix(langchain): preserve open MCP object arguments (#40414) fix(langchain): correct InterruptOnConfig documentation
  • Added configurable baseUrl support for bedrock-converse-stream requests, enabling Amazon Bedrock providers and compatible custom providers to use VPC or PrivateLink endpoints, FIPS hosts, and…
  • Corrupt credential databases are now backed up privately and recreated instead of preventing startup; signing in again restores credentials.
  • Fixed malformed Anthropic thinking signatures that could freeze sessions at 100% CPU.
  • Fixed Anthropic-compatible gateway tool-call handling so client-declared tools are reported with stopreason: "tooluse" and already-executed native provider tools are not exposed for clients to run…
  • Fixed gateway session isolation when clients omit a session key, preventing one conversation's retained provider state from affecting another.
  • Added the onnewwindow setting to choose whether new windows show the Launchpad (launchpad, the default) or an empty untitled buffer (emptytab). (#63522; thanks albertbogusz)
  • Fixed ctrl-tab jumping to random documents when the mouse moved during a quick tab switch. (#52671; thanks OmChillure)
  • Fixed a crash in editor: rotate selections forward and editor: rotate selections backward when using cursors on nonconsecutive lines. (#63937; thanks timvermeulen)
  • Fixed language servers from other projects appearing in the LSP Logs view and their statuses showing in unrelated windows' status bars. (#61221; thanks aviatesk)
  • Fixed layout issues in the Settings UI for recently created GitHub accounts. (#63630; thanks tidely)
  • fix(core)!: let bash expand project directory variables in command hooks
  • feat(core): cap websearch calls per session
  • feat: track background result execution across daemon and web shell
  • feat(cli): full /hooks dialog in OpenTUI
  • feat(core): emit hook progress events
  • 1648f10ac039e126635e26d4a16647331b2d6f0c: feat: add plan mode (#2822) (@vadiminshakov)
  • 051fb37ae1d6bd6d6f2f6cbc8a629d5f85aa9bd7: fifix(ui): color the to-do task name while the tool is still running (@taciturnaxolotl)
  • 2019da14717e4e00aeee7664873c6b78f147a3eb: fix(tui): unfreeze spinner clock when the boot busy probe lands (#3839) (@andreynering)
  • fd58b5ed201f490641d018cab6f06a29cdaff2c0: fix(ui): read the session transcript off the event loop (@taciturnaxolotl)
  • d55e017d60cdb87ecb21a19a9fed9a2097c0da64: perf(agent): read only the post-summary tail of a compacted session (@taciturnaxolotl)
n8n
  • core: Check Gateway credits eligibility against the correct sub-node (#38673) (0cf7e99)
  • core: Add v3 breaking change rule for the storage directory rename (#38636) (c3dcbbe)
  • core: Warn on deprecated N8NDBPINGTIMEOUT env var (#38569) (ab03087)
  • Vim mode is now available to everyone. Turn it on with /vim or by setting editorMode to vim for modal editing in the composer, with the current mode shown while you type.
  • Add /settings options to opt in to context management tools for agents and subagents
  • Set transcriptView to "concise" to group tool activity into expandable work summaries.
  • Add /config to open a sidebar configuration screen in the CLI
  • Add /sandbox Network host allow/deny rules without replacing your configured upstream proxy
  • feat(components): upgrade Guardrails with optional combined rule and model checks
  • fix: preserve restricted-component diagnostics in streamed errors
  • fix: stop double-prefixing catalog policy CHECK names under naming conventions
  • fix(migrations): stop double-prefixing CHECK constraint names under the naming convention
  • fix(db): give the flowversion CHECK constraint one name across create paths
  • feat(sso): open Sim from an identity provider's app dashboard
  • feat(cleanup): add per-type row limits to existing jobs
  • fix(tables): rework lock settings as Table Security and gate locked actions
  • fix(files): hydrate chat attachments and reject blank download URLs
  • fix(provenance): align file matching and report withheld attachments

