github kortix-ai/suna v0.13.49
v0.13.49 — Permissions decide for agents, and an agent grants only what it holds

latest release: dev-latest
2 hours ago

New

  • Permissions decide, for agents as for people. An agent that holds a permission can do the work end to end. kortix_permissions: all, "*", and any list that contains "*" mean the same thing. With all, an agent can also manage project members and delete the project. Creating credentials stays with people.
  • An agent can grant only what it holds. When an agent edits an agent's permissions, connectors, secrets, or Apps, it can add only what it holds itself. This applies through every route, change request, and push. An agent that does not hold every grant opens a change request instead of pushing the default branch directly.
  • One authorization path. Every agent with a kortix_permissions grant acts as itself, in every project. The per-project switch back to the authority of the person who started it is gone.
  • One bad permission entry no longer empties an agent. An entry Kortix cannot grant is skipped, and the rest of the agent's grant stays. kortix validate still reports it.
  • The Meta agent is platform-owned. It runs read-only and appears first in the agent picker.
  • No more active-session limits. Billing is the only limit on how many sessions run at once.
  • The blog is served from its own app at /blog.

Improved

  • A change-request merge that edits agents, triggers, or default_agent needs the same permission as the direct route.
  • The download links (/download/macos, /windows, /linux) fall back to the releases page after 3 seconds if GitHub does not answer.
  • Deleting a sign-in removes the accounts that only that person belonged to, and revokes all of that person's credentials.
  • The manager's session inventory no longer lists deleted warm drafts.

Fixed

  • kortix validate rejects invalid arguments.
  • The sandbox's /turn request is read correctly before streaming starts.
  • The mobile stop icon honors its size.
  • The infrastructure audit checks network ACL admin ports separately for IPv4 and IPv6.

What's Changed

  • chore: remove 4 unused symbols CodeQL flagged on the v0.13.48 promotion by @markokraemer in #8981
  • chore(secrets): track EXPO_ACCESS_TOKEN (Expo push) across all envs by @markokraemer in #8984
  • feat(web): serve /blog from the standalone blog app by @ArtemShatokhin in #8964
  • chore(release): staging VERSION → 0.13.49 [skip ci] by @github-actions[bot] in #8986
  • chore(release): VERSION → 0.13.49 [skip ci] by @github-actions[bot] in #8987
  • fix(cli): reject invalid validate arguments (KRTX-1339) by @agent-kortix in #8881
  • fix(test): one attestation file per PR so merges stop conflicting by @markokraemer in #8991
  • fix(infra): audit NACL admin ports per address family (KRTX-1458) by @agent-kortix in #8997
  • fix(worker): parse the /turn body before the SSE headers (KRTX-1387) by @agent-kortix in #8996
  • fix(sandbox): pin the meta image pnpm install to the checksum-verified artifact (KRTX-1384) by @agent-kortix in #8994
  • fix(tests): compare RTA-6's applied-nothing check on identity fields only (KRTX-1426) by @agent-kortix in #8992
  • fix(tests): make the packages lane green in worker sandboxes (KRTX-1411) by @agent-kortix in #8988
  • fix(mobile): honor StopIcon size prop (KRTX-1293) by @agent-kortix in #8862
  • fix(test): verify accepts packages skipped-sandbox-image, matching the merge gate by @markokraemer in #9001
  • feat(iam): permissions decide for agents as for people; "*" means all by @markokraemer in #9002
  • feat(meta): platform-owned Meta agent on pi, read-only, elevated in the picker by @markokraemer in #9017
  • feat(sessions): remove every active-session limit; billing is the only gate by @markokraemer in #9019
  • fix(release): v0.13.49 gate — Drata resource names, download fetch timeout, deployed-target flows by @markokraemer in #9021
  • fix(db): reclaim orphaned accounts when an auth user is deleted (KRTX-1300) by @agent-kortix in #9006
  • fix(api): drop soft-deleted warm drafts from the manager session inventory (KRTX-1298) by @agent-kortix in #9013
  • fix(iam): an agent grants only what it holds by @markokraemer in #9035
  • fix: main green for v0.13.49 — Meta agent platform type, i18n banner, SSO test anchor owner by @markokraemer in #9037
  • refactor(iam): one authorization path — delete the agent_principal flag by @markokraemer in #9027
  • test(shared): Meta sandbox guide assertions match #9017's heading and wording by @markokraemer in #9039
  • Promote main a0aa087 to staging by @markokraemer in #9040
  • Release v0.13.49 — Permissions decide for agents, and an agent grants only what it holds by @github-actions[bot] in #9044

Full Changelog: v0.13.48...v0.13.49

Don't miss a new suna release

NewReleases is sending notifications on new releases.