This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryUpdates config, stream, and providers across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds Thinking config to GLM models with corrected context/output limits. Adds Thinking config to GLM models with corrected context/output limits. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Feature | Medium |
Supports nested cached_tokens for Z.AI in streaming output. Supports nested cached_tokens for Z.AI in streaming output. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Fixes provider name handling in thinking injection by checking both names. Fixes provider name handling in thinking injection by checking both names. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Bugfix | Medium |
Correctly wires zaiSanitize into routing specs and fixes tools-skip orphan filtering. Correctly wires zaiSanitize into routing specs and fixes tools-skip orphan filtering. Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
Changelog
- 3d3e4b65b49bef9cfadfda72f0c9b0309d0e4294 Merge phase-001-cached-tokens: Z.AI cached_tokens tracking
- fb9f8073476fcf089cf7c3df4eeea2a01d52c4d5 Merge phase-002-message-sanitization: sanitization wiring fix
- 2abe59bfdcd8e8b8c03b1f81cd7b052a0d0d06ca Merge phase-003-thinking-config: GLM Thinking config
- 73730d47d690704f627a5010963c2cafb905c44a Merge phase-004-provider-name-fix: provider name fix
- 7b025eb3f8425fd6d2a0d7b4981a8a9cb8e420f7 feat(config): add Thinking config to GLM models and correct context/output limits
- 95354dcb963cf884049b207393e091b94a3b7394 feat(stream): support nested cached_tokens for Z.AI
- 9ff60f3e51fd507a77e228a030f181d34bad321d fix(providers): check both provider names in thinking injection
- 000b0e090a2a41e9df31458553dca8cf82b91ef2 fix(routing): wire zaiSanitize into specs and fix tools-skip orphan filtering
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Nenya
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]