This release adds 3 notable features for engineering teams evaluating rollout.
Published 14d
AI Agents & Assistants
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai-agents
email
livekit
mcp
sms
telephony
+2 more
twilio
voice-ai
Affected surfaces
auth
rbac
Summary
AI summaryAdd SMS inbound compliance, abuse‑monitoring guardrails and provider validation across core, API, and CLI.
Full changelog
hail CLI v0.11.0
Universal communication platform for AI agents — hail CLI binaries.
Install via Homebrew:
brew install hail-hq/tap/hail
Or download a binary below.
Changelog
- 8b24df5212f738768300b47e9f040734406e1f05 Merge pull request #14 from hail-hq/feat/sms-inbound-compliance
- d4332428a0a999e91e8e03ee3ccbb007ce41f7d2 chore: add uv lock
- 072afefd50c17cb232dfc2b0038e56cc53b3eabb Merge pull request #13 from hail-hq/feat/sms-inbound-compliance
- c919b83ea430f1725acb7ba724f091f2e8fdbf58 docs(release): changelog 0.12.0 SMS inbound & compliance; bump sdk 0.8.0; tick README inbound
- 0ec4cf084de926ba18260935156e779f48cea0bb Merge pull request #12 from hail-hq/feat/sms-inbound-compliance
- e5c175da1abcca8114bb7682882b8cfd25270e3a perf(sms): existence-only channel-suspension query
- f84dd35ebcf655a160e19365dfe486fc4d937f14 docs: add SMS inbound compliance hardening spec and plan
- b6477d2713d975b3b1d94a46166c572bd880f444 docs(sms): document sms.received webhook and Twilio opt-out; drop stale carry-forward
- 30607d9c4f2705bda209ba657b0018b4dc889bf8 feat(sms): split number FKs and add opt-in HELP/STOP/START compliance replies
- aba48c309892e7ec511cefb85273e00073aa6f27 docs(operations): document SMS channel suspensions and inbound open work
- 08d36d232d5619f002e063a81cdddf71befe1600 perf(db): index suppressions and usage_events for SMS list and abuse checks
- 898ebacedb52743f119cc4a5b5d92dc28f119696 fix(sms): harden inbound webhook, opt-out, and suppression paths
- 0a478573c576ae0ccffed3c4ba72241bcf52ff3b docs(plans): add SMS inbound & compliance implementation plan
- 4dff00fa5633b566b864b3bf642349edfcd06f28 fix(sms): verify inbound webhook signature against configured base URL; document abuse-monitor env vars
- 07a720da5176afd00628674447c66d59202e4d6b feat(cli,sdk): add sms suppressions list/delete
- f5f98a81b93e25265279b9593d2aac2b9e72c301 feat(core): add SMS abuse-monitoring guardrail and periodic worker
- 5070abe893e5782d331b2f8cba4529de9ee3c18e feat(api): add inbound sms webhook and suppression list/delete routes
- 049661a8dc1e4c3ed4730e5019e789912759df3b feat(core): add inbound sms ingest with opt-out handling and webhook fanout
- 60f54528d9f7ac4cab45d0087e8c20cfe60c624d feat(core): add ChannelSuspension, remove_suppression, wire into check_sms_allowed
- 785f47e7ad6dedc279d788e922a074733705eee4 feat(core): add Twilio inbound webhook signature verification
- feb39fd045f8c13195c2d077216bee85cc7021b5 docs(changelog): 0.11.0 — BYO provider keys
- ebb14ef08a5198a14f37128e75400cc9cf1fb6a4 Merge pull request #11 from hail-hq/feat/byo-capability-validation
- 15a6a63c8185d1a1c174a959d2acbe41165949f7 ci: exempt alembic migrations from the openapi gate
- 60224788ee9d11d21f55951a448e74a20ffbb7d3 fix(api): honor explicit provider in validate; 409 on concurrent-delete races; deterministic active-promote tiebreak
- ef4080bd852ab37968f3d854502121dd11e4112f chore(migrations): renumber provider-config-multi to 0028 (BYO merges before SMS)
- 17460b44e5f6a6f42c8b9e2a3d0dcf17793d6f56 docs(api): note the autoflush ordering delete-promote relies on
- 08f848bd32b37fb35eba457e1ac16fb1057d08ae feat(core): resolve the active provider config per layer
- 397f2ba466e005f8c122b3d95e4c008e8aee4fc1 fix(api): scope active-provider deactivation to preserve updated_at recency
- 1aea017d584b133c9a3450e7630c9727aa79b8c3 feat(api): provider-config routes keyed by (layer, provider) with active selection
- e9904ea3cce13f64872ac051ec7b2c2858ac5f1b feat(core): allow multiple provider configs per layer with one active
- 399ea528b5620fd70b7d57d0ede25e32637b6026 Merge pull request #10 from hail-hq/feat/byo-capability-validation
- 9c0807f9ccd95bffb912ba5ee01b4fc5900257c6 ci: exempt internal routes from openapi gate; doc how to add a provider probe
- 44cba7b8b7b7bda39923df6106e0897c4fe89052 feat(api): validate in-flight provider config (test before save)
- ccf98326695950cee5470bb1982e9b22293119c2 test(core): guard cartesia probe body against real voice_id; classify 3xx as indeterminate
- faabb7d2d33a37e4e06216b564fc15c22e5700f1 feat(api): return tri-state status from provider-config validate route
- 7c39a940c52973fbd8a53743c06c30ade8b9dc18 feat(core): capability-based provider-key validation with tri-state result
- a79e93efd8b38ce8b1d351cda4960b88de3cb231 docs(release): finalize 0.10.0 changelog + migration-footgun note
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hail.so
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]