diff --git a/docs.json b/docs.json index 48130b422..77c14e032 100644 --- a/docs.json +++ b/docs.json @@ -549,7 +549,21 @@ "enterprise/skills-and-plugins", "enterprise/plugin-marketplace", "enterprise/analytics", - "enterprise/release-notes" + { + "group": "Release Notes", + "icon": "rocket", + "pages": [ + "enterprise/release-notes/0.70.0", + "enterprise/release-notes/0.64.0", + "enterprise/release-notes/0.55.0", + "enterprise/release-notes/0.45.0", + "enterprise/release-notes/0.41.0", + "enterprise/release-notes/0.36.1", + "enterprise/release-notes/0.36.0", + "enterprise/release-notes/0.28.0", + "enterprise/release-notes/0.24.0" + ] + } ] }, { diff --git a/enterprise/release-notes.mdx b/enterprise/release-notes.mdx deleted file mode 100644 index b4ce91300..000000000 --- a/enterprise/release-notes.mdx +++ /dev/null @@ -1,1084 +0,0 @@ ---- -title: Release Notes -description: Release notes for OpenHands Enterprise -icon: clipboard-list ---- - -## 0.70.0 - -* **Refreshed UI** — Updated conversation and Settings experiences now align with OpenHands Agent Canvas for a more intuitive developer and admin experience. -* **Organization-Scoped Secrets** — Admins can create shared secrets for use across the Organization, reducing duplicate credential setup and centralizing access. -* **User Budget Dashboard** — Users can view their usage and monthly budget consumption under **Settings > Your Budget** for better spend visibility. -* **OAuth MCP Support** — Users can authenticate to MCP servers with OAuth, including supported services like GitLab and Atlassian Rovo, using their own identity. -* **Organization-Visible Automations** — Users can see Automations across their Organization, including who created them and which identity they run as; Admins can disable or delete them. -* **Automation Git Sync** — Admins can sync Automations with a Git repository for version history, backup, and pull request-based review workflows. - -### Enterprise Server - -#### Features -* feat: DB-driven free/default/verified model flags by @juanmichelini in https://github.com/OpenHands/enterprise/pull/191 -* feat: surface runtime ingress startup failures by @ak684 in https://github.com/OpenHands/enterprise/pull/332 -* feat: PLTF-3553 Add org condenser max_tokens rollout configuration by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/337 -* feat: enforce daily quota and surface structured 429 with settings link by @neubig in https://github.com/OpenHands/enterprise/pull/201 -* feat(budgets): add upgrade preflight and post-upgrade reconciliation gate by @hieptl in https://github.com/OpenHands/enterprise/pull/362 -* feat: add system_prompt and disabled_skills to conversation start API by @hieptl in https://github.com/OpenHands/enterprise/pull/335 -* feat(super-admins): flag-gate super-admin list discovery (OHE-3196) by @tofarr in https://github.com/OpenHands/enterprise/pull/390 -* feat(budgets): normalize per-member cycle baselines with provenance by @hieptl in https://github.com/OpenHands/enterprise/pull/365 -* feat: org-scoped secrets — backend Phase 1 (OHE-2568) by @tofarr in https://github.com/OpenHands/enterprise/pull/391 -* feat(analytics): emit PostHog events for HubSpot contact sync by @malhotra5 in https://github.com/OpenHands/enterprise/pull/392 -* feat(frontend): OpenHands-Neo settings theme aligned with agent-canvas by @FraterCCCLXIII in https://github.com/OpenHands/enterprise/pull/174 -* feat(secrets): org-scoped secrets UI — share checkbox and permission-gated actions [OHE-2568] by @tofarr in https://github.com/OpenHands/enterprise/pull/449 -* feat(mcp): run OAuth MCP installs from the app server by @hieptl in https://github.com/OpenHands/enterprise/pull/404 -* feat(conversations): add tags to start/update requests and a tags__contains search filter by @hieptl in https://github.com/OpenHands/enterprise/pull/432 -* feat: add exact name filter to GET /api/organizations by @hieptl in https://github.com/OpenHands/enterprise/pull/447 -* feat(budgets): show each user their own budget and usage by @hieptl in https://github.com/OpenHands/enterprise/pull/448 -* feat(orgs) : OHE-3303 : expose is_visible on organization listings by @tofarr in https://github.com/OpenHands/enterprise/pull/461 - -#### Bug Fixes -* fix: OHE-3155 : lazily repair free-tier LiteLLM allowlists on org upgrade by @tofarr in https://github.com/OpenHands/enterprise/pull/338 -* fix: refresh Bitbucket Data Center tokens for automation sandboxes by @ak684 in https://github.com/OpenHands/enterprise/pull/334 -* fix(budgets): recover missing member cycle baselines after upgrade by @hieptl in https://github.com/OpenHands/enterprise/pull/347 -* fix: restore Git identity after sandbox resume by @ak684 in https://github.com/OpenHands/enterprise/pull/333 -* fix(metrics): OHE-3110 : omit misleading "No budget limit" line in conversation metrics modal by @tofarr in https://github.com/OpenHands/enterprise/pull/349 -* fix: bulk-repair cross-user managed LLM key ownership by @ak684 in https://github.com/OpenHands/enterprise/pull/353 -* fix: expose desired and applied budget state by @ak684 in https://github.com/OpenHands/enterprise/pull/357 -* fix: fail budget maintenance on reconciliation errors by @ak684 in https://github.com/OpenHands/enterprise/pull/356 -* fix: gate Cloud on