Features
- feat(buffer): complete stable API tool coverage (#8779)
- feat(api): expose credential sharing and SSO administration (#8770)
- feat(models): add current frontier models (#8777)
- feat(integrations): add Ramp and Microsoft Intune (#8780)
- feat(permission-groups): add agent default (#8771)
- feat(providers): add Nebius Token Factory (#8759)
- feat(desktop): import local files from the background executor (#8672)
- feat(desktop): keep the machine awake for background chats and yield the page to the user (#8671)
- feat(desktop): show background desktop chats and keep the chat view display-only for them (#8670)
- feat(desktop): run a chat's desktop tools in the background executor (#8668)
- feat(mothership): let the worker choose models when the model picker is off (#8669)
- feat(desktop): bind turns to a desktop and enforce its deadlines from the row (#8650)
- feat(sso): allow self-hosted DNS verification bypass (#8681)
- feat(plane): add core integration with self-hosted support (#8660)
- feat(library): 25 Multi-Step AI Agent Examples Beyond Chatbots (#8677)
- feat(desktop): device registry, inbox and leased claims for a background executor (#8644)
- feat(library): Best Conversational AI Platforms With CRM and Helpdesk Integrations (#8639)
- feat(library): Best AI Coding Agents for Refactoring and Debugging: 5 Tools Compared (#8638)
- feat(mothership): keep each chat's reasoning effort, default to medium, restore Low (#8634)
- feat(projects): add project identity and lifecycle foundation (#8580)
- feat(workflows): stop a manual v2 run after a block, and
workflows run --stop-after(#8622) - feat(library): How do you build an AI bot for Discord without code? (#8613)
Improvements
- improvement(desktop): ship the background executor without a flag, close its QA gaps (#8782)
- improvement(files): add sharing to file resource view (#8775)
- perf(pii): batch spaCy NER passes in redact_batch (#8772)
- improvement(ci): check out same-repo pull requests through a git mirror (#8768)
- improvement(mothership): relabel the Sol pick GPT-6.1 Sol and retire the none effort (#8752)
- refactor(mothership): a saved Stop handoff's id wins on restore (#8747)
- refactor(mothership): keep a queued send's reused id in one field (#8746)
- refactor(mothership): one hold field and one retry field on a queued send (#8743)
- improvement(desktop): Electron E2E for desktop tool lifetimes against a live local Sim (#8697)
- refactor(mothership): one re-queue policy and one send payload, and keep a Stop-failed send waiting for the user (#8740)
- refactor(desktop): one forward-only state per recorded tmux run, and one check for a delivered result (#8737)
- improvement(outbox): load handler modules only for the event types a run will process (#8731)
- improvement(cron): only start outbox and file-search passes when work is due, via a shared scheduled-pass helper (#8713)
- improvement(triggers): move TRIGGER_TYPES to a dependency-free module (#8711)
- perf(cli): load a manual run's draft once and keep embedded CLI results lean (#8625)
- improvement(trigger): downsize connector sync and document processing machines (#8699)
- improvement(tables): read row counts and versions through an append-only change log (#8653)
- perf(sandbox): grant the run_code session lease in the reconnect instead of extra E2B round trips (#8621)
Bug Fixes
- fix(code-placeholders): reject arithmetic comparisons and heredoc operands (#8760)
- fix(desktop): poll desktop activity only for users with a desktop, keep XDG zsh configs integrated (#8785)
- fix(audit): harden data drains and expand security event coverage (#8778)
- fix(executor): preserve stop-after across pause and resume (#8776)
- fix(billing): converge Stripe subscription syncs and stop webhook echoes overwriting unsynced changes (#8764)
- fix(docs): publish full LLM text as a static asset (#8769)
- fix(docs): prerender complete LLM documentation (#8767)
- fix(tables): stop the fold sweep from starting a page query past its budget (#8766)
- fix(mothership): cancel desktop tools a signed-out turn starts late, guard the shown-once license key (#8757)
- fix(sandbox): keep reused E2B workbench leases within the runtime cap (#8758)
- fix(settings): protect generated keys and identity transitions (#8761)
- fix(mothership): use a spinner while workflow resources load (#8756)
- fix(mothership): close a pre-aborted SSE stream, keep the new-chat effort across a failed first send (#8754)
- fix(desktop): stop a run the model never got the result of (#8749)
- fix(outbox): log unloaded handler modules as a failure, not a completed run (#8755)
- fix(desktop): linear path trim, prompt Stop between keystrokes, clear a closed session's input marker (#8753)
- fix(ci): count both sides of a rename in the desktop live gate, keep canary reports (#8751)
- fix(desktop): keep a chat-view import alive while it works, by the lease its session renews (#8742)
- fix(mothership): a pure resend verdict, and Send-now drops a message the server already has (#8744)
- fix(mothership): send a late queue write to the chat a new-chat queue moved to (#8741)
- fix(desktop): leave a stopped native file tool's outcome to Stop (#8732)
- fix(mothership): keep a failed direct send ahead of follow-ups queued during its POST (#8738)
- fix(mothership): decide once whether a queued send may already be on the server (#8727)
- fix(desktop): frame each tmux format record so a newline in a field cannot forge a pane (#8725)
- fix(desktop): stop the agent's tmux runs a previous process left going (#8722)
- fix(mothership): retry a send that failed while the browser stayed online (#8726)
- fix(mothership): claim under the chat lock in the Stop-versus-recovery settlement test (#8728)
- fix(ci): tidy stop-session.sh scans, listings and arguments (#8724)
- fix(settings): prevent false unsaved prompts and preserve drafts (#8704)
- fix(mothership): keep any queued send the server may already hold from being edited (#8723)
- fix(desktop): run an agent command on tmux that cannot tag its pane, untracked (#8705)
- fix(ci): match E2E app tags literally, make them unique per run, and never stop the caller (#8721)
- fix(mothership): keep a withdrawn first message held at the queue head as written (#8717)
- fix(events): authorize the events queued before a stream opens once (#8718)
- fix(desktop): read tmux format output with a separator no tmux version escapes (#8720)
- fix(mothership): run same-workflow workflow tools in order instead of failing as busy (#8709)
- fix(webhooks): skip duplicate webhook deliveries already in progress instead of polling (#8712)
- fix(ci): stop the detached telemetry flush too, re-signal stragglers on a monotonic clock, and report HTTP E2E failures by route (#8706)
- fix(mothership): keep a chatless surface's queue across remounts and contain hung chat hook tests (#8707)
- fix(events): start every SSE response once its subscriptions are live (#8700)
- fix(chat): resolve a new chat's history entry to the chat route on Back, and say when an effort save fails (#8703)
- fix(analytics): protect production Google measurement (#8710)
- fix(mothership): close the remaining ways a chat send is lost, resent hot, or polled after unmount (#8695)
- fix(e2e): compile every timed route first in the HTTP suites and stop sessions completely (#8701)
- fix(mothership): prune composer contexts during render so fast typing cannot trip the update-depth limit (#8702)
- fix(plane): validate webhook fields by registration mode (#8698)
- fix(ci): stop each HTTP end-to-end app fully and start the next from an empty dev cache (#8686)
- fix(plane): correct tile styling and capped connector syncs (#8690)
- fix(mothership): keep a message the server never admitted instead of dropping it (#8674)
- fix(mothership): re-attach at once when the user returns to a recovered stream (#8675)
- fix(mothership): re-read the transcript until the server has saved a finished turn (#8676)
- fix(desktop): inbox persistence order, desktop-only overdue sweep, and ungated pickup windows (#8685)
- fix(mothership): end desktop tools at sign-out and settle held reports as final (#8673)
- fix(copilot): store tool file outputs from workspace chats under the Copilot user (#8680)
- fix(mothership): keep local file tools running when the chat view changes (#8666)
- fix(mothership): keep a new chat's effort pick changed while its first send is pending (#8662)
- fix(sandbox): judge session lease coverage from the request's own clock reading (#8665)
- fix(mothership): fail unclaimed desktop calls fast and stop dropping them silently (#8652)
- fix(mothership): default chat effort back to high (#8659)
- fix(projects): revoke banned users' keys first and create imported workflows atomically (#8657)
- fix(executor): unwrap boxed primitives by internal slot when checking JSON serializability (#8658)
- fix(mcp): treat different URL credentials as a new destination (#8656)
- fix(mothership): roll back a failed effort save by pick, not by value (#8655)
- fix(mothership): refuse desktop claims for unapproved or stopped calls (#8643)
- fix(seo): make content pagination indexable (#8651)
- fix(projects): restore workspace deletion and tighten Project lifecycle (#8631)
- fix(executor): fail a stop-after run whose routing skips the stop block (#8635)
- fix(credentials): keep the field-less GitHub App installation out of v2 provider discovery (#8632)
- fix(code-placeholders): reject shell arithmetic placeholders (#8628)
- fix(mcp): restrict MCP server destination changes to admins (#8629)
- fix(logs): keep a block log's file size from changing after the block completes (#8626)
- fix(executor): drop the full JSON clone of execution state at run completion (#8620)
- fix(chat): label simple effort options with the effort they send (#8619)
Other Changes
- ci: duration-balanced integration shards, warm desktop-live, CI on every PR (#8763)
- ci: faster, cheaper, consistently named CI (#8750)
- test(desktop): pin the journal snapshot before recovery, keep start going when the journal cannot load, and run tmux in the canary E2E (#8739)
- test(desktop): stop the agent's terminal commands in the real app, with real shells and real tmux (#8733)
- test(mothership): stop the online case of the accepted-resend test passing without its history check (#8730)
- chore(nextjs): upgrade to 16.4.0 (#8729)
- chore(trigger): fix queues that never serialized and schedule missing self-hosted crons (#8715)
- chore(table): remove unused table-update background task (#8708)
- docs(library): update 6-best-ai-observability-tools-for-production-agents-in-2026 (#8689)
- test(desktop): keep the SQL and TypeScript desktop-call classifiers in agreement (#8694)
- docs(library): update best-ai-agents-for-lead-enrichment-2026 (#8687)
- docs(library): update sim-vs-dedicated-chatbot-builders (#8684)
- docs(library): update top-ai-assistants-2026 (#8683)
- docs(library): update ai-agent-examples-by-department-and-industry (#8682)
- docs(library): update open-source-ai-agent-platforms (#8679)
- docs(library): update best-multi-agent-frameworks-2026 (#8678)
- test(mcp): exercise the real destination check in lifecycle tests (#8664)
- docs(workflows): describe what still runs when a stop-after target is ruled out (#8663)
- docs(library): update sim-open-source-zapier-alternative (#8646)
- docs(library): update ai-agents-in-procurement (#8648)
- docs(library): update mcp-security (#8649)
- docs(library): update aeo-vs-geo-what-answer-engine-and-generative-engine-optimization-actually-mean (#8647)
- docs(library): update ai-agent-observability (#8645)
- docs(library): update best-ai-agents-for-customer-support-automation (#8642)
- docs(library): update dify-alternatives (#8641)
- docs(library): update langgraph-alternatives (#8640)
- chore(terms): update terms of service (#8636)
- docs(library): update agentic-ai-coding-tools-what-they-are-and-how-the-top-options-compare (#8612)