Everything agent.
All related.

Discover the tools, follow the releases, and find your next big idea. Your little corner of the agent universe.

A pulse on the ecosystem 31 projects to explore 100 collected releases Collected 12 minutes ago

The starting lineup

Category collection

Frameworks projects

31 projects

Cs249R Book

Machine Learning Systems: Foundations, Scaling, Agentic AI, and Physical AI (Vols I–IV) • Harvard CS249r | https://mlsysbook.ai

Frameworks
Parlant

Build reliable customer-facing AI agents with Parlant: an interaction control harness optimized for controlled, consistent, and predictable LLM interactions.

Frameworks
Plandex

Open source AI coding agent. Designed for large projects and real world tasks.

Frameworks
Casdoor

An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, Face ID, Google Workspace, Azure AD

Frameworks
E2 B

Open-source, secure environment with real-world tools for enterprise-grade agents.

Frameworks

Handpicked projects. Official release feeds. No paid placements or invented popularity scores.

The bigger picture

Less scrolling. More knowing.

AI-assisted briefing

What changed, why it matters, and where to go deeper.

Pydantic AI·

Pydantic AI v2.44.0

Patches four security issues in web_fetch_tool and OpenTelemetry instrumentation, including a moderate cloud-metadata blocklist bypass and superlinear response processing that could stall the event loop. Also adds a Vercel AI SDK migration skill, stable AgentRunResult serialization, and a Storage page for persistence.

Why it matters

Security-hardens a popular agent framework; the Vercel migration skill and stable serialization shape are directly useful for builders migrating apps or building durable agents.

Go to the source
Google ADK·

Google ADK v2.9.1

Focuses on improving visibility into model reasoning steps by ensuring visible thoughts are requested during Claude adaptive thinking tasks. This is a targeted bug fix on top of the v2.9.0 release that introduced model failover, LiveKit voice support, and MCP SDK 2.x compatibility.

Why it matters

Useful for builders leveraging Claude's adaptive thinking in ADK workflows who need step-by-step reasoning to be surfaced correctly.

Go to the source

Generated Sep 17, 2026 · 18:30 GMT+0000. AI summaries can miss details; check the original notes.

Straight from the changelog

Small updates. Big possibilities.

Release explorer100 collected releases
Sunadev-latest

From the release notes

Mutable DEV CLI build for fc512f8d2cc0b4835bf2bedf9ef42b1d78b3b11c. Install: curl -fsSL https://kortix.com/install | KORTIX_CHANNEL=dev bash Defaults to https://dev-api.kortix.com.

Sunav0.13.23 — Per-call connector accounts, no more guessed account, and a sign-out fix

From the release notes

New Choose which account a connector runs as, per call. A connection now carries the accounts you may run it as, and the account is chosen when the connector is called rather than pinned to the whole session. The connector catalog, the SDK and the CLI all report the available accounts and the pinned default, and connectors/describe shows accounts instead of only tool counts. An ambiguous connector call is refused, not guessed. When several accounts are reachable and none is named or pinned as default, the call is denied with account_required instead of silently picking one — no more mail sent from the wrong mailbox. Choosing a connector account is discoverable in the CLI rather than a dead end. Improved A connector you have your own accounts for reads as connected, not "needs setup", and the admin connector list now agrees with what each caller can actually reach. Connector accounts are per connection instead of a connector-level strategy, and connections the old strategy flag made unreachable are revoked. The sandbox daemon's internals were reorganised behind explicit service boundaries, with its HTTP controllers separated from its adapters. Fixed A failed identity check no longer signs you out. A failed getUser round trip used to end the browser session; it no longer does, and the new-connection screen offers Upgrade when you are at the project cap. Connector authorization: finalizing a connection that the whole project can use now requires the connections-manage capability, matching the gate the connect step already applied. Previously a role with connector-write but not connections-manage could complete a project-wide shared connection. Auto-created connections no longer claim to be the default, and the CLI's account column no longer truncates away the pinned-default marker. Stale connector banner copy and a dead connector detail shell removed; the account list renders for every direct provider. What's Changed fix(auth): a failed getUser round trip no longer signs the browser out; /new offers Upgrade at the project cap by @markokraemer in #7352 refactor(connectors): credentials are a call-time choice — one access rule, no session gate, no strategy flag by @markokraemer in #7326 refactor(kortixd): introduce internal harness service boundaries by @DimitrijeGlibic in #7220 test(api): wait for the second lifecycle drain instead of a 200 ms margin by @markokraemer in #7357 fix(connectors): account-aware modal header, dead ConnectorDetail shell removed, reconcile re-activates a revoked account by @markokraemer in #7360 fix(build): quick-queue snapshot uses a reverse scan, unbreaking API typecheck on main by @markokraemer in #7368 fix(security): connect/finalize gates a project-owned account on connections.manage by @markokraemer in #7366 chore(staging): bring staging to main (connector-creds, git-connection-logout, 48 commits) by @markokraemer in #7356 Release v0.13.23 — Per-call connector accounts, no more guessed account, an

Deepseek Reasonixdesktop-v1.38.10: docs(release): finalize v1.38.10 notes / 确认 v1.38.10 中英更新日志 (#10479)

From the release notes

docs(release): prepare v1.38.10 notes Summary: Generate a bilingual, product-focused draft from merged pull request metadata. Reuse the selected release-bound PR when one is available. Verification: Validate the catalog, citations, bilingual fields, and rendered GitHub release notes before committing. docs(release): retain reviewed v1.38.10 notes and bind final CI repair Preserve the reviewed bilingual product changes and citations. Only update six guide links to the latest main-v2 source after the test and CI lifecycle repair. Catalog validation and all 11 release-note tests pass. Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: SivanCola 32437197+SivanCola@users.noreply.github.com

Deepseek Reasonixnpm-v1.38.10: docs(release): finalize v1.38.10 notes / 确认 v1.38.10 中英更新日志 (#10479)

From the release notes

docs(release): prepare v1.38.10 notes Summary: Generate a bilingual, product-focused draft from merged pull request metadata. Reuse the selected release-bound PR when one is available. Verification: Validate the catalog, citations, bilingual fields, and rendered GitHub release notes before committing. docs(release): retain reviewed v1.38.10 notes and bind final CI repair Preserve the reviewed bilingual product changes and citations. Only update six guide links to the latest main-v2 source after the test and CI lifecycle repair. Catalog validation and all 11 release-note tests pass. Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: SivanCola 32437197+SivanCola@users.noreply.github.com

Deepseek Reasonixdocs(release): finalize v1.38.10 notes / 确认 v1.38.10 中英更新日志 (#10479)

From the release notes

docs(release): prepare v1.38.10 notes Summary: Generate a bilingual, product-focused draft from merged pull request metadata. Reuse the selected release-bound PR when one is available. Verification: Validate the catalog, citations, bilingual fields, and rendered GitHub release notes before committing. docs(release): retain reviewed v1.38.10 notes and bind final CI repair Preserve the reviewed bilingual product changes and citations. Only update six guide links to the latest main-v2 source after the test and CI lifecycle repair. Catalog validation and all 11 release-note tests pass. Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: SivanCola 32437197+SivanCola@users.noreply.github.com

Firecrawlv2.11.359

From the release notes

Release API image v2.11.359

OpenAI Agents SDKv0.22.3

From the release notes

What's Changed fix(core): align conditional approvals with validated tool arguments by @seratch in #5066 fix(core): deliver tool-not-found output on server-managed resume by @hyeonsang010716 in #4947 fix(sandbox): keep command paths POSIX on a Windows host by @hyeonsang010716 in #4958 fix(sessions): handle concurrent async SQLite startup by @00200200 in #4987 fix(sessions): do not forward session limit as Conversations page size by @tiagovilasboas in #4961 fix(tracing): do not cache a missing OPENAI_API_KEY by @hyeonsang010716 in #5017 fix(extensions): include shell and apply_patch calls in AdvancedSQLiteSession's tool usage by @rioyu123 in #4982 fix(extensions): reap subprocesses on early stream close by @Hughhhhcoder in #4804 fix(extensions): preserve exact IDs in AdvancedSQLiteSession.delete_branch by @JiangLLM in #4980 Documentation & Other Changes docs: align repository security and contributor guidance by @jbeckwith-oai in #4962 docs: clarify Unix-local execution boundaries by @seratch in #5064 docs: update translated pages by @seratch in #5065 docs(examples): drop the duplicated word in the Temporal trace name by @simpleqt in #5079 chore: enable Python Dependabot coverage with release-age cooldowns by @jbeckwith-oai in #4964 chore: add code ownership and required release review guidance by @jbeckwith-oai in #4965 fix(deps): update vulnerable dependencies without changing SDK APIs by @jbeckwith-oai in #4963 chore(deps): update fastapi requirement from >=0.120.0 to >=0.141.1 in /examples/realtime/twilio_sip by @dependabot[bot] in #4966 chore(deps): update uvicorn requirement from >=0.38.0 to >=0.52.4 in /examples/realtime/twilio_sip by @dependabot[bot] in #4968 chore(deps): update openai requirement from <4,>=3.0.0 to >=3.8.0,<4 in /examples/realtime/twilio_sip by @dependabot[bot] in #4969 chore(deps): bump typing-extensions from 4.14.1 to 4.16.0 by @dependabot[bot] in #4970 chore(deps-dev): bump grpcio from 1.76.0 to 1.83.1 by @dependabot[bot] in #4971 chore(deps): bump sqlalchemy from 2.0.43 to 2.0.52 by @dependabot[bot] in #4973 chore(deps-dev): bump cryptography from 45.0.7 to 50.0.0 by @dependabot[bot] in #4975 ci: add Python and Actions CodeQL security scanning by @jbeckwith-oai in #4974 fix(ci): deploy docs after dependency and workflow updates by @dependabot[bot] in #4976 fix(deps): update python-multipart requirement from >=0.0.31 to >=0.0.32 in /examples/realtime/twilio by @dependabot[bot] in #5030 fix(deps): update python-dotenv requirement from >=1.2.2 to >=1.2.3 in /examples/realtime/twilio by @dependabot[bot] in #5031 fix(deps): update starlette requirement from >=1.3.1 to >=1.6.0 in /examples/realtime/twilio_sip by @dependabot[bot] in #5033 fix(deps): update python-dotenv requirement from >=1.2.2 to >=1.2.3 in /examples/realtime/twilio_sip by @dependabot[bot] in #5034 fix(deps-dev): bump pymdown-extensions from 11.0.1 to 11.0.2 by @dependabot[bot] in #5036 fix(deps): bump runloop-api-client from

Firecrawlv2.11.358

From the release notes

Release API image v2.11.358

Firecrawlv2.11.357

From the release notes

Release API image v2.11.357

Firecrawlv2.11.356

From the release notes

Release API image v2.11.356

Firecrawlv2.11.355

From the release notes

Release API image v2.11.355

Firecrawlv2.11.354

From the release notes

Release API image v2.11.354

Firecrawlv2.11.353

From the release notes

Release API image v2.11.353

Firecrawlv2.11.352

From the release notes

Release API image v2.11.352

Sunav0.13.22 — Private provider key pools, print whole conversations, and Entra SCIM fixes

From the release notes

New Private provider key pools. Bring several keys for one provider, keep them private or share them with named members, and let each session hold its own key. Sessions fail over to the next key and report the earliest retry time when a pool is exhausted. Gemini and ChatGPT keys pool too, and pooled keys are managed in Models. Pool access is bound to the session owner, and a pool is checked against the model you actually picked. Print a whole conversation. Cmd+P prints the full session as a clean document — every message, not one clipped screen of the app. Queued prompts you can see and edit. Queued messages show in a list above the composer. Press Up to edit the last one, and Resume picks the queue back up. Microsoft Teams install reports what happened. One-click install publishes in the background, lands on Channels with a real status, and offers a retry with the actual reason when publishing fails. Astra is available as a ChatGPT subscription model. Improved Faster project boot. New sessions fetch the project from storage instead of cloning it, and start sooner. Faster session lists. A project's session list is now a page, not the whole inventory. Menus open instantly — menus, popovers, tooltips and the command palette no longer wait to appear. Smaller sandbox images, which start faster. Git connections are organized per account, with one instance backend and an identity that cannot drift. Verifying with GitHub no longer signs you out, and the new-connection screen always has a way out. Fixed Microsoft Entra directory sync. Patches apply atomically, large directories paginate, groups survive while a user is inactive or a sign-in session is stale, deactivation and single-member removal behave correctly, and users resolve across the whole directory. The gateway retries a slow internal call instead of answering "Gateway unavailable". Composer drafts survive session startup, and opening session settings no longer closes itself while the composer takes focus. One session lifecycle drain at a time per API task, so queued work is not claimed twice. Session attachments are more reliable, and model prices show correctly in the ChatGPT picker. Security hardening across session cursors, webhook signing keys, and the remaining high-severity scanner findings. Database migrations apply cleanly on staging and production. What's Changed fix(teams): one-click install publishes in the background, records its outcome, and shows it by @Ino-Bagaric in #7341 fix(api): run one session lifecycle drain at a time per API task by @sutharjay1 in #7343 fix(api): run one session lifecycle drain at a time per API task (staging) by @sutharjay1 in #7344 fix(git): verify-with-GitHub no longer signs out; /new is a git account manager with a way out by @markokraemer in #7330 chore(release): staging VERSION → 0.13.22 [skip ci] by @github-actions[bot] in #7347 chore(release): VERSION → 0.13.22 [skip ci] by @github-actions[bot] in #7348 Default pooled pro

Sunav0.13.21 — Print whole conversations, private provider pools, and Entra SCIM fixes

From the release notes

New Print a whole conversation. Cmd+P prints the full session as a clean document — every message, not one clipped screen of the app. Queued prompts you can see and edit. Queued messages show in a list above the composer. Press Up to edit the last one, and Resume picks the queue back up reliably. Private provider connection pools. Bring several keys for one provider, keep them private or share them with named members, and let a session hold its own key. Sessions fail over to the next key and report the earliest retry time when a pool is exhausted. Gemini and ChatGPT keys pool too, and pooled keys are managed in Models. Astra is available as a ChatGPT subscription model. Improved Faster project boot. New sessions fetch the project from storage instead of cloning it, and start sooner. Faster session lists. A project's session list is now a page, not the whole inventory. Menus open instantly. Menus, popovers, tooltips and the command palette no longer wait to appear. Smaller sandbox images, which start faster. Git connections are now organized per account, with one instance backend and an identity that cannot drift. Fixed Microsoft Entra directory sync. Patches apply atomically, large directories paginate, groups survive while a user is inactive or a sign-in session is stale, deactivation and single-member removal behave correctly, and users resolve across the whole directory. The gateway retries a slow internal call instead of answering "Gateway unavailable". Composer drafts survive session startup, and opening session settings no longer closes itself while the composer takes focus. Session attachments are more reliable. Model prices show correctly in the ChatGPT picker. Security hardening across session cursors, webhook signing keys, and the remaining high-severity scanner findings. Database migrations now apply cleanly on staging and production. What's Changed feat(sandbox): bake rg, fd, bat, jq, fzf and a shell tool floor into every image by @markokraemer in #7264 refactor(sandbox): remove the fast cold boot image, its flag, and the experiments it gated by @markokraemer in #7268 test(release): dismiss the welcome card before Save in the repository-access journey by @markokraemer in #7276 fix(cli): connectors apps searches the Composio toolkit catalog by @markokraemer in #7277 feat(project-snapshot): S3 boot acquires the project 3.5× faster than Git (307 vs 1,078 ms) and boots 0.8 s sooner — presign at create, no HEAD on the boot path, kortixd gated on OpenCode's "server listening" by @DimitrijeGlibic in #7242 fix: restore terminal recovery and keep message retries in their session by @sutharjay1 in #7267 fix(usage): show zero cost for ChatGPT subscriptions by @markokraemer in #7278 chore(release): VERSION → 0.13.19 [skip ci] by @github-actions[bot] in #7285 fix: refresh terminal provider credentials after sandbox resume by @markokraemer in #7286 fix(session): isolate optional connector failures and preserve prompt qu

Firecrawlv2.11.351

From the release notes

Release API image v2.11.351

Casdoorv4.6.0

From the release notes

Changelog Features bb76eb6 feat: add magic link sign-in Bug fixes fbcb496 fix: keep empty forceLanguage empty so browser language detection works 0db629e fix: keep resolved RADIUS/push provider id through MFA setup enable step 4684d70 fix: read SAMLRequest case-insensitively in auth callback 91ae9d6 fix: redirect to the single OAuth provider only once instead of on every render 7bf924a fix: reset signin method rule when its name changes so WebAuthn stays visible

ComposioCLI Beta @composio/cli@0.4.2-beta.398

From the release notes

What's Changed docs: update toolkits, API spec, and meta tools data by @sdkrelease[bot] in #4419 docs(auth): note the auto-populated connection display_name by Anshu Garg (@anshugarg15) in #4503 docs: update toolkits, API spec, and meta tools data by @sdkrelease[bot] in #4510 fix(cli): block SSRF in proxy binary downloads by Alberto Schiabel (@jkomyno) in #4511 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.397...@composio/cli@0.4.2-beta.398

Firecrawlv2.11.350

From the release notes

Release API image v2.11.350

Deepseek ReasonixReasonix Studio v2.18.1

From the release notes

本版修复远端主机使用本机模型时报 unknown model,并移除 IM 机器人网关。 修复 远端主机使用本机模型时,新会话、模型列表和切换模型不再落到远端自己的配置,不再报 unknown model #10448 所选模型在本机不存在时,报错会说明缺模型的是本机,并提示如何改用远端自己的模型 (8b2a05c) 移除 reasonix bot 与 QQ、飞书、微信机器人网关;配置文件里已有的 [bot] 段原样保留,不影响 1.x (f352dfb) 升级须知 模型来源为本机的远端主机,若内核低于 2.18.1,下次连接会自动下载并替换远端内核 (437b982) macOS 已用 Developer ID 签名并公证,打开时不需要清除隔离属性。Windows 包未签名,SmartScreen 会告警:选「更多信息」,再选「仍要运行」。Linux 从 .deb 安装。 三个平台都能自更新:Linux 走自己的包,Windows 运行下一个安装器,macOS 替换自身 bundle。

Deepseek ReasonixReasonix Studio v2.18.0

From the release notes

本版修复 Windows 窗口打不开、读图模型误报看不到图、问题框不弹出,并精简内置文档。 修复 Windows 安装目录带 AppContainer 包授权时窗口打不开;启动时自动移除这类授权 #10435 读图模型不再声称看不到已附加的图片 (44150b0) Goal 续跑时不再提示读图模型"无法读图" (44150b0) 切换模型、重载扩展或切换工作区后,问题框和审批框不再被吞掉 (921a04b) 变更 内置文档除 README、使用指南、CLI 参考外只保留英文版,中文提问会检索到英文文档 (68b031a) 移除 内置文档检索中的版本历史,其内容停留在旧产品线的 1.24.1 (99c5360) macOS 已用 Developer ID 签名并公证,打开时不需要清除隔离属性。Windows 包未签名,SmartScreen 会告警:选「更多信息」,再选「仍要运行」。Linux 从 .deb 安装。 三个平台都能自更新:Linux 走自己的包,Windows 运行下一个安装器,macOS 替换自身 bundle。

Pydantic AIv2.44.0 (2026-09-16)

From the release notes

🛡️ Security This release fixes four security issues, all of them reached through web_fetch_tool or OpenTelemetry instrumentation. See each advisory for full details and affected versions. GHSA-vmxc-h2x2-jmf3 (moderate): the cloud-metadata and private-IP blocklists could be bypassed with an IPv6 zone identifier on a URL opted into local network access, via FileUrl(force_download='allow-local') or web_fetch_tool(allow_local_urls=True). Both are off by default. Reported by @euriconicacio. (#8401) GHSA-fpf4-vwcp-v4hp (moderate): web_fetch processed responses in superlinear time on the event loop, in both the HTML conversion and the charset decode, so a single attacker-chosen page could stall every agent in the process. Reported by @BrianWillows. (#8397, #8418, #8433) GHSA-22h6-qm39-v87j (low): web_fetch_tool's domain lists were compared as written rather than in the form the resolver uses, so a blocked domain could be reached under another spelling. (#8407, #8421) GHSA-4x9p-g9wm-8q7f (low): with InstrumentationSettings(include_content=False), spans still carried exceptions, error statuses, instructions and the output template. Reported by @BrianWillows. (#8403, #8408, #8419, #8428) Patched in 2.44.0 (v2) and 1.107.6 (v1). What's Changed ⚠️ Compatibility Notes Make RunContext.enqueue() safe from worker threads by @adtyavrdhn in #7758 Require a JSON Content-Type on UI adapter requests by @DouweM in #8396 Dispatch a capability @durable_operation called from a per-request hook, instead of silently running it inline by @DouweM in #8395 🚀 Features Add a Vercel AI SDK and Eve migration skill by @adtyavrdhn in #8357 Give AgentRunResult a stable serialized shape, and settle a finished stream into one by @DouweM in #8269 Add a Storage page so persistence is findable by @DouweM in #8336 Emit EnqueuedMessagesEvent when a realtime session delivers enqueued content by @DouweM in #8134 🐛 Bug Fixes Forward blocked_domains to OpenAI web search by @adtyavrdhn in #8323 Fix OpenAI hosted tool_search pairing in AG-UI by @adtyavrdhn in #8313 Let Agent.from_spec() construct without a model, deferring the requirement to run time by @DouweM in #8339 Let RealtimeSession.close() finish its teardown when the closing task is cancelled by @DouweM in #8142 Run a capability's prepare_tools over every tool the availability gate admits by @DouweM in #8071 Bound the realtime session event queue while nothing is iterating it by @DouweM in #8133 Report a run's own usage on its span, not the conversation total by @DouweM in #8417 New Contributors @mrchatam made their first contribution in #8286 @vedjaw made their first contribution in #7028 Full Changelog: v2.43.0...v2.44.0

Pydantic AIv1.107.6 (2026-09-16)

From the release notes

🛡️ Security A maintenance release for the v1 line, carrying the v1 backports of the four security fixes released in 2.44.0. See each advisory for full details and affected versions. GHSA-vmxc-h2x2-jmf3 (moderate): cloud-metadata and private-IP blocklist bypass via an IPv6 zone identifier, on a URL opted into local network access. Reported by @euriconicacio. (#8402) GHSA-fpf4-vwcp-v4hp (moderate): superlinear response processing in web_fetch, in both the HTML conversion and the charset decode, blocking the event loop. Reported by @BrianWillows. (#8399, #8434) GHSA-22h6-qm39-v87j (low): web_fetch_tool domain lists compared as written rather than in the form the resolver uses. (#8409) GHSA-4x9p-g9wm-8q7f (low): OpenTelemetry spans carrying exceptions, error statuses, instructions and the output template under include_content=False. Reported by @BrianWillows. (#8404, #8422, #8429) Also carried over: credentials are now dropped on a safe_download redirect whenever the full origin changes, not only the hostname (#8410). This was fixed on the v2 line some time ago and had never been backported. Patched in 1.107.6; all four are also patched on the v2 line in 2.44.0. What's Changed Every code change in this release is one of the security fixes above. Maintenance alongside them: Repair v1 CI and its mcp, anthropic, and duckduckgo extras (v1 backport) by @DouweM in #8406 Pin FastA2A below 1 in the a2a extra (v1) by @DouweM in #8412 Full Changelog: v1.107.5...v1.107.6

Kiro Crewv0.7.0-insider.4

From the release notes

What's Changed feat: backport app sources, artifact scroll and Windows MCP fixes by @bolichen97 in #11339 fix: refresh cached highlight worker CSP on insider by @bolichen97 in #11374 Full Changelog: v0.7.0-insider.3...v0.7.0-insider.4

ComposioCLI Beta @composio/cli@0.4.2-beta.397

From the release notes

What's Changed fix(cli): curated help for every command family and a help command by Alberto Schiabel (@jkomyno) in #4421 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.396...@composio/cli@0.4.2-beta.397

ComposioCLI Beta @composio/cli@0.4.2-beta.396

From the release notes

What's Changed feat(docs): redesign social preview cards by Malay Vasa (@Malayvasa) in #4502 feat(cli): plugin-adoption telemetry for setup and the plugin hint by Kshitij Jhunjhunwala (@KJ-11) in #4496 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.395...@composio/cli@0.4.2-beta.396

Sunav0.13.20 — Faster session lists in large projects

From the release notes

Fixed Projects with thousands of sessions no longer slow the app down. The session list now loads one page at a time — 50 sessions, with a Load more control — instead of returning every session on every refresh. On a project with 12,617 sessions that is a 46 KB response instead of about 11 MB, and the sidebar was refreshing it every five seconds. Opening, sharing, stopping, restarting or renaming a session now works however old the session is. These controls used to look the session up in the full list, so once a project grew past the first page the controls could quietly disappear. Improved Date grouping (Today, This week, Older), filters and search work as before, applied to the sessions you have loaded. A new database index serves the paged list, so a request no longer sorts every session in the project. Security The pagination cursor is encrypted and tied to both the project and the person viewing it. It cannot reveal a session they are not allowed to open, and it cannot be reused by anyone else. What's Changed Release v0.13.20 — Faster session lists in large projects by @github-actions[bot] in #7316 Full Changelog: v0.13.19...v0.13.20

Deepseek ReasonixReasonix Studio v2.17.0

From the release notes

本版的主线是让"检查通过"意味着它所说的那件事:模型可用性探测此前从不发工具,于是一个只会聊天的中转站通过了验证、在第一条消息上失败,而设置面板仍标着"已验证";一个 2024 年才有的可选字段被无条件发给每个 OpenAI 兼容端点,让不认它的网关拒掉整场会话。界面一侧,一个中文词在两处字典里有两种英文,英文窗口上的"保存"按钮读作 Transcript;补全菜单的内置动词由内核按进程语言渲染,于是中文机器上的英文窗口配一份中文菜单。另一条主线是老外壳的退役:Wails 那套连同它的 CGO 与 GTK/WebKitGTK 构建要求一次性移除,Studio 从此只有一个外壳;内核与控制器随之做了一轮按主题的归位。自 2.16.0 起 39 个提交,净减两万六千行。 升级路径:无需人工步骤。三平台照旧自更新——Linux 走 .deb,Windows 运行下一个安装器,macOS 替换自身 bundle。已安装的 2.10 及更早的 Wails 版本仍由现有的接管路径升到本版,那条路径不是 Wails 代码,未被此次退役触及。 修复 检查通过,然后第一条消息就失败 模型可用性探测现在带一个工具。Reasonix 是代理,一个递不进工具的模型跑不了一回合。探测此前只发 messages 和 max_tokens,于是一个应答聊天、拒绝 tools 数组的中转站通过了验证,用户的第一条消息才失败——而那一行仍显示"已验证"。被拒时它再问一次、这次不带数组,只有当去掉数组正是让请求答上来的那件事时才报"tools":结论来自第二次尝试成功,不是拒绝里的某个词。凭据错误与限流不给重试——第二次会因第一次的同一个理由被拒——所以那条"只试一次"的规则对它们原样保留。连接按钮从未声称超出它所证明的(它只列模型,它自己的注释就这么写),但"已连接,OpenAI 兼容"读起来像"可以用了"。现在那一行说得出"端点应答聊天、拒绝工具调用",这一句话把人送去换网关,而不是送进一场注定失败的会话。 不再为一个 token 计数器赔上整场会话。stream_options 被无条件发给每个 OpenAI 兼容端点。它是 2024 年的新增项,比它更早的、或转发时较真的网关会拒掉带着它的请求,而它要的只是用量记录——一个 token 数,不是一回合需要的任何东西。于是一个别的代理都能驱动的中转站,在这里每一条消息都被拒。客户端现在对每个端点问一次:请求体被拒就去掉这个字段重试,若这样答上来了,此后不再发它。按端点问一次而不是每次被拒都问,所以一个因别的理由拒绝请求体的网关不会被永远反复试探;值得一问的状态码是点名的三个——400、413、422——而不是整个 4xx,因为 402 的意思是账户付不出钱,再发一次什么也不会变。实测于一个为此搭的网关:此前每一回合都失败,现在完成一回合,字段发了一次、再没发过。 一个中文词,一种英文读法 五个中文词条在两份字典里各有一份定义,而目录是十个模块展开进一个对象——同一个键写两遍,留下的是后展开的那一份,另一种读法从此不可达。其中三处渲染了错的词:记录 在指标那边是 "Save"、在运行图那边是 "Transcript",运行图赢了,于是那个记录模型上下文窗口的按钮读作 Transcript;还原 在窗口控件是 "Restore"、在文件是 "Revert",文件赢了,于是最大化窗口的还原按钮自称 Revert;改动文件 在权限规则里指 edit_file 这个工具,在顶栏指改动文件数,顶栏赢了。一个中文词承担两种意思,修法是两个中文词,不是更聪明的查表:记录值的按钮改称"保存",窗口控件改称"向下还原"(Windows 中文里它就叫这个)。另外两处(模型、取消)两种写法渲染相同,失去那份从未胜出的定义;十二个写了两遍但值相同的键失去它们的副本。 补全菜单说窗口的语言,不说进程的。内置动词由内核措辞、在窗口里被读,两者不必一致:一台 CLI 说中文的机器上可以开着英文窗口。端点此前读配置里的桌面语言,而在没有设置时——那是默认值,意思是"跟随机器"——落到本进程按自己的 $LANG 装的那份目录。于是中文机器上的英文窗口,英文输入框下面挂着二十一条中文菜单。窗口才是"它正在画什么"的权威:配置里有值它早已采纳,没有值它跟随自己的区域设置,而那是内核读不到的。所以语言由请求携带,配置只回答那些什么都不说的客户端。 变更 Wails 外壳退役 一次事务,而不是逐件删除:desktop/next 与它的事件泵、remote_pump.go、/rx-replay、前端的 WAILS_* 常量与总线分支、apiPaths/apiPrefixes 白名单、vendored 的 go-webview2 分支,以及 Wails 依赖连同它的 CGO 与 GTK/WebKitGTK 构建要求。先删任何一件留下的都是一个坏掉的外壳,而不是一棵更小的树。 允许它发生的是那个条件本身:不再有任何只有那个外壳才有的语义,加上此前记为"未验证"的那一条——发布线。studio-v2.11.0(2026-09-01)到 2.16.0 已经七次发出 Electron 包,而从已安装的 Wails 2.10 跨过来这件事由维护者确认过,不是在这里假定的。 两个后果值得说出来。desktop 模块现在不含 CGO,所以 CI 与贡献者都不再为构建它安装 GTK 或 WebKitGTK,webkit2_41 标签从每条命令里消失。而老外壳装下的东西原样不动:winuninstall、Electron 外壳的接管路径、studio_line 的二进制名——已安装的 2.10 靠它们变成 2.11,它们都不是 Wails 代码。 迁移契约变成 docs/STUDIO_SHELL_BOUNDARIES.md:它立下的规则活得比迁移本身长,它记的那些账不必。契约里跟踪的展示层缺口原样转为已知缺口,并补上主机侧缺失的崩溃捕获。 内核随之失去只有那个外壳够得到的东西:update.LocalApplication(一个自身即应用的进程,Electron 的不是)、update.Here、appidentity 的 AppUserModelID 应用与快捷方式修复(Electron 自报 appId)、crashreport.CaptureStudioPanic。AppUserModelID 本身留下——Windows 的通知仍带着它。 内核按主题归位 四个各自占着一个包三分之一的文件,按它们服务的那个界面拆开,代码与规则一行未改: controller.go 3232 → 1430。七组方法回到它们的主题已经拥有的文件,回合入口(Send、RunTurn 与它们驱动的循环)拿到自己的一个。留下的是构造函数与访问器——每个主题都要读的那份会话状态——这就是行为搬到状态旁边之后,控制器剩下的东西。审批桥拿到的不止一次搬家:决定一次工具调用跑不跑的 gateApprover 此前住在 controller.go,在敏感路径之外;approval_bridge.go 现在被声明为敏感,评审与覆盖

Casdoorv4.5.0

From the release notes

Changelog Features fb38eae feat: add group add/delete actions to group tree page 39a1bba feat: support popup mode for Captcha providers Bug fixes 0f629eb fix: URL-encode OAuth state on interactive login, consent, prompt, signup and post-logout redirects 1d65427 fix: allow only global admins to change applications' custom HTML f82480a fix: allow org admins to import groups, roles and permissions via xlsx 15e3c21 fix: authorize get-permissions-by-submitter against the signed-in user d484bf5 fix: bind token exchange to the audience and organization of the target application f88e92c fix: block intranet addresses in non-built-in organizations' webhooks d8c06ad fix: check token revocation in token exchange, enforce MFA and verified email when binding social logins 1f4e299 fix: enforce SAML audience, validity window, InResponseTo and replay protection in SP 4c27d13 fix: index token by organization and user to speed up forbidding a user 7fc8c7f fix: mask global cert private keys from org admins 322f84d fix: move password history out of user table to avoid MySQL row size limit cd938de fix: restore Edit LDAP, organization transactions and MCP Store buttons missing from the new frontend 6a99ac7 fix: restrict email, SMS and notification providers to the caller's organization 0af4692 fix: restrict resource storage providers and file paths to the caller's organization and user f81531b fix: scope application credentials to their own organization 47558d3 fix: scope get-resources to the caller and restrict direct listing to admins 0aafb57 fix: scope rename triggers to their own organization 58aa959 fix: scope user rename to the user's own organization

ComposioCLI Beta @composio/cli@0.4.2-beta.395

From the release notes

What's Changed docs: update Python SDK reference from source by @sdkrelease[bot] in #4479 fix(core): stop dropping auth field metadata from toolkit auth details by Mo (@decknamec) in #4411 docs: broaden harness example category by Brendan O'Leary (@olearycrew) in #4492 docs: project API key permissions by mukund-composio in #4246 docs: add product architecture guides and KB entry points by Soham Basu (@sohambasu963) in #4294 docs(openai): replace assistants examples with responses by Srija Vuppala (@srijavuppala) in #4165 fix(core): contain async Pusher subscription errors by CoralGarden52 in #4448 docs(py): render raises sections and normalize reST in SDK reference by Alberto Schiabel (@jkomyno) in #4491 docs: update documentation for new changelog entries by @sdkrelease[bot] in #4356 docs: add Atomic Agent to Composio Connect clients by Dudka (@sosidudku1) in #4490 perf(cli): store large execute output by byte size, not tokens by Alberto Schiabel (@jkomyno) in #4483 New Contributors Mo (@decknamec) made their first contribution in #4411 mukund-composio made their first contribution in #4246 Srija Vuppala (@srijavuppala) made their first contribution in #4165 Dudka (@sosidudku1) made their first contribution in #4490 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.394...@composio/cli@0.4.2-beta.395

E2 B@e2b/cli@2.19.1

From the release notes

Patch Changes 5b015ad: Removed the hidden e2b template build command (alias bd). It printed a V1 deprecation notice and exited 1; the V1 build system it fronted is gone from the API. A script still calling it now gets commander's unknown-command error with the same exit code. Build templates with e2b template create or the Template SDK; e2b template migrate still converts a V1 project (see https://e2b.dev/docs/template/migration-v2). Updated dependencies [956e3ab] Updated dependencies [e1fbe86] Updated dependencies [80496c0] Updated dependencies [5b015ad] Updated dependencies [80496c0] Updated dependencies [e1fbe86] e2b@2.50.0

