This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Summary
AI summaryFixed correctness issues and silent drops in the Kiro agent handler.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Guard reserved keys in IDE frontmatter Guard reserved keys in IDE frontmatter Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Document remote MCP and Copilot CLI mirror Document remote MCP and Copilot CLI mirror Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Mirror MCP assets to Copilot CLI config Mirror MCP assets to Copilot CLI config Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Preserve unknown keys in MCP config files Preserve unknown keys in MCP config files Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Support remote MCP servers for Copilot Support remote MCP servers for Copilot Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Add agent asset support for Kiro client Add agent asset support for Kiro client Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Medium |
Reserve prompt key in IDE frontmatter Reserve prompt key in IDE frontmatter Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Dependency | Low |
Bump actions/setup-node from version 6 to version 7. Bump actions/setup-node from version 6 to version 7. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix lint issues in agent handler Fix lint issues in agent handler Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fix verify for deleted packaged servers Fix verify for deleted packaged servers Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Verify CLI mirror, skip packaged in shared Verify CLI mirror, skip packaged in shared Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fix correctness issues in Kiro agent handler Fix correctness issues in Kiro agent handler Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Refactor | Low |
Fix review issues in Kiro agent handler Fix review issues in Kiro agent handler Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Other | Low |
Add integration tests, fix silent drops Add integration tests, fix silent drops Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
Changelog
- 341133bb4e0fa32a62df05b93e84c559bdf45275 Bump actions/setup-node from 6 to 7
- f5503ae6ff8a30936320fc264119d05d668416fc Fix lint issues in agent handler
- fae3d34f98be46a0602714f4d955fa20bd8556f9 SK-687: Document remote MCP and Copilot CLI mirror
- 2bc505bd48d267a060c09d7af58f20dc96150869 SK-687: Fix verify for deleted packaged servers
- 823fb7093e684fc764b84027ba9576f044e64c0c SK-687: Mirror MCP assets to Copilot CLI config
- bf947c59b849e2f4c911f8dee03a60849c55a55f SK-687: Preserve unknown keys in MCP config files
- 279caf56d25b52002219bbf14346625287c4aad7 SK-687: Support remote MCP servers for Copilot
- d8d008c0f80800e0d3f0c5c53a8fd74144bba949 SK-687: Verify CLI mirror, skip packaged in shared
- 3e83020d6911527296f48d39154d4adc37970e97 SK-697 Add agent asset support for Kiro client
- e6f0f2c807f7285fd0ae69525f5fbe6a4f885111 SK-697: Add integration tests, fix silent drops
- 75e12ce9df27a67e56445b817d5be4ca2eacbef1 SK-697: Fix correctness issues in Kiro agent handler
- dbdf4b8464b941062811f804de6017b20318fd4f SK-697: Fix review issues in Kiro agent handler
- de631ef4766356957e52405de768f87c0ed02ae0 SK-697: Guard reserved keys in IDE frontmatter
- 6476b674b421327c6e249ee9fe2a26d1c16374f9 SK-697: Reserve prompt key in IDE frontmatter
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Sx
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]