This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
ReleasePort's take
Moderate signalThe release updates the WebSocket dependency `ws` to version 8.x to apply a security fix.
Why it matters: Security severity 80 triggers an immediate patch; all deployments using ws must upgrade to 8.x now.
Summary
AI summaryWebSocket dependency updated to ws 8.x with a security fix.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Updated WebSocket dependency `ws` to 8.x for security fix. Updated WebSocket dependency `ws` to 8.x for security fix. Source: llm_adapter@2026-05-31 Confidence: high |
— |
| Feature | Low |
Added Codex hook setup and status handling for Agent FM. Added Codex hook setup and status handling for Agent FM. Source: llm_adapter@2026-05-31 Confidence: high |
— |
| Feature | Low |
Added live GitHub release downloads badge to public README. Added live GitHub release downloads badge to public README. Source: llm_adapter@2026-05-31 Confidence: high |
— |
| Dependency | Low |
Updated public release workflows to latest pinned Go setup action. Updated public release workflows to latest pinned Go setup action. Source: llm_adapter@2026-05-31 Confidence: high |
— |
| Bugfix | Medium |
Station scenes now cleanly settle when agent yields, clearing stale indicators. Station scenes now cleanly settle when agent yields, clearing stale indicators. Source: llm_adapter@2026-05-31 Confidence: high |
— |
| Bugfix | Low |
Improved macOS titlebar and collapsed-sidebar layout behavior. Improved macOS titlebar and collapsed-sidebar layout behavior. Source: llm_adapter@2026-05-31 Confidence: high |
— |
| Refactor | Low |
Refreshed station scene with new Pixel Adventure elements. Refreshed station scene with new Pixel Adventure elements. Source: llm_adapter@2026-05-31 Confidence: low |
— |
| Refactor | Low |
Refreshed station scene with Pixel Adventure obstacles, hazards, checkpoints, pickups, and trampolines. Refreshed station scene with Pixel Adventure obstacles, hazards, checkpoints, pickups, and trampolines. Source: granite4.1:30b@2026-05-31-audit Confidence: low |
— |
Full changelog
Added
- Added Codex hook setup and status handling so Agent FM can surface Codex attention and permission states more reliably.
- Added a live GitHub release downloads badge to the public README.
Changed
- Refreshed the station scene with Pixel Adventure obstacles, hazards, checkpoint flags, fruit pickups, and trampoline milestone beats.
- Station scenes now settle cleanly when an agent yields back to the user, clearing stale subagent and skill indicators.
- Improved macOS titlebar and collapsed-sidebar layout behavior.
Security
- Updated WebSocket dependencies for the latest
ws8.x security fix. - Updated public release workflows to the latest pinned Go setup action.
Download AgentFM-macos-arm64-signed-notarized.dmg from the assets below.
Security Fixes
- Updated WebSocket dependencies for the latest ws 8.x security fix (CVE not specified)
- Updated public release workflows to the latest pinned Go setup action
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Agent FM
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]