E2 Be2b@2.50.0

From the release notes

Minor Changes 5b015ad: Removed the V1 template build operations and schemas from the generated API clients. The API no longer serves them (runtime 87968fc1e1fa); control planes carrying that change answer 410 Gone. Template builds go through the Template SDK. Visible removal, classified minor: the JS paths namespace loses POST /templates, POST /templates/{templateID}, POST /templates/{templateID}/builds/{buildID} and POST /v2/templates, and components['schemas'] loses TemplateLegacy, TemplateBuildRequest and TemplateBuildRequestV2; the Python e2b.api.client.models package loses TemplateLegacy, TemplateBuildRequest and TemplateBuildRequestV2, and e2b.api.client.api.templates loses the post_templates, post_templates_template_id, post_templates_template_id_builds_build_id and post_v2_templates modules. No SDK method accepted or returned them; code that imported these names directly must drop the import. The regenerated clients also pick up a documented 429 on most operations, a 409 on template create (v3), the upload-request headers on the build file-upload link, minLength: 1 on the v2 build source fields, and a deprecation marker on the always-empty logs field of the build status. Patch Changes 956e3ab: Apply the request headers the API returns with a template layer-file upload link. Azure Blob Storage requires x-ms-blob-type on the upload request, which its signed URL cannot carry, so COPY instructions failed on Azure-backed clusters. GCS- and S3-backed clusters return no headers and are unaffected. e1fbe86: Bump @connectrpc/connect and @connectrpc/connect-web to 2.2.0 (fixes Http2SessionManager.verify() hanging when the connection closes mid-verification and stops delivering stream messages after cancellation). 80496c0: Fix uploads of non-native ReadableStreams in the browser silently sending the text [object ReadableStream] instead of the data. Buffering a stream drained it with new Response(stream), which accepts any async iterable on Node (an undici extension) but only its own stream class in a browser, stringifying anything else. Streams are now drained through the reader, which every implementation supports. 80496c0: Report a sandbox killed mid-request as an actionable TimeoutError in the browser. When the connection to a sandbox drops mid-request the SDK probes the sandbox's health to tell a killed sandbox apart from a transient network blip, but the probe only ran for connection-dropped wordings it recognized, and the browser's (network error) was missing — so killing a sandbox while a command was running surfaced a generic SandboxError: [unknown] network error instead of TimeoutError: ... The sandbox was killed or reached its end of life while the request was in flight. e1fbe86: Bump undici to 7.29.1 and the optional undici8 fallback to 8.10.2 to pick up the September 2026 security fixes.

E2 B@e2b/python-sdk@2.50.0

From the release notes

Minor Changes 5b015ad: Removed the V1 template build operations and schemas from the generated API clients. The API no longer serves them (runtime 87968fc1e1fa); control planes carrying that change answer 410 Gone. Template builds go through the Template SDK. Visible removal, classified minor: the JS paths namespace loses POST /templates, POST /templates/{templateID}, POST /templates/{templateID}/builds/{buildID} and POST /v2/templates, and components['schemas'] loses TemplateLegacy, TemplateBuildRequest and TemplateBuildRequestV2; the Python e2b.api.client.models package loses TemplateLegacy, TemplateBuildRequest and TemplateBuildRequestV2, and e2b.api.client.api.templates loses the post_templates, post_templates_template_id, post_templates_template_id_builds_build_id and post_v2_templates modules. No SDK method accepted or returned them; code that imported these names directly must drop the import. The regenerated clients also pick up a documented 429 on most operations, a 409 on template create (v3), the upload-request headers on the build file-upload link, minLength: 1 on the v2 build source fields, and a deprecation marker on the always-empty logs field of the build status. Patch Changes 956e3ab: Apply the request headers the API returns with a template layer-file upload link. Azure Blob Storage requires x-ms-blob-type on the upload request, which its signed URL cannot carry, so COPY instructions failed on Azure-backed clusters. GCS- and S3-backed clusters return no headers and are unaffected.

Kiro Crewv0.7.0-insider.3

From the release notes

What's Changed feat: label and review tier for pinned app registries (backport #11155) by @bolichen97 in #11184 Full Changelog: v0.7.0-insider.2...v0.7.0-insider.3

Sunav0.13.19 — Reliable terminal connections after sandbox resume

From the release notes

Fix terminal connections that fail after a sandbox resumes because its provider credentials have changed. Refresh rejected provider credentials once for reads and discard stale credentials after a failed WebSocket handshake. Preserve application redirects and sandbox authentication errors. Do not replay writes when provider authentication fails. What's Changed chore(release): staging VERSION → 0.13.19 [skip ci] by @github-actions[bot] in #7284 fix: release provider credential recovery after sandbox resume by @markokraemer in #7287 Release v0.13.19 — Reliable terminal connections after sandbox resume by @github-actions[bot] in #7288 Full Changelog: v0.13.18...v0.13.19

Sunav0.13.18 — Sessions keep their own agent, and explicit repository access

From the release notes

Fixed Terminal opens on a stopped workspace. Opening Terminal requests a wake even before the first shell exists. Connection retries have a deadline and preserve shell output. Session switches keep message retries in the right workspace. Missing conversations stop repeated 404 or 410 requests without clearing cached history. Sessions keep their own agent. A session could be switched to an agent from a different project after a prompt that named no agent, which removed its access to connectors and the Kortix CLI. Every session now always runs as its own agent, and a session that was affected recovers on its next message. The first message on the home screen no longer gets stuck in the composer after a slow start. Project pages load cleanly. The project home shows the Kortix mark while it loads instead of a flashing placeholder. Session history is saved before a session stops, and responses from the in-sandbox model proxy are no longer returned in a corrupted encoding. Admin project list shows each project's own session counts. Customize settings show what you saved. After saving an agent or connector setting, a reload could show the previous value for up to a minute. Improved Connector activity uses consistent names. Connector calls appear as connector calls. Repository access is explicit. Agents now declare whether a session gets the project's files, replacing the older workspace modes. Older API clients keep reading restricted manifests correctly. Previews route correctly and set up shared sandboxes in isolation. Release checks are more reliable: preview environments use their own database, confirm the running runtime, and wait for completed agent artifacts before asserting on them. They also verify cold terminal wake and session-switch routing, allocate sufficient preview frontend memory, and check Docker readiness. What's Changed chore(release): VERSION → 0.13.16 [skip ci] by @github-actions[bot] in #7249 chore(release): VERSION → 0.13.17 [skip ci] by @github-actions[bot] in #7253 Replace workspace modes with explicit repository access by @markokraemer in #7240 fix(preview): a legacy HS256 session opens preview origins again by @markokraemer in #7258 fix(web): a timed-out first prompt no longer stays in the home composer by @sutharjay1 in #7254 fix(web): project home loading paints the Kortix mark, not a skeleton by @sutharjay1 in #7263 fix(api): session tokens no longer adopt another project's agent by @markokraemer in #7262 Release candidate: main 3e7d039 → staging by @markokraemer in #7266 chore(release): VERSION → 0.13.18 [skip ci] by @github-actions[bot] in #7269 chore(release): staging VERSION → 0.13.18 [skip ci] by @github-actions[bot] in #7270 hotfix(staging): editor manifest reads are fresh on every replica; release setup polls retry transport errors by @markokraemer in #7273 fix(web): connector tool calls say "connector", not "app" by @markokraemer in #7272 fix(api): Customize editor reads show the committe

Sunav0.13.17 — Signed-in previews open again

From the release notes

Fixed Previews open again when you are signed in. A sandbox preview opened from a session (prod-p<port>-sbx-….p.kortix.com) showed "Sign in to open this preview" even though you were signed in. Sign-in tokens are still issued with the older HS256 signature while the published key set already holds the newer ES256 key. The API already verified those tokens with the auth server, but the preview gate refused them. It now makes the same check, so the preview panel, pasted preview links, and preview WebSockets open for the account that owns the sandbox. A forged or expired token is still refused, and a test now fails if any verifier caller handles these results in its own way. Internal The release gate quarantines TUN-6 on deployed targets only: Bun's WebSocket client sends no User-Agent, so the edge firewall refuses the tunnel handshake on staging and prod. The flow still runs locally. What's Changed chore(release): staging VERSION → 0.13.16 [skip ci] by @github-actions[bot] in #7248 chore(release): staging VERSION → 0.13.17 [skip ci] by @github-actions[bot] in #7252 test(release): quarantine TUN-6 — Bun WebSocket handshake has no User-Agent, WAF 403s it on staging/prod by @Ino-Bagaric in #7255 hotfix(preview): a legacy HS256 session opens preview origins again by @markokraemer in #7259 Release v0.13.17 — Signed-in previews open again by @github-actions[bot] in #7261 Full Changelog: v0.13.16...v0.13.17

Google ADKv2.9.1

From the release notes

2.9.1 (2026-09-15) Highlights This release focuses on improving visibility into model reasoning steps when utilizing Claude's adaptive thinking capabilities. Claude Integration: Access the step-by-step reasoning process of Claude models by ensuring visible thoughts are requested during adaptive thinking tasks. (ba0d542) Bug Fixes request visible thoughts for Claude adaptive thinking (ba0d542)

Graphjinv3.20.78

From the release notes

Changelog a325fac chore: bump version to v3.20.78 [skip-release] [skip ci] b2950b3 feat(core): SQL roles_query in union role mode 9c1192e feat(core): per-role read grants in sources mode 6357681 feat(core): union role mode and trusted $groups variable aebaff0 fix(dialect): in and nin with array variables on MySQL and MariaDB text columns 33cd5e6 fix(dialect): nin with an array variable on MongoDB 3b32e85 fix(qcode): reject role filters that compile to nothing 75795ad refactor(core): rename the groups variable to $user_groups

Graphjinauth/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Graphjincmd/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Graphjinconf/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Graphjincore/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Graphjinplugin/otel/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Graphjinserv/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Graphjintests/v3.20.78

From the release notes

chore: bump version to v3.20.78 [skip-release] [skip ci]

Sunav0.13.16 — Project model access controls, GPT-6 Astra, and a desktop app you can always leave

From the release notes

New Project-level provider and model access controls. Owners and admins choose which model providers and which models a project may use, from one model management view that also holds provider links. Kortix managed models sit beside your own providers in the same list, a ChatGPT subscription shows its access beside its credentials, and the picker distinguishes "not shown" from "blocked" so a member sees why a model is unavailable. GPT-6 Astra is in the managed catalog. Select kortix/gpt-6-astra with image input, tools, and the supported reasoning efforts. Routing, prices, capability limits, and sandbox fallbacks are all in step. The desktop app always has a way out. The shell has no browser toolbar, so a page without an in-app exit was a dead end. Every such page now has Close, the Go menu has Back (Cmd/Ctrl+[) and Home (Cmd/Ctrl+Shift+H), a renderer crash offers Reload or Go Home instead of an empty window, and the Electron route allowlist now matches the web middleware's exactly. Improved One noun: project. The interface said "workspace" while the SDK, CLI, API, routes, manifest, and docs all said "project". Screen copy now says project in every one of the nine languages, each with its own word rather than a find-and-replace. The sandbox /workspace directory, the manifest's per-agent workspace: boundary, and Slack workspaces keep their names. Create a project in a specific account. The Switch project menu, already grouped by account, gains a "Create a project in {account}" row for each account where you are an owner or admin, including accounts that have no projects yet. The old global link never said which account it would land in. The SSO and SCIM setup wizards work again. Picking a provider did nothing, and Back or the step rail snapped you to the first step with a render loop in the console. Both are fixed, and a browser journey now walks every step of both wizards on every deploy. Tunnel file transfers are verified end to end. Binary files sent through the Computer Tunnel are checked by digest at the destination, an approval for one exact file no longer grants its parent directory, permission decisions are serialized so an approve and a deny cannot both win, and orphaned upload tasks are stopped. Fixed The sandbox model proxy asked upstream for compressed responses and could not decode them. It now requests identity encoding, so a session on a model that answered with zstd no longer fails its first turn. Internal Project snapshot config provider v2 (S3). Sessions can boot from a prebuilt, blob-less snapshot of the project's committed tree with the history hydrated off the boot path, falling back to Git when no snapshot is ready. Every environment gets a private snapshot bucket and the task-role grant; only staging names its bucket, so production sessions keep the Git path until the in-region measurement lands. The project-snapshot task role gets s3:ListBucket, so a missing object is a 404 and not a denied build, and the grant

Sunav0.13.15 — Account creation you can find, Review Center for everyone, and a steadier session view

