Fetching from the wire…
Tools2026-09-23 · source-backed
PR #47389 moves managed HTTP clients onto a policy-aware request builder: every redirect destination checked before routing, a permit held while response bodies stream, WebSocket reads and writes under revocable permits, and policy denials made non-retryable. Four follow-ups extend it to app-server, AWS auth, telemetry and remote-control traffic. Before this, a redirect or an already-open socket walked around your destination allowlist.
Each link below shares sources, entities, or timing with this story.
upstash/context7 (60,590 stars) shipped @upstash/[redacted] on August 7 on the 2026-07-28 protocol revision. HTTP serving is now stateless for both modern and legacy clients, and Redis-backed sessions are gone, which is a real operational simplification for anyone self-hosting...
Commits #45806 and #46066 stop a subagent or spawned thread from installing a plugin or raising an MCP consent prompt on its own, and #46042 adds read-only policy support to MCP tool requests so a thread can be handed a server it may query but not mutate through. GitHub compar...
Published September 7, it puts OpenAI Codex in the agent picker with a copy-ready ~/.codex/config.toml panel pointing Codex CLI and Desktop at Manifest over the Responses API (GitHub). Two compatibility fixes make it work: Responses-API role: "developer" instruction messages f...
Released 01:58 UTC on September 1, demoting update_plan to opt-in, so you need tools.update_plan.enabled = true in config to get planning back (GitHub). It also adds output_token_limit per individual MCP tool with truncation that survives session resume, allows :, @, / and . i...
A single Rust binary running MCP and HTTP servers over a local data directory, at 7,975 stars with about 217 added September 22. Agents write observations through lifecycle hooks that consolidate into ordinary markdown you can grep, edit in Obsidian and diff as commits, with r...
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.