Sep 15, 2026

Oh My Pi
  • Added optional queued-message preparation with cancellation-safe delivery and appended context
  • Fixed streaming CPU blowup on long turns: per-delta messageupdate snapshots now deep-clone only the blocks the stream actually touched instead of the entire accumulated message, eliminating the…
  • Native compaction now carries an existing local summary into the first provider-native request instead of losing the summarized history.
  • Subsequent native compactions preserve messages appended between a speculative snapshot and its commit, while honoring /clear boundaries.
  • Native replay compatibility checks the active provider and Responses API independently of whether future native compaction is enabled.
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Kortix
  • Previews open again when you are signed in. A sandbox preview opened from a session (prod-p<port>-sbx-….p.kortix.com) showed "Sign in to open this preview" even though you were signed in. Sign-in…
  • The release gate quarantines TUN-6 on deployed targets only: Bun's WebSocket client sends no User-Agent, so the edge firewall refuses the tunnel handshake on staging and prod. The flow still runs…
  • chore(release): staging VERSION → 0.13.16 [skip ci]
  • chore(release): staging VERSION → 0.13.17 [skip ci]
  • test(release): quarantine TUN-6 — Bun WebSocket handshake has no User-Agent, WAF 403s it on staging/prod
  • snapshot option for system prompts: Added a snapshot field to SystemPromptPreset and a new SystemPromptCustom typed dict. When snapshot is True, the session keeps the system prompt recorded on its…
  • Updated bundled Claude CLI to version 2.1.273
  • fix(core): improve destination validation and connection routing in web fetch utilities
  • fix(core): enforce RFC 9207 issuer identification in MCP OAuth flow
  • chore(release): bump version to 0.60.0-nightly.20260901.g0bd1d4397
  • Changelog for v0.58.0
  • fix(cli): isolate temporary directory for macOS Seatbelt sandbox
Claude Code
  • Added x-claude-code-request-class, x-claude-code-agent-type, x-claude-code-prev-tool-durations, x-claude-code-compaction and x-claude-code-context-compacted request headers for LLM gateways; opt…
  • Added a notification when an MCP server disconnects mid-session and automatic reconnection gives up, pointing at /mcp
  • Added forking a session started with claude --remote-control or /remote-control from the Claude app; the fork runs as a background session on your computer
  • Fixed Bash commands the permission checker cannot fully analyze skipping the prompt under permissions.blockReadsOutsideWorkingDirectories, and a subshell hiding a dangerous rm in bypass mode
  • Fixed skills synced from claude.ai staying available after your organization turns Skills off; they now move to the recoverable trash
Strands Agents
  • feat(storage): add bm25 search strategy (#4079) (495d1540e)
  • feat(sandbox): include partial output in shell timeout errors (#4325) (bd4020f8d)
  • feat(vended-tools): port Python notebook improvements to TS (#4281) (6c7988831)
  • feat(context-py): port strategy presets and agent rewire (#4282) (08ed4cfd3)
  • feat(context-ts): add context strategy presets + rewire defaults to use class (#4256) (a8b1b90af)
  • Run loop blocking detection. The agent now detects code that blocks the
  • Faster agent startup. The prefork server preloads libraries before
  • Improved agent lifecycle tracing. Traces now cover the full agent
  • feat(speechify): send Speechify-Caller-Version attribution header
  • fix(llm): reposition mid-conversation instructions for Gemini gateway and Mistral
  • Claude Integration: Access the step-by-step reasoning process of Claude models by ensuring visible thoughts are requested during adaptive thinking tasks. (ba0d542)
  • request visible thoughts for Claude adaptive thinking (ba0d542)
  • fix(internals): compare both matrices' column counts in cosineSimilarityMatrix
  • feat(memory): add DakeraMemory for persistent cross-session agent memory
  • fix(examples): migrate basicscolab and agentscolab notebooks from granite3.3 to granite4.1:8b
  • Feat/1479 OpenAI server
  • feat(infra): port Runnable interface to TypeScript
Sim
  • feat(providers): refresh model catalogs and support custom routing
  • feat(ui): add shared media lightbox with zoom controls
  • fix(landing): stabilize announcement scrolling and mobile previews
  • fix(executor): seed run-wide access key lists and scope exact-key cache grants
  • fix(settings): seed the server deployment shape on organization and standalone settings surfaces
Kilo Code
  • #14155 f894108 - Show message timestamps on hover in the chat transcript, including the turn's finish time and duration.
  • #14168 a16e5e9 - Show code added with "Add to Context" as a collapsible context card in the prompt input instead of pasting the path and code block as text
  • #12714 23ecd42 - Move marketplace catalog, installation, removal, and installed-item detection into the CLI backend so editor clients use the shared marketplace API.
  • #14159 0480c79 - Support a custom speech-to-text source. Point voice input at any OpenAI-compatible transcription API with a base URL and optional API key, instead of always using Kilo Gateway.…
  • #14149 60628ee - Move Add project to a fixed footer in the Agent Manager project list
  • Replace subscribeQueuedMessages({ resourceId, threadId }, listener) with subscribeThreadEvents({ resourceId, threadId }, listener) (listener now receives typed events like queue-count-changed).
  • @mastra/archil: ArchilFilesystem.grep() renamed to diskGrep().
  • Added the Studio Workflow Builder backend. Configure the editor with the new workflowBuilder option to enable a hidden, editor-owned agent that authors persisted workflow definitions: (#23493)
  • Added per-call background execution dispositions, awaited background calls, caller-scoped completion signals, and bounded delegated background tool execution. (#23026)
  • Added NotificationsStorage.updateNotificationsStatus() to set one status on many notifications of a thread in a single write. The notification inbox tool now uses it to mark a viewed page seen…
  • Add source-generated GLM-5.3 and GLM-5.3-Flash picker entries for Z.AI Coding Plan, Zhipu AI, and Zhipu AI Coding Plan.
  • Refresh related provider metadata, including GLM-5.2/5.3 highspeed entries where the source exposes them. Picker membership follows the maintained source's tool-calling eligibility; this does not…
  • GLM-5.3-Flash exposes image input and a 1M-token context window in generated source metadata.
  • Existing inherited GPT-6 Astra and GPT-5.6 presets and Gemini 3.8 Flash support are unchanged.
Cline
  • The app no longer gets stuck on "Desktop backend unavailable" when the backend is slow to start. The window asked for the backend's address exactly once and the shell stops waiting after about 15…
  • Confirming text with a Chinese or Japanese IME no longer sends the message. The Enter that commits an in-progress composition also reached the composer, so choosing a candidate fired off a…
  • The model picker refreshes its list every time you open it, instead of staying frozen until you restart the app. The Recommended and Free groupings come from a live feed, so a newly promoted free…
  • Signing in with Cline now explains what the plan includes. The sign-in card lists the regular free model promotions, ClinePass for generous usage across open-weight models like DeepSeek, Kimi, and…
  • Cline Pass now starts you on a model from your subscription. Its model list carries both subscription and free models and the default was simply the most recently published entry, so a subscriber…
  • npm: bash npm install -g base44@latest
  • Homebrew: bash brew install base44/tap/base44
  • Version: 0.1.15 NPM Tag: latest
  • #3780 486dcd2 Thanks @Grapedge! - Update the terminal UI engine, fixing link colors in wrapped markdown tables and @ file-completion ordering, and adding native clipboard support on Linux X11.
  • #3776 48fad6e Thanks @huangzheng2016! - Fix memory not being released when subagent scopes are disposed.
  • #3777 dc76b0c Thanks @huangzheng2016! - Fix progressively slower rendering on each round of large agent swarm runs.
  • #3631 1336be3 Thanks @wbxl2000! - Stop returning deleted sessions from global search before the search index catches up.
  • #3775 f248624 Thanks @huangzheng2016! - Reduce event-loop stalls and GC churn in sessions with many concurrent subagents.

Sep 14, 2026

  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Added fast mode in Claude Code Remote sessions (cloud and self-hosted runners): the host's fast-mode setting or /fast typed in the session applies where your organization allows it
  • Added mouse support to the /config panel in fullscreen mode: the wheel scrolls the settings list, a click on a setting's value changes it, and the row under the pointer is highlighted
  • Added claude self-hosted-runner --drain-marker-file <path>: when that file exists at a SIGTERM drain, the runner reports its exit to the server as a host drain (telemetry only)
  • Added per-command alloweddomains to Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refused
  • Added omitClaudeMd to agent frontmatter and --agents JSON, letting custom and plugin subagents run without user, project and local CLAUDE.md files; managed policy files still load
  • Revert model updates for patch release
  • Roll back MCP default version selection update #6d8152a
Deep Agents
  • Update readfile output formatting.
  • Surface DeepSeek V4.1 Flash in the model picker.
  • Surface locally tracked GitHub stacks in agent context.
  • Copy a model slug with Ctrl+click.
  • Show session length in the Debug Console.
Oh My Pi
  • 400-request debug dumps now redact provider-specific auth headers (x-goog-api-key, x-amz-security-token, and any header whose name carries a key/token/secret), not just a fixed allow-list, so a…
  • Enabled assistant prefill support for Ollama models
  • OpenCode Zen GPT-6 Astra requests now use the Responses endpoint instead of failing through chat completions with HTTP 500 (#12030).
  • Hub message/job waits now always use the adaptive window (5s, lengthening to 5m across back-to-back waits); removed the timeoutMs argument and async.pollWaitDuration setting.
  • Added a privacy warning to memory reports reminding users to review data for secrets before sharing
  • feat(network): add organization-specific HTTPS egress
  • feat(copilot): show model-authored tool activity
  • fix(integrations): remove workspace Search configuration
  • fix(chat): share thinking and preserve natural activity labels
  • fix(search): shorten direct retrieval and simplify result states
  • Restored ACP session model, effort, mode, and reasoning chunk boundaries when loading, resuming, or forking sessions. (@JacobNWolf)
  • Show remote config authentication errors during startup and exit with a failure status.
  • Request summarized adaptive thinking for GitHub Copilot models.
  • @heimoshuiyu
  • feat(console): add batch workspace block endpoints
  • Remote dashboard sessions no longer expire on refresh bursts (#110061, fixes #55712; salvage #71548 @Doud-FR, #55717 @liuhao1024). Both refresh paths on the gateway (cookie gate and the desktop's…
  • Long-lived processes stop leaking duplicate state.db writer handles (#110934, fixes #100896 #103339; salvage #107974 @kshitijk4poor, mapping @Rroven): gateway, dashboard/Desktop backend, ACP and…
  • hermes update (git installs), or re-run the installer one-liner.
  • Docker / Hermes Cloud: images build from this tag (nousresearch/hermes-agent:v2026.9.14).
  • Removes configurable message-prefix filtering from channels, so eligible messages now follow normal sender, group, mention, and pairing policies without a prefix.
  • fix(core)!: read command hook timeout in seconds
  • Lets approved Web Shell Goal proposals start automatically after their owning turn finishes, removing the need to copy a manual /goal set command.
  • feat(sdk): add a peer endpoint so a program outside Qwen Code can join cross-session messaging
  • Adds optional Goal limits via model.goalMaxTurns and model.goalMaxActiveMinutes, and rebases active Goal time on restore.
  • 🐛 Resolve variables in Forge option arrays.
  • 🐛 Strengthen preview isolation, linked draft permissions and preview session creation.
  • 🐛 Restrict WhatsApp sessions to internal runtime access.
  • 🐛 Authenticate webhook responses and relay subscriptions, and enforce webhook ownership and write access.
  • 🐛 Protect SMTP configuration tests and special-use IP ranges against SSRF.
  • 6f670995436a0bab99e3fdddd0eebc5c52c39072: fix(home): require path boundary when shortening or expanding ~ (#3552) (@teddytennant)
  • 066f4444d086aeac877ec0a67eb2a3d56fedde27: openaicompat: bump fantasy to fix regression around reasoning-only turns (@meowgorithm)
  • feat(linear): filter Updated Issue trigger by changed fields (#15435) @AdamSelene, @claude, @OdaiAhmed99
  • fix(pieces): declare remaining runtime deps for datadog and scrapeless (#15519) @kishanprmr
  • fix(pieces): hide body input for GET/HEAD requests (#15398) @kishanprmr
  • feat(gmail): add AI actions for the gmail.modify scope (label, trash, archive) (#15512) @kishanprmr
  • feat(google-drive): Optimize google drive list files (#15461) @danielpoonwj, @kishanprmr
  • #3749 6126472 Thanks @liruifengv! - web: AI session titles are now always on — a title is generated after the first turn and can be regenerated from the rename field, with no experimental flag…
  • #3670 a9efbe0 Thanks @Grapedge! - Delete sessions from the session picker: press Ctrl+X on a session, then y to confirm.
  • #3763 dd6a411 Thanks @liruifengv! - web: add user agreement and privacy policy entries to the Settings → About page.
  • #3750 775a6c3 Thanks @7Sageer! - Add the loopcontrol.compactionmaxattempts config option to set the maximum total attempts for a failing compaction request (default 5).
  • #3667 9296e68 Thanks @sailist! - Add the dynamicallyloadedtools capability to official Kimi Code models when the service declares support for message-level tool declarations.
  • editor: Fixes issue that prevented some users from revoking their end-user credentials (#38455) (3d8f578)
  • core: Add log streaming events for instance reports (#38483) (6174e8e)
  • Open Interpreter 0.0.43
  • Maintenance release based on upstream Codex rust-v0.154.0. Adds easy choices for Gemini 3.8 Flash and 3.7 Flash, Z.AI ZCode and GLM support, and inherited GPT-6 Astra plus GPT-5.6 Sol, Terra, and…

