This release adds 4 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
ReleasePort's take
Moderate signalRelease rea‑agents 1.3.0 adds guided MCP workflow prompts and several usability improvements while tightening security on investigation artifact inputs.
Why it matters: The high‑severity (90) restriction on investigation artifact inputs mitigates potential abuse; developers and SREs should review the new input validation behavior before deploying.
Summary
AI summaryUpdates Bug Fixes, 1.3.0, and Tests across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
restrict investigation artifact inputs in security module restrict investigation artifact inputs in security module Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
add guided MCP workflow prompts add guided MCP workflow prompts Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
add persistent cross-version investigation workspaces add persistent cross-version investigation workspaces Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
add provider-neutral persistent snapshots in analysis module add provider-neutral persistent snapshots in analysis module Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
persist snapshots and close Hopper reliably persist snapshots and close Hopper reliably Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
add caller-safe typed error projections in errors module add caller-safe typed error projections in errors module Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
return structured typed tool results from MCP return structured typed tool results from MCP Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
bound regex search work in bridge module bound regex search work in bridge module Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
cancel analysis and close documents reliably in Hopper cancel analysis and close documents reliably in Hopper Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
render actionable analysis errors in CLI render actionable analysis errors in CLI Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
1.3.0 (2026-07-13)
Features
- add guided MCP workflow prompts (08d5b91)
- add guided MCP workflow prompts (24c3adb)
- add persistent cross-version investigation workspaces (c52eb46)
- add persistent cross-version investigation workspaces (41366ed)
- analysis: add provider-neutral persistent snapshots (c439b9e)
- analysis: persist snapshots and close Hopper reliably (c6407ef)
- errors: add caller-safe typed error projections (3be439c)
- mcp: return structured typed tool results (eb38e4c)
Bug Fixes
- bridge: bound regex search work (733a382)
- bridge: bound regex search work (65682ee)
- ci: remove unused setup type export (c5728af)
- cli: render actionable analysis errors (af8c4ef)
- copy: use agent terminology (12060f6)
- errors: improve recovery guidance (77454dc)
- errors: return actionable caller-safe failures (fb0da03)
- hopper: cancel analysis and close documents reliably (179870e)
- hopper: return addresses for procedure relationships (2c707ab)
- linux: start Hopper demo sessions headlessly (32c5080)
- linux: start Hopper demo sessions headlessly (75818d1)
- security: restrict investigation artifact inputs (a2076b4)
Tests
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rea
All releases →Related context
Related tools
Earlier breaking changes
- vrea-agents-2.0.0 mcp now requires Evidence for managed reconstruction.
- vrea-agents-1.0.0 contracts APIs now return structured discriminated output shapes
- vrea-agents-0.3.0 rename identity package and CLI to REA
- vrea-0.2.0 rename identity package and CLI to REA
Beta — feedback welcome: [email protected]