From the release notes

New Review Center is on for every project. It is no longer behind a feature flag — the routes, registry, contract, web surfaces, CLI, and docs all ship it by default. A public App can recognise you. public used to mean both "anyone with the link may open this" and "nobody is ever recognised". Now an App you share outside your company still greets your own team, shows them the controls a visitor should not see, and records who acted. Improved Creating an account is reachable again, and it lands you in the account you created. The control had no live entry point, and the one path that reached it dropped you back where you started. There is now a "Create an account…" row in the workspace switcher, and creating an account opens its first workspace with that account selected. Connector categories show their true size. The catalogue counted one page of results and headed every category with "· 1". Categories are now grouped over the complete catalogue on the server, and "View all" filters to the set its heading counted. Secret intake forms read better. Field hints written by an agent become real links, every non-form step shares one status notice, and the header no longer runs under the close button. Modals opened over modals stack correctly. A modal opened while another was open could render underneath it; it now takes the layer above, and the switch control meets contrast in both themes. Session hover cards line up. Sessions carrying a Slack, schedule, or shared marker opened their card inset from the sidebar edge; every row now anchors at the same place. Fixed Sending a message no longer makes the transcript jump twice. An idle send moved the view down and then glided it back. The send is now recognised as the working turn, so the view moves once. Internal 4xx denials are logged as warnings, not errors. Roughly 43% of production error-level lines were expected denials — expired tokens, a project-scoped token refused a cross-project read, an agent missing a grant — which buried real faults. Severity now follows the status class; the lines stay queryable and Sentry behaviour is unchanged. A dropped audit batch now says why. The log recorded the whole failing statement plus its bound parameters — IP addresses, user agents, account and project ids — while hiding the SQLSTATE that distinguishes a transient timeout from a permanent constraint violation. It now reports the code and cause, with no statement text and no parameters. A forced test exit raises a workflow annotation instead of a line buried in a 40,000-line CI log. The staging deploy asserts the host-only access cookie from main, matching what staging already checked. What's Changed feat(apps): a public App can recognise you without shutting anyone else out by @markokraemer in #7197 chore(release): staging VERSION → 0.13.15 [skip ci] by @github-actions[bot] in #7211 chore(release): VERSION → 0.13.15 [skip ci] by @github-actions[bot] in #7212 fix(web): stack modals opened over

Copilot Kitv1.72.0

From the release notes

This release repairs several v1 runtime surfaces that were silently broken since v1.50.0 and removes the deprecated useRenderTool shim from React Native.

Copilot Kitchannels/v0.10.0

From the release notes

This release trims the dependency footprint of the Teams and Slack channel packages and fixes Telegram code-block formatting. The headline change is a breaking one for self-hosted Teams users: the Microsoft Agents SDK and Express are now optional peer dependencies.

Deepseek Reasonixdesktop-v1.38.9: docs(release): 准备 v1.38.9 中英更新日志 (#10361)

From the release notes

docs(release): prepare v1.38.9 notes Summary: Generate a bilingual, product-focused draft from merged pull request metadata. Reuse the selected release-bound PR when one is available. Verification: Validate the catalog, citations, bilingual fields, and rendered GitHub release notes before committing. docs(release): restore v1.38.9 upgrade notes after regeneration Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: SivanCola 32437197+SivanCola@users.noreply.github.com

Deepseek Reasonixnpm-v1.38.9: docs(release): 准备 v1.38.9 中英更新日志 (#10361)

From the release notes

docs(release): prepare v1.38.9 notes Summary: Generate a bilingual, product-focused draft from merged pull request metadata. Reuse the selected release-bound PR when one is available. Verification: Validate the catalog, citations, bilingual fields, and rendered GitHub release notes before committing. docs(release): restore v1.38.9 upgrade notes after regeneration Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: SivanCola 32437197+SivanCola@users.noreply.github.com

Deepseek Reasonixdocs(release): 准备 v1.38.9 中英更新日志 (#10361)

From the release notes

docs(release): prepare v1.38.9 notes Summary: Generate a bilingual, product-focused draft from merged pull request metadata. Reuse the selected release-bound PR when one is available. Verification: Validate the catalog, citations, bilingual fields, and rendered GitHub release notes before committing. docs(release): restore v1.38.9 upgrade notes after regeneration Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: SivanCola 32437197+SivanCola@users.noreply.github.com

ComposioCLI Beta @composio/cli@0.4.2-beta.394

From the release notes

What's Changed docs(core): fix tools.getInput and tools.proxyExecute examples by Alberto Schiabel (@jkomyno) in #4481 fix(cli): bare --stream, dead Slack slug in help, tools info exit code, unknown listen slug by Nishant Gupta (@2nishantg) in #4344 New Contributors Nishant Gupta (@2nishantg) made their first contribution in #4344 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.393...@composio/cli@0.4.2-beta.394

Deepseek ReasonixReasonix Studio v2.16.0

From the release notes

本版的主线是让屏幕上写着的东西与内核里的事实是同一件:任务面板读内核发布的那份清单而不再从转录里把它猜回来,一次被拒的工具调用带着主机给它的身份而不是一句话,卡片名出内核真正跑的那个能力,能力清单在调用被花掉之前就说出它要的参数。工作台补上四件它做不到的事——会话内查找、代码块高亮、消息改写重发、能力名到卡片。回合多了一个出口:把清单交回用户,而不是被主机推着往下走。界面一侧是一轮以实测为准的整理(阅读尺寸与栏宽、等宽面、汉字下的小型大写、浅色的灰、卡片的高度成本),以及三个早已失灵的门。自 2.15.0 起 43 个提交。 升级路径:无需人工步骤。三平台照旧自更新——Linux 走 .deb,Windows 运行下一个安装器,macOS 替换自身 bundle。 新增 工作台:四件它做不到的事 会话内查找。转录只挂载几十张卡片,所以浏览器自带的查找只看得见屏幕上那些:200 条消息时 DOM 里有 59 张卡,第一条根本找不到。查找改读行本身——saidBy() 对 Item 是穷尽的,新卡片必须回答它携带什么文本。命中用高亮注册表画,而不是包一层标签:那等于重写 React 拥有的 markdown,而那些卡片在每一个增量上重渲染。 代码块高亮。rehype-highlight 像 katex 一样惰性加载,输出的是 class 而非内联颜色——自己写十六进制的高亮器会离开令牌系统、从此不跟随主题。调色板是四个新令牌,注释与标点走 --faint 和 --muted,跟随对比度档位。没有标注语言的围栏不上色:猜一门语法等于把散文画成代码。 一条消息可以改写后重发。由内核已有的两件事组合而成:把对话回卷到那一回合,然后发送。RewindResult 的 TS 镜像少了 conversationOk,于是"动了文件但对话仍在"与"对话被截断"无从分辨——那会把消息发两次。类型补全,这一对进了 wireparity。 调用解析到的能力会到达卡片,仅当名字尚未说出它时:tool:grep 写在 Search 旁边是一件事说两遍,skill:review 不是。 任务清单,与回合的出口 面板画的是清单主人所持的状态。GET /todos 一直在发布那份权威清单——最新一次 todo_write 与其后每一次 complete_step 推进的合并——而窗口从来没调用过它。面板自己从转录里解析 todo_write 的参数重建一份,那是 rebuildTodoState 的第二份实现,并在两处漂开:它不重放 complete_step,所以每一次签收都丢了;它不看回执,所以一份被内核拒绝的清单成了计划。每一次重建——挂载、面板重绑、流中断——都把面板重置回"模型最后写下的样子"。已签收的条目渲染成当前项、此后任何调用都推不动它,这就是"待办面板清不掉"从外面看的样子。 任务清单根本不可能从转录导出:推进不是 todo_write 调用,而被拒绝的写入是。所以 fromHistory 不再尝试,窗口去问;回合结束再读一次,因为有些移动没有事件可说(一次取消会让内核重建自己的状态);读取失败时面板保持原样而不是清空。 投影在状态移动时就欠下,而不只是 id 变了的时候。withTodoIdentityTail 只要每个步骤 id 还能在视图里读到就认为不欠——而 id 永远读得到,它们就在模型自己的 todo_write 参数里。底下的状态不会留在原地:complete_step 在主机侧推进那份权威清单而模型什么也没写。于是一份主机已经翻过页的清单还按模型最后写下的样子读着,下一次签收点的是主机已不认为是当前的那一项——complete_step 拒绝它,代价是满上下文下的一整轮,且学不到任何关于任务的东西。23 个录制会话里 complete_step 在 43 次调用中失败 16 次,这一类是其中最大的一组。 一个回合可以把清单交回用户,而不是被驱动。带着未完项停下来此前一律读作"活没干完",continueUntilReady 会拿主机写的一句话把它推上至多八轮。对模型能独自推进的步骤这是对的;对下一步输入在用户手上的步骤是错的——呈现一项并等待回复,与提前退出无从分辨,于是一份每回合走一项的清单根本没法走:回合停下、主机重启它、整张清单在一轮里全吐出来。 await_user 成为除 ask 与 conclude_blocked 之外第三种由模型决定的收尾,它点名等待中的那一项和用户需要提供什么,清单原样保留,就绪判定豁免未完项,续跑循环不运行。守卫是结构性的:必须有一份未完清单、step_id 必须点中其上未完成的一项、必须有可交互的用户——无头运行拒绝它并被指向 conclude_blocked。 工具表面与能力 一个工具在 schema 里,就是此刻可调用的。此前存在三种状态而模型只分得清两种:在 schema 里且可调用、注册了但藏在 use_capability 后面、以及在 schema 里却会被拒——最后一种不是任何人的本意。update_goal 就住在第三种里:534 个真实会话中它被调用 121 次,拒绝 116 次。 把工具钉住不动的那条理由被量掉了(benchmarks/tool-surface-cache)。"改 schema 会把缓存前缀搅浑"对任何位置的改动为真、对末尾的追加为假,而没有任何东西测过哪一条适用。实测:同一个工具在头部要 896 个缓存 token,在中部 384,追加在尾部不花任何东西;一个尾部工具在"有/无"之间来回三次,缓存读数稳定在 1920 与 2048 之间、没有一次未命中尖峰——因为缺席的那份表面是在场那份的字节前缀,一条缓存同时服务两者。于是 ProviderSchemas 分两段排序:稳定工具在前,本回合准入的上下文工具在后。 能力清单说出一次调用要被held到的参数。藏在 schema 之外的能力靠列目录再按 id 调用来够到,而清单只有 id 没有参数,第一次调用只能是猜。534 个会话里 12 次调用对 3 次 inspect,5 次带回"它需要……"。契约错误在调用被花掉之后才打印的两张表,现在在调用之前就在清单里:必填字段名,和每一个声明过的属性。从目标自己的 schema 经注册表读出——不是注册表工具、或 schema 没声明属性的条目什么也不说,而不是报一张空表让读者当成"它不要参数"。 卡片名出内核真正跑的那个东西。内核注册的 54 个工具里有 22 个在两张表里都没有条目,于是一次经 use_capability 的调用渲染成它自己 title-case 过的 id,顶着那个"折角的纸"标记。一次委派、一次记忆写入、一次安装全都读作文件读取,而类别颜色——那一行唯一的警示——是中性的那个。install_source 是其中最糟的一个:它不是只读的,它安装一个 MCP 服务器,而它根本没有身份。兜底标记改为中性圆点:"·" 是一份文档,一个没有条目的名字此前在声称自己读过文件。 重新打开的转录说得出代理够到的是哪个能力。实时转录读作 "Remember · 2026-08-

