Skip to content

Proliferate

vproliferate-v0.3.42 scope: proliferate Feature

This release adds 7 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Summary

AI summary

Broad release touches Raw Commits, Highlights, Internal / Release, and server.

Full changelog

Proliferate v0.3.42

Production hotfix for July 18, 2026.

Reason: Deploy merged assistant streaming, composer, and caret fixes from PRs #1416 and #1417.

Release Metadata

| Field | Value |
| --- | --- |
| Version | proliferate-v0.3.42 |
| Hotfix | hotfix-2026-07-18-56 |
| Base | 17001c8 |
| Head | 0184483 |
| Compare | 17001c8...0184483 |
| Surfaces | web, desktop |
| Workflow | Actions run |

Highlights

  • #1303 feat(workflows): add managed Cloud product experience by @pablonyx (area:sdk, area:docs, area:product)
  • #1327 feat(agents): show harness update download progress by @pablonyx (area:desktop, area:anyharness, area:sdk, area:docs, area:product)
  • #1336 feat(agents): use catalog-driven unattended session defaults by @pablonyx (area:anyharness, area:sdk, area:server, area:cloud, area:docs, area:product)
  • #1354 feat(integrations): add durable external-action approvals by @pablonyx (area:anyharness, area:sdk, area:server, area:cloud, area:docs, area:product)
  • #1384 feat(cloud): reap orphaned provider sandboxes by @pablonyx (area:server, area:cloud, area:docs, area:release)
  • #1389 feat(workspaces): restore missing worktrees safely by @pablonyx (area:desktop, area:anyharness, area:sdk, area:docs, area:product)

Features

  • #1303 feat(workflows): add managed Cloud product experience by @pablonyx (area:sdk, area:docs, area:product)
  • #1327 feat(agents): show harness update download progress by @pablonyx (area:desktop, area:anyharness, area:sdk, area:docs, area:product)
  • #1336 feat(agents): use catalog-driven unattended session defaults by @pablonyx (area:anyharness, area:sdk, area:server, area:cloud, area:docs, area:product)
  • #1354 feat(integrations): add durable external-action approvals by @pablonyx (area:anyharness, area:sdk, area:server, area:cloud, area:docs, area:product)
  • #1384 feat(cloud): reap orphaned provider sandboxes by @pablonyx (area:server, area:cloud, area:docs, area:release)
  • #1389 feat(workspaces): restore missing worktrees safely by @pablonyx (area:desktop, area:anyharness, area:sdk, area:docs, area:product)
  • #1398 feat(chat): unify rich composer surfaces by @pablonyx (area:docs, area:product)

