Skip to content

kdlbs/kandev

v0.82.0 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

acp agent-orchestration agentic-ai agentic-development-environment ai-agents claude-code
+13 more
code-review coding-agents developer-tools github-copilot go kanban nextjs self-hosted task-manager tui vibe-coding workflow-automation worktrees

Affected surfaces

deps

Summary

AI summary

Updates Bug Fixes, 0.82.0 - 2026-07-25, and Performance across a mixed release.

Full changelog

[!WARNING]
macOS, Windows desktop installers in this release are unsigned development builds.
They may require manual OS security bypasses and are not trusted downloads.

0.82.0 - 2026-07-25

Features

  • opt-in authentication & multi-user segregation (#1930)
  • notify user when a kandev update is detected (#1924) by @ClemDNL
  • show full timestamp as tooltip on chat message relative time (#1925) by @ClemDNL
  • re-request dismissed reviews (#1921)
  • move subtask action to task context menu (#1920)
  • add opt-in plugin auto-updater (#1903)
  • add keybindings and modal window capabilities (#1895)
  • add configurable command prefix for sandboxed ACP launch (#1888) by @tito
  • nest a task under another as a sub-task from the sidebar (#1837) by @jcoatelen-ledger
  • create local repositories from new tasks (#1849)
  • improve task sidebar overflow cue (#1908)
  • add simplified resource metrics display (#1904)
  • mark selected task repositories (#1881)
  • add external vcs file links (#1883)
  • move GitLab MR linking to task menus (#1868)
  • resolve @prompt references in workflow prompts (#1865)
  • add global app status surface (#1869)
  • add cross-integration entity references (#1862)
  • host-side conversation reads + utility-agent invoke (#1852)
  • complete GitLab integration parity (#1832)
  • add planner and worker agent orchestration (#1834)
  • explain repository scope (#1842)
  • add main-top-bar slot for the default app top bar (#1841)

Bug Fixes

  • polish clarification custom answer input (#1942)
  • restore managed native service updates (#1943) (#1945)
  • make remote repository entry reliable (#1936)
  • route update alerts through notification providers (#1938)
  • scope in-session agent MCP calls to the task owner (#1937)
  • confine tarball extraction with os.Root (#1934)
  • move Docker client to the maintained moby client module (#1935)
  • deduplicate model options and restore reasoning scroll (#1933)
  • improve queue scrolling and diff comment feedback (#1932)
  • scope walkthrough overlays to their task (#1928)
  • resolve low and medium Dependabot alerts (#1926)
  • resolve open high-severity Dependabot advisories (#1919)
  • preserve chat focus when restoring task layout (#1923)
  • distinguish session notification events (#1918)
  • harden ACP launcher configuration (#1917)
  • make plugin reload idempotent so re-boot never duplicates slots (#1914)
  • keep composer usable during clarifications (#1916)
  • patch critical Dependabot advisories (#1915)
  • support make dev on native Windows (#1886) by @JnManso
  • restore sidebar task title overflow (#1913)
  • collapse completed silent subagent cards (#1901)
  • stabilize task and workspace creation (#1910)
  • sign and verify release tags (#1902)
  • distinguish archived automation runs from cancelled ones (#1860) by @ClemDNL
  • strip echoed command from persisted shell output (#1898) by @ClemDNL
  • resume an unarchived task's archive-cancelled and multi-repo sessions (#1905) by @ClemDNL
  • preserve saved panel focus on task return (#1907)
  • support long Git worktree paths on Windows (#1878)
  • improve session failure recovery UX (#1866)
  • dedupe repository listing and close local-path create race (#1897) by @ClemDNL
  • inherit service temporary environment (#1894)
  • scope Office agent tools and task mutations (#1867)
  • restore persisted file tree expansions (#1892)
  • list logical drives in folder picker (#1870)
  • focus deferred clarification custom answer (#1871)
  • scope PR branch failure guidance (#1873)
  • hide workspace ownership marker (#1874)
  • clarify task title editing (#1875)
  • separate office task session ownership (#1893)
  • publish session state_changed when archiving cancels sessions (#1891) by @ClemDNL
  • retain enhanced prompt results (#1854) by @ASRagab
  • follow session switch when moving between different-agent steps (#1879)
  • re-clone provider repos when local path is missing or not a git repo (#1876)
  • prevent blank mobile task views (#1877) (#1889)
  • select pull request on review surface (#1857)
  • preserve custom layout proportions across screens (#1872)
  • stop PR polling on denied GitHub access (#1864)
  • unload previous version before reloading on plugin update (#1861)
  • restore line expansion for multi-repo diffs (#1856)
  • select utility agents per plugin (#1855)
  • reject disallowed cross-origin state changes in CORS (#1850)
  • keep draft pull requests out of merge-ready state (#1851)
  • preserve inherited workspaces on subtask deletion (#1840)
  • surface orphaned tasks in pipeline view after step deletion (#1809) by @yattdev
  • reset office session state when execution profile changes (#1846)
  • scope and label clarification shortcuts (#1847)
  • reconcile dockview size before restoring layout (#1843) (#1845)
  • order plugins before system (#1844)

Performance

  • cache storage analysis results (#1911)
  • speed up CI check feedback (#1882)

Security Fixes

  • Resolved open high‑severity Dependabot advisories
  • Patched critical Dependabot advisories
  • Hardened ACP launcher configuration

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kdlbs/kandev

Get notified when new releases ship.

Sign up free

About kdlbs/kandev

All releases →

Related context

Beta — feedback welcome: [email protected]