Fetching from the wire…
Tools2026-09-13 · source-backed
PR #10305 fixes trace-capture evaluation so a crash on one example assigns failure_score instead of dropping the row, which previously caused an indexing error or silently shifted every later result. The release ties that to missing and misaligned validation results reported against 3.3.1, and the fix needs no upstream GEPA upgrade. PR #10212 adds code_proposer= alongside instruction_proposer=, handing custom proposers the selected Flex code components, candidate source, reflective examples, task descriptions and context blurbs, and taking back replacement module source per component. Anyone who ran GEPA optimization on 3.3.1 should rerun it, because a silent off-by-one in validation rows means your selected candidate may be wrong.
Each link below shares sources, entities, or timing with this story.
Released August 3, experimental dspy.Flex moves program structure into the optimizer's search space: given a signature, GEPA rewrites predictors, control flow, and the Python/LM call balance against your metric, with optimizer-authored source always running inside a CodeInterp...
The September 11 prerelease bundles lm15 request/response/streaming types under dspy.lm15 and makes engine="auto" prefer native execution, selecting LiteLLM before execution only for unsupported routes or inputs that can't be represented faithfully. Auth failures, timeouts and...
This is my favorite research finding of the day. GEPA, an ICLR 2026 oral now shipping as dspy.GEPA, optimizes prompts by having an LM reflect in natural language on an execution trace, what went well, what failed, then evolving a tree of candidate prompts. Across six tasks it...
Here's the one you can act on today. DSPy shipped 3.3.0b1 with a new ReActV2 module, and if you're still hand-tuning prompt strings, you're doing manual labor a compiler should do. You declare a task as a typed Input to Output signature, pick a reasoning strategy, and MIPROv2...
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
A month ago, TeamPCP compromised Trivy's GitHub Actions runners. Then they trojanized LiteLLM on PyPI. Now Wiz Research confirms they've expanded to npm via a worm called CanisterWorm, using stolen publish tokens to push malicious packages across JavaScript's package ecosystem...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.