Sep 13, 2026

  • An expired Cline sign-in now produces one actionable error instead of two dead ends. A turn that fails before the runtime takes the prompt was reported twice — the hub's detail-less run.failed…
  • The Account page now offers a sign-in prompt when your Cline refresh token is rejected, instead of an error card whose Retry failed the same way. A rejected refresh was falling back to the…
  • Signing out of Cline and Cline Pass now sticks. Sign-out removes the provider entry, but the runtime re-imports missing providers from the classic extension's stored credentials on every command,…
  • The settings sidebar's Models section is now API Providers, with an icon to match — it is where you configure providers and their credentials, not where you pick a model
  • A failed voice input now shows a "Speech input failed" toast in chat with the actual error, instead of dropping you into Settings → Voice. Any error that wasn't a browser exception was treated as…
  • Fixed Windows OAuth sign-in failing on every attempt after an upgrade when a previous run left a stale native callback registration behind; handlers registered by older binaries are now recognized…
  • Fixed DeepSeek V4.1 Flash dropping image attachments on hosts without their own carve-out, so the natively multimodal model is no longer treated as text-only
  • LiteLLM model groups keep the image input their deployment declares, instead of having attachments replaced with the "model does not support vision" placeholder (#11982,
  • Fixed OpenCode Zen/Go Muse Spark models failing every tool-call turn with a 400 "reasoning encryptedcontent was not issued to this caller" error: the gateways proxy the Responses lane to Meta but…
  • Added collab.autoStart (off | view | control): every local interactive session hosts itself as it starts and rotates its room on /new, /resume, fork, or branch, so a phone or dashboard can reach…
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release

Sep 12, 2026

  • Added Agent.getPendingToolResults() for reconstructing live displays before buffered tool results are persisted
  • Added opt-in host authorization and exact-once streamed child execution for discard-safe local reads.
  • Tool <name> not found now also suggests mounted xd:// devices, not just the advertised tool set, via the new suggestFallbackToolNames option (#11516,
  • Speculative stream sessions are now discarded when a hook or argument transform replaces a call's arguments while keeping its ID, instead of releasing deferred work planned from the original code
  • Charm Hyper accounts now report their remaining prepaid credit balance in /usage
  • Fixed read-only git commands in Bash unexpectedly asking for permission after a session had been running for a while (regression in 2.1.269)
  • Connector discovery excludes raw HTTP connectors that do not support MCP tools.
  • A single invalid connector no longer prevents the rest of your connectors from loading; an individual tool with an oversized schema is dropped on its own, and accounts over the connector cap keep…
  • Automatic session titles use the active model on custom Mistral endpoints.
  • Smart-approve now appears in the Vibe Desktop mode picker when enabled via its rollout, and a background refresh no longer drops it.
  • ACP clients (Zed/JetBrains) always list the active mode, so a session can never get stuck on a mode missing from its own list.
  • SmallestTTSService now uses Smallest AI's continuation API: text fragments within the same LLM turn share a contextid so the server joins them into one continuous generation instead of resetting…
  • Added LiveKitParams.audiooutqueuesizems to configure the outgoing rtc.AudioSource buffer size. Defaults to LiveKit's 1000 ms, so existing behaviour is unchanged.
  • Added enableturndetection to GradiumSTTService. With it on, Gradium's server-side end-pointing signal decides when user turns start and end instead of the pipeline's VAD, and the service…
  • ⚠️ Behavior change: Pipecat now supports the openai 3 SDK, and the openai dependency is widened to >=1.74.0,<4, so a fresh resolve picks openai 3. It builds its HTTP clients on httpx2 instead of…
  • Widened the anthropic dependency to >=0.49.0,<2 to support the anthropic 1 SDK. AnthropicLLMService sends temperature, topk and topp through the request's extrabody, since the Messages API methods…
  • efba40b7bf88ca143587cbdebb74cf1b463c316a: feat: OpenAI oAuth (@andrinoff)
  • 4a74b9e095792217e95867bf74c1aa86fef44ee2: fix(sessions): keep list position after deletion (#3769) (@ifsin)
  • 33be610debb1eaf33bac40e0b089e1aa84d05602: fix: @meowgorithm review (@andrinoff)
  • 63829edfa302a120d954866bada40e1ca9003ea8: fix: always emit tool results right after calls (#3743) (@andrinoff)
  • cdc72006bf73e9d137516d3fa44c44d64ec192cf: fix: always show full bash command in tui, output stays collapsible (@andreynering)
  • Add a first-run banner describing the run, and open clai sessions with it
  • Preserve text part boundaries after tool calls in OpenAIChatModel
  • fix(temporal): key tool opt-out checks on operation kind, not an MCP import
  • @KaranJayakumar made their first contribution

