Evidence record / openhands

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-07-01-openhands-oss-line-received-no-new-tag-in-window-newest-non-cloud

OSS line received NO new tag in-window: newest non-cloud tag is still 1.8.0 (2026-06-10) (channel: main-unreleased, 2026-06-24). Operator consequence: Self-hosted / OSS operators get no security relief this window: the dependency-CVE fixes that landed on main and were cut into cloud-1.39.0/1.40.0 are NOT available in any OSS release tag. Anyone pinning to OSS 1.8.0 remains exposed to the pyjwt/tornado/aiohttp/opentelemetry/protobufjs/ws CVE set unless they build from main. Watch for an OSS 1.9.0. Full receipted detail lives in harvest/watchlist.md.

Receipt

Finding metadata

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Finding ID: 2026-07-01-openhands-oss-line-received-no-new-tag-in-window-newest-non-cloud

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact