Evidence record / openhands

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-07-01-openhands-cloud-1-39-0-tagged-2026-06-24-with-a-large-16-item-cve

cloud-1.39.0 tagged (2026-06-24) with a large (~16-item) CVE/dependency-security batch plus multi-model LLM discovery, Jira Data Center OAuth, and conversation limits (channel: tagged-release, 2026-06-24). Operator consequence: Cloud operators should upgrade and re-audit dependency posture: batch closes CVE-2026-48526 (pyjwt 2.13.0), CVE-2026-49855 (tornado 6.5.7), CVE-2026-54278 (aiohttp 3.14.1), CVE-2026-53539 (python-multipart >=0.0.30), CVE-2026-45409 (idna 3.15), CVE-2026-49458/GHSA-cmwh-pvxp-8882 (dompurify), CVE-2026-44727 (jupyter-server 2.20.0), CVE-2026-54283 (starlette 1.3.1), and ~8 more. New per-user Jira Data Center OAuth token persistence/injection and BYOK gating change how identity and model access are governed — study before enabling. Full receipted detail lives in harvest/watchlist.md.

Receipt

Finding metadata

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Finding ID: 2026-07-01-openhands-cloud-1-39-0-tagged-2026-06-24-with-a-large-16-item-cve

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact