Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 4mo AI Coding Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-collaboration anthropic anticipatory-ai artificial-intelligence claude-code
+12 more
code-analysis debugging developer-productivity developer-tools developer-tools-monorepo fair-source healthcare-ai large-language-models llm memdocs python testing

Affected surfaces

auth

Summary

AI summary

React Router XSS vulnerability fixed (CVE-2026-22029).

Full changelog

What's Changed in v4.0.2

  • test: Fix 12 test failures for v4.0.1 maintenance release (0bc4d995)
  • test: Add 167 comprehensive tests across 5 modules, boost coverage 53% → ~70% (58a091db)
  • test: Fix 20 test failures across security, router, workflow, and integration tests (59ae1e8e)
  • test: Add 160 comprehensive tests for telemetry CLI and doc orchestrator (f2ab7e93)
  • fix: Resolve 2 Ruff code quality issues (F841, B007) (edb63946)
  • test: Fix test failures and add 207 new tests, boost coverage to 93.91% on workflow_commands (ac1dbe24)
  • test: Add 158 tests across routing and models modules, boost coverage significantly (a9499e7c)
  • test: Add comprehensive routing module tests (82 tests total) (10d2ce33)
  • fix: Add 5-minute timeout to workflow execution to prevent hanging (f7369c9a)
  • chore: Pattern learning data, CLI JSON mode improvements, and minor fixes (b7323e7a)
  • test: Add 80 new tests, increase coverage from 28.50% to 35.86% (+7.36%) (c497eeb8)
  • feat: Implement real analysis tools for v4.0 meta-orchestration workflows (8461c84e)
  • wip: Save TestCoverageBoostCrew and v4.0 experiments before rollback (d69e7c15)
  • feat: Add dedicated webview panels for Meta-Orchestration workflows (232e265f)
  • fix: Resolve all mypy type errors (6 errors fixed) (4c01a1d1)
  • feat: Add Meta-Orchestration section to dashboard with v4.0 workflows (9fb983f0)
  • feat: Wire Health Check button to orchestrated health check (v4.0) (92d3f8e3)
  • feat: Auto-open VS Code Health Panel after health check completes (db79c095)
  • feat: Replace web dashboard with VS Code extension integration for health check (0b8f9314)
  • feat: Add actionable recommendations and web dashboard support to health check (b3489e9f)
  • docs: Update meta-orchestration tutorial for domain-agnostic positioning (6a072cba)
  • feat: Add orchestrated health check workflow with CLI integration (d80ffea3)
  • docs: Add comprehensive meta-orchestration tutorial (27979291)
  • feat: Release v4.0.0 - Meta-Orchestration Era 🎭 (9417cf4c)
  • feat: Add parallel test execution with pytest-xdist (4-8x faster) (9683c49c)
  • Release v3.11.0: Phase 2 Performance Optimizations - 46% Faster (b0133830)
  • fix: Resolve release blockers - type errors and security scanner (15bef7de)
  • test: Add comprehensive Phase 1 & 2 test improvements (79 tests) (39911dd2)
  • test: Add comprehensive Redis fallback and recovery tests (a139b579)
  • docs: Add comprehensive performance optimization final report (91e63a09)
  • perf: Increase AST cache size and measure performance - 1.54x speedup (3947816f)
  • fix: Use TYPE_CHECKING for Element type hint in test_runner (1aa47083)
  • perf: Optimize Cost Tracker with batch writes - 1,300x speedup (b87903ff)
  • docs: Add Phase 2 implementation summary and status (68ead950)
  • perf: Implement Phase 2 optimizations - caching, indexing, profiling infrastructure (986bc2f0)
  • docs: Add Phase 2 performance optimization plan and roadmap (e1365361)
  • perf: Optimize list copy operations across codebase (f928d9aa)
  • chore: Apply automated linting and formatting fixes across codebase (b6b1d0bd)
  • feat: Add VSCode morning briefing panel and update empathy patterns (4488778d)
  • fix(ci): Fix tier pattern analysis workflow shell errors (ded73555)
  • feat: Enhanced tier fallback system with comprehensive testing and documentation (9d0cf208)
  • security: Fix React Router XSS vulnerability (CVE-2026-22029) (36bd9ec9)
  • fix(lint): Document intentional broad exception handling with noqa comments (69c8700a)

Full Changelog: https://github.com/Smart-AI-Memory/empathy-framework/compare/v3.10.2...v4.0.2

Security Fixes

  • CVE-2026-22029 — React Router XSS vulnerability fixed

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Smart-AI-Memory/empathy-framework

Get notified when new releases ship.

Sign up free

About Smart-AI-Memory/empathy-framework

Five-level AI collaboration system with persistent memory and anticipatory capabilities. MCP-native integration for Claude and other LLMs with local-first architecture via MemDocs.

All releases →

Beta — feedback welcome: [email protected]