Sep 11, 2026

  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Serve MCP Apps: AG2 can now serve MCP Apps, with structured tool output and extension support.
  • Input requests, both directions: An AG2 MCP server can ask the calling client for input, and an AG2 MCP client can answer a server that asks for it.
  • outputscan: A new policy that inspects what a tool returns, rather than what it was asked to do. Every policy so far ran before the call; this one runs after, so a tool that returns something it…
  • Middleware: Chat spans now record the full history and tool-call output, rather than a partial view.
  • Dead table-of-contents anchors and moved contribution-policy links repaired.
Sim
  • feat(library): What to Look for in an AI Workflow Automation Platform: Buyer's Checklist
  • feat(assistant): support image attachments
  • feat(library): Why No-Code AI Agents Need Live Web Access (And How to Wire It Up)
  • fix(sidebar): change organization logos from the icon
  • fix(redis): size cold-connection waits to survive a dead handshake
  • Anthropic server-side compaction as a remote compaction backend: model lines the beta supports (compat.supportsServerCompaction, rule-owned in the catalog: Opus 4.6+, Sonnet 4.6+, Fable/Mythos 5)…
  • compact() now forwards the caller's oneshotRetry opt-out to every summarization oneshot; auto-compaction's outer retry loop no longer multiplies with the inner transient-failure retries.
  • Anthropic server-side compaction (compact-2026-01-12 beta): anthropicCompaction on StreamOptions sends the compact20260112 context-management edit, the streamed compaction block is surfaced as an…
  • Added historical decimation prompt-cache breakpoints every 15 user turns on Anthropic requests, so long conversations retain stable cached prefixes during branching, rewinds, and session resume
  • Defaulted Anthropic OAuth requests to 1h prompt-cache retention where supported, matching Claude Code subscriber behavior and preventing cache expiry during idle intervals
  • No more second writers. Profile gateways wrote hosted-room state into the root state.db every 5 seconds; the dashboard opened a writable handle on startup; cron's lifecycle guard did a raw open()…
  • Healthy WAL databases stop wedging. OpenZFS (deleted) dentries and a close() racing an appendmessage both produced a sticky DeletedWalGenerationError on a perfectly good store; the read pool was…
  • FTS damage no longer kills your turn. An error scoped to the full-text-search index was classified as whole-file corruption and fail-closed the conversation. It's now ftsindex: search degrades,…
  • One corrupt row no longer kills sessions list, export, or insights. A TEXT timestamp or a 1e30 epoch used to crash the whole listing; malformed marker JSON crashed jsonextract; more than 999 ids…
  • Sessions never bind to or read another profile's database. The Desktop launch backend could pin itself to the wrong profile's state.db under a HERMESHOME override race; sessionsearch by bare ID…
  • Added claude plugin eval: run a plugin's eval suite against Claude Code and get scored, reproducible results (JSON + HTML report); see claude plugin eval --help
  • Added /output-style [name] to list and switch output styles, including over Remote Control and in cloud and other headless sessions
  • Added a diff of the files a Bash command changed to the Bash tool result when the Bash tool handles file edits (setting bashEditDiffEnabled)
  • Added OTELMETRICSINCLUDEREPOSITORY to tag OpenTelemetry metrics and events with vcs. repository attributes; commit events get vcs.ref.head. with OTELLOGTOOLDETAILS
  • Added CLAUDECODEGATEWAYMODELDISCOVERYTIMEOUTMS to extend the LLM gateway /v1/models discovery timeout (default 3s)
  • feat: click an image attachment to open it full size
  • feat: only the creator can turn an automation back on
  • feat: allow editing automations on cloud backends
  • feat: show which identity an automation runs as
  • feat: use DB-driven free/default model flags in Canvas
  • .NET: Replace deprecated AWSSDK.Extensions.Bedrock.MEAI with AWS.Bedrock.MEAI
  • .NET: Remove Azure.AI.OpenAI dependency
  • .NET: Track and update A2A task state
  • .NET: Update Azure AI Projects to 3.0.0 beta 1
  • .NET: Bump Aspire.Hosting from 13.5.2 to 13.5.3
  • New /branch command forks the current conversation into a new resumable session, leaving the current session unchanged. Resume the copy in another terminal with vibe --resume <id>.
  • Bump the local harness runtime to v0.4.5.
  • Make @ file mentions use Git-aware discovery and accept standalone pasted files and folders.
  • Retained chats remain readable and restore their worktrees when work resumes.
  • New session logs are no longer readable by other users on POSIX systems.
  • #2193 87bd594 Thanks @mattzcarey! - Extract facet ("sub-agent") machinery into packages/agents/src/dynamic-agents/, add the this.dynamicAgents capability facade, and reposition facets as an…
  • #2175 8ffb3ad Thanks @mattzcarey! - Lifecycle owns a durable job queue, driven as an alarm event loop.
  • #2198 99e5e2e Thanks @mattzcarey! - Add RoutedAgents (agents/routing), a Lifecycle capability that codifies the "user hub with one Durable Object per chat" topology: an owning Agent keeps a…
  • #2196 ec93caf Thanks @mattzcarey! - Add the experimental agents/sessions Lifecycle capability and the agents/context module.
  • Session.create(this).withContext(...) → install new Sessions() on the Lifecycle and declare blocks with new ContextBlocks([...]) from agents/context.
  • None called out in this changelog.
  • Added trace filters for span names, model providers, timing, outcomes, identity, and version lineage. (#23018)
  • Added deleteFeedback() and deleteScores() to observability storage. Both accept a batch of ids and optional organizationId / resourceId tenant scope, are idempotent, and are implemented by the…
  • Added typed input and output payloads for the spans Mastra records itself: AGENTRUN, MODELGENERATION, MODELSTEP and MODELINFERENCE. Every other span type keeps any. Stored spans narrow the same…
  • Added portable top-level string metadata predicates to advanced trace queries. Invalid metadata keys and values are rejected consistently, and valid predicates work inside recursive Boolean…
  • core: Execute MCP toolkit members on workers (#38277) (1025dc7)
  • core: Reuse an existing consent grant after the visitor authenticates mid-flow (#38249) (52c8a72)
  • core: Trust the CA from GITSSLCAINFO for source control HTTPS remotes (#38297) (3234078)
  • The composer now shows the current branch's GitHub pull request — PR number, merge status, changed-line totals, and CI checks. Click through to open it in your browser, or expand CI to inspect…
  • The Customize view's Tools, Skills, and Rules tabs now read as one consistent list instead of three different ones, matching the pattern Plugins already used. Tools gets a search bar that filters…
  • Deleting a queued prompt no longer leaves it in the transcript as a message that never ran. The sidecar inferred a queued prompt had started whenever the pending list shrank and its head changed —…
  • A session forked from a checkpoint restore no longer comes back stuck on "Thinking...". Sessions that materialize with seeded history never passed their status when persisting, so the row and…
  • Sending an image with no text no longer fails with "session input requires a prompt string" — the composer asks for a message instead of letting the request through to a backend that rejects it
  • Added sendmessage support for progress updates.
  • Added targeted conversation deletion.
  • Added support for managing tool approvals through tools.json.
  • Improved MCP reliability and safety by hardening OAuth device-flow and credential handling, preserving refresh tokens, making configuration updates bounded and non-destructive, reporting protocol…
  • Improved background subagent and conversation reliability, including recoverable start/stop behavior, scheduled-job delivery, clearer orchestration enforcement, preventing one conversation from…
  • Release notes — formatted for people, with expandable sections.
  • Changelog — plain Markdown for AI agents and tools.
  • Signed source: 3a9d69db306cd7f081e06254cb89c4bcc14a7107.
  • Full stable validation: passed, attempt 2. Qualification also verified 15 performance measurements and 20 real OpenAI completions across 10 upgrade baselines.
  • Core npm publication: passed; exact qualified bytes, registry signatures, provenance and fresh install verified.
  • Added LatencyBreakdown.contributions, a timeline of the user-to-bot interval whose durations sum to the measured latency. It names the time no service reports — VAD silence, turn detection,…
  • Eval scenario turns can play an audio file as the user instead of synthesizing text. A turn's audio: names a recording, resolved relative to the scenario file, in any format soundfile reads (WAV,…
  • Added a cancellablebyllm argument to LLMSwitcher.registerfunction(), which forwards it to every LLM the switcher fronts. Tools registered through a switcher can now opt into LLM-side cancellation,…
  • Added AssemblyAISyncSTTService, a segmented speech-to-text service backed by AssemblyAI's Sync API: pipeline VAD segments the audio and each segment (up to 120 seconds) is transcribed in one HTTP…
  • AzureSTTService.Settings gained segmentationsilencetimeoutms, which sets how much silence (100–5000 ms) Azure allows inside a phrase before it emits a final transcript. Azure's default of 500 ms…
  • Sandboxes cannot outlive their work. A session turn now has an absolute ceiling as well as a renewable one. Renewal asks whether a turn is still running, and a wedged turn answers "yes" forever,…
  • Fewer server errors when the database is busy. Connection-class and contention failures are now recognised as the temporary conditions they are and retried, instead of being reported as server faults.
  • Errors say what actually went wrong. A failure now carries its real cause rather than the message of whatever wrapped it, and how serious it is follows that cause. Ordinary customer state no…
  • A large unused database index is gone, removing its write cost from every audit record. It was 8.6 GB and had served no read in two and a half months.
  • One subscription dialog, in the right place. The upgrade dialog now renders above the deepest panel that opened it, so its controls stay reachable and screen readers can see it. Escape closes it…

