Security
Securing agent workflows, outputs, and infrastructure
Build a playbook about Security
Save articles from this feed, then generate a personalized implementation guide
crewAI v1.15.17 introduces declarative conversational flows with opt-in conversational mode, improves tool handling with AMP slug support and oversized message chunking, and fixes critical bugs including MCP server configuration, agent scope closure, tool error attribution, and OpenAI Responses API compatibility. The release enhances security with SSRF checks per redirect hop and resolves native tool call issues.
★★★★★OpenAI Agents Python v0.22.0 is a minor release focused on runtime hardening and provider configuration improvements. Key changes include redacting blocked tool outputs from replay state, rejecting conflicting provider options when explicit clients are used, isolating usage accounting between RunState checkpoints, and expanding handoff agents in generated graphs. Applications combining explicit `openai_client` with `organization` or `project` parameters must migrate those values to the `AsyncOpenAI` client constructor.
★★★★★Claude Code v2.1.234 introduces environment variable configuration for project directories, GitLab merge request integration, automatic session continuation at usage limits, and significant security hardening against Windows NT-namespace path exploits. The release includes numerous bug fixes for session management, permission handling, markdown rendering, and Remote Control functionality, plus UX improvements for fullscreen mode and mid-turn command execution.
★★★★★OpenAI Agents Python v0.21.1 is a maintenance release featuring enhanced sandbox capabilities, improved timeout handling, and critical bug fixes across core, chat completions, realtime, and session management. Key additions include model call timeouts, run-scoped sandbox directories, Docker networking controls, and Modal sandbox resource options. The release addresses issues with call approval decisions, audio truncation, path normalization, and SQLite conflicts.
★★★★★OpenClaw v2026.8.1-beta.2 introduces critical security enhancements with secret egress host binding, expands AI model support (GPT-5.6 Ultra with Sol/Terra/Luna runtimes), and improves plugin lifecycle management through shared SDK monitors. Key additions include SQLite backup/restore capabilities, macOS app profile isolation, and enhanced Control UI reliability with better update recovery. The release strengthens security posture through plugin provenance warnings and trusted-source restrictions while improving user experience across channels, authentication, and workspace management.
★★★★★OpenAI Agents Python v0.21.0 is a minor release introducing provider-neutral testing APIs and OpenAI Python v3 compatibility. Key additions include new testing utilities for deterministic Agent, Sandbox, Realtime, and Voice workflows without provider requests, updated HTTPX2-aware request handling, and numerous hardening fixes across core, MCP, Sandbox, Realtime, and Voice modules. The release maintains backward compatibility while improving state isolation, error handling, and validation strictness.
★★★★★Claude Code v2.1.233 introduces GitLab merge request support, optional user identity forwarding for spend attribution, memory limits for Bash tools on Linux, and WebFetch cache configuration. The release includes multiple bug fixes for cloud sessions, MCP v2 connections, permission prompts, CPU usage, skill command handling, and Windows path validation. Several improvements enhance performance, error handling, and accessibility across different platforms and deployment scenarios.
★★★★★Claude Code v2.1.232 introduces major improvements to subagent forking, cross-session messaging, and security hardening. Key features include default subagent forking with prompt cache inheritance, @-mention syntax for direct session communication, GitLab marketplace support, and numerous security fixes for permission bypasses and credential handling. The release also enhances Remote Control stability, improves managed settings validation, and fixes various UI and performance issues.
★★★★★crewAI v1.15.15 introduces enhanced flow reporting capabilities with outcome, duration, and human-in-the-loop signal tracking. The release includes critical security updates for torch and gitpython dependencies, fixes for event emission during boundary hook aborts, and standardization of CLI flags to kebab-case. Bug fixes also address span export scoping to prevent tracer provider conflicts.
★★★★★Claude Code v2.1.228 is a maintenance release fixing critical bugs in interactive sessions, Git integration on Windows, model switching, cross-session messaging, and self-hosted runners. Key improvements include hardened skill syncing from claude.ai, better Vertex AI credential handling, improved UI feedback during compaction, and updated file-writing permissions for newer models. The release addresses 17 distinct issues spanning session stability, remote control functionality, plugin caching, and settings management.