Fixes

  • #1305 fix(server): classify transient GitHub outages by @pablonyx (area:server, area:docs)
  • #1307 fix(product): classify local Git prerequisite states by @pablonyx (area:anyharness, area:docs, area:product)
  • #1308 fix(server): handle resumable SSE peer closes by @pablonyx (area:server)
  • #1309 fix(server): release gateway transaction before proxying by @pablonyx (area:server, area:docs)
  • #1310 fix(web): gate local agents and expected cancellation telemetry by @pablonyx (area:website, area:product)
  • #1311 fix(desktop): recover orphaned worker credentials by @pablonyx (area:desktop, area:anyharness, area:sdk, area:server, area:docs, area:release, area:product)
  • #1313 fix(anyharness): keep agent stderr out of Sentry by @pablonyx (area:anyharness, area:sdk, area:docs, area:product)
  • #1317 fix(product): redact support report diagnostics by @pablonyx (area:desktop, area:docs, area:product)
  • #1319 fix(server): allow Web environment GitHub returns by @pablonyx (area:server)
  • #1320 fix(product): separate desktop transport failures by @pablonyx (area:desktop, area:cloud, area:product)
  • #1321 fix(product): classify expected auth control states by @pablonyx (area:desktop, area:docs, area:website, area:product)
  • #1322 fix(deploy): enforce hosted Redis deployment contract by @pablonyx (area:server, area:docs, area:release)
  • #1326 fix(product-client): recover ready workspace chats by @pablonyx (area:product)
  • #1329 fix(product-client): classify missing Cowork threads as query state by @pablonyx (area:docs, area:product)
  • #1335 fix(integrations): enforce Slack OAuth scope ceiling by @pablonyx (area:server, area:docs)
  • #1337 fix(product-client): prevent replaced sessions from resurfacing by @pablonyx (area:product)
  • #1341 fix(integrations): fail closed on Slack writes by @pablonyx (area:server, area:docs)
  • #1347 fix(cloud): recover missing managed sandboxes by @pablonyx (area:server, area:cloud, area:docs)
  • #1352 fix(transcript): surface native subagent activity by @pablonyx (area:anyharness, area:sdk, area:docs, area:product)
  • #1353 fix(goals): fence UI cancellation lifecycle by @pablonyx (area:docs, area:product)
  • #1359 fix(server): commit first-run claim before responding by @pablonyx (area:server)
  • #1361 fix(auth): map Google token rejections by @pablonyx (area:server, area:docs)
  • #1362 fix(server): commit invitation writes before responding by @pablonyx (area:server, area:docs)
  • #1363 fix(auth): map rejected GitHub profile callbacks by @pablonyx (area:server, area:docs)
  • #1365 fix(desktop): explain unavailable local folder picker by @pablonyx (area:desktop, area:docs, area:product)
  • #1366 fix(cloud): bootstrap repo-less sandboxes without GitHub App by @pablonyx (area:server, area:cloud, area:docs)
  • #1367 fix(anyharness): reject unapplied session modes by @pablonyx (area:anyharness)
  • #1382 fix(community): replace expiring Discord invite by @pablonyx (area:desktop, area:docs, area:product)
  • #1385 fix(sessions): resume interrupted empty-session creation by @pablonyx (area:anyharness, area:sdk, area:docs, area:product)
  • #1390 fix(product-client): suggest a valid api-key env var for opencode by @pablonyx (area:desktop, area:product)
  • #1392 fix(cloud): commit workspace creation before response by @pablonyx (area:server, area:cloud, area:docs)
  • #1395 fix(product-client): honor cloud-only default branches by @pablonyx (area:product)
  • #1400 fix(anyharness): materialize selected Codex API key by @pablonyx (area:anyharness)
  • #1401 fix(server): commit agent key creation before response by @pablonyx (area:server)
  • #1416 perf(chat): smooth assistant streaming and composer input by @pablonyx (area:docs, area:product)

Performance

  • #1349 perf(transcript): batch high-volume stream reduction by @pablonyx (area:sdk, area:product)

Docs / Website

  • #1325 docs(local): document native services and WSL2 setup by @pablonyx (area:docs)

Internal / Release

  • #1141 chore(server): remove orphaned faux-workspace seed scripts and unused passlib dependency by @Rahul-Ganesan (area:server)
  • #1240 chore(deps): update npm minor and patch dependencies by @dependabot[bot] (area:desktop, area:anyharness, area:sdk, area:server, area:cloud, area:website, area:release, area:product)
  • #1288 chore(deps): bump the github-actions group across 1 directory with 6 updates by @dependabot[bot] (area:release)
  • #1306 test(release): retained-release receipts for Tier 4 N-1 artifact identity by @pablonyx (area:docs)
  • #1323 chore(agents): update managed coding-agent harnesses by @pablonyx (area:anyharness, area:server, area:docs, area:release)
  • #1334 fix(web): classify expected lifecycle cancellations by @pablonyx (area:sdk, area:website, area:product)
  • #1340 fix(release): close failed billing boot fixture by @pablonyx (area:release)
  • #1357 fix(release): harden INT audit probe by @pablonyx (area:docs, area:release)
  • #1358 fix(release): repair managed-cloud Route53 cleanup by @pablonyx (area:release)
  • #1360 fix(release): configure local worker API base URL by @pablonyx (area:release)
  • #1364 test(intent): make T2-SH-6 fixture run-scoped by @pablonyx (area:docs, area:release)
  • #1369 test(release): verify workspace file secret materialization by @pablonyx (area:cloud, area:release)
  • #1371 test(release): re-land local Tier-3 collector repairs missing from main by @pablonyx (area:release)
  • #1372 test(release): resolve the newest local session, not the stalest by @pablonyx (area:release)
  • #1376 test(release): claim first-run setup once per local world by @pablonyx (area:release)
  • #1377 test(release): snapshot pre-send sessions before the route-change new chat by @pablonyx (area:release)
  • #1378 test(release): select gateway route per harness in LOCAL-4 browser world by @pablonyx (area:release)
  • #1379 fix(cloud): trace workspace provisioning phases by @pablonyx (area:server, area:cloud)
  • #1380 ci(agent-catalog): protect scheduled Catalog Probe by @pablonyx (area:anyharness, area:docs, area:release)
  • #1386 test(server): align gateway tests with bound sessions by @pablonyx (area:server, area:cloud)
  • #1387 test(release): evict the claimed-owner cache when a local world closes by @pablonyx (area:release)
  • #1388 test(release): wait for the Project picker to settle after harness-ready reload by @pablonyx (area:release)
  • #1391 test(release): type gateway-unsupported and no-eligible-model outcomes consistently by @pablonyx (area:release)
  • #1397 test(release): return LOCAL-4 batch to Home between cells by @pablonyx (area:release)
  • #1407 fix(release): isolate manual qualification worlds by @pablonyx (area:release)
  • #1417 refactor(chat): satisfy frontend structure rules by @pablonyx (area:product)

