This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Summary
AI summaryUpdates 0.18.0] - 2026-05-19, Bug Fixes, and Chores across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add sandboxd egress token client Add sandboxd egress token client Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add direct gateway egress proxy routes Add direct gateway egress proxy routes Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Route sandboxd egress through direct gateway Route sandboxd egress through direct gateway Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add direct egress telemetry Add direct egress telemetry Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add mstl whoami command Add mstl whoami command Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Rename mstl binary to mistle Rename mstl binary to mistle Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add mistle profile list Add mistle profile list Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add mistle profile get Add mistle profile get Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Support api key sandbox profile reads Support api key sandbox profile reads Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Support api key sandbox instance connections Support api key sandbox instance connections Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Support api key profile writes Support api key profile writes Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Support api key profile versions Support api key profile versions Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add pty transport contract Add pty transport contract Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Support api key profile instance starts Support api key profile instance starts Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Start active sandbox profile instances Start active sandbox profile instances Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add pty transport token endpoint Add pty transport token endpoint Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add sandbox create and get cli commands Add sandbox create and get cli commands Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add sandbox list command Add sandbox list command Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add sandbox list pagination flags Add sandbox list pagination flags Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add gateway pty transport route Add gateway pty transport route Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add mistle codex sandbox proxy Add mistle codex sandbox proxy Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add billing settings section Add billing settings section Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Stabilize direct sandbox transports Stabilize direct sandbox transports Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Simplify Jira site URL entry Simplify Jira site URL entry Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
List sandbox profile versions in cli List sandbox profile versions in cli Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add pi agent runtime Add pi agent runtime Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add mstl core profile draft setup script update Add mstl core profile draft setup script update Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add profile setup script cli command Add profile setup script cli command Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Publish mistle cli release artifacts Publish mistle cli release artifacts Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Feature | Medium |
Add dashboard API key management Add dashboard API key management Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
Full changelog
[0.18.0] - 2026-05-19
Features
- Add sandboxd egress token client (#2167)
- Add direct gateway egress proxy routes (#2168)
- Route sandboxd egress through direct gateway (#2169)
- Add direct egress telemetry (#2170)
- Add mstl whoami command (#2171)
- Rename mstl binary to mistle (#2174)
- Add mistle profile list (#2178)
- Add mistle profile get (#2179)
- Support api key sandbox profile reads (#2180)
- Support api key sandbox instance connections (#2181)
- Support api key profile writes (#2182)
- Support api key profile versions (#2184)
- Add pty transport contract (#2183)
- Support api key profile instance starts (#2185)
- Start active sandbox profile instances (#2187)
- Add pty transport token endpoint (#2188)
- Add sandbox create and get cli commands (#2189)
- Add sandbox list command (#2190)
- Add sandbox list pagination flags (#2191)
- Add gateway pty transport route (#2192)
- Add mistle codex sandbox proxy (#2197)
- Add billing settings section (#2198)
- Stabilize direct sandbox transports (#2195)
- Simplify Jira site URL entry (#2211)
- List sandbox profile versions in cli (#2230)
- Add pi agent runtime (#2228)
- Add mstl core profile draft setup script update (#2233)
- Add profile setup script cli command (#2237)
- Publish mistle cli release artifacts (#2238)
- Add dashboard API key management (#2241)
- Add Codex thread navigation (#2242)
Bug Fixes
- Stabilize snapshot refresh schedule form (#2172)
- Refine snapshot refresh UI (#2175)
- Explain missing trigger events (#2177)
- Trust system test CA for direct egress WSS (#2194)
- Normalize direct egress websocket close codes (#2196)
- Trust configured ca for direct http egress (#2200)
- Preserve default roots for direct egress ca (#2201)
- Trust proxy ca for transparent wss smoke (#2202)
- Focus revealed integration setup fields (#2209)
- Set sandbox base home (#2212)
- Preserve snapshot progress details expansion (#2214)
- Align sandboxd egress route matching (#2215)
- Stabilize sandbox local registry egress (#2213)
- Default repo selector to none outside workspace (#2216)
- Emit egress token lifecycle operation records (#2219)
- Bypass gateway for unmatched sandboxd egress (#2217)
- Trust local project for mistle codex (#2222)
- Use sandbox-reachable gateway urls for pty transport (#2223)
- Surface trigger sandbox startup failures (#2227)
- Proxy direct egress through dev gateway relay (#2229)
- Use sandbox-reachable egress smoke upstreams (#2231)
- Trust egress smoke upstream ca in sandbox (#2236)
- Update vite fixture lockfile (#2239)
- Retry transient trigger delivery failures (#2244)
Refactors
- Remove bootstrap egress transport (#2176)
- Rename automations to triggers (#2186)
- Remove legacy pty bootstrap streams (#2210)
- Split mistle cli command domains (#2226)
Documentation
- Document cloud-only PostHog and Stripe config (#2173)
Tests
- Use valid websocket frames in egress smoke (#2193)
- Harden gateway egress wss smoke (#2199)
- Accept logged transparent egress nft bypass rules (#2221)
Chores
- (deps) Bump @scalar/hono-api-reference from 0.10.13 to 0.10.14 (#2207)
- (deps) Bump @types/node from 25.6.0 to 25.6.2 (#2205)
- (deps) Bump rcgen from 0.14.7 to 0.14.8 in /packages/sandboxd (#2204)
- (deps) Bump @hono/zod-openapi from 1.3.0 to 1.4.0 (#2203)
- (deps) Bump turbo from 2.9.9 to 2.9.12 (#2206)
- Align sandboxd opentelemetry crates (#2232)
- (deps) Bump vite from 8.0.11 to 8.0.12 (via audit fix) in /tests/system/fixtures/vite-dev-server (#2208)
- Align aws s3 sdk packages (#2234)
- Verify release artifact digests (#2235)
- Update codex cli to 0.131.0 (#2240)
- Update opencode runtime to 1.15.1 (#2243)
- (release) V0.18.0 (#2247)
Breaking Changes
- Rename mstl binary to mistle
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Mistle
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]