Sep 10, 2026

  • Billing opens one subscription dialog from the account hub. Its controls remain accessible, and Escape closes the subscription dialog while keeping account settings open.
  • Session Git pushes honor explicit ref grants within the effective IAM role. Manager-authorized sessions can update shared branches; agent grants cannot elevate a member to manager ref authority.
  • Connectors keep working after a bad manifest read. A session no longer loses every connector when one read of kortix.yaml answers wrong. Each grant now records the manifest revision it came from;…
  • Connector denials say why. connectornotassigned now names the agent, its granted list, the manifest revision, and what to change. A declared connector with no credential answers…
  • Slack progress is never silently dropped. slack step and slack send fail with a reason when a checkpoint or an answer does not reach the thread, instead of reporting success. A replayed idle event…
  • chore: isolate ruff dependencies in ci
  • fix(telemetry): describe option objects in the session report
  • chore: remove commented-out keepalive stub from Deepgram V2 STT
  • docs: remove stale example references after examples revamp
  • fix(openai): don't replace a TTS prewarm that is still in flight
  • Models: Safeguard agent uptime by automatically failing over to backup models when the primary model encounters errors. (c300b8d)
  • Integrations: Build rich voice and telephony agents using the newly added LiveKit runner. (f277d91)
  • Workflows: Simplify graph workflow management by authoring and loading ADK 2.0 graphs directly from declarative YAML configurations. (2a9461b)
  • MCP: Work with MCP SDK 2.x servers as well as 1.x. Installs continue to resolve 1.x by default; install 2.x deliberately to opt in. (856acf2)
  • Workflow node resumption: A node that failed now runs again when the workflow resumes, where before it replayed as though it had completed. Make node bodies idempotent: a node that performs an…
  • Added to the Claude apps gateway: with pricing: set in gateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so /cost and telemetry match the spend meter
  • Added a startup warning for gateways when accesscontrol.allowcidrs is empty, and a one-time warning the first time a request arrives from a public address
  • Added the gatewayInternalNetworks managed setting, letting administrators allow /login to a Claude apps gateway on their organization's own public IPv4 block
  • Added claude self-hosted-runner --remove-session-state (default off): delete each session's per-session directories under <base-dir>/sessions/ when the session ends
  • Added configDirectory to the output of claude auth status --json
  • Tool <name> not found now names a plausible intended target when the advertised set contains one, e.g. Tool mcpabc123xyz789read not found. Did you mean read?. A model that mis-transcribes a long…
  • Fixed the token estimator counting developer messages as free and ignoring images in user content, which let context budgeting, pruning and the compaction trigger read a transcript as far smaller…
  • Fixed repeated local compaction omitting messages retained before the previous compaction record, while preserving original entry IDs and /clear boundaries.
  • Raised remote compaction request timeout from 3 minutes to 5 minutes so long Codex/gpt-6-astra compact streams can finish before the watchdog aborts them.
  • Fixed proxy responses dropping the cost the server reported; recorded costs are kept instead of being recomputed.
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Kilo Code
  • #14013 d2381d7 - Enable the experimental shared agent board (Kilo Swarm) with the KILOEXPERIMENTALSHAREDAGENTBOARD environment variable, or the umbrella KILOEXPERIMENTAL, in addition to the…
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
  • VS Code extension: debug submenu with log level picker, open log file, and a togglable session status panel showing agent statistics (steps, tokens, tokens/sec, context, cost)
  • Open the session picker faster by building the merged session listing once per cursor walk instead of on every page.
  • Renamed SessionBackendKind literals from "python"/"rust" to "legacy"/"unified" to match backend identity naming.
  • An "always" permission grant that fails to reach ~/.vibe now warns instead of passing silently: ConfigOrchestrator.setfield returns its errors rather than raising, so an ignored failure looked…
  • Steered prompts now preserve their host-provided display content in app-server session history.
  • improvement(search): reduce redundant metadata reads
  • fix(search): verify Atlassian access and clarify source setup
  • fix(search): preserve source rows during approval updates
  • fix(search): tighten Google sync and invitation recovery
  • fix(search): reserve interactive embeddings from their own admission lane
  • Knowledge base service-API keys were scoped to the whole workspace: one key could read and write every knowledge base in the tenant, so giving an integration access to a single knowledge base…
  • The workflow canvas required a mouse to reposition anything. Nodes, multi-node selections, comment markers, and draft comments can now be moved with the arrow keys — hold Shift for larger steps —…
  • Plugin authors now have public profile pages at /marketplace/creator/<handle>, listing their creations with a publisher sidebar, reachable from a new Creator Center entry in the sidebar help menu.…
  • The Markdown form field-name limit was hard-coded at 128 characters, with no way to accommodate longer generated field names. It is now configurable through MARKDOWNFORMFIELDNAMEMAXLENGTH (Docker)…
  • CSV cells were passed through pandas type inference before indexing. Leading-zero codes became floats (00123 → 123.0), empty cells became the literal string nan, and cells containing NA or NULL…
  • samples: Add Magentic custom-manager prompts and MLflow observability examples (#7876, #8085)
  • agent-framework-core: Add shared vector-store abstractions, portable filters, and an in-memory vector store (#8014, #8115)
  • agent-framework-core: Add a maximum-duration bound and stop-reason signal to the tool invocation loop (#7772)
  • agent-framework-core: Support mixed workflow invocation keyword arguments (#7963)
  • agent-framework-ag-ui: Add emitmessagessnapshot configuration for suppressing the terminal message snapshot (#7808)
n8n
  • core: Bound peak memory during source control push (#37975) (b3c32da)
  • Safer provider and channel boundaries: bundled providers and channel adapters now bound untrusted response bodies, reject oversized inputs before expensive work, and preserve safe recovery when…
  • More reliable long-running delivery: agent, gateway, retry, and channel paths now handle cancellation, retries, partial sends, and process-stream failures without losing work or replaying unsafe…
  • Stronger bundled-plugin resilience: local-model, browser, media, and collaboration plugins recover cleanly from malformed payloads, timeouts, and transient upstream failures. (#119942) Thanks…
  • Safer tool and workspace use: browser automation, local tools, workspace reads, and plugin metadata handling now reject malformed or oversized inputs before they can interrupt an active agent run.…
  • More dependable local integrations: local-model discovery, speech, meeting, and collaboration integrations now make bounded requests and surface failures without destabilizing the gateway.…
  • ChatGPT Subscription (Codex) now lists only the models your plan can actually use. Two separate paths filled the picker from the shared OpenAI catalog, so GPT-4o, GPT-4.1, and chatgpt-image-latest…
  • Windows updates no longer fail with "Error opening file for writing". The compiled sidecar re-executes itself as the detached Cline Hub daemon, which outlives the app by design, and Tauri's NSIS…
  • Your prompt is no longer lost when a send fails before the turn starts — switching to Codex and having the OAuth refresh throw, for instance. The runtime never took the prompt, so post-send…
  • Providers that authenticate through a local CLI — Claude Code, Codex CLI — can now start sessions without an API key. They showed as Configured in Settings via their local-auth capability, but…
  • OpenCode is now treated as a local CLI provider rather than an OAuth one, so it shows the local CLI notice instead of a browser sign-in button that could not do anything. It authenticates from the…
  • Recommended GLM 5.3 models are now available in code workflows (#6211).
  • Added pricing support for Fireworks GLM-5.3 and GLM-5.3 Flash usage (#6221, #6223).
  • Workspace switches now ask for confirmation before restarting the server (#6178).
  • Effort changes are now included in cache identity for OpenAI and Anthropic requests (#6196).
  • Standardized the recent-thread environment variable (#6205).

