Fetching from the wire…
Public story · 2026-09-06 · high
The alpha release also patches every High CVE and 60-day-old Medium in the image, and rotates the JWT before it expires instead of after a failed request.
Why now: HolmesGPT posted the 0.41.0-alpha release notes on September 6.
HolmesGPT's 0.41.0-alpha release, posted September 6, turns git-synced skills into a first-class skill_repos concept that refreshes live. Push a runbook skill to the repo and every running Holmes instance picks it up immediately.
For on-call teams, that cuts out a build-and-deploy cycle. Updating an SRE agent's diagnostic steps used to mean building and shipping a new image.
The same release clears a security backlog inside the image. Every High-severity CVE gets patched, and so do Mediums that had sat unpatched for more than 60 days. A separate fix rotates the realtime JWT before it expires, replacing a design where the token only refreshed after a request already failed with an auth error.
The release notes don't say how skill_repos decides when to refresh, or whether a bad skill push can be rolled back as fast as it went out. For a team pointing Holmes at a repo full of untested runbooks, that's the open question: live sync cuts deploy friction, but it also means a bad push reaches production alerts with nothing in between.
Each link below shares sources, entities, or timing with this story.
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
xintaofei/codeg is a Rust desktop app, self-hosted server and Docker image pulling transcripts from Claude Code, Codex, OpenCode, Pi and Grok Build into a shared multi-agent workspace, speaking both ACP and ADE. It's at 3,125 stars with 223 open issues, created February 9, pus...
magnitudedev/magnitude recommends models that fit your hardware, then downloads, tunes and serves them to Pi, OpenCode, Hermes, OpenClaw, Codex, Claude Code, Oh My Pi and Cline. Since the August 21 coverage, it cut three CLI releases inside 44 hours: 0.0.9 on September 1 at 07...
Anthropic released Claude Fable 5.1 on September 1. Claude Code v2.1.257 made it the default Fable model at 17:53 UTC that day, with a 1M-token context window, $10 per million input tokens, $50 per million output, and $0.25 per million on cache reads (claude-code CHANGELOG). B...
v0.1.117, tagged August 28 one day after v0.1.116 and pushed again today, is an MIT-licensed Rust tool that turns Claude Code, Codex or OpenCode into research agents that propose an idea, change code, launch an experiment and inspect evidence in a loop. Each run gets an isolat...
The CNCF Sandbox project shipped fixes on August 26 for command injection in the Kubernetes toolset plus slab, kubevela, inspektor_gadget and aks follow-ups, SSRF in fetch_webpage and connectivity_check, and hardening of kubectl-run to execute without a host shell (GitHub). Th...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.