an explicit ACP provider allowlist by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/336 -* fix(sandbox): allow max_num_sandboxes=1 by accepting 0 in pause_old_sandboxes by @hieptl in https://github.com/OpenHands/enterprise/pull/386 -* fix: upgrade postcss to 8.5.18+ to fix path traversal vulnerability by @mamoodi in https://github.com/OpenHands/enterprise/pull/396 -* fix: Update js-yaml for CVE remediation by @mamoodi in https://github.com/OpenHands/enterprise/pull/401 -* fix: resolve duplicate migration revision 162 (rename to 164, make idempotent) by @tofarr in https://github.com/OpenHands/enterprise/pull/445 -* fix(bitbucket-dc): validate tokens against /projects so scoped PATs pass by @hieptl in https://github.com/OpenHands/enterprise/pull/423 -* fix: Tag Enterprise telemetry by deployment kind by @malhotra5 in https://github.com/OpenHands/enterprise/pull/441 -* fix: replace stale custom LLM key when switching back to the managed default profile by @juanmichelini in https://github.com/OpenHands/enterprise/pull/425 -* fix: heal stale org-level BYOR LLM key on conversation start (#421) by @juanmichelini in https://github.com/OpenHands/enterprise/pull/437 -* fix(sandbox): make resume state-aware and preserve conflict semantics by @hieptl in https://github.com/OpenHands/enterprise/pull/422 - -#### Maintenance -* test: add a postgres test-database harness by @jlav in https://github.com/OpenHands/enterprise/pull/321 -* test: point the shared database fixtures at postgres by @jlav in https://github.com/OpenHands/enterprise/pull/322 -* test: drop the per-file sqlite engine fixtures by @jlav in https://github.com/OpenHands/enterprise/pull/323 -* chore: Add quint-specs folder with quint lockfile by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/293 -* test(budgets): add the org-budgets Quint spec and oracle instrumentation by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/370 -* revert: remove instance-level admin user lifecycle API by @neubig in https://github.com/OpenHands/enterprise/pull/325 -* docs: clarify DEPLOYMENT_MODE vs app_mode for cloud/self-hosted detection by @juanmichelini in https://github.com/OpenHands/enterprise/pull/454 -* refactor: remove vestigial /api/refresh-tokens endpoint and dead token-fetch code by @tofarr in https://github.com/OpenHands/enterprise/pull/435 - ---- - -### Software Agent SDK - -#### Features -* feat(agent-server): add OpenAI Responses gateway by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4694 -* feat(sdk): StreamContext mints the stream identity and closes every stream by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4822 -* feat(profiles): scope which secrets an agent profile receives by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4931 -* feat(agent-server): conversation-scoped runtime APIs and clients by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4966 -* feat(sdk): extend existing conversation and workspace APIs for automation by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5010 -* feat(workspace): add AgentSandboxWorkspace (Kubernetes, kubernetes-sigs/agent-sandbox) by @aleks-stefanovic in https://github.com/OpenHands/software-agent-sdk/pull/4516 -* feat(agent-server): publish python-minimal image by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5088 -* feat(profiles): scope saved secrets at lookup by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5017 -* feat(agent-server): add docker runtime mode for per-conversation containers by @rbren in https://github.com/OpenHands/software-agent-sdk/pull/3403 -* feat(plugin): add the Agent Plugins mcp.json loader by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5093 - -#### Bug Fixes -* fix(tools): add logging filter to redact secrets from libtmux log output by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4871 -* fix(sdk): add sk-oh-* OpenHands API key pattern to redact_api_key_literals by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4947 -* Fail over to fallback LLM immediately on hard quota exhaustion by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4917 -* fix(llm): remove LLM.modify_params past its v1.47.0 removal deadline by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4954 -* fix(acp): materialise only the running provider's file secrets by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4927 -* fix(sdk): generate titles with Responses and subscription streaming by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4968 -* fix(ts-client): reject browser-only downloads early in Node.js by @BORAN002 in https://github.com/OpenHands/software-agent-sdk/pull/4982 -* fix(sdk): strip inline reasoning from LLM-generated titles by @aniketwaghh in https://github.com/OpenHands/software-agent-sdk/pull/4703 -* fix(agent-server): enforce the paginated search limit by @mkuri in https://github.com/OpenHands/software-agent-sdk/pull/4991 -* fix(agent-server): use a minimal Debian Python/Node runtime by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5077 -* fix(sdk): don't deep-copy the agent LLM in ask_agent by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5085 -* fix(agent-server): delegate MCP OAuth callback to FastMCP instead of forking it by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4821 -* fix(agent-server): preserve