Skip to content

l33tdawg/sage

v11.5.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic-ai artificial-intelligence bft-consensus bft-network distributed-systems governance

Affected surfaces

crypto_tls

ReleasePort's take

Moderate signal
editorial:auto 11d

The v11.5.0 release enforces WSS TLS minimum version 1.3 for natter service communication and hardens the release candidate against unspecified vulnerabilities.

Why it matters: Enforcing TLS 1.3 raises secure‑communication standards; hardening mitigates potential undisclosed risks in v11.5.0, prompting immediate evaluation of affected deployments.

Summary

AI summary

Updates Quick Start (sage-gui) ```bash, abci, and sage-gui across a mixed release.

Changes in this release

Security High

Enforces WSS TLS minimum version 1.3 for natter communication

Enforces WSS TLS minimum version 1.3 for natter communication

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds size caps, open‑pipe quotas, and stale‑pipe expiry to the pipe subsystem

Adds size caps, open‑pipe quotas, and stale‑pipe expiry to the pipe subsystem

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Introduces the app‑v17 empty fork gate in ABCI

Introduces the app‑v17 empty fork gate in ABCI

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Implements quorum‑scaled challenge, memory reinstate, and vote cleanup for app‑v17 in ABCI

Implements quorum‑scaled challenge, memory reinstate, and vote cleanup for app‑v17 in ABCI

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds quorum‑governed memory lifecycle and pipe hardening to the release

Adds quorum‑governed memory lifecycle and pipe hardening to the release

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Corrects tooltip keyboard and viewport behavior issues

Corrects tooltip keyboard and viewport behavior issues

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Hardens the v11.5.0 release candidate against unspecified vulnerabilities

Hardens the v11.5.0 release candidate against unspecified vulnerabilities

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

SAGE v11.5.0

Sovereign Agent Governed Experience — persistent, governed memory for AI agents.

Quick Start (sage-gui)

# Download and extract for your platform, then:
./sage-gui setup    # Interactive setup wizard
./sage-gui serve    # Start your personal memory node

See the README for full documentation.

Changelog

  • 44f226bcd1003f3b4e99765dcb47b563c2fd5614 feat(abci): mint the app-v17 empty fork gate (v11.5 Sprint 2 / C1)
  • 6a45c4d6cf38869f0083f6a4f3dcabdf90fd4669 feat(abci): quorum-scaled challenge, memory reinstate and vote cleanup on app-v17 (C2/C3/C5)
  • 0ca47c6e84ad92c76bda9906ff73c4fbfd75cdcb feat(pipe): size caps, open-pipe quotas and stale-pipe expiry (E8 residual)
  • b299d080cdca60c7c475a8e64653cf39e570e5b0 fix tooltip keyboard and viewport behavior
  • 2e77bb414f9e68f071b00729bdadbd9daf609489 fix(natter): set the WSS TLS floor to 1.3 (gosec G402)
  • a04725470b37c5de7a5acfc97520614efa889fb3 fix: harden v11.5.0 release candidate
  • 766e2b753db297582aff1472ef6c4f75043b7f25 release(v11.5.0): quorum-governed memory lifecycle + pipe hardening
  • ffcf558fb0bf66eab62c9051f3ba07ce9a0bc599 test(abci): app-v17 4-validator cluster ladder test + determinism harness disk fix

Security Fixes

  • Natter: set WSS TLS floor to 1.3 (gosec G402)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track l33tdawg/sage

Get notified when new releases ship.

Sign up free

About l33tdawg/sage

Institutional memory for AI agents with real BFT consensus. 4 application validators vote on every memory before it's committed — no more storing garbage. 13 MCP tools, runs locally, works with any MCP-compatible model. Backed by 4 published research papers.

All releases →

Related context

Beta — feedback welcome: [email protected]