OpenHands thawed its open-source tags for four days, then refroze with the release sitting in draft
The open-source line, frozen at 1.8.0 since 2026-06-10, took six tags between 2026-07-06 and 2026-07-09 through 1.11.0, shipping the authlib fix and draining the backlog. Nothing has been tagged since. The 1.12.0 release pull request has been open in draft with a clean mergeable state since 2026-07-09 while cloud tags continued to ship, and a new high-severity vite advisory reached cloud only. The install documentation still directs self-hosters to the 1.8 image.
What this changes for operators
- Self-hosters should move to 1.11.0 rather than following the documented 1.8 image, which carries every advisory 1.9.0 closed, and should decide whether to track main for the vite fix or accept the exposure until a tag arrives.
Featured in
- Assume the Rule Does Not Bind / 2026-07-27
Run: 2026-07-27-weekly-digest-2026-07-02_2026-07-27-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-07-27-openhands-oss-tags-thawed-then-refroze
Research evidence and publication history are open in the repository.