Skip to content

Hephaestus

v0.7.21 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

a2a agent agent-framework agent-os-desktop agent-skills agentic-ai
+13 more
agentic-workflow agentos agents agents-team agentshub ai-agents autonomous-agents llm llm-agents llm-tools mcp multi-agent-systems ochestration

Affected surfaces

auth

Summary

AI summary

Adds value‑free credential request metadata to the public local credential map.

Full changelog

Credential request contract for borrowed agents and plugins.\n\n- Adds value-free credential request metadata to the public local credential map: provider, env name, allowed hosts, allowed operations, scope, setup URL, input mode, save target, and broker mode.\n- Clarifies that host-bound broker isolation requires a real local process/IPC boundary; legacy runtime env injection is explicitly not equivalent.\n- Updates auto-activation, source-of-truth, runtime boundary, schema, and project memory templates for Desktop/terminal secure credential prompts and future broker enforcement.\n\nVerification: scripts/verify-package.sh, scripts/public_safety_check.sh, architecture sync-check.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Hephaestus

Get notified when new releases ship.

Sign up free

About Hephaestus

Open Agent OS for Claude Code, Codex, and Cursor with a meta-agent builder, A2A Hub routing, local ontology, and memory/security gates. Apache-2.0.

All releases →

Related context

Beta — feedback welcome: [email protected]