Docker conversation metadata route by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5112 -* fix(agent-server): preserve legacy conversations in Docker catalogs by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5128 -* fix(agent-server): stop rescanning Docker conversations by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5137 -* fix(agent-server): preserve Docker proxy root paths by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5140 -* fix(deps): hold fastmcp below 4 so browser tools keep working in unlocked installs by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/5153 -* fix(plugin): enforce package path containment in plugin formats by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5101 -* fix(agent-server): create Docker conversation workspaces by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5130 -* fix(agent-server): block Docker restarts during deletion by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5132 -* fix(agent-server): expose Docker host gateway by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5164 -* fix(tests): track upstream reasoning_effort support for kimi-k2.5 by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/5183 -* fix(workspace): preserve caller's AgentContext in load_skills_from_agent_server() by @vnktadithya in https://github.com/OpenHands/software-agent-sdk/pull/4876 -* fix(sdk): stamp the output item id on Responses stream deltas by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5204 -* fix(agent-server): use MCP OAuth credentials passed inline on the agent by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/5078 -* fix(secret): resolve this server's own LookupSecret URLs in-process by @lkshrk in https://github.com/OpenHands/software-agent-sdk/pull/5026 -* Fix #5205: Reset agent_settings when deleting active ACP profile by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/5206 - -#### Maintenance -* ci: enable API compliance and condenser test labels by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4204 -* fix(ci): open PR for merged artifact cleanup by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4933 -* chore: forbid getattr and setattr in SDK by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4906 -* ci: check Python API breakage on release PRs by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4971 -* chore: remove merged PR artifacts by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/5020 -* chore: enable Dependabot uv ecosystem by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5050 -* chore: isolate Dependabot uv updates by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5060 -* ci: accept the existing search limit schema repair by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/5032 -* test(ts-client): migrate from Jest to Vitest by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5075 -* test(examples): exclude agent-sandbox example from example tests by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5083 -* ci(version-bump-prs): push the TypeScript client bump with the bot PAT by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5089 -* chore(agent-server): remove deprecated desktop URL endpoint past its 1.49.0 deadline by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/5105 -* refactor(sdk): delegate plugin skills discovery to load_skills_from_dir by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5086 -* test(plugin): end-to-end tests for the Agent Plugins package format by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5160 - ---- - -### Automation - -#### Features -* feat: add user-authenticated KV access by @tofarr in https://github.com/OpenHands/automation/pull/445 -* feat: scope git sync to organizations so cloud deployments can sync by @hieptl in https://github.com/OpenHands/automation/pull/429 -* feat: make automation sandbox cleanup delay configurable by @hieptl in https://github.com/OpenHands/automation/pull/459 -* feat: select an agent profile for delegated automation work by @neubig in https://github.com/OpenHands/automation/pull/479 -* feat: allow raw automations to start disabled by @XiaoFeiCode in https://github.com/OpenHands/automation/pull/387 - -#### Bug Fixes -* fix(presets): install SDK into the run virtualenv by @palrohitg in https://github.com/OpenHands/automation/pull/460 -* fix: tolerate transient SQLite write contention by @neubig in https://github.com/OpenHands/automation/pull/462 -* fix: route automation commands through SDK workspaces by @neubig in https://github.com/OpenHands/automation/pull/481 -* fix: release request sessions before route telemetry by @neubig in https://github.com/OpenHands/automation/pull/458 -* fix: cut redundant/noisy PostHog telemetry events by @malhotra5 in https://github.com/OpenHands/automation/pull/486 -* fix(git-sync): preserve selected agent profiles by @neubig in https://github.com/OpenHands/automation/pull/501 -* fix: Add deployment kind to automation telemetry by @malhotra5 in https://github.com/OpenHands/automation/pull/497 -* fix: let org members create automations by @hieptl in https://github.com/OpenHands/automation/pull/496 - -#### Maintenance -* ci: bring .pr/ artifact workflow to parity with software-agent-sdk by @all-hands-bot in https://github.com/OpenHands/automation/pull/435 -* fix(ci): pull MinIO test image from Quay by @palrohitg in https://github.com/OpenHands/automation/pull/447 -* fix(ci): let triage and repository writers own readiness by @neubig in https://github.com/OpenHands/automation/pull/507 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat: PLTF-3553 Add Helm values for org condenser defaults by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1214 -* feat: wire the git sync wrapping secret and a /workspace volume by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1213 -* feat(openhands): add budget preflight and reconciliation gate hook jobs by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1251 -* feat(replicated): OHE-3231 expose the automation conversation archive delay as a ConfigOption by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1244 -* feat: configure Keycloak admin login through Replicated by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1269 - -#### Bug Fixes -* fix: validate embedded storage capacity for bundled MinIO by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1220 -* fix: stop cert-manager from claiming uploaded LiteLLM TLS secrets by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1221 -* fix(replicated): PLTF-3561 drop dead laminar-query-engine status informers by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1255 -* fix(replicated): PLTF-3561 drop dead laminar-quickwit status informers by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1256 -* fix(replicated): PLTF-3560 cover all LiteLLM credentials in restart checksum by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1258 - -#### Maintenance -* fix(ci): send the run identifiers the E2E binding selects on [ref PLTF-3540] by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1228 -* ci: block the openhands release PR on a red unstable E2E [ref PLTF-3540] by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1149 -* fix(e2e): complete new-user login past the 2FA-settings reminder by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1242 -* fix(replicated-deploy): Make the Replicated deploy job re-runnable and its failures more legible by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1243 -* chore: PLTF-3548 raise preflight memory recommendation to 32Gi by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1249 -* test(e2e): cover budget maintenance incidents by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1117 -* chore: PLTF-3561 Add laminar app-server and consumer pod logs to support bundle by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1253 -* test: rename end-to-end test for budgets by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1263 -* build: retry helm package to tolerate transient chart-dependency download failures by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1264 - -## 0.64.0 - -This release brings **shared LLM provider connections at the org level**, letting one connection back many members' managed profiles, and adds **configurable GPG commit signing** at the user level with a Set GPG Key button in app settings. Administrators gain new tools for organization lifecycle: a superadmin can seed a new org via a normal invitation, and Git providers can now be connected and disconnected post-auth from Settings → Integrations. Enterprise also splits automation permissions into separate view and manage roles. - -### Enterprise Server - -#### Features -* feat: add ENABLE_BYOR_EXPORT env var and frontend feature flag by @tofarr in https://github.com/OpenHands/enterprise/pull/232 -* feat: configurable GPG commit signing at user level (OHE-3115) by @tofarr in https://github.com/OpenHands/enterprise/pull/264 -* feat: add Set GPG Key button to app settings by @tofarr in https://github.com/OpenHands/enterprise/pull/274 -* feat: add database-driven feature flag library (OHE-3101) by @tofarr in https://github.com/OpenHands/enterprise/pull/217 -* feat(org): shared LLM provider connections (cloud) by @juanmichelini in https://github.com/OpenHands/enterprise/pull/219 -* feat: link daily quota increase requests by @neubig in https://github.com/OpenHands/enterprise/pull/283 -* feat: add cron script to clean stale app_conversation_start_task rows by @tofarr in https://github.com/OpenHands/enterprise/pull/290 -* feat: OHE-3197 : Unify ENABLE_BILLING resolution through the feature flag env fallback by @tofarr in https://github.com/OpenHands/enterprise/pull/301 -* feat: split automations permission into view and manage by @tofarr in https://github.com/OpenHands/enterprise/pull/304 -* feat: add GET /organizations/{org_id}/members/{user_id} by @hieptl in https://github.com/OpenHands/enterprise/pull/313 -* feat: connect and disconnect Git providers post-auth from Settings > Integrations by @hieptl in https://github.com/OpenHands/enterprise/pull/309 -* feat(enterprise): allow superadmin to seed a new org via a normal invitation by @lilagrc in https://github.com/OpenHands/enterprise/pull/292 -* feat(enterprise): instance-level admin user lifecycle API (disable/enable/delete) by @neubig in https://github.com/OpenHands/enterprise/pull/181 -* feat: OHE-3178 : add per-conversation event index for efficient search by @tofarr in https://github.com/OpenHands/enterprise/pull/327 - -#### Bug Fixes -* fix: delete