Sep 9, 2026

  • fix(webeye): allow raw-CDP screenshot rescue on persistent-context browsers (#8588) (24d08f8ad)
  • Gate passkey 2FA behind the enterprise plan with a visible book-a-demo upsell tile (SKY-14535) (#8587) (92976292e)
  • Run each Copilot build test in a browser that matches where the test starts (SKY-16164) (#8586) (a93ad7831)
  • Give type's forced click the same focus fallback as the plain click (SKY-16451) (#8585) (f4b56073d)
  • SKY-16029 / SKY-16325: Add FDE hours and payment terms to organization pricing (#8583) (b8d86f041)
  • Add telemetry to track checkpoint runtime and CLI usage.
  • Fix gateway errors reported inside an HTTP 200 response.
  • Keep deploy push on the AMP create source.
  • Report scrape failures instead of raising IndexError in the Oxylabs integration.
  • Route all DashScope models through the native provider.
Sim
  • feat(slack): improve source connections and app Home
  • improvement(redis): warm the shared connection at process start
  • improvement(landing): optimize hero and customer image loading
  • improvement(search): clarify integration approval and setup
  • improvement(redis): pair lock acquire failures with connection state
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • feat(vended-tools): port notebook tool to Python (#4132) (545d9ed07)
  • feat(bidi): simplify Google and OpenAI model configs (#4189) (6d4f61f28)
  • feat(python): add backgroundTasks to Agent (#4226) (42e5a61bd)
  • fix(session): filter malformed immutable snapshot IDs (#4199) (6d6c8fcea)
  • fix(telemetry): use semantic system instructions for agent spans (#4222) (e5ebbd67d)
  • fix(clipboard): only report copy success if it happens
  • fix: stop long reasoning traces from running away with the heap
  • fix(config): honor providers.json when auto-update is disabled
  • fix: inline code copying
  • fix: flickering screen when inline code was present
  • Added maxEffortLevel setting (top-level or per model under modelSettings): caps the effort level on every provider, including Bedrock, Vertex and Foundry; users can still pick a lower level
  • Added --system-prompt-snapshot off to render the system prompt fresh on every request instead of reusing the conversation's recorded prompt (for iterating on prompt text)
  • Fixed Cowork scheduled tasks in the cloud failing at startup for organizations whose managed settings require sandboxing
  • Fixed /context and other local command output rendering blank on mobile clients
  • Fixed shift+enter and option+backspace not working after reconnecting to a tmux or ssh session inside an agent view
  • feat: show manifest-declared value statements on dashboard cards and rows
  • feat: Make automation run UI task-outcome aware
  • feat: enable LLM provider connections on cloud
  • feat: allow editing a custom cron expression from the edit-automation modal
  • feat: unified cloud settings entrypoint for Agent Canvas
  • Codex SSE streams that end without a terminal completion event now retry when replay-safe and remain transient errors when partial output prevents replay (#11349).
  • /rename without a title now generates a session name from recent conversation using the configured tiny model.
  • Added opt-in experimental notes-backed context windows with persistent branch-local notes, searchable original session history, retained latest user requests, and a model-callable rollover tool,…
  • /loop accepts --until '<cmd>' / --while '<cmd>' to gate each iteration on a shell command's exit status, so a loop can stop on real project state instead of only a count or duration.
  • Read error and preview rendering now sanitizes tabs and Windows-style CRLF (e.g. ssh host-key failures, tab-indented fetched content) so raw output can no longer tear the result frame.
  • Added automatic language detection for untitled buffers. (#61412; thanks amtoaer)
  • Added support for rendering LSP 3.18 Markdown diagnostic messages from language servers. (#61030; thanks aviatesk)
  • Fixed searching for full SHA-256 commit hashes in the Git Graph. (#63371; thanks albertbogusz)
  • Added support for effort-based reasoning when using OpenRouter models. (#61308; thanks codello)
  • Added support for renaming Terminal Threads from the Threads Sidebar. (#63494)
  • fix(worker): disable piece cache prewarm
  • Revert "fix(connections): stop oauth2 connections failing to save when the code has special characters"
  • Desktop keeps 15 recent managed Code worktrees by default, configurable in Local Coding settings; cleanup skips active, dirty, untracked, or unpushed worktrees.
  • Background process tools (process.start, process.stop, process.output, process.list, process.write) now show the command or process ID in the call header and a typed result widget instead of raw JSON.
  • Tool call groups now fold into a single compact summary line by default. Click to expand the full list. Ctrl+O toggles all groups and result bodies. The summary shows present-tense labels while…
  • Show a loading spinner in the conversation while /reload is in progress
  • A risky call is returned to the model to self-correct rather than interrupting the human, escalating to an approval prompt only after a streak; no failure path auto-approves
  • feat: support current image generation tool options
  • fix(sandbox): prevent UnixLocal file API symlink races
  • fix(sessions): reset compaction response chain after pop
  • docs: document v0.22.1 behavior updates
  • release: 0.22.2
  • core: Keep reporting the original job error when the job key is gone (#38028) (cfc385f)
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
  • @mastra/factory: defineBoard() phases must add kind, working phases must add role, and initialPhase must be resting.
  • @mastra/factory: global rules object removed (FactoryRules, defaults/merge/assert helpers, new MastraFactory({ rules })); tool-result rules move onto defineBoard({ tools }) and configVersion…
  • @mastra/factory: GET /web/factory/projects/:id/attention response shape changed (tier removed; counts/latest fields moved under kinds[kind]...).
  • @mastra/playground-ui: TraceDataPanelView replaces partialThreadTabSlot with messagesPanelSlot; TracesLayout replaces sidePanelWide with sidePanelWidth: 'half' | 'wide' | 'full'.
  • Added tenant-scoped trace deletion arguments for observability storage with a limit of 1,000 trace IDs per batch. (#22553)
  • Fixed the live chat stream doubling text and dropping messages mid-turn. The sidecar has two Hub sockets that both receive a session's events — ClineCore's own client and the observer client — and…
  • Fixed a queued prompt's own message vanishing from the chat. When you queue a prompt behind a running turn, the runtime drains the queue just before it answers the previous send, so the previous…
  • Cline no longer stops silently mid-task when a model gets stuck repeating itself. The loop detector stops a run after 5 identical tool calls and the mistake tracker after 6 consecutive failures,…
  • The editor tool's error message now names the file, says whether oldtext was null or omitted, and states how to recover. Models that fill optional parameters with null (seen with kimi-k3) hit a…
  • Fixed your Cline Pass model selection being replaced when you start a new chat. Catalogs are discovery data, not validation — the bundled catalog can omit live Cline Pass models and refreshes can…
  • #3613 d4d20d2 Thanks @liukx0205! - Add read-only tools to the /btw side agent.
  • #3524 f6a9c39 Thanks @RealKai42! - Add an experimental Updates panel with paginated progress messages from the main agent and subagents; enable it with KIMICODEEXPERIMENTALNOTIFYUSER=1.
  • #3634 e831fd1 Thanks @7Sageer! - The subagent model pool ([secondarymodel]) is now always on; the experimental secondary-model flag and the KIMICODEEXPERIMENTALSECONDARYMODEL opt-out have been…
  • #3671 e6bc8b8 Thanks @liruifengv! - web: support permanently deleting sessions from the session row context menu, with a confirmation prompt.
  • #3526 55685c5 Thanks @RealKai42! - Stop reminding the model of its context budget before automatic compaction.
  • Added the Astra system prompt for GPT-6 models.
  • Preserved Bedrock DeepSeek model IDs, including ARN-based IDs, so they resolve correctly. (@YeEmrick)
  • Updated the Azure provider SDK to pick up compatibility fixes.
  • Updated the OpenAI provider SDK to pick up compatibility fixes.
  • Added reasoning effort variants for supported GitLab GPT and Claude models. (@far-ouq)
  • Reject invalid DeferredToolResults.approvals values
  • Add a GitHubCopilotProvider for GitHub Copilot's OpenAI-compatible API
  • Honor anthropicdisallowssamplingsettings in BedrockConverseModel
  • Resolve non-object $ref definitions inline in code-mode function signatures
  • Validate ToolReturnContent without a Python call per JSON node
  • Added GPT-6 Astra support (#6141).
  • Reuses the server across workspace switches (#6152).
  • Limits thread resume age (#6068).
  • Improved workspace isolation by resolving project policy per workspace, scoping project dotenv to workspaces, and isolating LangSmith auth and workspace tracing (#6064, #5980, #6061).
  • Improved transcript tail reconciliation by bounding and serializing reconciliation work (#6057, #6143).

