Skip to content

This release adds 2 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agents analytics antigravity claude-code cli-tool codex
+11 more
cursor cursor-ai insights kiro large-language-models mcp pi playground registry self-hosted skills

Affected surfaces

auth

Summary

AI summary

Updates 1.9.9] - 2026-07-07, Testing, and GitBook across a mixed release.

Full changelog

[1.9.9] - 2026-07-07

Added

  • add JSON output for scan (cli) (223973f)
  • GitHub OAuth sign-in + SSO settings robustness fixes (auth) (9675ba6)

Documentation

  • remove BlazeUp references (0923059)
  • add license commitment (35a6f54)
  • remove outdated rules references (cursor) (0b47917)
  • add Cursor integration to summary (186e3bb)
  • add Cursor integration guide (ba6f935)
  • clarify enterprise license boundary (09e3202)
  • add Copilot integration to summary.md (49e64b8)
  • add Copilot integration guide (integrations) (b74058b)

Fixed

  • hide IDs from component versions (web) (5d02072)
  • wrap MCP environment descriptions (web) (959c971)
  • make visibility migration idempotent (server) (b875fc4)
  • populate OpenCode plugin hook fields (harness) (f8d8f6b)
  • count all secret redactions (security) (1304137)
  • reject leading-zero semver (versioning) (cfd8be7)
  • correct internal git url setting hint (mcp) (55a4499)
  • restore strict version match, show correct upgrade/downgrade command (cli) (330339f)
  • use full page redirect after login to prevent auth loop on multi-replica deployments (auth) (3a2bd32)
  • validate sp_key_encryption_password when SAML is configured (ee) (7b468ba)
  • remove unnecessary quotes from type annotation (ee) (420a6da)
  • override entryPoint to bypass nginx envsubst on $uri (infra) (5fd2c1f)
  • resolve web container crash-loop on ECS (nginx upstream failure) (infra) (bca2c04)
  • align ClickHouse version to 26.6 across all modules (infra) (96bdefd)
  • remove dangerous rm -rf /data/postgres/* from data host user-data (infra) (6ea8268)
  • resolve connectivity and deployment issues in aws and aws-standard terraform modules (infra) (2f8cb59)
  • evaluate enterprise config dynamically on SSO/SCIM requests (ee) (f815b44)
  • relax version enforcement for self-hosted servers (cli) (6d6dca4)
  • suggest noninteractive self upgrades (cli) (89e211f)
  • resolve latest telemetry version (pi) (f2347dd)

GitBook

Other

  • relicense core as Apache 2.0 (e65969d)

Testing

  • cover doctor helpers (cli) (6aee651)
  • add Pi harness config generator tests (api) (428542e)
  • add unit tests for harness specs (69bd6cf)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track BlazeUp-AI/Observal](https:

Get notified when new releases ship.

Sign up free

About BlazeUp-AI/Observal](https:

All releases →

Related context

Earlier breaking changes

  • v1.6.0 rename logger alias to optic (audit)
  • v1.2.0 Removes legacy pre-JSONL modules in insights.
  • v1.2.0 Removes agent visibility and team access features.
  • v1.1.0 Replace deployment_mode API field with licensed boolean.
  • v0.8.0 Removes goal template, replaces with required prompt field in agent configuration.

Beta — feedback welcome: [email protected]