This release includes 1 security fix for security teams reviewing exposed deployments.
Published 20h
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
agent
ai
api
cli
developer-tools
llm
+1 more
python
Affected surfaces
breaking_upgrade
Summary
AI summaryCVE‑2026‑14257 security fix applied to base, dev, and server sandbox images.
Full changelog
Highlights
- Added deterministic route arbitration, turn-contract enforcement, regression baselines, and fact-based completion evidence.
- Added tracked process cleanup, reusable workspace provisioning, and containment for incomplete subagent reports.
- Added Moonshot/Kimi K3, K2.7 Code, K2.7 Code Highspeed, and K2.6 support with reasoning continuation and cache affinity.
- Refreshed the ChatGPT subscription model catalog and honored provider-reported final-answer phases.
- Added
SYLLIPTOR_WEB_TOOLSas a master switch for web tools and search backends.
This release contains the July 20-26 core updates and excludes the VS Code extension work.
Verification
- GitHub CI passed on Python 3.11 and 3.12: 6,519 tests passed and 23 skipped on each version.
- macOS CLI smoke, package build, wheel smoke install, and distribution validation passed.
- Version 0.11.2 was published to PyPI through trusted publishing.
- Tagged base, dev, and server sandbox images were rebuilt with the CVE-2026-14257 fix; Trivy scans, provenance attestations, keyless signatures, and runtime smoke passed.
See CHANGELOG.md for the complete change list.
Security Fixes
- CVE-2026-14257 — fixed in rebuilt base, dev, and server sandbox images; Trivy scans, provenance attestations, keyless signatures, and runtime smoke passed
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About AlysisAi/sylliptor
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]