This release includes 2 security fixes for security teams reviewing exposed deployments.
Affected surfaces
ReleasePort's take
Moderate signalVersion v0.5.0 updates crossbeam‑epoch and quinn‑proto to patch RUSTSEC‑2026‑0204 and RUSTSEC‑2026‑0185.
Why it matters: Patches CVEs RUSTSEC‑2026‑0204 and RUSTSEC‑2026‑0185; upgrade to v0.5.0 immediately if using these dependencies.
Summary
AI summaryUpdate crossbeam-epoch and quinn-proto to fix RUSTSEC-2026-0204 and RUSTSEC-2026-0185.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Update crossbeam-epoch and quinn-proto to patch RUSTSEC-2026-0204 and RUSTSEC-2026-0185 Update crossbeam-epoch and quinn-proto to patch RUSTSEC-2026-0204 and RUSTSEC-2026-0185 Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Add `-s` / `--system-prompt` to supply run-wide agent instructions Add `-s` / `--system-prompt` to supply run-wide agent instructions Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Add `write-answers` config key or `--write-answers` to output Q/A blocks at 100 columns Add `write-answers` config key or `--write-answers` to output Q/A blocks at 100 columns Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Add `--no-ignore` to include ignored text files in scans and watch mode Add `--no-ignore` to include ignored text files in scans and watch mode Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Honor `.gitignore`, `.ignore`, and Git exclude files during scans, watch mode, and skip binary files Honor `.gitignore`, `.ignore`, and Git exclude files during scans, watch mode, and skip binary files Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Preserve edited multiline marker bodies when removing completed marker delimiters Preserve edited multiline marker bodies when removing completed marker delimiters Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Refactor | Low |
Replace `marker_limits_edition_range` with backward-compatible `edition-constraints` policy and default post‑edit reconciliation Replace `marker_limits_edition_range` with backward-compatible `edition-constraints` policy and default post‑edit reconciliation Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
Added
- Supply additional run-wide agent instructions with
-sor--system-prompt - Write question responses back as aligned, 100-column
Q:/A:blocks with thewrite-answersconfig key or--write-answers - Include ignored text files in scans and watch mode with
--no-ignore
Changed
- Replace
marker_limits_edition_rangewith the backward-compatibleedition-constraintspolicy and make post-edit vicinity reconciliation the default - Honor
.gitignore,.ignore, and Git exclude files during scans and watch mode, and skip binary files in scanning, listing, and reading
Fixed
- Preserve edited multiline marker bodies when removing completed marker delimiters
Security
- Update
crossbeam-epochandquinn-prototo releases that address RUSTSEC-2026-0204 and RUSTSEC-2026-0185
Security Fixes
- dep: RUSTSEC-2026-0204 — update crossbeam-epoch to a version that addresses the vulnerability
- dep: RUSTSEC-2026-0185 — update quinn-proto to a version that addresses the vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About rik
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]