Skip to content

docker-agent

v1.84.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agents ai

Affected surfaces

auth

Summary

AI summary

Updates Technical Changes, What's New, and Bug Fixes across a mixed release.

Full changelog

This release adds a lean TUI user setting, hardens MCP OAuth token storage, and includes several refactoring changes to make toolsets, providers, and embedder dependencies more explicit.

What's New

  • Adds a settings.lean global user config option to make the lean TUI the default for interactive runs, while preserving explicit CLI overrides including --lean=false
  • Adds a headless chat session API (pkg/embeddedchat) for embedding docker-agent runtime conversations in non-docker-agent UIs
  • Makes OpenAI, Anthropic, Google, and Amazon Bedrock providers optional via build tags, allowing embedders to drop unneeded providers and shrink binary size
  • Makes the RAG toolset opt-in to remove the cgo dependency on go-tree-sitter from embedders that don't need it

Bug Fixes

  • Fixes the Shift+Tab thinking-level cycle to include the max effort tier for Claude models that support it (Opus 4.7+, Fable 5, Mythos 5)
  • Fixes potential token loss and repeated keyring access in the OAuth token store
  • Hardens MCP OAuth token file storage with cross-process locking, reload-before-write merge semantics, Windows-safe atomic file replacement, and migration of legacy keyring entries

Technical Changes

  • Replaces the single keyring OAuth token bundle with a keyring-sealed AES-256/AES-GCM encrypted file, storing only a fixed-size key in the OS keyring
  • Refactors toolset and provider registries to be explicit rather than relying on blank imports and init() functions
  • Decouples embedder dependencies so that pkg/runtime, pkg/model/provider, and pkg/tools/mcp no longer transitively pull in openai-go and 99designs/keyring; moves the OS-keyring-backed MCP OAuth store to its own pkg/tools/mcp/keyringstore sub-package
  • Removes unused agent in the wasm runtime

What's Changed

  • docs: update CHANGELOG.md for v1.83.0 by @docker-read-write[bot] in https://github.com/docker/docker-agent/pull/3179
  • Add lean TUI user setting by @rumpl in https://github.com/docker/docker-agent/pull/3181
  • docs: update /docs for PRs merged 2026-06-18–20 by @aheritier in https://github.com/docker/docker-agent/pull/3183
  • refactor: make toolsets and providers explicit by @dgageot in https://github.com/docker/docker-agent/pull/3184
  • fix: seal MCP OAuth tokens with keyring-backed file by @dgageot in https://github.com/docker/docker-agent/pull/3185
  • Remove unused agent in wasm runtime by @rumpl in https://github.com/docker/docker-agent/pull/3187
  • refactor: decouple embedder deps and register keyring store explicitly by @dgageot in https://github.com/docker/docker-agent/pull/3189

Full Changelog: https://github.com/docker/docker-agent/compare/v1.83.0...v1.84.0

Security Fixes

  • Hardens MCP OAuth token file storage with cross-process locking, reload-before-write merge semantics, Windows-safe atomic replacement, and migration of legacy keyring entries; fixes potential token loss and repeated keyring access

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track docker-agent

Get notified when new releases ship.

Sign up free

About docker-agent

AI Agent Builder and Runtime by Docker Engineering

All releases →

Related context

Earlier breaking changes

  • v1.71.0 Freezes configuration schema v9 and starts v10 as latest version

Beta — feedback welcome: [email protected]