This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summaryAdds value‑free credential request metadata to the public local credential map.
Full changelog
Credential request contract for borrowed agents and plugins.\n\n- Adds value-free credential request metadata to the public local credential map: provider, env name, allowed hosts, allowed operations, scope, setup URL, input mode, save target, and broker mode.\n- Clarifies that host-bound broker isolation requires a real local process/IPC boundary; legacy runtime env injection is explicitly not equivalent.\n- Updates auto-activation, source-of-truth, runtime boundary, schema, and project memory templates for Desktop/terminal secure credential prompts and future broker enforcement.\n\nVerification: scripts/verify-package.sh, scripts/public_safety_check.sh, architecture sync-check.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hephaestus
Open Agent OS for Claude Code, Codex, and Cursor with a meta-agent builder, A2A Hub routing, local ontology, and memory/security gates. Apache-2.0.
Related context
Related tools
Beta — feedback welcome: [email protected]