This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Light signalAit v0.55.50 hardens multi-agent branch landing with ref locks and stale-base checks to prevent unsafe automated commits. The release includes control plane documentation, embeds next_action in agent context, and fixes adversarial reviewer API key inheritance.
Why it matters: Teams using multi-agent branch automation should deploy this hardening to prevent unsafe landing. Test the adversarial reviewer fix and review new control plane documentation before deployment.
Summary
AI summaryHardened multi-agent control plane prevents unsafe landings by using ref locks and stale‑base checks.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Hardens same-target branch landing with ref locks and stale-base checks Hardens same-target branch landing with ref locks and stale-base checks Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Adds multi-agent control plane guide and acceptance coverage Adds multi-agent control plane guide and acceptance coverage Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Embeds next_action in primary agent context commands Embeds next_action in primary agent context commands Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Fixes adversarial reviewer API key inheritance with local claude -p Fixes adversarial reviewer API key inheritance with local claude -p Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
Release 0.55.50 adds the multi-agent control plane guide and acceptance coverage, embeds next_action in primary agent context commands, hardens same-target branch landing with ref locks and stale-base checks, and fixes the built-in Claude Code adversarial reviewer to use local claude -p without inheriting ANTHROPIC_API_KEY.
Security Fixes
- Hardened same‑target branch landing with ref locks and stale‑base checks
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Ait
All releases →Related context
Related tools
Earlier breaking changes
- v0.55.52 Keep the built-in claude-code reviewer pinned to the local claude -p CLI even when repository policy defines a conflicting command override.
Beta — feedback welcome: [email protected]