MCP servers from a null mcp_config entry by @hieptl in https://github.com/OpenHands/enterprise/pull/270 -* fix: remove --forked from test commands to fix coverage measurement by @tofarr in https://github.com/OpenHands/enterprise/pull/277 -* fix: include registered marketplaces in the conversation skills listing by @hieptl in https://github.com/OpenHands/enterprise/pull/286 -* fix: stop polling behind the re-auth modal once the session expires by @hieptl in https://github.com/OpenHands/enterprise/pull/298 -* fix: stop title updates clobbering conversation metadata by @hieptl in https://github.com/OpenHands/enterprise/pull/299 -* fix(budgets): make LiteLLM spend reporting resilient by @ak684 in https://github.com/OpenHands/enterprise/pull/242 -* fix: prevent invalid proxy tokens after managed profile changes by @saurya in https://github.com/OpenHands/enterprise/pull/209 -* fix(analytics): use detected automation trigger by @neubig in https://github.com/OpenHands/enterprise/pull/147 -* fix: Updated release please config to include uv.lock by @tofarr in https://github.com/OpenHands/enterprise/pull/330 -* fix: prevent cross-user managed LLM key attribution by @ak684 in https://github.com/OpenHands/enterprise/pull/317 -* fix(ui): disable telemetry UI in self-hosted enterprise by @ak684 in https://github.com/OpenHands/enterprise/pull/326 - -#### Maintenance -* refactor(frontend): remove legacy max-budget settings control by @saurya in https://github.com/OpenHands/enterprise/pull/213 -* chore: remove dead code by @tofarr in https://github.com/OpenHands/enterprise/pull/271 -* chore: remove redundant comments across enterprise codebase by @tofarr in https://github.com/OpenHands/enterprise/pull/272 -* chore: remove comments referencing previous functionality by @tofarr in https://github.com/OpenHands/enterprise/pull/273 -* test: replace mocked sessions with SQLite fixtures in org invitation store by @tofarr in https://github.com/OpenHands/enterprise/pull/276 -* docs: fix stale, wrong, and inapplicable documentation references by @tofarr in https://github.com/OpenHands/enterprise/pull/275 -* chore: remove Reo tracking integration by @neubig in https://github.com/OpenHands/enterprise/pull/227 -* refactor: PLTF-3545 PLTF-3546 flatten enterprise/ into the repo root and move to uv by @jlav in https://github.com/OpenHands/enterprise/pull/312 - ---- - -### Software Agent SDK - -#### Features -* feat: add manifest to installed canvas extension responses by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4611 -* feat(sdk): add ask_oracle tool by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/3673 -* feat(agent-server): add INSTALL_ACP_PROVIDERS build arg by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4687 -* feat: move TypeScript client into monorepo by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4702 -* feat(agent-server): add INSTALL_CAPABILITIES build arg by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4698 -* feat: add ACP-less agent-server image fallback by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4805 -* feat(observability): allow selecting Laminar instruments by @Shimada666 in https://github.com/OpenHands/software-agent-sdk/pull/4434 -* feat(acp): centralize ACP npm installation metadata by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4832 -* feat(agent-server): add /sockets/session/{id} with a non-Event envelope by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4807 -* feat(acp): add Kimi Code, plus the hardening the other provider PRs share by @ysntony in https://github.com/OpenHands/software-agent-sdk/pull/4714 -* feat(sdk): register Pi as a built-in ACP provider by @Deep070203 in https://github.com/OpenHands/software-agent-sdk/pull/4419 -* feat(acp): add OpenCode as a built-in ACP provider by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4827 -* feat: add GPT-6 Astra model support by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4861 -* Add claude-sonnet-5 to PROMPT_CACHE_MODELS by @swabeinvader in https://github.com/OpenHands/software-agent-sdk/pull/4043 -* feat(plugin): map client extensions under the dev.openhands namespace by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4496 - -#### Bug Fixes -* fix(agent-server): keep crash recovery result on interrupted action branch by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4488 -* fix(workspace): honor explicit provider host when injecting git clone tokens by @rsd-darshan in https://github.com/OpenHands/software-agent-sdk/pull/4571 -* fix(agent-server): replace global _lifecycle_lock with per-conversation locks by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4570 -* fix(tools): unique user_data_dir per conversation to prevent SingletonLock collisions by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4602 -* fix(sdk): bound AsyncExecutor.close() so it cannot hang forever by @AaronAbuUsama in https://github.com/OpenHands/software-agent-sdk/pull/4548 -* fix(agent-server): detect all secret-bearing fields for the plaintext-save warning, not just llm.api_key by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4618 -* fix: enable condenser for subscription LLMs via existing completion dispatch by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4517 -* fix(sdk): resolve