This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summarySession list hierarchy correctly nests older Codex role subagent sessions after gaps, and transcript rendering reduces memory spikes.
Full changelog
Added
- OpenCode: Renamed session titles (set via
/rename) are now persisted as custom session titles, matching Claude and Codex behavior.
Fixed
- Session list hierarchy now nests older Codex role subagent sessions that record only
source.subagentwhen a same-workspace parent can be inferred, even after multi-hour gaps. - Resume launch AppleScript now receives commands via
osascriptargv instead of source interpolation, reducing script-injection surface. - Transcript rendering now uses a bounded transcript cache and preloads Whole Session Raw/Pretty content outside
bodyto reduce memory spikes and UI stutter on large sessions. - Claude OAuth shared cache writes now apply restrictive POSIX permissions on cache directory and files.
- IndexDB bootstrap now configures
busy_timeoutand runs schema/bootstrap migration steps inside a single transaction for safer concurrent startup.
Security Fixes
- Resume launch AppleScript now receives commands via `osascript` argv, reducing script‑injection surface
- Claude OAuth shared cache writes apply restrictive POSIX permissions on cache directory and files
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Agent Sessions
Local-first macOS app to browse, search, analyze, and resume supported AI coding-agent session history across Codex, Claude Code, OpenCode, Cursor Agent, Hermes, OpenClaw, Copilot CLI, and more.
Related context
Related tools
Beta — feedback welcome: [email protected]