Mastra@mastra/turso@0.1.6

From the release notes

@mastra/turso@0.1.6

Mastra@mastra/upstash@1.4.6

From the release notes

@mastra/upstash@1.4.6

Mastra@mastra/valkey@0.2.3

From the release notes

@mastra/valkey@0.2.3

Mastra@mastra/valkey-streams@0.5.2

From the release notes

@mastra/valkey-streams@0.5.2

Mastra@mastra/vercel@1.6.0

From the release notes

@mastra/vercel@1.6.0

Mastra@mastra/voice-google-gemini-live@0.14.10

From the release notes

@mastra/voice-google-gemini-live@0.14.10

Mastra@mastra/voice-openai-realtime@0.14.0

From the release notes

@mastra/voice-openai-realtime@0.14.0

Mastra@mastra/voice-xai-realtime@0.2.10

From the release notes

@mastra/voice-xai-realtime@0.2.10

Mastramastra@1.30.0

From the release notes

mastra@1.30.0

Mastramastracode@0.40.0

From the release notes

mastracode@0.40.0

Kiro Crewv0.7.0-insider.2

From the release notes

What's Changed refactor: extract shared hardened gh runner for all gh spawn paths (#342) by @bolichen97 in #2407 feat(security): operator keystone extension for OAuth consent-endpoint allowlist (#1341) by @bolichen97 in #2402 fix: redact model-authored tool titles on all deny surfaces (#2274) by @bolichen97 in #2389 feat(chat): message-level pinning with pinned messages panel by @RohanK6 in #1676 ci(review): expand Opus to correctness blocking + sync fork prompt by @iamwhatever in #2379 feat(mcp-pool): Toggle all switch for poolable MCP servers by @chenmingwei23 in #2433 fix(knowledge): make the three auto-ingest paths opt-in by @bolichen97 in #2448 fix(dev-fleet): report slow actions as indeterminate, not as a fake percentage by @chenmingwei23 in #2439 test(dashboard): make chat-pins transient-I/O test portable on Windows by @iamwhatever in #2454 feat(voice): add a push-to-talk key for voice input by @CrysisDeu in #1608 feat(watchdog): detect a stalled turn from outside the turn's read loop by @chenmingwei23 in #2466 feat: receive images, voice and files on the Weixin channel by @chenmingwei23 in #2444 fix(dev-fleet): refuse the sync when pip cannot reinstall into the live venv by @chenmingwei23 in #2445 fix(prepare-pr): re-mirror the local review gate onto the current CI contract by @iamwhatever in #2456 feat(voice): show info banner + mic-click modal on remote instances by @cixuuz in #2471 refactor: centralize title hydration by @JoernZheng in #2467 fix(test_wait_tool_early_end): scope the wait-tool fake clock to the wait loop thread by @tlobinger in #2460 fix(terminal): complete subcommands for tools the user installed by @dwu96 in #2429 feat: first-party fixed-argv carve-out in sandbox fail-close (#1563) by @bolichen97 in #2428 feat: verify internal-API session claims via unix-socket peer creds (#302) by @bolichen97 in #2424 fix: re-vet cron jobs at fire time; move SEL key to trust/ (#1881) by @bolichen97 in #2421 build: target Node 24 LTS with a single 22+ floor everywhere (#1070) by @bolichen97 in #2415 feat: pin tunnel sessions to daemon-verified tailnet peer (#1762) by @bolichen97 in #2411 fix(appstore): compute app trust fields server-side (#580) by @bolichen97 in #2408 fix: detect and audit tier downgrades in nested-sandbox passthrough (#691) by @bolichen97 in #2406 fix: per-root hardlink-scan budgets with loud truncation (#646) by @bolichen97 in #2387 fix: make revocation generation cover refresh tokens (#2028) by @bolichen97 in #2388 ci: gate vendored _vendor tree behind a sha256 manifest (#492) by @bolichen97 in #2392 fix(dashboard): restore isort-clean import order in the dashboard auth module by @iamwhatever in #2479 feat(instances): carry the kiro-cli context so a sent session resumes by @iamwhatever in #2260 revert: withdraw multi-account Telegram until a bot is governable (#2203) by @chenmingwei23 in #2476 docs(autosde): forbid new work on the gateway boot path by @CrysisDeu in #2472 docs: revis

Kiro Crewv0.7.0-insider.1

From the release notes

0.7.0 insider 1

Copilot Kitintelligence-mastra/v1.71.2

From the release notes

Align the package version with CopilotKit 1.71.2. The API and implementation are unchanged from 0.1.0.

Copilot Kitintelligence-langgraph/v1.71.2

From the release notes

Align the package version with CopilotKit 1.71.2. The API and implementation are unchanged from 0.1.0.

Copilot Kitintelligence-mastra/v0.1.0

From the release notes

Initial release of @copilotkit/intelligence-mastra: native processor, skill tools, and agent wrapper for verified learned skill delivery, including resumed tool execution. #7129

Copilot Kitintelligence-langgraph/v0.1.0

From the release notes

Initial release of @copilotkit/intelligence-langgraph: verified learned skill delivery for native LangGraph agents, with skill tools and invocation handling. #7072 #7129

Copilot Kitv1.71.2

From the release notes

This release adds native Intelligence runtime support to @copilotkit/runtime and improves how the Inspector handles ephemeral threads. Features Native Intelligence runtimes and shared conformance (#6967): The TypeScript runtime now consumes the released @ag-ui/mcp-apps-middleware@^0.1.0 and runs against the same cross-language conformance suite as CopilotKit's native runtimes. This release also includes several runtime hardening fixes: Enforces MCP tool visibility filtering and unambiguous account/proxy selection, rejecting proxy requests outside the selected agent scope. Preserves identity and request-boundary contracts — SDK update precedence and mounted routing are retained, browser identity aliases can no longer override the authenticated user, and stop requests are cloned before application authentication consumes the body. Validates AG-UI tool arguments against their JSON schemas, keeping relaxed structured output limited to the A2UI tool. Preserves safe failure reporting and completion analytics — failures are reported without private diagnostic payloads, and completion counts are retained for streams containing RUN_ERROR. Advertises and consumes the January MCP Apps MIME type correction (text/html;profile=mcp-app). Fixes Preserve the ephemeral Threads upgrade path in the Inspector (#7098): The Inspector no longer treats any Threads list endpoint as durable Threads support. OSS apps using an in-memory agent runner can now inspect ephemeral conversations while still seeing a clear path to durable Threads: The full Rich Threads setup CTA is shown when Threads are unavailable, or when Intelligence is off and no local threads exist. When the first ephemeral thread appears, the Inspector switches to the thread list with a "Keep your threads" banner explaining that history can disappear on restart. "Make them permanent" opens the full setup view inline, with a sticky "Back to your threads" link to return to local history. The banner and setup override are removed once Intelligence becomes available. Remove optional feedback prompt copy from Inspector onboarding (#7099): Dropped an unnecessary optional diagnostic-feedback instruction from the shared feature setup prompt used by Threads and Learning, while retaining the instruction not to reveal credentials.

ComposioCLI Beta @composio/cli@0.4.2-beta.393

From the release notes

What's Changed perf(cli): list connected accounts once per execute by Daksh (@sudodaksh) in #4475 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.392...@composio/cli@0.4.2-beta.393

ComposioCLI Beta @composio/cli@0.4.2-beta.392

From the release notes

What's Changed docs: explain token custody architecture and deployment options by Brendan O'Leary (@olearycrew) in #4446 fix(cli): restore automatic plugin setup on install by Kshitij Jhunjhunwala (@KJ-11) in #4485 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.391...@composio/cli@0.4.2-beta.392

ComposioCLI Beta @composio/cli@0.4.2-beta.391

From the release notes

What's Changed perf(cli): move the compiler and tokenizer out of the executable by Daksh (@sudodaksh) in #4469 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.390...@composio/cli@0.4.2-beta.391

Best Of Agent HarnessesMid-September 2026: the harness-matters-more catalog, QM, Prime Agent, OpenJarvis

From the release notes

What's new Three harnesses from the YC Paper Club talk are in. Prime Agent (Prime Intellect, 95.5% on ARC-AGI-3 with Opus 5), QM (Y Combinator's multiplayer harness for work), and OpenJarvis (Stanford's local-first stack). 167 harnesses, stars captured 2026-09-13. Three new decision guides (16 total). Why the harness matters more than the model: the measurements (ARC-AGI-3 30% to 95.5% on the same weights, SWE-bench Pro 23% to 52%, Cursor 46% to 80%, Harness-Bench rank correlation -0.05), a table of twenty labs, papers, and practitioners with checked links, and what the claim does not mean, from the YC Paper Club session of September 7. Managed vs self-hosted always-on agents: Grok Bot, Claude Managed Agents, QM, OpenClaw, Hermes, OpenJarvis. Who owns the computer, who pays for idle time. The best AI agent harnesses in 2026, ranked by category: the top three per category from the live data, regenerated on every weekly refresh. README and machine-readable surfaces. The intro now carries the long-horizon numbers, the two eras of harnesses, and the pairing rule. Two new FAQ entries (the thesis, Grok Bot) flow to the README, llms.txt, harnesses.json, and the site's FAQPage. llms.txt states the thesis in its blurb; the site adds llms-full.txt (llms.txt plus every guide). Site. Every guide page carries TechArticle JSON-LD with real published and modified dates, breadcrumbs on all project, category, and guide pages, and a per-URL sitemap date. Guide links now resolve on the site (they previously pointed at .md paths that 404 under /compare/). MCP. compare prefers a guide that names the compared projects in its title. The 0.5.2 package on PyPI already serves the new projects and guides from main; the tie-break ships in the next package release.

Hermes AgentHermes Agent v0.21.3 (v2026.9.14)

From the release notes

Hermes Agent v0.21.3 (v2026.9.14) Release Date: September 14, 2026 Patch release. This tag rolls up the ~338 PRs merged since v0.21.2 into a stable tagged release for downstream consumers (Docker images, Hermes Cloud, hosted deployments). It exists so the remote-gateway sign-in fixes below reach Cloud agents, which auto-update to the newest release tag. What this patch ships for remote Desktop / Cloud users Remote dashboard sessions no longer expire on refresh bursts (#110061, fixes #55712; salvage #71548 @Doud-FR, #55717 @liuhao1024). Both refresh paths on the gateway (cookie gate and the desktop's native bearer route) now coalesce concurrent requests carrying the same rotating refresh token, so a Desktop wake burst can no longer replay an already-rotated token into the Portal's reuse detection and revoke the whole session. Refresh also runs off the event loop, so a slow identity provider no longer freezes /api/status. Pairs with Portal-side NousResearch/hermes-portal#1209 (sliding 30-day idle horizon, 5-minute rotated-token grace). Also requested for this tag Long-lived processes stop leaking duplicate state.db writer handles (#110934, fixes #100896 #103339; salvage #107974 @kshitijk4poor, mapping @Rroven): gateway, dashboard/Desktop backend, ACP and CLI readers attach read-only and in-process writers share the registry handle, so the N live SessionDB handles precursor stops firing on a healthy topology. About this release Measured at commit 9b419a2d3c2657c192008e732149d61170b32c01, the window since v0.21.2 contains 1,036 non-merge commits across 2,642 changed files (+131,690 / −37,096) and 338 merged PRs. Also in the window, undocumented here on purpose: server→client JSON-RPC requests and a Pydantic wire-contract registry with generated TS/OpenRPC for the TUI/Desktop gateway (#110521, #110522); reasoning-effort selection on every model picker, a composer pill and per-auxiliary control in Desktop; OpenRouter OAuth PKCE login; HEIF/HEIC/AVIF image decoding; the Honcho peer-model setup rework; MCP OAuth refresh tokens bound to their issuer; a daily MCP re-auth nudge in Desktop; Wan 3.0, Kling 3.0 / Kling Image v3, MiniMax H3 Max Turbo, Gemini Omni Flash 1.1 and Meta Muse in the FAL catalogs; Slack pasted tables and the Agent Sessions API; multiplexed-profile isolation and gateway-liveness fixes; and the state.db WAL refusal on cross-VM filesystems. Full curated release notes for this window ship with v0.22.0, which will document everything from v0.21.0 onward — highlights, feature areas, and complete contributor credits. Nothing in this window is skipped. Updating hermes update (git installs), or re-run the installer one-liner. Docker / Hermes Cloud: images build from this tag (nousresearch/hermes-agent:v2026.9.14). Full changelog: v2026.9.11...v2026.9.14

ComposioCLI Beta @composio/cli@0.4.2-beta.390

From the release notes

What's Changed perf(cli): defer the TypeScript compiler and generation pipeline by Daksh (@sudodaksh) in #4468 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.389...@composio/cli@0.4.2-beta.390

