This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 3.11.0, and 2026-06-11 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Wire untrusted-content fence into agent-facing output for security hardening. Wire untrusted-content fence into agent-facing output for security hardening. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Medium |
Add dashboard retry logic: once then return 409 on state‑write conflicts. Add dashboard retry logic: once then return 409 on state‑write conflicts. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Medium |
Introduce guidelines list subcommand and MCP tool. Introduce guidelines list subcommand and MCP tool. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Align frontmatter tool grants with body instructions in agents. Align frontmatter tool grants with body instructions in agents. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Parse CLI asynchronously so bootstrap errors surface actionably. Parse CLI asynchronously so bootstrap errors surface actionably. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Stop three per‑item catches from swallowing rate‑limit errors in core. Stop three per‑item catches from swallowing rate‑limit errors in core. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Hoist PR‑list memos above early returns in dashboard to satisfy Rules of Hooks. Hoist PR‑list memos above early returns in dashboard to satisfy Rules of Hooks. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Reflect SPA shelve/unshelve actions immediately in dashboard UI. Reflect SPA shelve/unshelve actions immediately in dashboard UI. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Surface corrupt‑Gist, permission, and rate‑limit errors from gist bootstrap. Surface corrupt‑Gist, permission, and rate‑limit errors from gist bootstrap. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Stop reporting rate‑limited release fetches as no releases in repo‑vet. Stop reporting rate‑limited release fetches as no releases in repo‑vet. Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Preserve forensics and surface recovery when state.json is unparseable. Preserve forensics and surface recovery when state.json is unparseable. Source: granite4.1:30b@2026-06-11-audit Confidence: low |
— |
| Bugfix | Low |
Surface Gist checkpoint push failures in structured output from state module. Surface Gist checkpoint push failures in structured output from state module. Source: granite4.1:30b@2026-06-11-audit Confidence: low |
— |
Full changelog
3.11.0 (2026-06-11)
Features
- dashboard: retry once then return 409 on state-write conflicts (#1403) (ac72ed3), closes #1397
- guidelines: add guidelines list subcommand and MCP tool (#1400) (085e127), closes #1393
- security: wire the untrusted-content fence into agent-facing output (#1396) (e1599a0), closes #1372
Bug Fixes
- agents: align frontmatter tool grants with body instructions (#1395) (47d5ed2), closes #1377
- cli: parse asynchronously so bootstrap errors surface actionably (#1401) (4364c61), closes #1386
- core: stop three per-item catches from swallowing rate-limit errors (#1404) (867610c), closes #1391
- dashboard: hoist PR-list memos above early returns (Rules of Hooks) (#1384) (d03a30c), closes #1369
- dashboard: reflect SPA shelve/unshelve immediately (#1362) (37d1dc6)
- gist: surface corrupt-Gist, permission, and rate-limit errors from bootstrap (#1387) (2c6d2cd), closes #1367
- repo-vet: stop reporting rate-limited release fetches as no releases (#1390) (5939a1d), closes #1373
- state: preserve forensics and surface recovery when state.json is unparseable (#1389) (d4beadb), closes #1371
- state: surface Gist checkpoint push failures in structured output (#1388) (e4766f4), closes #1370
Security Fixes
- Security: Wire the untrusted-content fence into agent-facing output (hardens against malicious content injection)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About costajohnt/oss-autopilot
Open source contribution manager with PR tracking across repos, issue discovery, CI failure diagnosis, and maintainer response drafting. Available as CLI, MCP server, and Claude Code plugin.
Related context
Related tools
Beta — feedback welcome: [email protected]