Sep 8, 2026

Claude Code
  • Fixed a 2.1.265 regression affecting LLM-gateway and proxy setups: the undocumented CLAUDECODEUSEGATEWAY environment variable, previously ignored unless ANTHROPICBASEURL and ANTHROPICAUTHTOKEN…
  • fix(frontend): render no icon for plain select trigger
  • fix: detect watsonx models behind LiteLLM proxy
  • fix(cli): clean up failed serve inputs
  • fix(components): stop lazy loading from wiping the built-in registry
  • fix(kb): allow recreating names after locked deletion
Sim
  • feat(files): support heading images and simplify image selection
  • feat(landing): redesign marketing and product pages
  • improvement(docs): simplify navigation and share editor previews
  • fix(credentials): scope personal connections to organizations
  • fix(landing): refine product previews and customer media
Agno
  • fix: clean startup logs and initialize durable queue storage
  • fix: preserve Control Plane access with public surfaces
  • Release: v3.0.9
  • GitHub Copilot sign-in keeps the GitHub-owned Copilot CLI OAuth app on Enterprise domains: private instances run their own OAuth registry and reject the github.com-registered OpenCode client,…
  • GitHub Copilot sign-in uses the minimal-grant OpenCode OAuth app again (read:user only): GitHub renders each app's existing per-user grant on the consent page, so Enterprise organizations that…
  • GitHub Copilot plan/model-policy 403s no longer count as credential failures for credential-lifetime decisions: the token is valid, so stored credentials are preserved instead of wiped
  • Fixed custom google-generative-ai providers failing mid-turn model fallback when Gemini 3 tool calls are replayed without their original thought signature (#11270).
  • Added advisor.maxNotesPerUpdate setting and WATCHDOG.yml configuration (default 4): allows reasoning verifiers to batch findings in a single review update without being rate-limited.
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
  • Changelog for v0.58.0-preview.0
  • chore(release): bump version to 0.59.0-nightly.20260825.g812f7a2bc
  • fix(core): prevent SSRF in MCP OAuth metadata discovery and authentication
  • fix(core): enforce fail-closed workspace trust and filter mcpServers in restricted mode
  • Support GPT-6 Astra models
  • Tool calling for goose-agent
  • Kotlin callers can now configure Databricks AI Gateway path
  • Require HTTPS for Snowflake connections
  • Bind CLI session naming to trusted path
Strands Agents
  • feat: export context manager types as experimental (#4231) (ec6eb54a5)
  • feat: accept cacheconfig on Ollama, Writer, and SageMaker (#4232) (42aedfc03)
  • feat(context-py): port stash integration (#4187) (a642b4177)
  • feat(mcp): add prefixwithservername and continueonerror defaults to loadservers (#4177) (def3be9b4)
  • feat(context-py): port offloading stratgies (#4146) (e3f3ee49d)
Qwen Code
  • Managed memory availability now respects the memory.enableManagedAutoMemory setting (#6941). Hosts that disable managed auto memory no longer see remember/dream requests admitted or managed-memory…
  • Size-triggered microcompaction now clears old tool results toward a low watermark (#8464), so it no longer rewrites another part of the conversation prefix on every subsequent turn. Provider…
  • chore: bump version to 0.8.2
  • chore(release): sdk-typescript v0.1.4
  • Fix: Use resolved authType to initialize ACP agent
Kilo Code
  • Move a session to a worktree directly from the worktree editor.
  • Fork a session from the worktree editor.
  • Add Ctrl+1/2/3/0 shortcuts to cycle mode, model, and reasoning effort.
  • Exclude Kilo worktrees from IntelliJ project indexing.
  • Run project run configurations delegated to Gradle inside a worktree.
  • Safer updates: rehearse core and plugin changes in isolated candidate state before activation, support eligible 2026.9.2 migrations, and recover abandoned update records without stopping a healthy…
  • Performance: preserve warm prompt caches, reduce unnecessary work during cold session updates and memory search, and reuse worker builds between sessions. Related #140681. (#140449, #140730,…
  • Skill Workshop: keep skills in one persistent agent-owned collection across workspaces, compare complete skill instructions, and retire missing-draft suggestions safely through Doctor. Related…
  • Browser tabs, live and native: watch agent pages repaint and open external links in native Mac tabs that remain with their window across chat switches. (#140988,
  • Your provider accounts, together: manage connected accounts and supported account priority directly in Models settings. (#132451) Thanks @jesse-merhi.
  • Revert "fix(connections): stop oauth2 connections failing to save when the code has special characters"
  • feat(core): support image results in web search tools
  • feat(core): customize output guardrail blocked messages
  • feat(mcp): add server-wide guardrails to MCP tools
  • feat(sandbox): add configurable Unix-local environment isolation
  • feat(sandbox): allow labels on Docker sandbox containers
  • Deprecate fallbackmodel in favor of fallbacksubagentmodel on ImageGeneration and XSearch
  • Add openai-codex provider for ChatGPT/Codex subscription authentication
  • Add a direct image generation API with ImageGenerator
  • Report Anthropic native web searches in RequestUsage.details and price them in cost
  • Wrap botocore transport errors in ModelAPIError in BedrockConverseModel
  • Every supported language now has complete translations across settings, onboarding, project home and sidebar, sessions, password recovery, sign-in, and workspace administration. Serbian is a new…
  • Headless auth: multi-factor enrolment, enterprise SSO, and profile updates are available through the API and the SDK (PATCH /v1/auth/user, KortixSession.subscribe as the replacement for…
  • Kortix Apps: one identity guard for every App (createKortixAppGuard, groups always populated), and an embedded App can complete its own sign-in (cookieSameSite).
  • Session brief: hover a session to see its summary.
  • Connector catalogue: one-letter searches work, cache entries are compared by identity, and panel padding and search were corrected.
  • Inherited upstream presets: gpt-6-astra, gpt-5.6-sol,
  • Google AI Studio IDs: gemini-3.8-flash, gemini-3.7-flash,
  • Anthropic IDs: claude-fable-5-1, claude-opus-5, claude-sonnet-5, and claude-haiku-4-5-20251001. These are current active provider-documented IDs surfaced in the model guide.
  • Z.AI IDs: glm-5.1, glm-5, glm-5-turbo, and the free/lightweight glm-4.7-flash. These are the provider-documented
  • Open Interpreter's OIX-specific work here is provider/catalog, transport,

