This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 2.1.0, and Code Refactoring across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Harden authority and runtime conformance boundaries. Harden authority and runtime conformance boundaries. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Add managed characterization and coverage closure. Add managed characterization and coverage closure. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Add managed characterization and reconstruction coverage. Add managed characterization and reconstruction coverage. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Add explicit package‑runner setup wizard to CLI. Add explicit package‑runner setup wizard to CLI. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Add support for package‑name in CLI setup wizard. Add support for package‑name in CLI setup wizard. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Add BYO ILSpy oracle diagnostics for .NET. Add BYO ILSpy oracle diagnostics for .NET. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Add authenticated Windows loopback transport for Ghidra. Add authenticated Windows loopback transport for Ghidra. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Bind imports to admitted target bytes in Ghidra. Bind imports to admitted target bytes in Ghidra. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Define Windows P0 admission boundary for Ghidra. Define Windows P0 admission boundary for Ghidra. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Inspect Windows headless installations in Ghidra. Inspect Windows headless installations in Ghidra. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Launch bounded Windows headless sessions via Ghidra. Launch bounded Windows headless sessions via Ghidra. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Improve CLI setup onboarding workflow. Improve CLI setup onboarding workflow. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Add binding and constant‑value semantic IR for JavaScript analysis. Add binding and constant‑value semantic IR for JavaScript analysis. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Recover commonjs and esm module relationships in JavaScript analysis. Recover commonjs and esm module relationships in JavaScript analysis. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Add webpack and rspack runtime adapters to JavaScript execution layer. Add webpack and rspack runtime adapters to JavaScript execution layer. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Add scoped process capture elicitation to permissions subsystem. Add scoped process capture elicitation to permissions subsystem. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Classify Windows PE admission metadata in target analysis stage. Classify Windows PE admission metadata in target analysis stage. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Define native authority boundary for Windows platform integration. Define native authority boundary for Windows platform integration. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | High |
Admit real CLI GUID and fat CIL bodies in .NET analysis engine. Admit real CLI GUID and fat CIL bodies in .NET analysis engine. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | High |
Downgrade truncated CIL identity and coverage to prevent overflow errors. Downgrade truncated CIL identity and coverage to prevent overflow errors. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Preserve native generated‑file line endings during build process. Preserve native generated‑file line endings during build process. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Require explicit selections in CLI setup wizard to avoid defaults. Require explicit selections in CLI setup wizard to avoid defaults. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Make agent‑facing schemas self‑describing for contracts compliance. Make agent‑facing schemas self‑describing for contracts compliance. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Correct CLI pointer and byref signatures for accurate type representation. Correct CLI pointer and byref signatures for accurate type representation. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Resolve package and dirname entrypoints by context in Electron loader. Resolve package and dirname entrypoints by context in Electron loader. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Remove retired native rebuild steps from CI pipeline. Remove retired native rebuild steps from CI pipeline. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Keep missing unpacked ASAR entries unavailable in Electron runtime. Keep missing unpacked ASAR entries unavailable in Electron runtime. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Preserve native endpoint diagnostics for Ghidra integration calls. Preserve native endpoint diagnostics for Ghidra integration calls. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Preserve Windows batch invocation semantics during Ghidra execution. Preserve Windows batch invocation semantics during Ghidra execution. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Refactor | Low |
Rename skill component to reverse‑engineer‑anything. Rename skill component to reverse‑engineer‑anything. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
