This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryDocker GitHub Actions supply‑chain hardening with full SHA hashes.
Full changelog
v1.5.2
Security
- Docker GitHub Actions pinned to full SHA hashes (supply chain hardening)
Fixed
- SonarCloud reliability bugs in test scripts resolved
- CI workflow stabilization
Security Fixes
- Docker GitHub Actions pinned to full SHA hashes (supply chain hardening)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About chernistry/bernstein
Deterministic multi-agent orchestrator for 18 CLI coding agents (Claude Code, Codex, Cursor, Aider, Gemini CLI, OpenAI Agents SDK, and more). MCP server mode (stdio + HTTP/SSE) exposes the orchestrator to any MCP client. Git worktree isolation per agent, HMAC-chained audit trail, cost-aware model routing via contextual bandit. ~11K monthly PyPI downloads, Apache 2.0.
Related context
Related tools
Beta — feedback welcome: [email protected]