Sep 7, 2026

  • Existing install: hermes update
  • Fresh install: curl -fsSL | bash
  • Managed deployments should update through their deployment tooling using the new tag.
  • Added Discord channel support, including improved gateway failure reporting after startup. (#5992,
  • Added chat-scoped conversation history with configurable storage and optional hybrid search. (#6105, #6115,
  • Added MCP configuration tools, channel-based MCP server authorization, hot reload for MCP configuration, and OAuth/device authentication support for Slack and GitHub MCP integrations. (#6097,…
  • Added more flexible subagent execution, including background expendable subagents, dcode-style subagents in fork mode, fresh subagents, per-task tool selection, and on-demand subagent…
  • Added defensive research defaults and a configuration-hardening self-review skill, with missing research subagent defaults backfilled. (#6131, #6136,
  • macOS (-sea assets): unsigned (Apple secrets not configured)
  • Linux (-sea assets): SHA256SUMS-sea published with the release
Oh My Pi
  • Fixed reasoning-off requests (e.g. GitHub Copilot gpt-6-astra) surfacing 400 Unsupported value: 'none' … Supported values are: … instead of retrying at the lowest allowed effort: the…
  • Fixed Cursor GPT off-tier requests sending raw -none sibling ids (e.g. gpt-5.6-sol-none-fast), which the Run endpoint rejects; they now normalize to the base model id with no reasoning parameter,…
  • Bills Astra API requests above 272K input at the documented 2x input / 1.5x output long-context tier; the Codex subscription route stays exempt with free cache writes
  • Fixed Astra's extended window over-advertising input by 128K; it now uses the documented 922K input cap inside the 1.05M total context
  • Fixed explicit Codex context-window overrides widening past the server-honored maximum; they now clamp to the documented ceiling like upstream Codex
  • perf(worker): compute prewarm pieces and code steps server-side ( #15310 )
  • > 📌 Upgrading a self-hosted instance? Review the Breaking Changes page for any actions required before you upgrade.
n8n
  • core: Ensure running job cleanup when a workflow run rejects (#37826) (257f0bb)
  • core: Keep a serving external secrets provider active when its replacement fails (#37872) (865fa12)
  • Anthropic SDK 1.x — AG2 adapts to the breaking changes in the Anthropic SDK 1.x line, with Anthropic model name references updated to match.
  • OpenAI SDK 3.x — Support for the OpenAI SDK 3.x line, including hosted shell and MCP events.
  • AnthropicBashTool — New built-in tool, with improved event handling for Anthropic.
  • toolblocklist — Deny specific tools by pattern, the inverse of the allowlist, for cases where blocking a known-bad set is clearer than enumerating everything permitted.
  • argvalidation — Validate tool arguments before the call runs.

Sep 6, 2026

  • Added Muse Code subscription sign-in, credential refresh, inference, and quota reporting in /usage, with durable rate-limit backoff so quota refresh recovers instead of repeatedly retrying.
  • Added Muse Code as a provider with Muse Spark models and live account-scoped discovery.
  • Muse Code subscriptions now resolve a compact edit-prompt variant, cutting recurring per-request tool bytes without touching other providers.
  • Added Meta's new max reasoning effort tier to Muse Spark 1.3 (standard) on the Meta Model API and Muse Code.
  • Fixed OpenCode Go/Zen live model discovery (GET /v1/models) missing x-opencode-session and omp's User-Agent: discovery requests now attribute with the stable install id so the requests OpenCode…
  • feat(comparisons): add answer-first lead, per-section H2s, and AEO copy fixes
  • feat(browser): add verified form filling and horizontal scroll
  • feat(editor): replace canonical input toggle with icon switch
  • feat(models): gate forced tool use by model capability
  • fix(copilot): stream append previews as deltas instead of a snapshot per token
  • Stream PTC tool calls natively.
  • Keep private state out of subagent propagation.
  • 6c89fe2 release(langchain-quickjs): 0.3.7
  • 916d7d7 fix(quickjs): keep private state out of subagent propagation
  • c366c49 feat(quickjs): stream PTC tool calls natively
  • Bug fixes and reliability improvements
  • No notable changes
  • No account runs on an empty wallet. Paid per-seat and credit-plan accounts used to keep spending past $0 with no floor; one six-seat account settled $588.81 against a $150 monthly grant with the…
  • Work that already ran is always recorded. A settlement that the wallet could not cover used to be refused, which deleted the record of the spend and left "Spent this period" frozen while compute…
  • Wallet alerts agree with the server. Every wallet alert and billing string in the app now reads the account's billing state, so the sidebar and the project page no longer disagree about whether…
  • Credits have their own tab in account settings, with the available balance and where it comes from. Plan keeps its own card.
  • Push authority is scoped to who is pushing. A session credential can push only to its own branch. Pushing other refs and deleting refs are two new permissions, project.gitops.ref.any and…