2.1.0 (2026-07-18)
Features
- add managed characterization and coverage closure (1943496)
- add managed characterization and reconstruction coverage (02c913b)
- cli: add explicit package-runner setup wizard (891a11f)
- cli: improve setup onboarding (4851449)
- cli: improve setup onboarding (16002ff)
- cli: support package-name setup wizard (1b90e7f)
- doctor: admit the Windows x64 Ghidra boundary (32dda0c)
- dotnet: add BYO ILSpy oracle diagnostics (aa200ce)
- ghidra: add authenticated Windows loopback transport (629ffc3)
- ghidra: bind imports to admitted target bytes (be19c3f)
- ghidra: define the Windows P0 admission boundary (6b1fd16)
- ghidra: inspect Windows headless installations (86e44be)
- ghidra: launch bounded Windows headless sessions (bc0fb45)
- harden authority and runtime conformance boundaries (b537ebf)
- javascript: add binding and constant-value semantic IR (3ea8523)
- javascript: add binding and constant-value semantic IR (3d71bb5)
- javascript: add webpack and rspack runtime adapters (7bccb7c)
- javascript: add webpack and rspack runtime adapters (44c7017)
- javascript: recover commonjs and esm module relationships (9766fc0)
- javascript: recover commonjs and esm module relationships (6c41791)
- permissions: add scoped process capture elicitation (e6cfce3)
- skill: rename skill to reverse-engineer-anything (9356634)
- target: classify Windows PE admission metadata (24274fe)
- windows: define native authority boundary (a1a6b42)
Bug Fixes
- build: preserve native generated-file line endings (00a3078)
- ci: remove retired native rebuild steps (2d22731)
- ci: validate packaged Windows CLI commands exactly (43418ee)
- cli: require explicit setup selections (992ec50)
- contracts: make agent-facing schemas self-describing (0df11dd)
- dotnet: admit real CLI GUID and fat CIL bodies (735973b)
- dotnet: correct CLI pointer and byref signatures (1387be0)
- dotnet: correct CLI pointer and byref signatures (fb9ff56)
- dotnet: downgrade truncated CIL identity and coverage (736a4e1)
- dotnet: downgrade truncated CIL identity and coverage (dae6807)
- electron: keep missing unpacked ASAR entries unavailable (fb6964a)
- electron: resolve package and dirname entrypoints by context (4847fc4)
- electron: resolve package and dirname entrypoints by context (1ac9a09)
- ghidra: preserve native endpoint diagnostics (5970a71)
- ghidra: preserve Windows batch invocation semantics (0ac418d)
- ghidra: validate Windows control characters explicitly (4dccbec)
- managed: emit valid x64 conformance PE (dcd94f1)
- managed: emit valid x64 conformance PE (c52a822)
- managed: preserve page incompleteness in graph and comparison (a6f02a0)
- managed: preserve page incompleteness in graph and comparison (8ee0f04)
- mcp: clarify advertised schema fields (1581e40)
- npm: use latest entry points without install scripts (34252f5)
- npm: use latest entry points, remove install scripts, and rename skill (bf85ee6)
- preserve optional unknown filters (db1efef)
- remove unused boundary exports (49f1ec1)
- satisfy dead-code and generated-doc checks (b15a9ec)
- setup: preserve onboarding after refactor (da48033)
- skill: disclose retired skill cleanup (4c69e61)
Code Refactoring
- adapters: split oversized provider workflows (1a99a60)
- app: split session and CLI workflows (c6ee004)
- domain: split analysis boundaries (e2c868c)
- finish lint cleanup (2bea405)
- managed: split metadata analysis (20c88dd)
- setup: keep planner helpers private (2d1f961)
- simplify authorization boundaries (2e5b443)
- simplify doctor and error projections (37f4ac6)
- skill: keep only the canonical skill identity (a7c1e87)
- skill: remove legacy skill compatibility (8cf0dd2)
- split oversized analysis workflows (af2399e)
- split oversized analysis workflows (3e61a63)
- windows: keep capability outcomes module-private (585f523)
Documentation
- cli: describe every command input (d4be3e7)
- ghidra: define the experimental Windows P0 (8b5ae41)
- managed: align normalized CIL claims with shipped v1 semantics (9a92a79)
- managed: align normalized CIL claims with shipped v1 semantics (3f788e9)
- normalize inherited source paths (d33213a)
- preserve generated source links (2ea375f)
- prioritize agent usability in tool design (ad17fe7)
- refresh Electron path resolution API (734a4ef)
- refresh generated API reference (f5f653b)
- regenerate managed coverage API with Node 24 (e47c00e)
Tests
- add limit monotonicity and partial-evidence regressions (2cce98c)
- add limit monotonicity and partial-evidence regressions (4afd970)
- ci: guard Windows Ghidra workflow isolation (81ed68f)
- ci: guard Windows Ghidra workflow isolation (98540c8)
- cli: cover package-name binary alias (40e2f94)
- hopper: add semantic runtime conformance (da1da3b)
- package: align setup preflight contract (b33ebb1)
Continuous Integration
- ghidra: add Windows P0 acceptance and real-engine lanes (0b35510)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rea
All releases →Related context
Related tools
Earlier breaking changes
- vrea-agents-2.0.0 mcp now requires Evidence for managed reconstruction.
- vrea-agents-1.0.0 contracts APIs now return structured discriminated output shapes
- vrea-agents-0.3.0 rename identity package and CLI to REA
- vrea-0.2.0 rename identity package and CLI to REA
Beta — feedback welcome: [email protected]