Section

Platform

A coding agent becomes market infrastructure when its install path, plugins, UI, cloud surface, and defaults decide who can actually use it.

Platform covers how agent harnesses become usable products and ecosystems for new operators: install paths, distribution, packages, plugins, skills, SDK / CLI / GUI shape, cloud and enterprise packaging, integrations. The adoption and distribution lane - not a catch-all for everything platform-shaped. Evaluation, governance defaults, and sandbox policy belong to Control Plane or Runtime.

Other sections

July 2026

  1. 2026-07-02 / Codex

    Codex 0.142.5 stops writing full Responses WebSocket payloads to trace logs

    • Codex rust-v0.142.5 says full Responses WebSocket request payloads no longer go to trace logs.
    • Upgrade where traces are retained, centralized, or shared. Then restrict or purge older traces because the old behavior may have logged prompts, repo content, or secret-bearing tool inputs.
  2. 2026-07-01 / OpenHands

    OpenHands shipped its dependency-CVE fixes on the cloud channel; the OSS 1.8.0 line is frozen and a new CVE already sits untagged on main

    • Last window's unreleased dependency-CVE batch reached tags this window -- but only on the CLOUD channel: cloud-1.39.0 (2026-06-24, ~16-item CVE/dependency batch) and cloud-1.40.0 (2026-06-26, a 4-item CVE/GHSA batch). The OSS line got NO new tag; the newest non-cloud release is still 1.8.0 (2026-06-10).
    • It is worse than merged-vs-shipped: it is now cloud-vs-self-host. A managed OpenHands Cloud tenant is patched; a self-hoster on the 1.8.0 tag is not, with no fixed OSS tag to move to. And a fresh authlib CVE (CVE-2026-44681 -- an unauthenticated open redirect in Authlib's OIDC grant, CWE-601, phishing-grade at CVSS 6.1; commit e6fe505) already sits on main after cloud-1.40.0 -- untagged again.
    • Determine your channel and act on it: on Cloud, you are covered; on the OSS 1.8.0 tag, you are unpatched for this batch and must either run a build from main (inheriting all its churn) or wait for an OSS tag that has not come for three windows.

June 2026

  1. 2026-06-24 / OpenHands

    OpenHands shipped a five-item dependency-CVE batch to main on 2026-06-23 -- in no tagged release

    • A batch of dependency security fixes landed on `main` on 2026-06-23 -- CVE-2026-44727 (jupyter-server 2.20.0), CVE-2026-49458 (dompurify 3.4.6), GHSA-6v7p-g79w-8964 (msgpack 1.2.1), CVE-2026-45409 (idna 3.15), GHSA-gj48-438w-jh9v (bleach 6.4.0) -- but no tag was cut; the only release remains 1.8.0 from 2026-06-10.
    • Determine which channel you run. An operator on 1.8.0 has none of these fixes; an operator on a build from main has them. This is the same merged-vs-shipped gap that defined last window, now continuing into this one -- 'fixed' is true on main and false in the binary most operators run.
  2. 2026-06-23 / Gemini CLI

    Gemini CLI's Antigravity migration funnel reached stable

    • Stable v0.47.0 carries the Antigravity migration funnel: a built-in `antigravity-support` skill that hands users a `curl ... | bash` install of a separate `agy` binary (#27765), plus a removed five-show cap on the 'Antigravity is coming to town' banner so it now shows every session for free- and unpaid-tier users (#27676). The clearest sign yet of a managed succession — shipped to stable in the same release that left the skill path-traversal security fix in preview.
    • Operators should expect the migration prompt every session on free/unpaid tiers and treat the in-product `curl | bash` install of `agy` as a supply-chain decision, not a default to accept silently.
  3. 2026-06-23 / OpenClaw

    OpenClaw's WCAG 2.1 AA accessibility pass reached stable

    • PR #89822's WCAG 2.1 AA pass reached stable v2026.6.8 (June 16), having been beta-only last window: dark-mode contrast lifted to the 4.5-to-1 floor (verified >=4.8:1), real keyboard `:focus-visible` rings, and a 12-pixel font floor across 136 elements. The cleanest 'reached the operator' event of the fortnight.
    • Operators should verify their dashboard against the stable WCAG AA build — check dark-mode contrast and tab through for a visible focus ring; a previously beta-only accessibility capability is now on the default channel.
  4. 2026-06-13 / OpenClaw

