Skip to content

Oh My Codex

v0.20.2 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Summary

AI summary

Updates Dependencies and release collateral, Highlights, and Additional fixes across a mixed release.

Changes in this release

Feature Medium

Adds surface‑aware native spawn_agent role routing with transactional, recoverable binding and cross‑process lock cleanup.

Adds surface‑aware native spawn_agent role routing with transactional, recoverable binding and cross‑process lock cleanup.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Allows native subagents to stop without a generic auto‑nudge.

Allows native subagents to stop without a generic auto‑nudge.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Isolates prompt/session provenance across concurrent chats and rejects ambiguous session aliases.

Isolates prompt/session provenance across concurrent chats and rejects ambiguous session aliases.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Preserves explicit AGENTS.md merge policy in setup and honors an explicit worker policy in Team.

Preserves explicit AGENTS.md merge policy in setup and honors an explicit worker policy in Team.

Source: llm_adapter@2026-07-16

Confidence: high

Feature Medium

Ignores stale foreign state‑transition mirrors.

Ignores stale foreign state‑transition mirrors.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Prevents accidental workflow invocation from quoted, negated, documented, malformed, or other non‑invocation mentions.

Prevents accidental workflow invocation from quoted, negated, documented, malformed, or other non‑invocation mentions.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Ensures authenticated deep‑interview terminal state writes succeed.

Ensures authenticated deep‑interview terminal state writes succeed.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Preserves foreign Codex hook coordinates during operations.

Preserves foreign Codex hook coordinates during operations.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Accepts BOM‑prefixed state input.

Accepts BOM‑prefixed state input.

Source: llm_adapter@2026-07-16

Confidence: high

Bugfix Medium

Ensures detached panes retain tmux‑owned terminal environment values.

Ensures detached panes retain tmux‑owned terminal environment values.

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

oh-my-codex v0.20.2

0.20.2 is a patch release for the reliability and workflow-safety work in the exact range v0.20.1..f5e4753135ebc86342e7353300ac3ec5d9ae3d8d.

Highlights

  • Authenticated fresh App leaders can bootstrap Ralplan role intent in-turn through durable, fail-closed leader attestation and atomic recovery (#3184; issue #3181).
  • Native spawn_agent role routing is surface-aware; adapted-role tracker/marker binding is transactional, recoverable, and protected by cross-process lock cleanup (#3152, #3166; issue #3118). Native subagents can stop without a generic auto-nudge (#3180).
  • Prompt/session provenance is isolated across concurrent chats, fallback notifications are deduplicated across processes, and canonical Ralplan state rejects ambiguous session aliases (#3168, #3165, #3158).
  • Setup preserves explicit AGENTS.md merge policy, Team honors an explicit worker policy, and stale foreign state-transition mirrors are ignored (#3164, #3136, #3172).

Additional fixes

  • Explicit prompt-leading workflow invocation prevents accidental activation from quoted, negated, documented, malformed, or other non-invocation mentions (#3140; issue #3133).
  • Authenticated deep-interview terminal state writes succeed (#3179); foreign Codex hook coordinates are preserved (#3151); BOM-prefixed state input is accepted (#3169); and detached panes retain tmux-owned terminal environment values (#3183; issue #3175).

Dependencies and release collateral

  • Updated actions/setup-node 6 → 7 (#3154), TypeScript 6.0.3 → 7.0.2 (#3155), @types/node 26.1.0 → 26.1.1 (#3156), and @biomejs/biome 2.5.2 → 2.5.3 (#3157).
  • #3129 reconciled 0.20.1 post-publish evidence; its direct branch commit and merge commit are release-collateral-only. 29bdeb5c5670c133d9f2feda7512ee01e80a63d5 is the version-development preparation commit.

Merged PRs since v0.20.1

#3129, #3136, #3140, #3151, #3152, #3154, #3155, #3156, #3157, #3158, #3164, #3165, #3166, #3168, #3169, #3172, #3179, #3180, #3183, #3184. Issues #3118, #3133, #3162, #3163, #3175, #3177, and #3181 are associated issues, not additional PRs.

Compatibility

Patch release with no intentional breaking CLI or package-layout changes.

Validation

Local build, lint, typecheck, full Node/Rust tests, packed-install smoke, independent review, dev and main candidate CI, all seven native builds, native-asset verification, GitHub release publication, npm provenance publication, and isolated public-registry install/CLI boot passed for the shipped candidate. The packed smoke used the exact Codex CLI 0.142.5 boundary. Full evidence is recorded in docs/qa/release-readiness-0.20.2.md.

Contributors

Thanks to Bellman, cristph, dependabot[bot], and James Myers for contributing to this release.

Full Changelog: v0.20.1...v0.20.2

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Oh My Codex

Get notified when new releases ship.

Sign up free

About Oh My Codex

All releases →

Related context

Earlier breaking changes

  • v0.18.5 Ultragoal completion now requires independent reviewer and architect evidence before marking complete.

Beta — feedback welcome: [email protected]