Other Changes

  • #1343 test(release): constrain staging qualification cells by @pablonyx
  • #1402 fix(testing): reuse qualification TLS capacity by @pablonyx

Artifacts

| Lane | Tag |
| --- | --- |
| Desktop | desktop-v0.3.42 |

Raw Commits

View commits
  • 6eaaf7d chore(deps): bump the github-actions group across 1 directory with 6 updates (#1288)
  • ee9735f chore(deps): update npm minor and patch dependencies (#1240)
  • 0a15512 feat(workflows): add managed Cloud product experience (#1303)
  • a9915ea fix(product): classify local Git prerequisite states
  • a682d33 fix(server): release gateway transaction before proxying
  • b682fb1 fix(web): gate local agents and expected cancellation telemetry (#1310)
  • e6d0c15 fix(server): classify transient GitHub outages (#1305)
  • 9d5d70c fix(server): handle resumable SSE peer closes (#1308)
  • 50f133c fix(anyharness): keep agent stderr out of Sentry (#1313)
  • 390d873 fix(product): separate desktop transport failures (#1320)
  • 72b4937 fix(product): classify expected auth control states (#1321)
  • 8ad3684 fix(server): allow Web environment GitHub returns (#1319)
  • 840ddeb fix(product): close support diagnostics privacy gaps (#1317)
  • 1ee44f9 fix: harden desktop worker credential rotation (#1311)
  • eb5be95 chore(agents): update managed coding-agent harnesses (#1323)
  • 1e5fd54 fix(deploy): enforce hosted Redis deployment contract (#1322)
  • 9d9620b test(release): retained-release receipts for Tier 4 N-1 artifact identity (#1306)
  • e30a533 chore(server): remove orphaned faux-workspace seed scripts and unused passlib dependency (#1141)
  • 4740431 docs(local): document native services and WSL2 setup (#1325)
  • 8c447f2 fix(product-client): recover ready workspace chats (#1326)
  • d132508 fix(product-client): classify missing Cowork threads as query state (#1329)
  • f47ee5d feat(agents): show harness update download progress (#1327)
  • 6be4e7f fix(web): classify expected lifecycle cancellations (#1334)
  • 1c690d9 fix(integrations): enforce Slack OAuth scope ceiling (#1335)
  • 3c617a5 feat(agents): use catalog-driven unattended session defaults (#1336)
  • db65613 fix(release): close failed billing boot fixture (#1340)
  • bf8c097 fix(release): fail closed on leaked runner handles (#1344)
  • 1786d5c fix(product-client): prevent replaced sessions from resurfacing (#1337)
  • 45bfa43 test(release): constrain staging qualification cells (#1343)
  • bd76405 test(release): preserve self-host setup failure phase (#1348)
  • e10e4a5 fix(release): preserve local qualification truth (#1350)
  • 34dc170 perf(transcript): batch high-volume stream reduction (#1349)
  • 5c9a4e9 fix(integrations): fail closed on Slack writes (#1341)
  • e49688e test(release): recover managed-cloud resources after cancellation (#1351)
  • 475ac02 test(release): attest managed-cloud LiteLLM attribution (#1355)
  • 57fa376 fix(release): repair managed-cloud Route53 cleanup (#1358)
  • 090bfb6 fix(release): harden INT audit probe (#1357)
  • fd26a53 fix(goals): fence UI cancellation lifecycle (#1353)
  • dc31edc fix(transcript): surface native subagent activity (#1352)
  • 689a196 fix(cloud): recover missing managed sandboxes (#1347)
  • c9768f7 feat(integrations): add durable external-action approvals (#1354)
  • ff41cd7 fix(server): commit first-run claim before responding (#1359)
  • f0faeca fix(release): configure local worker API base URL (#1360)
  • 6631529 fix(auth): map Google token rejections (#1361)
  • 9510ba8 fix(server): commit invitation writes before responding (#1362)
  • 22cf3f0 fix(auth): map rejected GitHub profile callbacks (#1363)
  • 917367a test(intent): make T2-SH-6 fixture run-scoped (#1364)