    A WCAG 2.1 AA pass (beta) and a deliberate consent-over-convenience choice on search

    • OpenClaw shipped a measured WCAG 2.1 AA pass on its browser dashboard (contrast above 4.5:1, a focus ring, a 12px font floor across 136 elements) in a BETA tag (v2026.6.7-beta.1), plain-language mobile provider states, and pinned-commit ClawHub skill installs. It also made key-free web search an explicit opt-in (stable v2026.6.8), trading zero-config convenience for explicit consent on where queries egress.
  5. 2026-06-09 / Gemini CLI

    Google steers Gemini CLI users toward a separate Antigravity CLI

    • A transition banner exempted from the 5-show cap shipped to STABLE (v0.45.2) so 'Antigravity is coming to town' shows every session; a PREVIEW build (v0.47.0-preview.0) added in-product migration commands and a skill pointing to Antigravity CLI, a separate Google product. Reads as the start of a managed succession for Gemini CLI; track whether feature investment shifts to Antigravity and whether trust/policy semantics carry over.
  6. 2026-06-09 / Codex

    Codex ships one-click import of Claude Code and Cowork setup

    • App 26.608 added Migrate-to-Codex flows importing supported setup from Claude Code and Claude Cowork, including during onboarding: a defection on-ramp off Anthropic's coding agents and a concrete cross-tool config-portability surface.
  7. 2026-06-09 / Claude Code

    Anthropic's Fable 5 launches and is adopted across rival harnesses within days

    • Claude Code 2.1.170 shipped access to Claude Fable 5, a 'Mythos-class' model; OpenClaw and Pi added Fable 5 support within days (Pi with xhigh effort). A frontier model now reaches the long tail of agent harnesses in a week; the governance lever is the model-allowlist work (separate signal).
  8. 2026-06-09 / Codex

    Goal mode, worktrees, and inline review come to the iPhone

    • ChatGPT iOS 1.2026.153 added /goal, branch selection, worktree creation, and inline review comments. Persistent long-horizon objectives, env-isolated work, and code review now run from the smallest surface, widening who can drive serious agent work and from where.
  9. 2026-06-06 / Hermes Agent

    Hermes adds a desktop app, a browser admin panel, and remote-gateway connect

    • v0.16.0 'The Surface Release' adds a native Electron desktop app, a browser web-admin dashboard, and remote-gateway connect over OAuth or username/password, collapsing install-to-first-message to seconds and adding a new authority boundary (the dashboard auth gate) that operators exposing it must govern.
  10. 2026-06-05 / Paperclip

    Paperclip drops 'zero-human companies' for 'manage AI agents for work'

    • PR #7580 retires the 'zero-human companies' tagline for 'the app people use to manage AI agents for work', a repositioning its in-window engineering backs up (human board visibility, audited recovery, approval gates). Calibration signal: the autonomous-company metaphor is being repriced toward human-in-the-loop operating software.
  11. 2026-06-03 / Codex

    Amazon Bedrock integration runs Codex models under AWS-managed authentication and billing

    • An operator with AWS infrastructure can now run OpenAI models through Amazon Bedrock, moving authentication and billing under AWS IAM and cost allocation instead of an external OpenAI API path.
    • This reframes where the trust and identity boundary sits — Codex model calls become AWS-native, which changes compliance and credential-management decisions for AWS-policy organizations.
    • Verification path: provision Codex models via Bedrock, confirm IAM scoping and that no model traffic leaves the AWS-managed path before treating it as compliance-satisfying.
  12. 2026-06-03 / Codex

