composes with: Codex
Every accepted signal whose underlying finding declares
composes: [codex]. Composition is one-directional from the
originating finding's perspective.
The Codex profile carries the current evergreen state for the Codex surface itself.
May 2026
-
OpenHands becomes the GUI shell for other harnesses, with org-level LLM profiles
composes with Claude Code , Codex , Gemini CLI
- Evaluators of OpenHands as a multi-agent shell: enable `ENABLE_ACP` against your preferred ACP back-end (Claude Code, Codex, Gemini CLI) and test the policy surface — the greyed-out settings while ACP is active are intentional.
- Multi-tenant SaaS operators must confirm they are on 2026-05-22+ to get the MCP/ACP env scoping fix. Audit MCP credentials that may have been shared across org members pre-fix.
- Enterprise admins should treat the org-level LLM profile model as the canonical place to set 'this org uses these models' policy.
- Operators on the release channel need to know none of this is in a tagged 1.x release yet — main-branch only.
Run: 2026-05-27-weekly-digest-2026-05-13_2026-05-27-frontier-v0
-
Hermes ships PyPI, lazy adapter install, native Windows beta
composes with Aider , Cline , Codex , Continue
- Builders who bounced off the prior clone-and-shell installer should re-evaluate Hermes — `pip install hermes-agent` plus lazy adapter install plus Windows beta plus Zed ACP Registry listing materially lower the floor.
Run: 2026-05-27-weekly-digest-2026-05-13_2026-05-27-frontier-v0
-
`hermes proxy`: local OpenAI-compatible endpoint backed by operator OAuth
composes with Aider , Cline , Codex , Continue
- Operators running `hermes proxy` on the documented loopback default (`--host 127.0.0.1`) inherit a low-risk posture; the proxy accepts client `Authorization` headers and strips them before attaching the Hermes OAuth upstream. Operators changing the bind to a non-loopback address must place their own auth in front of the port — the proxy itself does not authenticate local callers.
Run: 2026-05-27-weekly-digest-2026-05-13_2026-05-27-frontier-v0
-
Honcho identity mapping and credential-pool isolation
composes with Aider , Cline , Codex , Continue
- Multi-user gateway operators should upgrade past the Honcho commits (week of 2026-05-21) and the credential-pool isolation commit (2026-05-27) before running shared-thread deployments — these are quiet correctness fixes for cross-user contamination.
Run: 2026-05-27-weekly-digest-2026-05-13_2026-05-27-frontier-v0
-
Kanban corruption-hardening wave (post-v0.14.0)
composes with Aider , Cline , Codex , Continue
- Kanban-dependent multi-agent operators should treat the post-v0.14.0 line as the integrity-floor baseline; the corruption-hardening wave volume is the signal.
Run: 2026-05-27-weekly-digest-2026-05-13_2026-05-27-frontier-v0