Skip to content
Guidance/Daily Briefing
digesteveryonedigestevidenceradarmodelcli8 min read · Aug 5, 2026

Radar brief — 2026-08-05

Security hardening and session control dominate: Claude Code masks sandbox credentials, Goose patches a CLI RCE path, Cline locks plan mode, and Codex ships safer cyber-model defaults plus plugin/thread upgrades.

What the evidence shows

Curated signals favor versioned GitHub releases (≈55% GitHub/changelog mix). Highest-signal items cluster on security, agent/session UX, MCP/plugins, and model routing — with several prereleases adding noise.

Claude Codev2.1.221
Key Signal & Impact
VS Code Focus view hides tool noise behind per-turn summaries (Ctrl+Alt+F). Linux/WSL sandbox gains mode: "mask" for credential files (sentinel + egress substitute); macOS falls back to deny. Broad agent/MCP/settings surface churn.
OpenAI Codex CLIrust-v0.146.0
Key Signal & Impact
Named sessions (/new, /clear), pin/switch side conversations, thread forks (incl. temporary), Agent Plugins manifests + marketplaces (Bedrock, Claude Code), app-server ↔ remote Code Mode over WebSocket.
OpenAI Codex CLIrust-v0.145.0
Key Signal & Impact
Experimental paginated thread history/resume/search; /import migrates Cursor & Claude Code settings, MCP, plugins, sessions, memories; experimental Bedrock login; GPT-5.6 Sol default on Bedrock.
OpenAI Codex CLIrust-v0.146.1
Key Signal & Impact
Safer automatic-review defaults for cyber-capable models; permission changes explained in the terminal UI.
Goosev1.44.0
Key Signal & Impact
Security: arbitrary command execution via goose review / git core.fsmonitor (GHSA-r5pp-p5r8-466r). Also latest Gemini models, Stop-hook working_dir, Sakana/Fugu provider.
Clinev4.1.4
Key Signal & Impact
Plan mode is human-driven only (no model plan→act flip). Hard-blocks file-editing shell, redirects, mutating git, package installs in plan mode. Skills shown with workflows; Chutes provider recognized.
Clinedesktop-v0.0.8
Key Signal & Impact
Edit any earlier message → fork session, restore workspace checkpoint, re-run. Transactional/atomic restores; more reliable checkpoints after restart/compaction/resume.
Clinesdk/v0.0.67
Key Signal & Impact
Reasoning effort/budget normalized from models.dev catalog; Anthropic thinking modes handled; OpenRouter default → anthropic/claude-sonnet-5.
Google Antigravity1.1.10
Key Signal & Impact
Business sign-in for Gemini Enterprise (Cloud project auth, seat/license, regional inference, org admin controls).
Zed AIv1.15.0-pre
Key Signal & Impact
git.diff_base (HEAD vs default-branch merge base); drag files from Project Panel to external apps (macOS/Linux Wayland); JSX/TSX linked editing + Emmet in arrow/return bodies. Prerelease.
OpenCodev1.18.5
Key Signal & Impact
Adaptive thinking / Responses phase fixes; Mistral reasoning history + prompt-cache stability; MiniMax thinking variant fix; server terminal/review/discovery updates.
Windsurfv3.6.27
Key Signal & Impact
Windows cert-store loading fixed for TLS-inspecting proxies; Devin Local edit/write/apply_patch/notebook_edit refuse writes through symlinks.
Gemini CLIv0.54.0-preview.0 / v0.55.0-nightly.*
Key Signal & Impact
Preview/nightly train: HTTPS enforcement for Google creds, session ID rotate on model fallback, capacity exhaustion as terminal, InvalidStreamError UI propagation, Antigravity agent-runner work. Prerelease.
xAI Grok CLI (Grok Build)ed6d543
Key Signal & Impact
ACP session resume/close; cap live workflow subagents at 16; model switch during plan approval; extract MCP images before truncation; sandbox no longer refuses start on large deny-glob walks.

For developers

  • Patch Goose now if you run ≤ v1.44.0 — treat GHSA-r5pp-p5r8-466r as urgent; don’t leave goose review exposed on untrusted repos until upgraded.
  • Claude Code v2.1.221: try Focus view when long tool traces drown the chat; on Linux/WSL, prefer sandbox mode: "mask" for credential files instead of blanket deny where you still need egress auth.
  • Cline v4.1.4: plan mode is stricter — investigation stays read-only; don’t expect the model to self-promote to act. Use skills/workflows from the slash menu deliberately (name collisions no longer silently shadow).
  • Cline Desktop v0.0.8: use mid-thread edit + checkpoint restore to rewind bad turns without manual git archaeology; failed restore should not half-apply.
  • Codex CLI 0.145→0.146.x: /import is the fast path off Cursor/Claude Code; use named sessions, pins, and temporary forks for parallel spikes; if you touch cyber-capable models, keep 0.146.1’s safer auto-review defaults.
  • OpenCode v1.18.5: worth grabbing for Mistral cache/history and Claude adaptive-thinking breakage; skip the PR screenshot/video “releases.”
  • Windsurf: symlink write refusal is a real foot-gun fix — don’t rely on approved edits that path through links.
  • Gemini CLI / Zed pre / Grok commit builds: fine for personal experimentation; pin only if you need a specific fix (HTTPS creds, subagent cap, git.diff_base).