    Sites plugin (preview) adds in-app website and web-app creation and deployment

    • An operator can now create, deploy, and manage websites, dashboards, and web apps directly within Codex, removing the external-tool step for web deployment.
    • ChatGPT Business workspaces include Sites by default, so the operator decision is whether to allow/govern an in-product deploy surface that may already be enabled.
    • Verification path: confirm whether Sites is enabled in your Business workspace and whether agent-initiated deployments fit your hosting/governance policy before relying on it.
  13. 2026-06-03 / Gemini CLI

    v0.45.0 stable bundles terminal hardening, session-context cleanup, and an MCP blacklist-bypass fix

    • Operators on preview or older stable builds get a single upgrade decision: move to v0.45.0 to pick up Termux relaunch/resize fixes, session-context filtering on history resume, sequential tool execution for update_topic, Vim keybinding fixes, and an MCP blacklist-bypass prevention fix.
    • The MCP blacklist-bypass prevention is the security-bearing item: it closes a path where a blacklisted MCP tool/server could still be reached, so operators relying on MCP allow/deny controls should upgrade before trusting the blacklist.
    • Verification path: release tag v0.45.0 notes (published 2026-06-03T01:05:14Z) enumerate the bundled fixes.
    • Single composite upgrade decision - bundled small fixes all gated on 'upgrade to v0.45.0' stay one signal.
  14. 2026-06-03 / Gemini CLI

    CI labeler switched to pull_request_target, granting write context to fork PR runs

    • Contributors and maintainers should note the PR-size labeler now runs under pull_request_target, which executes in the base-repo context with write-capable token access on fork PRs.
    • This is the classic pwn-request surface: pull_request_target with any checkout or execution of fork-controlled content can leak the elevated token; operators forking or auditing the repo's CI should confirm the workflow does not check out and run untrusted PR code.
    • Verification path: .github/workflows/pr-size-labeler.yml line 4 trigger change from pull_request to pull_request_target.
    • Single decision for the repo-security auditor: review this workflow's token scope and whether it touches fork-controlled inputs.
  15. 2026-06-03 / Agent Zero

    Remote Link renamed to Remote Control with selectable tunnel providers and handshake version advertisement

    • Operators managing distributed deployments must update remote-connectivity terminology (Remote Link -> Remote Control) and can now choose among Cloudflare, Microsoft Dev Tunnels, Serveo, and Tailscale
    • Version advertisement in connector handshakes lets CLI clients detect server compatibility, changing how operators coordinate client/server upgrades across a fleet
  16. 2026-06-03 / OpenHands

    Upgrade frontend deps (axios 1.16.0, dompurify 3.4.0) to close CVE-2026-44492 and CVE-2026-41238

    • Two browser-facing frontend dependencies were patched in the window: axios to 1.16.0 (CVE-2026-44492, commit 73d1d9a) and dompurify to 3.4.0 (CVE-2026-41238, commit b025cd2). Two commits, one operator action: rebuild and redeploy the frontend bundle.
    • Self-hosters pinning older lockfiles must bump both manually; a stale frontend build leaves both CVEs live.
  17. 2026-06-03 / Flue

    v0.9.0 breaking app-config migration: routing/provider imports, provider-ID format, SDK mount paths, and beta session-state reset

    • Upgrading to v0.9.0 forces a developer to rewrite application imports: routing moves from `@flue/runtime/app` to `@flue/runtime/routing`, provider APIs and `observe` come from `@flue/runtime`, and Workers AI types from `@flue/runtime/cloudflare` — code will not compile until updated.
    • Provider model values now require `provider-id/model-id` format and `registerProvider()`/`configureProvider()` must share one ID; SDK mount paths now derive from `baseUrl` pathname — both are silent runtime-behavior changes that mis-route calls if not updated.
    • Persisted beta session state is now rejected; the operator must clear or migrate the session store before upgrading or sessions fail to restore — a distinct destructive pre-upgrade step gated on the same v0.9.0 cutover.
    • All of these share one verb (update-before-upgrade) for one persona (the Flue app developer) and one verification path (build + smoke-test against v0.9.0), so they route as a single platform migration signal.