structured builtin tool specs remotely by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4691 -* fix(agent-server): stop fanning streaming deltas out to every subscriber by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4689 -* fix(acp): never inject workspace project skills into an ACP agent (#4019) by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4699 -* fix(sdk): mask model output in the durable MessageEvent by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4783 -* fix(sdk): match nested repo paths by ancestry, not string prefix by @alanhuangyoo in https://github.com/OpenHands/software-agent-sdk/pull/4767 -* fix(tools): mask secrets in every tool's observation at the shared chokepoint by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4788 -* fix(agent-server): keep the idle timer alive during streamed completions by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4790 -* fix(sdk): remove secrets from subprocess env by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4801 -* fix(sdk): persist events before publishing them, return the assigned seq by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4806 -* fix(llm): allow security_risk param on read-only tools like finish by @sideeffffect in https://github.com/OpenHands/software-agent-sdk/pull/4153 -* fix(sdk): require fastmcp>=3.2.0 so expired MCP OAuth tokens refresh by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4857 -* fix(sdk): pick up a user message that arrives during an async step by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4194 -* fix(agent-server): propagate load_memory preference to all launch paths by @vnktadithya in https://github.com/OpenHands/software-agent-sdk/pull/4566 -* fix: respect OH_PERSISTENCE_DIR for all ~/.openhands paths by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/4476 -* fix(ci): align ready-for-dev gates with OpenHands pipefail-safe approach by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4607 -* fix(tests): stop pinning LLM capability tests to upstream metadata by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4879 -* fix(ci): centralize release publication dispatches by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4886 -* fix(agent-server): restore subscription credentials in pre-flight validation by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4898 -* fix(llm): register litellm_proxy alias pricing so spans aren't silently $0 by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/4836 -* fix(extensions): compose local source with repo_path by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4839 - -#### Maintenance -* docs: document SDK repository boundaries by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4587 -* chore(ci): clarify issue readiness bot comment and reference templates by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/4625 -* Relax ready-for-dev heading check to accept h2 headings by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4632 -* docs(examples): align Ask Oracle conventions by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4655 -* refactor(agent-server): share ACP provider payload as a parent-independent Docker layer by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4651 -* test(agent-server): cover conversation reads not serializing behind an unrelated start by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4685 -* ci: enforce SDK and TypeScript client version parity by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4779 -* refactor(agent-server): remove the VNC/desktop stack entirely by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4792 -* refactor(agent-server,ci): remove overdue org_config field and catch this class of gap in check_deprecations.py by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4795 -* ci: remove the endpoint-audit PR comment, report via the job summary by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4825 -* test(acp): live conformance + model-acceptance probes for built-in providers (#4830 P0) by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4834 -* ci(typescript-client): run integration tests against the branch's agent-server by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4844 -* perf(sdk): make EventLog.append cost flat against conversation length by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4697 - ---- - -### Runtime API - -#### Features -* feat: OHE-3139 : Split cleanup CronJob into per-phase jobs by @tofarr in https://github.com/OpenHands/runtime-api/pull/729 -* feat: overlay database warm-runtime configs onto ConfigMap entries by name by @ak684 in https://github.com/OpenHands/runtime-api/pull/731 -* feat: Add coverage gate to unit test workflow by @tofarr in https://github.com/OpenHands/runtime-api/pull/737 - -#### Bug Fixes -* fix: redact sensitive URL query parameters in pod crash logs by @all-hands-bot in https://github.com/OpenHands/runtime-api/pull/706 -* fix: treat empty ADMIN_PASSWORD as unset so admin routes stay disabled by @ak684 in https://github.com/OpenHands/runtime-api/pull/730 -* fix: OHE-3187 : clean up warm runtimes orphaned by split-brain claim by @tofarr in https://github.com/OpenHands/runtime-api/pull/735 - ---- - -### Automation - -#### Features -* feat: add structured task outcomes to