Fetching from the wire…
Security2026-09-21 · source-backed
PR #46962, merged September 21, replaces raw error strings from config.load failures with typed metadata, because configuration load errors could print configuration values into a report people routinely paste into bug threads. New behavior reports file, line and column when a ConfigLoadError is available and otherwise only the I/O error kind. Regression snapshots assert both tested JSON reporting modes omit test credentials. A diagnostic command that dumps your config into a shareable artifact is a category of bug I'd bet exists in three more tools right now.
Each link below shares sources, entities, or timing with this story.
Ollama cut v0.34.0-rc1 on September 5 at 23:49 UTC, and the headline item changes the shape of the local-versus-hosted decision rather than the performance of either side: Ollama-hosted open models can be selected directly inside ChatGPT Desktop, with setup driven from the Oll...
Created September 19, a single-binary MCP server routing every command and file operation onto a remote host over your existing OpenSSH config, keys, agent and jump hosts in one multiplexed session (GitHub). The local machine exposes only allowlisted folders through local_ls,...
PR #44870, merged September 11 and in rust-v0.155.0-alpha.4, pulls worktrees out of /experimental. A local daemon missing thread/backgroundTerminals/list now blocks worktree creation and /cd with upgrade instructions rather than failing obscurely. The 80-commit window also wir...
PR #29214, merged September 11 and in nightly v0.61.0-nightly.20260912, stops --sandbox runs mounting the host user's persistent configuration and credentials. It replaces host directory mounts with sanitized config files, standardizes on realpath resolution during path-sensit...
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
Released 01:58 UTC on September 1, demoting update_plan to opt-in, so you need tools.update_plan.enabled = true in config to get planning back (GitHub). It also adds output_token_limit per individual MCP tool with truncation that survives session resume, allows :, @, / and . i...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.