Skip to content

Mistle

v0.19.0 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

ReleasePort's take

Light signal
editorial:auto 13d

Version v0.19.0 of Mistle introduces numerous new features and restores critical functionality while addressing several bugs.

Why it matters: Patch to v0.19.0 immediately to regain Pi chat, re‑enable API key revocation, and invalidate stale gateway credentials; plan migrations for added composer slash commands, session deletion, and sandbox memory limits.

Summary

AI summary

Updates 0.19.0] - 2026-05-21, Refactors, and Bug Fixes across a mixed release.

Changes in this release

Feature Medium

Add composer slash commands for streamlined prompt composition.

Add composer slash commands for streamlined prompt composition.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Support deleting sessions for improved session lifecycle management.

Support deleting sessions for improved session lifecycle management.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Show original codex thread metadata in UI.

Show original codex thread metadata in UI.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add mistle CLI update command for easier CLI management.

Add mistle CLI update command for easier CLI management.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add Pi to session chat workbench and enable attachment parity.

Add Pi to session chat workbench and enable attachment parity.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Scaffold mistle MCP server and profile infrastructure.

Scaffold mistle MCP server and profile infrastructure.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Scaffold file search stream protocol and implement support.

Scaffold file search stream protocol and implement support.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Enable codex goal and review composer commands.

Enable codex goal and review composer commands.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Scaffold control plane MCP endpoint with auth and profile tools.

Scaffold control plane MCP endpoint with auth and profile tools.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add pi model selection and runtime conversation navigator.

Add pi model selection and runtime conversation navigator.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Detect and report dashboard build drift issues.

Detect and report dashboard build drift issues.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add sandbox usage events table and event writer.

Add sandbox usage events table and event writer.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add gateway MCP token auth and credential injection.

Add gateway MCP token auth and credential injection.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add Codex plan command and authenticate control plane tokens.

Add Codex plan command and authenticate control plane tokens.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Allow and manage multiple identity link provider configurations.

Allow and manage multiple identity link provider configurations.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add one-off schedule support with CRUD and dispatch workflow.

Add one-off schedule support with CRUD and dispatch workflow.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add composer context mentions feature.

Add composer context mentions feature.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Link accounts by provider config and select credentials by connection.

Link accounts by provider config and select credentials by connection.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Add MCP profile setup script tool and test tools.

Add MCP profile setup script tool and test tools.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Expose sandbox context to agents.

Expose sandbox context to agents.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Support opencode prompt commands.

Support opencode prompt commands.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Select git signing connection for sandbox profiles.

Select git signing connection for sandbox profiles.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Surface external setup script updates in UI.

Surface external setup script updates in UI.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Support bounded sandboxd stdin payloads.

Support bounded sandboxd stdin payloads.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Duplicate sandbox profiles for easy configuration reuse.

Duplicate sandbox profiles for easy configuration reuse.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Feature Medium

Support GitHub app installation selection.

Support GitHub app installation selection.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Performance Medium

Raise e2b sandbox memory capacity limit to 16GB.

Raise e2b sandbox memory capacity limit to 16GB.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Bugfix Medium

Re-enable API key revoke actions functionality.

Re-enable API key revoke actions functionality.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Bugfix Medium

Restore Pi chat functionality after TUI handoff.

Restore Pi chat functionality after TUI handoff.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Bugfix Medium

Invalidate gateway credential cache on connection updates.

Invalidate gateway credential cache on connection updates.

Source: granite4.1:30b@2026-05-21-audit

Confidence: high

Full changelog

[0.19.0] - 2026-05-21

Features

  • Add composer slash commands (#2245)
  • Support deleting sessions (#2255)
  • Show original codex thread metadata (#2256)
  • Add mistle cli update command (#2253)
  • Add Pi to session chat workbench (#2257)
  • Scaffold mistle mcp server (#2266)
  • Scaffold file search stream protocol (#2268)
  • Add Pi attachment and follow-up parity (#2271)
  • Scaffold file search stream in sandboxd (#2272)
  • Add mcp profile tools (#2270)
  • Enable codex goal composer command (#2274)
  • Add fff file search stream support (#2275)
  • Scaffold control plane MCP endpoint (#2276)
  • Add pi model selection (#2278)
  • Add runtime conversation navigator (#2280)
  • Add control plane MCP profile tools (#2281)
  • Detect dashboard build drift (#2279)
  • Add control plane MCP auth config (#2285)
  • Add sandbox usage events table (#2289)
  • Add gateway MCP token auth (#2290)
  • Add Codex plan command (#2288)
  • Authenticate control plane MCP tokens (#2295)
  • Add pi runtime conversation navigator (#2296)
  • Add sandbox usage event writer (#2298)
  • Expose identity link provider config ids (#2300)
  • Add profile version MCP schema (#2301)
  • Record sandbox usage events from worker workflows (#2306)
  • Allow multiple identity link provider configs (#2305)
  • Configure Mistle MCP runtime plans (#2310)
  • Add codex review composer command (#2314)
  • Add Mistle MCP profile toggle (#2316)
  • Support opencode prompt commands (#2323)
  • Add config-level identity link provider management (#2318)
  • Inject mistle mcp credentials through gateway (#2327)
  • Add composer context mentions (#2330)
  • Raise e2b memory cap to 16gb (#2335)
  • Link accounts by provider config (#2329)
  • Add mcp profile setup script tool (#2337)
  • Expose sandbox context to agents (#2340)
  • Update setup assistant mcp guidance (#2344)
  • Add mcp setup script test tools (#2347)
  • Prepare schedules for one-off runs (#2346)
  • Surface external setup script updates (#2351)
  • Add one-off schedule dispatch workflow (#2353)
  • Support bounded sandboxd stdin payloads (#2358)
  • Select linked principal credentials by connection (#2342)
  • Select git signing connection for sandbox profiles (#2350)
  • Wire one-off schedule CRUD (#2362)
  • Label multi-config identity links (#2355)
  • Scope setup assistant mistle mcp access (#2360)
  • Support negative trigger event parameters (#2371)
  • Add maintenance script mcp tools (#2375)
  • Sync maintenance assistant mcp updates (#2380)
  • Add sandbox resume visibility (#2383)
  • Duplicate sandbox profiles (#2388)
  • Support GitHub app installation selection (#2387)