May 2026

  1. 2026-05-27 / OpenHands

    OpenHands becomes the GUI shell for other harnesses, with org-level LLM profiles

    composes with Claude Code , Codex , Gemini CLI

    • Evaluators of OpenHands as a multi-agent shell: enable `ENABLE_ACP` against your preferred ACP back-end (Claude Code, Codex, Gemini CLI) and test the policy surface — the greyed-out settings while ACP is active are intentional.
    • Multi-tenant SaaS operators must confirm they are on 2026-05-22+ to get the MCP/ACP env scoping fix. Audit MCP credentials that may have been shared across org members pre-fix.
    • Enterprise admins should treat the org-level LLM profile model as the canonical place to set 'this org uses these models' policy.
    • Operators on the release channel need to know none of this is in a tagged 1.x release yet — main-branch only.
  2. 2026-05-27 / Hermes Agent

    Hermes ships PyPI, lazy adapter install, native Windows beta

    composes with Aider , Cline , Codex , Continue

    • Builders who bounced off the prior clone-and-shell installer should re-evaluate Hermes — `pip install hermes-agent` plus lazy adapter install plus Windows beta plus Zed ACP Registry listing materially lower the floor.
  3. 2026-05-12 / Pi Coding Agent

    Package scope migration to earendil-works; harness SDK stream config

    • Operators with global Pi installs should run `pi update --self` once @earendil-works/pi-coding-agent is published to migrate from the old @mariozechner scope.
    • Operators with Pi pinned in CI, Dockerfiles, or package.json by the old @mariozechner/pi-coding-agent name should update their references to @earendil-works/pi-coding-agent.
  4. 2026-05-12 / OpenClaw

    Per-agent message restrictions, gated code install, and onboarding wayfinding

    • Operators deploying public-facing or sandboxed agents should evaluate `tools.message.crossContext` and `tools.message.actions.allow` overrides to restrict agent message sends to the current conversation without changing the global bot policy.
    • Operators running long-horizon OpenClaw sessions should know that session memory is now bounded: the memory dreaming promotion cap compacts oldest auto-promoted sections while preserving user-authored notes. Unbounded auto-memory growth is no longer the default behavior.
    • Operators deploying OpenClaw for new users should test the improved CLI onboarding wayfinding: setup, onboarding, configure, and channel commands now explain the next useful command at each step.
  5. 2026-05-12 / Hermes Agent

    Hermes drops mistralai from [all] extras after PyPI quarantine of 2.4.6

    • Operators who installed hermes-agent[all] on or around 2026-05-12 should verify whether mistralai==2.4.6 is present in their environment and remove it if so.
    • Operators needing Mistral Voxtral TTS must switch to explicit hermes-agent[mistral] install; it no longer ships in [all] while quarantine is active.
  6. 2026-05-12 / Flue

    Flue: programmable harness with run observability, virtual sandbox, and shell env security fix

    • Operators using shell env for credentials in pre-v0.4.1 Flue sessions should verify their session store does not contain unredacted values — the v0.4.1 shell env redaction fix is a security patch.
    • Operators using `sandbox: 'local'` should re-test: it is now genuinely local (direct host access, no just-bash), changing the isolation boundary for agents running in CI.
    • Operators building on Flue should evaluate `flue logs` and run history (v0.5.0) as the primary evidence trail for autonomous agent invocations.
  7. 2026-05-07 / OpenHands

    Agent harnesses are becoming full development platforms.

  8. Accessibility is becoming a frontier capability.

  9. Accessibility is a frontier capability, not marketing polish

    • Everyday adoption depends on setup recovery, visible progress, voice/chat surfaces, readable UI, OAuth clarity, and fewer dead ends.
  10. Integrations are volatile; the operating loop has to be durable

    • Provider lists, plugin systems, transports, and model profiles will keep changing.
  11. Plugin, extension, and skill ecosystems are becoming the integration surface.

    • The practical power of worker CLIs increasingly depends on plugins, hooks, extensions, skills, and transport modules, not just the base model.
  12. Worker integrations are not durable doctrine.

    • Pi removed built-in Gemini CLI and Antigravity support while adding many providers; Gemini preview/nightly channels differ materially; Codex alpha releases and app-server surfaces move quickly.

<- All signals