For teams

  • Security desk: prioritize Goose v1.44.0 (RCE advisory), Windsurf v3.6.27 (symlink write + enterprise CA/proxy), Claude Code credential masking, and Codex 0.146.1 cyber-model review defaults in the same change window.
  • Plan/act policy: Cline’s hard plan-mode blocks are enforceable control, not prompt theater — good baseline for regulated or junior-heavy fleets; document that models can no longer self-switch to act.
  • Enterprise identity: Antigravity 1.1.10 Business sign-in maps Gemini Enterprise seats, region, and admin controls — evaluate if you standardize on Google Cloud terms rather than consumer auth.
  • Migration: Codex /import (Cursor/Claude settings, MCP, plugins, sessions, memories) reduces dual-tool drift; pair with plugin marketplace allowlists (Bedrock/Claude Code manifests in 0.146.0).
  • Session governance: Codex thread pin/fork + Cline transactional checkpoints support audit-friendly “try, rewind, re-run” without discarding the parent thread — define retention expectations for temporary forks and restored workspaces.
  • Prerelease gate: Zed v1.15.0-pre and Gemini nightlies/previews stay off default golden images until stable tags; track git.diff_base and Antigravity-runner work for the next stable cut.

What to ignore

  • OpenCode pr-38252-videos and pr-37967-screenshots-final — erification artifacts, not product releases.
  • Dense Gemini nightly bump chains without clear user-facing notes — useful only if you are reproducing a named core fix.
  • Raw “+N more changes” bulk without security/session/MCP impact — noise relative to the scored signals above.
  • Open proposals at P5 (Codex 0.145/0.144.6, Cline 4.0.7, Grok sync, OpenCode videos/1.18.5, Zed 1.13.0-pre, Goose 1.44.0) — backlog ideas, not evidence of shipping priority.

Watch next

  • Claude Code follow-through on skills / context-files / permissions surfaces flagged alongside Focus view and mask mode.
  • Codex Agent Plugins marketplace adoption and stability of remote Code Mode WebSocket hosts.
  • Goose post-advisory residual risk (any remaining git-hook or review entry points).
  • Cline whether plan-mode hard blocks expand to more tool classes; Desktop checkpoint UX under multi-root workspaces.
  • Gemini CLI preview → stable promotion of HTTPS credential enforcement and capacity-exhaustion terminal behavior.
  • Zed git.diff_base landing in a non--pre tag.
  • Windsurf/Devin Local: any broader symlink/path-canonicalization policy beyond edit tools.

How to use DevAgentRadar

  • Read What the evidence shows first — every row is tied to a versioned URL in the evidence set; nothing is inferred from marketing.
  • Developers: apply individual version actions (patch, toggle, migrate) on your own machine before changing team defaults.
  • Teams: batch security-tagged upgrades (Goose, Windsurf, Codex cyber defaults, Claude mask mode) and treat prereleases as observe-only.
  • Ignore low-signal PR artifact tags and stale improve-with proposals unless they map to a current version in the table.
  • Re-check GitHub release pages for the listed assistants when themes shift (security, mcp, breaking) — this brief is a radar slice, not a support contract.

Evidence appendix

  • Evidence window: top curated signals (versioned releases preferred)
  • Assistants tracked: 22
  • Signals in this brief: 18
  • Trusted source mix (GitHub/changelog vs HTML): 55%
  • Open improvement proposals: 8
  • Sources reporting errors: 0

High-signal releases used

  • Claude Code v2.1.221: [VSCode] · Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with — source

  • OpenAI Codex CLI rust-v0.146.0: Name new sessions with /new or /clear, pin important threads, and switch between side conversations without closing them. (#34605, #34840, #35011) · Support — source

  • Zed AI v1.15.0-pre: This week's release includes a new git.diff_base setting for choosing whether editor gutters, file-status colors, and git: diff show uncommitted changes aga — source

  • Google Antigravity 1.1.10: Added Business sign-in for Gemini Enterprise accounts, so you can authenticate with a Google Cloud project under Google Cloud terms, use a license seat allocate — source

  • OpenAI Codex CLI rust-v0.145.0: Added experimental paginated thread history with efficient resume, search, persisted names, sub-agent support, and memories. (#33364, #33907, #34085, #34229, #3 — source

  • Goose v1.44.0: Arbitrary command execution in goose CLI via goose review (via git core.fsmonitor config) - [GHSA-r5pp-p5r8-466r](https://github.com/aaif-goose/goose/security — source

  • Cline desktop-v0.0.8: Edit any earlier message in a conversation — the app forks the session at that point, rewinds the workspace to that run's checkpoint, and re-runs from your edit — source

  • Cline v4.1.4: Recognize Chutes as a provider. · Show skills alongside workflows in the slash command menu, and disambiguate commands that share a name instead of letting one — source

  • Cline sdk/sdk/v0.0.67 — Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each p — source

  • OpenAI Codex CLI rust-v0.146.1: Apply safer automatic-review defaults for cyber-capable models and explain permission changes in the terminal interface. (#37057) · #37057 [0.146] Backport safe — source

  • OpenCode v1.18.5: Improve Claude adaptive thinking handling across more response shapes. · Avoid OpenAI Responses phase handling that could break some conversations. · Preserve g — source

  • Gemini CLI v0.54.0-preview.0: Changelog for v0.53.0-preview.0 · Changelog for v0.52.0 · chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 · fix(caretaker): sanitize and wrap — source

  • Gemini CLI v0.55.0-nightly.20260729.g3499c84f7: chore/release: bump version to 0.54.0-nightly.20260728.gbef611950 · feat(pr-generator-db): implement Firestore concurrency dual-locking and test ingestion utili — source

  • Gemini CLI v0.55.0-nightly.20260801.gf47d6c6f7: fix(core): classify capacity exhaustion as terminal to prevent retry hangs · fix(core,cli): propagate InvalidStreamError details to UI for specific empty respon — source

Open proposals

Was this guidance useful?

Anonymous · one vote per visitor · re-click to clear. Helps improve digests—not a product ranking.