preset finish tool by @malhotra5 in https://github.com/OpenHands/automation/pull/334 -* feat: replace the parse-only source registry with a provider descriptor and verifier registry by @VascoSch92 in https://github.com/OpenHands/automation/pull/378 -* feat: persist accepted events to deduplicate redeliveries and expose events that matched nothing by @VascoSch92 in https://github.com/OpenHands/automation/pull/381 -* feat: report lifetime per-status run counts on the runs list by @hieptl in https://github.com/OpenHands/automation/pull/383 -* feat: report live run phases for dashboard visibility by @hieptl in https://github.com/OpenHands/automation/pull/388 -* feat: add in-service Slack Socket Mode via a supervised stream transport by @VascoSch92 in https://github.com/OpenHands/automation/pull/384 -* feat: split automation permissions into view and manage by @tofarr in https://github.com/OpenHands/automation/pull/415 -* feat: auto-disable for consecutively failing automations [PLTF-3374] by @dylan-openhands in https://github.com/OpenHands/automation/pull/397 -* feat: route events to an existing conversation via a derived conversation id by @VascoSch92 in https://github.com/OpenHands/automation/pull/385 -* feat: add ready-for-dev issue and PR readiness gates by @neubig in https://github.com/OpenHands/automation/pull/380 -* feat: restrict automation edits to the creator by @hieptl in https://github.com/OpenHands/automation/pull/427 - -#### Bug Fixes -* fix: capture automation failure modes as status states by @malhotra5 in https://github.com/OpenHands/automation/pull/345 -* fix: treat missing tarball objects as permanent and defer superseded deletes until commit by @hieptl in https://github.com/OpenHands/automation/pull/356 -* fix: auto-disable unhealthy automations by @malhotra5 in https://github.com/OpenHands/automation/pull/352 -* fix: scope automation management to the org instead of the owner by @VascoSch92 in https://github.com/OpenHands/automation/pull/399 -* fix: require preset automations to use finish tool by @malhotra5 in https://github.com/OpenHands/automation/pull/405 -* fix: Forward X-Org-Id during automation auth by @malhotra5 in https://github.com/OpenHands/automation/pull/403 -* fix(automation): purge expired local-mode run workspaces by @trungminhdo4-glitch in https://github.com/OpenHands/automation/pull/277 - -#### Maintenance -* perf: remove redundant readiness query by @Linxiushen in https://github.com/OpenHands/automation/pull/303 -* refactor: extract a transport-neutral accept_event() from the webhook handler by @VascoSch92 in https://github.com/OpenHands/automation/pull/367 -* chore: add Dependabot configuration by @neubig in https://github.com/OpenHands/automation/pull/372 -* docs: document automation repository boundaries by @neubig in https://github.com/OpenHands/automation/pull/369 -* ci: enforce minimum 76% coverage on unit tests by @tofarr in https://github.com/OpenHands/automation/pull/419 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat(local-kind): PLTF-3527 enable Agent Canvas at /canvas by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1168 -* feat(replicated): PLTF-3456 enable automations by default for new installs by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1158 -* feat(runtime-api): sync split cleanup CronJob from runtime-api#729 by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1178 -* feat(e2e): PLTF-3514 dispatch e2e test revision bumps to saas-deploy by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1148 -* feat: enable warm-runtime config overlay mode for Replicated by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1183 -* feat: configure Enterprise SSO for Replicated VM deployments by @jpelletier1 in https://github.com/OpenHands/OpenHands-Cloud/pull/1116 -* feat: add CronJob to clean stale app_conversation_start_task rows by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1196 -* feat: enable appConversationStartTaskClean CronJob by default by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1197 -* feat(skills): PLTF-3531 add upgrade-rollback-runbook skill by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1204 -* feat(skills): PLTF-3531 add gke-install cluster-install skill by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1205 -* feat(skills): PLTF-3531 add eks-install cluster-install skill by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1203 -* feat: diagnose runtime ingress failures in support bundles by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1208 - -#### Bug Fixes -* fix(local-kind): PLTF-3527 use bundled MinIO for conversation/event storage by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1163 -* fix(replicated): drop the KOTS update check that ruins the target cursor by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1175 -* fix: Disable agent-canvas telemetry by default for self-hosted by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1156 -* fix(e2e): PLTF-3515 give the Tavily test its own conversation by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1146 -* fix: rename warm-runtime default config to v1_current to match the app default spec lookup by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1181 -* fix: give the Runtime API admin password a real KOTS field