This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+10 more
Summary
AI summaryUpdates Code Refactoring, 1.7.0, and Bug Fixes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds versioned JavaScript Application Graph capability. Adds versioned JavaScript Application Graph capability. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds function analysis and conformance to Ghidra integration. Adds function analysis and conformance to Ghidra integration. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds private headless provider session support in Ghidra integration. Adds private headless provider session support in Ghidra integration. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds read‑only inventory operations to Ghidra integration. Adds read‑only inventory operations to Ghidra integration. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Adds explicit provider registry and target binding to session handling. Adds explicit provider registry and target binding to session handling. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Low |
Reconstructs JavaScript application structure in artifact component. Reconstructs JavaScript application structure in artifact component. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes unreliable clean source checkouts in CLI startup. Fixes unreliable clean source checkouts in CLI startup. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fixes setup, upgrade, and process test regressions. Fixes setup, upgrade, and process test regressions. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Replaces managed Hopper on reinstall during setup. Replaces managed Hopper on reinstall during setup. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Refactor | Low |
Removes provider‑specific target and snapshot state from domain module. Removes provider‑specific target and snapshot state from domain module. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Refactor | Low |
Extracts reusable provider lifecycle primitives into process module. Extracts reusable provider lifecycle primitives into process module. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
1.7.0 (2026-07-15)
Features
- artifact: reconstruct JavaScript application structure (aa46abf)
- domain: add versioned JavaScript Application Graph (2ca5672)
- ghidra: add function analysis and conformance (d8321de)
- ghidra: add private headless provider session (f0e625d)
- ghidra: implement read-only inventory operations (b1c07dd)
- session: add explicit provider registry and target binding (941d710)
Bug Fixes
- address setup, upgrade, and process test regressions (960d759)
- address setup, upgrade, and process test regressions (02f12b9)
- cli: make clean source checkouts start reliably (ed17e76)
- cli: make clean source checkouts start reliably (6ba9765)
- setup: replace managed Hopper on reinstall (0ca93f9)
Code Refactoring
- domain: remove provider-specific target and snapshot state (21da71e)
- process: extract reusable provider lifecycle primitives (70e1a0f)
Documentation
- api: refresh profile source anchors (bd3cf96)
- api: refresh provider source anchors (a7621c2)
- architecture: define provider selection and analysis profiles (75f8696)
- architecture: define provider selection and analysis profiles (f9f2fbe)
- reconcile product documentation with shipped behavior (addc208)
- reconcile product documentation with shipped behavior (54056a9)
- refresh Ghidra inventory API links (a45de27)
- regenerate JavaScript graph API with Node 24 (da4817a)
Tests
- keep package setup verification read-only (acaf030)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rea
All releases →Related context
Related tools
Earlier breaking changes
- vrea-agents-2.0.0 mcp now requires Evidence for managed reconstruction.
- vrea-agents-1.0.0 contracts APIs now return structured discriminated output shapes
- vrea-agents-0.3.0 rename identity package and CLI to REA
- vrea-0.2.0 rename identity package and CLI to REA
Beta — feedback welcome: [email protected]