This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThe v11.5.0 release enforces WSS TLS minimum version 1.3 for natter service communication and hardens the release candidate against unspecified vulnerabilities.
Why it matters: Enforcing TLS 1.3 raises secure‑communication standards; hardening mitigates potential undisclosed risks in v11.5.0, prompting immediate evaluation of affected deployments.
Summary
AI summaryUpdates Quick Start (sage-gui) ```bash, abci, and sage-gui across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Enforces WSS TLS minimum version 1.3 for natter communication Enforces WSS TLS minimum version 1.3 for natter communication Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds size caps, open‑pipe quotas, and stale‑pipe expiry to the pipe subsystem Adds size caps, open‑pipe quotas, and stale‑pipe expiry to the pipe subsystem Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Introduces the app‑v17 empty fork gate in ABCI Introduces the app‑v17 empty fork gate in ABCI Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Implements quorum‑scaled challenge, memory reinstate, and vote cleanup for app‑v17 in ABCI Implements quorum‑scaled challenge, memory reinstate, and vote cleanup for app‑v17 in ABCI Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds quorum‑governed memory lifecycle and pipe hardening to the release Adds quorum‑governed memory lifecycle and pipe hardening to the release Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Corrects tooltip keyboard and viewport behavior issues Corrects tooltip keyboard and viewport behavior issues Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Hardens the v11.5.0 release candidate against unspecified vulnerabilities Hardens the v11.5.0 release candidate against unspecified vulnerabilities Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
SAGE v11.5.0
Sovereign Agent Governed Experience — persistent, governed memory for AI agents.
Quick Start (sage-gui)
# Download and extract for your platform, then:
./sage-gui setup # Interactive setup wizard
./sage-gui serve # Start your personal memory node
See the README for full documentation.
Changelog
- 44f226bcd1003f3b4e99765dcb47b563c2fd5614 feat(abci): mint the app-v17 empty fork gate (v11.5 Sprint 2 / C1)
- 6a45c4d6cf38869f0083f6a4f3dcabdf90fd4669 feat(abci): quorum-scaled challenge, memory reinstate and vote cleanup on app-v17 (C2/C3/C5)
- 0ca47c6e84ad92c76bda9906ff73c4fbfd75cdcb feat(pipe): size caps, open-pipe quotas and stale-pipe expiry (E8 residual)
- b299d080cdca60c7c475a8e64653cf39e570e5b0 fix tooltip keyboard and viewport behavior
- 2e77bb414f9e68f071b00729bdadbd9daf609489 fix(natter): set the WSS TLS floor to 1.3 (gosec G402)
- a04725470b37c5de7a5acfc97520614efa889fb3 fix: harden v11.5.0 release candidate
- 766e2b753db297582aff1472ef6c4f75043b7f25 release(v11.5.0): quorum-governed memory lifecycle + pipe hardening
- ffcf558fb0bf66eab62c9051f3ba07ce9a0bc599 test(abci): app-v17 4-validator cluster ladder test + determinism harness disk fix
Security Fixes
- Natter: set WSS TLS floor to 1.3 (gosec G402)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About l33tdawg/sage
Institutional memory for AI agents with real BFT consensus. 4 application validators vote on every memory before it's committed — no more storing garbage. 13 MCP tools, runs locally, works with any MCP-compatible model. Backed by 4 published research papers.
Related context
Related tools
Beta — feedback welcome: [email protected]