★★★★★OpenClaw v2026.6.33 is a major security and reliability release featuring safer network boundaries with response size caps and credential protection, more reliable long-running agents with improved stall detection, stronger channel delivery for Discord and Telegram, safer credential recovery mechanisms, and support for extended-stable package updates. The release includes 169 merged PRs addressing authorization, tool authority, external tooling scoping, and numerous stability fixes across gateway, provider, browser, and webhook systems.
★★★★★OpenClaw v2026.6.34 is an extended-stable maintenance release focused on security hardening and reliability improvements without new features. Key enhancements include safer browser and network boundaries with sandboxed routes, more resilient agent and provider runs with improved session handling, stronger channel recovery mechanisms, safer operator diagnostics with credential protection, and more robust local runtime state management. The release includes 25 merged PRs addressing execution safety, delivery stability, and gateway reliability, with upcoming deprecations for Plugin SDK migration scheduled after July 24.
★★★★★Claude Code v2.1.225 introduces gateway spend-limit support with detailed cap information, adds workspace trust prompts for untrusted directories, and fixes critical issues including OAuth token handling, MCP server authentication failures on macOS, safety-filter refusal counting, cross-session message persistence, and conversation history corruption. The release also improves Remote Control functionality with direct photo handling and enhanced session messaging capabilities.
★★★★★Google ADK Python v1.38.0 release introduces safety settings forwarding to the Live API and addresses critical security and stability issues. Key improvements include preventing shell execution vulnerabilities in ReadFileTool, excluding problematic nltk dependency versions, fixing Live API agent transfers, and enhancing evaluation error handling. This release focuses on security hardening and reliability improvements for agent development.
★★★★★crewAI version 1.15.13 is a maintenance release focusing on bug fixes and documentation improvements. Key fixes include preserving LiteLLM provider routing, hardening LLM event-bus mocks, correcting Anthropic cache token usage reporting, and addressing a security vulnerability in the h2 dependency. Documentation enhancements include a new locale synchronization workflow and corrections to README links and contribution guidance.
★★★★★Claude Code v2.1.224 introduces self-hosted environments for running Claude sessions on custom machines, adds archive-based plugin installation with SHA-256 pinning, and implements cross-session messaging capabilities. The release includes enhanced sandbox credential-masking options, improved Remote Control connection handling, and numerous bug fixes addressing session management, file path resolution, and clipboard operations. Key security and stability improvements focus on credential protection, sandbox violation visibility, and preventing silent data loss in paste operations.
★★★★★Claude Code v2.1.223 introduces owner wildcard marketplace controls, improves security by fixing permission bypass vulnerabilities and sandbox escapes, and enhances model discovery and session management. Key updates include stricter command obfuscation prevention, workflow sandbox isolation fixes, and better handling of context windows across Claude models. The release also refines the code review workflow and improves managed settings merging for enterprise deployments.
★★★★★OpenAI Agents Python v0.19.4 is a maintenance release focused on stability and correctness across tool execution, guardrails, session management, and real-time features. The release includes 16 bug fixes addressing tool result preservation, error handling, concurrent operation cancellation, and streaming content filtering. Additional improvements cover sandbox token budgets, MongoDB session state enforcement, and deterministic test reliability.
★★★★★Claude Code v2.1.222 is a maintenance release focused on security hardening, bug fixes, and stability improvements. Key fixes address worktree isolation for destructive git commands, tool restriction bypasses in background tasks, proxy connectivity issues, and usage attribution accuracy. The release also improves auto mode safety, refines model selection precedence, and removes the ultraplan feature.
★★★★★OpenAI Agents Python v0.19.3 is a maintenance release focused on bug fixes and stability improvements across core agent functionality, session management, real-time features, and extensions. The release addresses 34 bug fixes including tool name collision resolution, guardrail reporting, streaming behavior, and session persistence. Key areas improved include MCP auto-pagination, sandbox hardening, real-time audio handling, and AnyLLM provider stream management.
★★★★★