This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
ReleasePort's take
Moderate signalThe upcoming Rea release 0.2.0 renames the identity package and its CLI from “identity” to “REA”. Existing scripts that invoke the old name will break.
Why it matters: A breaking change with severity 70 requires updating any automation or tooling that references the former 'identity' command before upgrading to Rea 0.2.0.
Summary
AI summaryUpdates Bug Fixes, 0.2.0, and Code Refactoring across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
reject unsafe local inputs in boundaries module reject unsafe local inputs in boundaries module Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Breaking | High |
rename identity package and CLI to REA rename identity package and CLI to REA Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
add guided local onboarding to CLI add guided local onboarding to CLI Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
add dynamic binary lifecycle to session component add dynamic binary lifecycle to session component Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
require an executable Hopper launcher in doctor command require an executable Hopper launcher in doctor command Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
persist detected Hopper launcher during setup persist detected Hopper launcher during setup Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
preserve consent and startup target kind in setup preserve consent and startup target kind in setup Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
launch analysis without stealing focus in Hopper launch analysis without stealing focus in Hopper Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
make loader selection non-interactive in Hopper make loader selection non-interactive in Hopper Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
preserve invalid MCP configuration during setup preserve invalid MCP configuration during setup Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
cancel startup and probe PE offsets in targets component cancel startup and probe PE offsets in targets component Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
tolerate exited Hopper helpers in verify command tolerate exited Hopper helpers in verify command Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Refactor | Low |
share runtime between CLI and MCP share runtime between CLI and MCP Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
0.2.0 (2026-07-12)
Features
- cli: add guided local onboarding (8ca3db8)
- identity: rename package and CLI to REA (3d70812)
- session: add dynamic binary lifecycle (f32e718)
Bug Fixes
- boundaries: reject unsafe local inputs (15e8cf3)
- doctor: require an executable Hopper launcher (aee9cb8)
- hopper: launch analysis without stealing focus (ff321dc)
- hopper: make loader selection non-interactive (2b7ef86)
- setup: persist detected Hopper launcher (b2866e4)
- setup: preserve consent and startup target kind (a67054f)
- setup: preserve invalid MCP configuration (88f5edc)
- targets: cancel startup and probe PE offsets (66b8d6e)
- verify: tolerate exited Hopper helpers (b167bd7)
Code Refactoring
- cli: share runtime between CLI and MCP (97541d8)
Documentation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rea
All releases →Related context
Related tools
Earlier breaking changes
- vrea-agents-2.0.0 mcp now requires Evidence for managed reconstruction.
- vrea-agents-1.0.0 contracts APIs now return structured discriminated output shapes
- vrea-agents-0.3.0 rename identity package and CLI to REA
Beta — feedback welcome: [email protected]