This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summaryPaid agents no longer bypass server policy and now require Agentlas sign‑in plus credit checks.
Full changelog
Paid agents are no longer short-circuited locally. /hep-call <paid-slug> now goes through the same server policy as everyone: Agentlas sign-in (automatic) + the server credit gate (OWN_CALL_CREDITS for your own cloud packages), instead of a local blocked_paid_overlap dead-end. Credit/auth refusals are surfaced cleanly; the runtime never reads local source to role-play a paid agent.
Breaking Changes
- Removed local short‑circuit for paid agents; `/hep-call` now follows server policy (Agentlas sign‑in + OWN_CALL_CREDITS check).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hephaestus
Open Agent OS for Claude Code, Codex, and Cursor with a meta-agent builder, A2A Hub routing, local ontology, and memory/security gates. Apache-2.0.
Related context
Related tools
Beta — feedback welcome: [email protected]