This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 1.5.0, and Tests across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds passive website reverse engineering capability. Adds passive website reverse engineering capability. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Drops disallowed redirect evidence in browser component. Drops disallowed redirect evidence in browser component. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Scopes CDP events and fails closed in browser component. Scopes CDP events and fails closed in browser component. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Scopes workers and binary frame sizes in browser component. Scopes workers and binary frame sizes in browser component. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Hardens PTY events and configured roots. Hardens PTY events and configured roots. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Defers cache write grants in permission system. Defers cache write grants in permission system. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Resolves triaged correctness issues. Resolves triaged correctness issues. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Resolves validation and artifact edge cases. Resolves validation and artifact edge cases. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
1.5.0 (2026-07-14)
Features
Bug Fixes
- browser: drop disallowed redirect evidence (8481be9)
- browser: scope CDP events and fail closed (5279d77)
- browser: scope workers and binary frame sizes (dfc06cf)
- harden PTY events and configured roots (ae8b1c5)
- harden PTY events and configured roots (31b40f3)
- permission: defer cache write grants (6a3fd5b)
- permission: defer cache write grants (f840e70)
- resolve triaged correctness issues (2575b30)
- resolve triaged correctness issues (e8ed307)
- resolve validation and artifact edge cases (2468682)
- resolve validation and artifact edge cases (ef7f2f9)
Documentation
Tests
- cli: allow cold-start integration timing (7d5621d)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rea
All releases →Related context
Related tools
Earlier breaking changes
- vrea-agents-2.0.0 mcp now requires Evidence for managed reconstruction.
- vrea-agents-1.0.0 contracts APIs now return structured discriminated output shapes
- vrea-agents-0.3.0 rename identity package and CLI to REA
- vrea-0.2.0 rename identity package and CLI to REA
Beta — feedback welcome: [email protected]