Ponytailv4.10.0

From the release notes

Two new homes for Ponytail. The headline: native Cursor support through hooks.json, with a scripts/cursor-hooks.js install that merges into your existing Cursor hooks file and leaves everything else in it alone. Also new: a Grok Build skills adapter, VS Code Copilot is finally detected correctly (no more Claude Code statusline nudge there), and the Claude.ai marketplace validator accepts the plugin again. What's Changed fix: drop commandWindows from hooks.json for Claude.ai marketplace validation (#593) by @prayag0one4 in #601 fix: detect VS Code Copilot via CLAUDE_PLUGIN_ROOT fallback (#528) by @krishrathi1 in #579 feat: add Grok Build native skills adapter (revive #561) by @p-clements in #661 docs: add Trendshift badge to READMEs by @DietrichGebert in #801 docs: add Trendshift monthly ranking badge by @DietrichGebert in #802 docs: put daily, weekly and monthly Trendshift badges in one row by @DietrichGebert in #803 docs: Built with Ponytail, Retriever by @DietrichGebert in #830 feat: add native Cursor hooks via hooks.json (#817) by @DietrichGebert in #869 New Contributors @prayag0one4 made their first contribution in #601 @p-clements made their first contribution in #661 Full Changelog: v4.9.0...v4.10.0

ComposioCLI Beta @composio/cli@0.4.2-beta.389

From the release notes

What's Changed fix(cli): stop tiktoken special-token literals from failing execute by Daksh (@sudodaksh) in #4464 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.388...@composio/cli@0.4.2-beta.389

ComposioCLI Beta @composio/cli@0.4.2-beta.388

From the release notes

What's Changed perf(cli): cut 221ms and 44MB RSS off every CLI invocation by Daksh (@sudodaksh) in #4463 Full Changelog: https://github.com/ComposioHQ/composio/compare/@composio/cli@0.4.2-beta.387...@composio/cli@0.4.2-beta.388

Casdoorv4.4.0

From the release notes

Changelog Features d60b5ae feat: add configurable password history check e1aa116 feat: add organization-level defaultTokenFields for new applications d6f2cb6 feat: show device, IP and last active time for each session e7f2799 feat: support app-level dark logo fbacaea feat: support group-level subscriptions ed417c1 feat: support invite-only pricing Bug fixes 3eb9231 fix(web): keep draft rows in key-value tables 0920d5d fix: carry the OAuth provider's email_verified through to the user (#5828) 251c76b fix: don't mark every group as having children in GetGroups() 6d6587d fix: keep CORS headers for concrete origins in proxy 991a5f1 fix: keep MFA providers in masked application so users can set up RADIUS MFA 0123751 fix: let RFC 7592 DCR endpoints bypass AutoSigninFilter 145f4c8 fix: only expire the logging-out user's tokens on session logout 5dd3de0 fix: record syncer errors instead of panicking at startup 4054ad5 fix: skip CORS headers when request has no Origin

Copilot Kitv1.70.3

From the release notes

v1.70.3 Install npm install @copilotkit/react-core@1.70.3 @copilotkit/react-ui@1.70.3 @copilotkit/runtime@1.70.3 Changes Remove the inspectorLearning option from Fetch, Express, and Hono handlers. Inspector Learning now requires an Intelligence runtime with a configured Learning container, not debug mode or a separate opt-in. Remove this option from existing handler configurations. (#6957) React and A2UI Provider-level humanInTheLoop tools now wait for respond, keep parallel calls independent, and report an error when aborted instead of an empty success. (#6851) Custom useDefaultRenderTool renderers can return null to hide selected tool calls without a type error. (#6942) Add development-only warnings for unmatched tool-call renderers and A2UI surfaces that never render or cannot resolve their root component. React and web-component renderers now consistently prefer nested surface IDs. (#6802) Runtime and Inspector Preserve unread request payloads in the Express bridge when body-parser sets an empty body but skips parsing, including multipart and plain-text requests. (#6490) Home and launcher Learning status now comes from Learning's own endpoint rather than Memory availability. Enabled launcher toggles now appear green. (#6957) Documentation Correct the v1 useCopilotChat source documentation: appendMessage is the public programmatic-send method; sendMessage is internal. Include the v2 migration path. (#6940) Document frontend-tool setup requirements for nine integrations, including Built-in Agent, Agno, Deep Agents, and Strands. (#6874) Add Microsoft Agent Framework guidance for backend approval interrupts, alongside the tool-based approval workflow. (#6922) Add AWS AgentCore troubleshooting for HTTP 401: Missing Authentication Token, covering runtime credentials, expired tokens, invocation URLs, and request routing. (#6920) Full changelog

Pydantic AIv2.43.0 (2026-09-11)

From the release notes

What's Changed 🚀 Features Add a first-run banner describing the run, and open clai sessions with it by @DouweM in #7447 🐛 Bug Fixes Preserve text part boundaries after tool calls in OpenAIChatModel by @KaranJayakumar in #8235 fix(temporal): key tool opt-out checks on operation kind, not an MCP import by @adtyavrdhn in #8257 New Contributors @KaranJayakumar made their first contribution in #8235 Full Changelog: v2.42.0...v2.43.0

Copilot Kitv1.71.1

From the release notes

This release focuses on runtime MCP fixes, React hook performance, and improvements to the Inspector's onboarding experience.

Graphjinv3.20.77

From the release notes

Changelog 039ee52 chore: bump version to v3.20.77 [skip-release] [skip ci] 1e376f5 fix(openapi): isolate request-scoped upstream credentials

Hermes AgentHermes Agent v0.21.2 (v2026.9.11)

From the release notes

Hermes Agent v0.21.2 (v2026.9.11) — The state.db Patch Release Release Date: September 11, 2026 Patch release. v0.21.0 shipped a large rewrite of the session store's connection handling, and for some installs it made state.db fragile: second writers cancelling each other's locks, healthy databases reported as corrupt, one bad row killing sessions list. This release closes that class and rolls up everything else that landed on main in the four days since v0.21.1. About this release Measured at commit 04dd80a977f40b05e5b2054111747af07a61886a, the window since v0.21.1 contains 947 non-merge commits across 1,869 changed files (+182,504 / −15,564) and 312 merged PRs. 140 contributors appear in commits, co-author trailers, or salvage credits. ✨ Highlights state.db reliability campaign (six PRs, 44 issues closed) If your state.db broke after 0.21.0, this is the release for you. Six PRs fix the root causes rather than the symptoms: No more second writers. Profile gateways wrote hosted-room state into the root state.db every 5 seconds; the dashboard opened a writable handle on startup; cron's lifecycle guard did a raw open() on a live database (which cancels the gateway's POSIX locks — the classic "how to corrupt SQLite" recipe); doctor --fix would checkpoint under a live holder. All four are gone: hosted rooms live in shared-state.db, the dashboard opens read-only first, the guard goes through the tracked connection registry, and doctor --fix refuses a checkpoint it can't prove is safe. (#108076 — salvage #103489 @RikETS, #102682 @JoaoMarcos44, #108012 @Halldrix, #105428 @TaoMasterCoder) Healthy WAL databases stop wedging. OpenZFS (deleted) dentries and a close() racing an append_message both produced a sticky DeletedWalGenerationError on a perfectly good store; the read pool was handed out under an unconfirmed journal mode; a transient disk I/O error on WSL2 killed get_session on the first attempt; and a "state.db locked" banner was broadcast after the lock had already cleared. (#108082 — salvage #107411 @chelsealong, #105578 @ca-shrimp, #105711 @gaoanze888, #106958 @nikkoxgonzales; co-authored @QDung210, @fangliquanflq, @Sahilvishnaliya) FTS damage no longer kills your turn. An error scoped to the full-text-search index was classified as whole-file corruption and fail-closed the conversation. It's now fts_index: search degrades, the index rebuilds later, the transcript store is untouched. Same PR: doctor names structural damage honestly instead of "FTS write corruption", the FTS write probe catches the stale-index shape that passed every check while every write failed, .recover output no longer fails startup on orphan FTS5 shadow tables, header-zeroed databases recover instead of being refused, and the dashboard analytics poller returns a 503 instead of 520K tracebacks a day. (#108130 — salvage #97843 @SulthanZahran1 + #97841 @Finn763, #88604 #56824 #103657 @liuhao1024, #106890 @nftpoetrist, #103321 @jangomango76, #91413 @leegunwoo98, #102808

Microsoft Agent Frameworkdotnet-1.21.0

From the release notes

What's Changed .NET: Replace deprecated AWSSDK.Extensions.Bedrock.MEAI with AWS.Bedrock.MEAI by Ben Thompson (@BenGearset) in #7983 .NET: Remove Azure.AI.OpenAI dependency by Roger Barreto (@rogerbarreto) in #7986 .NET: Track and update A2A task state by SergeyMenshykh in #7998 .NET: Update Azure AI Projects to 3.0.0 beta 1 by Roger Barreto (@rogerbarreto) in #7995 .NET: Bump Aspire.Hosting from 13.5.2 to 13.5.3 by Dependabot (@dependabot)[bot] in #8029 .NET: [BREAKING] Add file_access_read_lines and move the line-numbering contract onto AgentFileStore by Anton Sokolovskyi (@antsok) in #7671 Bump Anthropic from 12.42.0 to 12.43.0 by Dependabot (@dependabot)[bot] in #8028 .NET: Bump AgentMemory.AgentFramework from 1.4.1 to 1.5.0 by Dependabot (@dependabot)[bot] in #8027 .NET: [BREAKING] Clarify A2A agent run modes by SergeyMenshykh in #8032 .NET: Clarify declarative workflow input serialization by 宇宙的山峰 (@UniversePeak) in #8046 .NET: Preserve streamed annotations in Foundry hosted responses by Roger Barreto (@rogerbarreto) in #7984 .NET: Improve Hosted Agent LRA Resilient Recovery Sample by Roger Barreto (@rogerbarreto) in #8082 .NET: Include workflow outputs in hosted agent responses by 宇宙的山峰 (@UniversePeak) in #8020 .NET: Improve inline skill argument error guidance by SergeyMenshykh in #8118 .NET: Bump Azure.Monitor.OpenTelemetry.Exporter from 1.5.0 to 1.8.3 by Dependabot (@dependabot)[bot] in #7887 [BREAKING] .NET: Isolate LocalCodeAct subprocess environment by Eduard van Valkenburg (@eavanvalkenburg) in #8159 .NET: Scope OpenAI hosting storage by isolation key by SergeyMenshykh in #8146 .NET: chore: updates source link dependency due to transitive vulnerability by Vincent Biret (@baywet) in #8179 .NET: chore: updates Microsoft owned testing dependencies by Vincent Biret (@baywet) in #8167 .NET: ci: update Microsoft.CodeAnalysis.NetAnalyzers and Microsoft.VisualStudio.Threading.Analyzers versions by Vincent Biret (@baywet) in #8166 .NET: chore: updates microsoft extensions and related packages to their latest version, as well as global.json dotnet sdk version to align by Vincent Biret (@baywet) in #8190 .NET: Bump Azure.AI.Projects to 3.0.0-beta.2 by Roger Barreto (@rogerbarreto) in #8165 .NET: fix: revalidate file skill paths before use by SergeyMenshykh in #8151 .NET: Opt in to client function forwarding for Responses hosting by Roger Barreto (@rogerbarreto) with @Copilot in #7844 .NET: chore: updates additional analyzers packages by Vincent Biret (@baywet) in #8198 .NET: Harden LocalCodeAct OS validation by Eduard van Valkenburg (@eavanvalkenburg) in #8239 .NET: upgrades xunit and other dependencies by Vincent Biret (@baywet) in #8202 .NET: ci/promote removed apis by Vincent Biret (@baywet) in #8229 .NET: fix: do not forward headers on redirect by Vincent Biret (@baywet) in #8164 .NET: updates open telemetry deps by Vincent Biret (@baywet) in #8253 .NET: Dotnet: reset $LASTEXITCODE per command in persistent Po

