Toolsnono Kernel-Enforced Zero-Trust Sandbox for AgentsGitHub·high signalXBlueskyLinkedInCopy linkZero-trust sandbox with kernel-level enforcement seccomp namespaces. Atomic rollback and cryptographic audit chain. 642 stars in 27 days. Heavier than lighter sandboxes.SourceSource pageGitHub↳ Follow the threadPolicy dependency / Threat patternWeaviate v1.39.2 makes its MCP server stateless and refuses GET with a 405GitHubPolicy dependency / Stack layerCherry Studio v2.0.9 unifies tool approval into one declarative policy and lets the provider catalog hot-update without an app releaseGitHubPolicy dependency / Stack layerHalofy ships an open governance layer for agents with identity, policy, provenance, audit and signed erasureGitHubStack layer / ContrastCopilotKit shipped three tags in six days including a same-day Python SDK release, at 37,068 starsGitHubStack layer / ContrastGradient open-sources a full reinforcement-learning loop for training tool-using research agents with GRPOGitHubThreat pattern / Update threadHolmesGPT 0.40.0 is almost entirely a security release: command injection across five toolsets, SSRF, and signed bash approval prefixesGitHubPolicy dependency / Stack layerOmniRoute broke a 27-day release silence with v3.8.50 on August 26 and maintains a rolling provider-catalog export tagGitHubStack layer / Update threadUnsloth v0.1.803-beta adds experimental auto compaction that keeps evicted turns searchable past the context limitGitHub