This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
ReleasePort's take
Moderate signalGuard join ceremony outbound dials against abuse in version v11.4.7.
Why it matters: Severity 90 triggers security focus on protecting join ceremony outbound connections; operators must review mitigation for affected surface areas.
Summary
AI summaryUpdates Quick Start (sage-gui) ```bash, sage-gui, and v11.4.7 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Guard join ceremony outbound dials against abuse Guard join ceremony outbound dials against abuse Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Security | Medium |
Perform security and release hardening Perform security and release hardening Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Low |
Run frontend static gate without npm lockfile Run frontend static gate without npm lockfile Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Low |
Use current setup-node pin for frontend static gate Use current setup-node pin for frontend static gate Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
Full changelog
SAGE v11.4.7
Sovereign Agent Governed Experience — persistent, governed memory for AI agents.
Quick Start (sage-gui)
# Download and extract for your platform, then:
./sage-gui setup # Interactive setup wizard
./sage-gui serve # Start your personal memory node
See the README for full documentation.
Changelog
- f23f8b4e6e01aa5371372bfc977e9b983b93a876 fix(release): run frontend static gate without npm lockfile
- 785dbcb1f978ab4d2e5942eb201630ab037809b3 fix(release): use current setup-node pin for frontend static gate
- 02fa7ce057f1abe7ea6bbbaf59120ed892102b78 fix(security): guard join ceremony outbound dials
- 4ab89a07f7fd2a2af538ec11e0156a2e005cf938 release(v11.4.7): security and release hardening
Security Fixes
- Guard join ceremony outbound dials — fixes a security vulnerability.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About l33tdawg/sage
Institutional memory for AI agents with real BFT consensus. 4 application validators vote on every memory before it's committed — no more storing garbage. 13 MCP tools, runs locally, works with any MCP-compatible model. Backed by 4 published research papers.
Related context
Related tools
Beta — feedback welcome: [email protected]