  • 47b1b05 fix(desktop): explain unavailable local folder picker (#1365)
  • 60fb8ff fix(cloud): skip GitHub auth for repo-less sandboxes (#1366)
  • 7214da0 test(release): verify workspace file secret materialization (#1369)
  • 1269ee5 fix(anyharness): reject unapplied session modes (#1367)
  • 9b01957 test(release): re-land local Tier-3 collector repairs missing from main (#1371)
  • 7045e35 test(release): resolve the newest local session, not the stalest (#1372)
  • 7f9151d test(release): harden qualification execution reliability (#1373)
  • 52e5a70 test(release): claim first-run setup once per local world (#1376)
  • 44ea800 test(release): attest managed-cloud candidate c872b36ed (#1374)
  • cbd67e3 test(release): snapshot pre-send sessions before the route-change new chat (#1377)
  • 3b90003 test(release): select gateway route per harness in LOCAL-4 browser world (#1378)
  • ca92564 fix(cloud): trace workspace provisioning phases (#1379)
  • efa3c77 fix(community): replace expiring Discord invite (#1382)
  • 8ffd75a ci(agent-catalog): protect scheduled Catalog Probe (#1380)
  • f2f8908 test(server): align gateway tests with bound sessions (#1386)
  • b4d1929 feat(workspaces): restore missing worktrees safely
  • 3efb0f3 fix(ci): satisfy restore repository shape gates
  • 4a17a1b test(release): evict the claimed-owner cache when a local world closes (#1387)
  • f4851ff test(release): wait for the Project picker to settle after harness-ready reload (#1388)
  • 5b1378f fix(product-client): suggest a valid api-key env var for opencode (#1390)
  • 583955d test(release): type gateway-unsupported and no-eligible-model outcomes consistently (#1391)
  • 72c20b3 fix(workspaces): restore the recorded current branch
  • 3c6069d feat(cloud): reap orphaned provider sandboxes (#1384)
  • 5e6cbea Merge pull request #1389 from proliferate-ai/codex/restore-missing-worktree-1383
  • a37d679 fix(cloud): commit workspace creation before response (#1392)
  • 6421a85 fix(sessions): resume interrupted empty-session creation (#1385)
  • 9b225a8 fix(product-client): honor cloud-only default branches (#1395)
  • 216278f test(release): attest managed-cloud candidate 8c13ae78a (#1399)
  • 9d6466c test(release): return LOCAL-4 batch to Home between cells (#1397)
  • bd58ece fix(anyharness): materialize selected Codex API key (#1400)
  • 482f76c fix qualification TLS capacity (#1402)
  • 027ff93 fix(server): commit agent key creation before response (#1401)
  • 6a7b0eb test(release): attest managed-cloud fixture source sha
  • 6242bb2 test(release): attest managed-cloud evidence repair sha
  • a91b0ff feat(chat): render user prompts as markdown (#1393)
  • 7744513 feat(chat): add rich workspace composer (#1396)
  • 196b509 feat(chat): unify rich composer surfaces (#1398)
  • a4311a2 fix(release): isolate manual qualification worlds (#1407)
  • 6fdec94 test(release): attest managed-cloud version repair (#1408)
  • d49dc63 test(release): attest fixture TLS repair (#1412)
  • 1dd3710 fix(release): wait for local sidebar navigation readiness (#1413)
  • a62ca4e perf(chat): smooth assistant streaming and composer input (#1416)
  • e6c7592 test(release): attest managed-cloud composer repair (#1415)
  • a1d94a1 refactor(chat): satisfy frontend structure rules (#1417)
  • 0184483 release: prepare hotfix-2026-07-18-56

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Proliferate

Get notified when new releases ship.

Sign up free

About Proliferate

Open-source local and cloud agent IDE for Claude Code, Codex, Gemini CLI, OpenCode, and similar coding agents; parallel workspaces, subagents, plugins, MCP, and review/merge flow around real CLI sessions.

All releases →

Related context

Beta — feedback welcome: [email protected]