✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 18.1.0, and 2026-07-17 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds REST CRUD for user and system API keys with unified authority model. Adds REST CRUD for user and system API keys with unified authority model. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Requires a human session to issue API keys via REST endpoints. Requires a human session to issue API keys via REST endpoints. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Adds user friction evaluator in evals module. Adds user friction evaluator in evals module. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Surfaces user.id span attribute on spans, traces, and sessions in tracing. Surfaces user.id span attribute on spans, traces, and sessions in tracing. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Offers Phoenix docs MCP server during px setup in CLI. Offers Phoenix docs MCP server during px setup in CLI. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Connects an app to Phoenix and verifies traces arrive during px setup in CLI. Connects an app to Phoenix and verifies traces arrive during px setup in CLI. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Splits users and API keys into dedicated settings tabs UI. Splits users and API keys into dedicated settings tabs UI. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Virtualizes the models table in Settings UI. Virtualizes the models table in Settings UI. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Dependency | Low |
Updates arize-phoenix-evals dependency to version 3.1.1. Updates arize-phoenix-evals dependency to version 3.1.1. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Low |
Bounds /v1/users/api_keys page size at 1000 to prevent excessive data retrieval. Bounds /v1/users/api_keys page size at 1000 to prevent excessive data retrieval. Source: llm_adapter@2026-07-17 Confidence: high |
— |
Full changelog
18.1.0 (2026-07-17)
Features
- api: REST CRUD for user and system API keys (257a77d)
- api: REST CRUD for user and system API keys with a unified authority model (50cc3db)
- api: REST requires a human session to issue API keys (7e30e1a)
- cli: offer the Phoenix docs MCP server during px setup (99dec5a)
- cli: px setup — connect an app to Phoenix and verify traces arrive (f94067b)
- evals: add user friction evaluator (#14193) (1ae1a39)
- settings: split users and API keys into dedicated settings tabs (c58854f)
- settings: vertical settings tabs on large screens with responsive fallback (df56d8d)
- settings: virtualize the models table (20de8b9)
- tracing: surface user.id span attribute on spans, traces, and sessions (#14398) (3245845)
- ui: clarify AI provider credential storage with browser/server tabs (49ac09c)
Bug Fixes
- agents: stop logging PXI messages (#14388) (dcf466c)
- api: bound the /v1/users/api_keys page size at 1000 (ea38b1b)
- auth: correct cookie names in auth.md discovery doc (cb37e9c)
- cost: update built-in model token prices (#14397) (047694f)
- deps: update arize-phoenix-evals to 3.1.1 (510c1e9)
- evals: skip LiteLLM on Python 3.14 (#14407) (bc9b533)
- overflow bars on tiledpanel extra actions (#14430) (1c764c9)
- playground: keep template format selected (#14431) (d736071)
- table row hover and cursor styles (#14428) (3fddd0a)
- ui: align credential tab checkmark and explain env-var-only server credentials (ad6ece6)
- ui: cap IO tooltip height and add scroll fades (38e037a)
- ui: increase IO tooltip open delay to 700ms (46ef55f)
- ui: prevent trace note overflow (#14376) (1d5b1a6)
Documentation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- varize-phoenix-v19.0.0 GraphQL createUserApiKey and createSystemApiKey reject API-key callers.
- varize-phoenix-v18.0.0 Changes session time-range filters to use interval-overlap semantics.
- varize-phoenix-v17.0.0 Adds system settings for admin-managed assistant enablement and trace recording policy
- varize-phoenix-v16.0.0 Sandboxing and Code Evaluators introduce breaking changes in Phoenix v16.0.0.
- varize-phoenix-v15.7.0 Removes v1 /chat route and associated code
Beta — feedback welcome: [email protected]