Graphjinv3.20.76

From the release notes

Changelog eadb4c1 chore: bump version to v3.20.76 [skip-release] [skip ci] 6c7711d fix: scope physical identifiers and detect schema changes

Kiro Crewv0.6.0

From the release notes

Kiro Crew stops being one agent on one machine: choose the harness that runs your sessions, start a chat on another crew you are connected to, and let crew members dispatch workers of their own. Chat gets quieter, with folded diffs, resumed sessions that stop re-reading their own context, and refused commands that tell the agent what it may do instead. Python 3.12 is the new floor. Before you upgrade Python 3.12 is now the floor: a host on 3.10 or 3.11 must move up before installing or updating, and every installer provisions 3.12 itself when the system package manager has none. The installer now brings its own Python: curl -fsSL https://download.crew.kiro.dev/cli.sh | sh provisions a pinned CPython rather than using the system one, so pass --system-python if you deliberately build against yours. The command gate no longer fences credential paths by reading the command text: the sandbox's bind masks are the fence now, so check that agent.sandbox in config.json is not off if you were relying on that text gate. An unattended auto-run plan now stops after two hours: raise it with orchestrator.max_plan_duration_seconds in config.json, or set 0 to remove the ceiling; a stage-gated plan is never cut. Pick the harness that runs your sessions (Preview) Claude Code, Codex and KAS are selectable harnesses: turn on Developer Mode in Settings → Developer (off by default), then pick one under Developer → Agent Backend, where each option says whether it is installed, missing on this machine, or waiting on a gateway restart. A tool pre-approved in Claude's own settings never reaches Crew's approval path, so its deny rules and audit log do not see that call, and Codex refuses to start while the sandbox is off. Monitor loops, project changes, follow-up cards and conversation reset work on every backend, where they previously failed closed outside Kiro CLI. Remote crews become one dashboard (Preview) Run a chat on another crew you are connected to: set instances.enabled in config.json and turn on Settings → Developer → Feature Previews → Chat on a crew (both off by default), then pick the peer under New chat on crew in the sidebar's new-chat menu; the transcript stays local while every turn runs on that crew. A session that runs elsewhere carries a server badge and the crew's name in your sidebar, so remote work is openable from the list you already read. Crews connect themselves on app load and on tab focus, on by default and switchable at Settings → Remote Instances → Auto-connect crews. Chat that stays out of the way Diffs start folded as a chip naming the file and its +N/-M counts, and Settings → Chat → Plain diffs (off by default) renders patches as plain monospace text instead. A sketch pad and a share action: the composer's + menu gains a Sketch row that draws an image and attaches it, and an assistant reply's Share as image action exports a branded PNG or prefills an X or LinkedIn post. The composer says where you are, and gets out of the

Kiro Crewv0.6.0-insider.7

From the release notes

What's Changed fix(deps): backport the electron js-yaml 4.3.2 pin to release/0.6.0 by @bolichen97 in #10076 Full Changelog: v0.6.0-insider.4...v0.6.0-insider.7

Google ADKv2.9.0

From the release notes

Changelog 2.9.0 (2026-09-10) Highlights This release focuses on agent resilience and ecosystem integration by introducing automatic model failover, native voice support via LiveKit, and compatibility with MCP SDK 2.x. Models: Safeguard agent uptime by automatically failing over to backup models when the primary model encounters errors. (c300b8d) Integrations: Build rich voice and telephony agents using the newly added LiveKit runner. (f277d91) Workflows: Simplify graph workflow management by authoring and loading ADK 2.0 graphs directly from declarative YAML configurations. (2a9461b) MCP: Work with MCP SDK 2.x servers as well as 1.x. Installs continue to resolve 1.x by default; install 2.x deliberately to opt in. (856acf2) Breaking changes Workflow node resumption: A node that failed now runs again when the workflow resumes, where before it replayed as though it had completed. Make node bodies idempotent: a node that performs an external side effect and then fails will perform that side effect again on every resume. GCS tool local paths: The GCS tools now read and write local files only inside the directory named by local_file_root, and refuse local file access entirely when that setting is absent. Paths may be absolute or relative, and are judged by where they resolve. In-memory sessions only: InMemorySessionService now raises SessionNotFoundError when an event is appended to a session it does not hold, instead of accepting the event and discarding it. The database-backed services already behaved this way, so this affects in-memory sessions alone. Two further changes are marked breaking in the commit log but do not affect a default installation. Nested workflow retry changes behavior only for a node that already sets retry_config. The MCP SDK 2.x field handling applies only if you install MCP 2.x deliberately, which this release does not resolve to. All changes ⚠ BREAKING CHANGES retry a nested workflow when a node inside it fails confine GCS tool local file paths to a configured root rerun a failed node on resume instead of replaying it as complete raise SessionNotFoundError when appending to an unknown session mcp: under MCP SDK 2.x, fields a server sends that the SDK does not declare no longer reach the caller. 2.x closed its models, so an unknown key on a CallToolResult, or on a tool declaration read via raw_mcp_tool, is discarded during validation before ADK sees it. _meta is unaffected: it is a declared field and still arrives. Nothing in ADK can restore the others; a server that relies on vendor extensions should move them under _meta. On 1.x they still arrive as before. Features add a2a_state_forwarding sample (1b28de4) add FallbackModel for automatic failover between models (c300b8d) add get_authenticated_url and get_signed_url to GcsArtifactService (10ac52b) add ignore_args option to tool trajectory evaluation (e2a213f) add transfer_reason to transfer_to_agent to prevent loops (22ab4d8) agent evaluations pri

E2 B@e2b/python-sdk@2.49.1

From the release notes

Patch Changes 5e418dc: Document that onResume / on_resume needs a control plane that knows the option: an older self-hosted or BYOC control plane drops the memory field and restores memory while reporting success, instead of rejecting the request. 9136603: Retry control-plane HTTP requests up to three times after 429 responses using the server's delta-seconds Retry-After delay. Retries can be configured or disabled with retries, and stop when waiting would exhaust the request timeout. Envd requests, including filesystem operations, and volume-content requests are not retried.

E2 Be2b@2.49.1

From the release notes

Patch Changes 90e3fc5: Reject invalid Sandbox.create lifecycle options and Sandbox.connect onResume values before requiring an API key, matching the Python SDK. 5e418dc: Document that onResume / on_resume needs a control plane that knows the option: an older self-hosted or BYOC control plane drops the memory field and restores memory while reporting success, instead of rejecting the request. 9136603: Retry control-plane HTTP requests up to three times after 429 responses using the server's delta-seconds Retry-After delay. Retries can be configured or disabled with retries, and stop when waiting would exhaust the request timeout. Envd requests, including filesystem operations, and volume-content requests are not retried.

9Router# v0.5.75 (2026-09-10)

From the release notes

Covers the 24 commits since the v0.5.69 tag. The package version already moved to 0.5.75 in 4a39068 (CLI model selector), so the release commit is the changelog alone, matching the convention in eb712ca/4eda76e2a. Co-Authored-By: Claude Code noreply@anthropic.com

Microsoft Agent Frameworkpython-1.18.0

From the release notes

[1.18.0] - 2026-09-10 Added samples: Add Magentic custom-manager prompts and MLflow observability examples (#7876, #8085) agent-framework-core: Add shared vector-store abstractions, portable filters, and an in-memory vector store (#8014, #8115) agent-framework-core: Add a maximum-duration bound and stop-reason signal to the tool invocation loop (#7772) agent-framework-core: Support mixed workflow invocation keyword arguments (#7963) agent-framework-ag-ui: Add emit_messages_snapshot configuration for suppressing the terminal message snapshot (#7808) agent-framework-ag-ui, agent-framework-core: Add supported MCP Host-history conversion for persisted AG-UI conversations (#8130) agent-framework-azure-ai-search, agent-framework-core: Add an Azure AI Search implementation of the shared vector-store APIs (#8153) agent-framework-redis, agent-framework-core: Add Redis HASH and JSON vector stores (#8156) agent-framework-qdrant: Add the alpha Qdrant vector-store connector (#8154) agent-framework-postgres: Add the alpha PostgreSQL/pgvector connector (#8155) Changed agent-framework, agent-framework-core, agent-framework-foundry, agent-framework-lab: [BREAKING] Isolate Lab dependency resolution, remove Lab from core[all], and support Azure AI Projects through 2.6 with OpenAI 3.x (#8188) agent-framework-core: [BREAKING - experimental] Add ranged file reads and move the line-numbering contract onto AgentFileStore (#7669) agent-framework-core: [BREAKING - experimental] Centralize file, memory, session, and skill path normalization (#8123) agent-framework-anthropic, agent-framework-azure-ai-search, agent-framework-azure-cosmos, agent-framework-bedrock, agent-framework-copilotstudio, agent-framework-core, agent-framework-foundry, agent-framework-gemini, agent-framework-mem0, agent-framework-openai: [BREAKING] Make SecretString a masked value wrapper rather than a str subclass and align provider credential handling (#8127) agent-framework-github-copilot: [BREAKING] Make workspace file hooks opt-in and document enable_file_hooks migration (#7517) agent-framework-foundry-hosting: [BREAKING - beta] Restrict checkpoint deserialization by default and allow applications to register additional checkpoint types (#8045) agent-framework-core, agent-framework-foundry: Move Foundry evaluation serialization into the Foundry integration (#8031) agent-framework-github-copilot: Update the GitHub Copilot SDK dependency to 1.0.11 and align file-operation behavior (#8002) agent-framework-ag-ui, agent-framework-devui: Expand compatibility through FastAPI 0.141 (#8052) agent-framework-core, agent-framework-hyperlight: Update Hyperlight Sandbox to 0.6 and enable supported Python 3.14 installations (#8174) agent-framework-foundry, agent-framework-foundry-hosting, agent-framework-openai: Lazily load Foundry and OpenAI integrations to avoid unnecessary import-time dependencies (#8219) agent-framework-devui: Update frontend transitive dependencies (#8019, #8009, #8175

Copilot Kitv1.71.0

From the release notes

This release converges React Native's render-tool hooks onto react-core, improves Copilot context timing during page navigation, and adds provider-level agent configuration. It also includes fixes for nullable tool schemas, the Vue human-in-the-loop lifecycle, and the Inspector experience.

Best Of Agent HarnessesSeptember 2026 update

From the release notes

What changed since August 12 MCP server works again. agent-harnesses-mcp 0.5.2 pins the MCP SDK below 2.0. The 2.0 release (July 28) renamed FastMCP, and 0.5.1 crashed on startup for anyone who installed it. Install: claude mcp add agent-harnesses -- uvx agent-harnesses-mcp. Cold-tested: initialize and tools/list complete, 10 tools. 164 harnesses, 12 categories. New in the tables: YYLO (coding agent products), AnythingLLM (personal agent runtimes), ClawBench (evaluation and benchmarking). Flowise stays listed with its archived flag instead of moving to the Graveyard. Roo Code is out of the turnkey coding agent pick and stays in the tables with its archived flag. On the radar. DeepSeek Harness (pinned, not ranked, pending a star-velocity check on 2026-10-07), Google Antigravity SDK, L∞pGate, and eight community submissions below the ranked-table bar. Community submissions now reach the curation queue. Open "Add project" issues feed the weekly discovery run, so the biweekly curation pass vets them with live repo data and closes the issue when an entry lands. Site. The nav shows a live star count that links back to the repo. Weekly rescores on August 16, 23, 30, September 6 and 9 refreshed every star count and the landscape charts. Thanks to contributors HelpMatey (#61), InsightFactoryAPP (#111), reacher-z (#60), rxdt (#69), and danawoodman (#78).

Best Of Agent Harnessesmcp-v0.5.2

From the release notes

agent-harnesses-mcp 0.5.2: pin the mcp SDK below 2 so the server star…

A rolling collection from official feeds, not a complete release archive. Dates are reported by each source.

Related, by design

The ecosystem moves fast.
Keep the good stuff close.

01

Find your people’s tools

A curated directory of agent frameworks and building blocks. Explore by what you want to make.

02

Follow the actual changes

Release notes collected from official repositories. Every update takes you back to the source.

03

Make it your own

Save the projects you care about. Your collection stays in this browser, without another account.