Bug Fixes

  • Ignore unknown sandbox protocol fields (#2267)
  • Reject duplicate sandbox tunnel stream opens (#2283)
  • Clean up reset tunnel stream state (#2284)
  • Improve signoz connection region selection (#2287)
  • Refine pi composer controls (#2299)
  • Clarify setup assistant draft startup (#2303)
  • Preserve snapshot refresh edits for setup assistant (#2308)
  • Refine maintenance assistant prompt (#2312)
  • Stabilize dashboard build drift snapshot (#2313)
  • Hide Pi tool-call assistant messages (#2317)
  • Preserve auth invite error payloads (#2319)
  • Generate pi sandbox session titles (#2322)
  • Prepublish system test sandbox image (#2336)
  • Re-enable api key revoke actions (#2339)
  • Track pi rpc process readiness (#2341)
  • Track opencode server readiness (#2343)
  • Recover sandboxd runtime process coordination (#2357)
  • Keep sessions search list mounted (#2364)
  • Run tensorlake sandboxd maintenance through sudo (#2365)
  • Restore Pi chat after TUI handoff (#2366)
  • Invalidate gateway credential cache on connection updates (#2361)
  • Attribute sandbox startup events to phases (#2368)
  • Decode setup assistant mcp tokens in sandboxd (#2370)
  • Show resolved github signing connection (#2373)
  • Handle inaccessible resource links (#2372)
  • Handle stateless github app setup callbacks (#2381)
  • Redirect provider app setup state errors (#2385)
  • Run Tensorlake sandbox commands as root (#2389)

Refactors

  • Generalize workbench conversation naming (#2269)
  • Remove CLI MCP server (#2282)
  • Move tunnel session file upload state (#2286)
  • Move tunnel session agent stream state (#2291)
  • Move tunnel session telemetry helpers (#2293)
  • Move tunnel session file search state (#2297)
  • Move port access session state (#2302)
  • Move port access routing (#2304)
  • Move port access control handling (#2307)
  • Remove storage usage event types (#2309)
  • Move operation stream handling (#2311)
  • Move gateway request handling (#2315)
  • Extract process stream session handling (#2321)
  • Scope agent stream session handling (#2324)
  • Split sandboxd session gateway request handling (#2325)
  • Extract sandboxd session exec and pty handling (#2326)
  • Extract sandboxd session bootstrap handling (#2328)
  • Split sandboxd tunnel session modules (#2331)
  • Colocate sandboxd session unit tests (#2332)
  • Split sandboxd session workflow tests (#2333)
  • Split sandboxd session router (#2334)
  • Split sandboxd module hotspots (#2338)
  • Split pi proxy internals (#2348)
  • Split sandboxd structural helpers (#2354)
  • Split sandboxd opencode proxy module (#2359)
  • Split egress proxy infrastructure (#2363)
  • Split sandboxd state facade (#2367)
  • Split codex proxy session module (#2378)
  • Split sandboxd control module (#2382)
  • Split sandboxd egress proxy module (#2384)
  • Split codex proxy facade (#2386)
  • Split codex session manager modules (#2390)

Documentation

  • Require setup assistant validation before saving (#2352)
  • Move CLI install notes (#2374)

Tests

  • Stabilize operation stream close flush (#2320)
  • Cover multi-config webhook attribution (#2356)

Chores

  • Bump codex cli to 0.132.0 (#2277)
  • Rename sandbox usage event types (#2292)
  • Add sandbox resumed usage event type (#2294)
  • (deps) Bump @opentelemetry/sdk-metrics to 2.7.1
  • (deps) Bump @tailwindcss/vite to 4.3.0
  • Add fd to sandbox base image (#2345)
  • Update jsx-email to v3 (#2369)
  • (release) V0.19.0 (#2391)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Mistle

Get notified when new releases ship.

Sign up free

About Mistle

All releases →

Related context

Beta — feedback welcome: [email protected]