with a generated default by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1182 -* fix: advertise the runtime API ingress to fuse mounts by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1184 -* fix(chart): render reaper archive volume under a volumes: key (staging reaper outage) by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1185 -* fix(ci): bypass broken deploy-gate check temporarily by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1186 -* fix: make E2E repo-test prompt explicitly instruct file edit by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1189 - -#### Maintenance -* ci: check the agent-server tag against the enterprise SDK pin by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1167 -* ci: make the Replicated deploy check blocking, with a break-glass label [PLTF-3535] by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1187 -* test: harden 003 legacy conversations spec (from #1176, without 005 canvas spec) by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1200 -* docs(skills): PLTF-3531 use --context=0 for helm diff in upgrade-rollback runbook by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1206 -* test(e2e): verify managed LLM key ownership by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1207 - -## 0.55.0 - -This release centers on **daily conversation quotas** for Enterprise Server, which add a read-only usage page with a reset countdown, org-level exemptions, and self-service quota increase requests verified by work email. Enterprise installs also gain **dedicated sandbox node scheduling**, with declared app and sandbox node roles, affinity plumbing across all pod specs, a config option to turn it on, and a preflight check that warns when it is enabled without a matching node. Issue tracker coverage expanded through an org-scoped Jira Cloud resolver with an email-match mode and through Azure DevOps resolver webhook configuration. The Agent SDK added an Agent Plugins manifest loader, structured output, a pre-flight LLM validation endpoint, and read-at-use LLM provider connections, while the Runtime API now anchors runtime reaping, database pruning, and the idle-grace period on last activity rather than creation time. The remainder of the release covers extensive billing and credit-handling fixes and hardened Keycloak identity matching that keys on the Keycloak subject rather than email. - -### Enterprise Server - -#### Features -* feat(settings): increase LLM profile limit to 50 and make it configurable by @jpelletier1 in https://github.com/OpenHands/enterprise/pull/114 -* feat: add cloud workspace file-listing endpoint (OHE-3053) by @lilagrc in https://github.com/OpenHands/enterprise/pull/135 -* feat: Expose organization creation teaser UX by @malhotra5 in https://github.com/OpenHands/enterprise/pull/151 -* feat: set SaaS default model to Kimi K3 and migrate GLM 5.2 settings by @juanmichelini in https://github.com/OpenHands/enterprise/pull/190 -* feat: org-scope the Jira Cloud resolver and add email-match mode for OHE by @hieptl in https://github.com/OpenHands/enterprise/pull/192 -* feat(frontend): add data-testid to changes refresh button by @tofarr in https://github.com/OpenHands/enterprise/pull/203 -* feat: add daily conversation quota schema foundation by @neubig in https://github.com/OpenHands/enterprise/pull/180 -* feat: add read-only quota usage page with reset countdown by @neubig in https://github.com/OpenHands/enterprise/pull/199 -* feat: add work-email quota increase requests with self-service verification by @neubig in https://github.com/OpenHands/enterprise/pull/200 -* feat: add org-level daily conversation quota exemptions by @neubig in https://github.com/OpenHands/enterprise/pull/212 -* feat: accept Jira Cloud picker mentions of the service account by @ak684 in https://github.com/OpenHands/enterprise/pull/223 -* feat(settings): auto-rotate invalid managed LLM keys on settings writes by @tofarr in https://github.com/OpenHands/enterprise/pull/231 -* feat: migrate Kimi K3 settings to DeepSeek V4 Flash by @neubig in https://github.com/OpenHands/enterprise/pull/253 - -#### Bug Fixes -* fix: resolve LLM profile keys in /users/me expose-secrets response by @hieptl in https://github.com/OpenHands/enterprise/pull/168 -* fix: handle null identity_provider for direct Keycloak logins by @tofarr in https://github.com/OpenHands/enterprise/pull/169 -* fix: URL-encode Redis password in authed URL for coredis/limits by @tofarr in https://github.com/OpenHands/enterprise/pull/177 -* fix: close dropdown menu after selection when wrapped in a label by @hieptl in https://github.com/OpenHands/enterprise/pull/176 -* fix: stop redacting the Jira DC base URL in agent output by @hieptl in https://github.com/OpenHands/enterprise/pull/182 -* fix: inject Bitbucket DC server URL, repo URL, and token context into agent prompt by @hieptl in https://github.com/OpenHands/enterprise/pull/183 -* fix(auth): make Keycloak HTTP retries configurable by @neubig in https://github.com/OpenHands/enterprise/pull/186 -* fix: OHE-3100 : use sandbox_spec.working_dir instead of hardcoded /workspace by @tofarr in https://github.com/OpenHands/enterprise/pull/188 -* fix(auth): make LiteLLM management timeout configurable by @neubig in https://github.com/OpenHands/enterprise/pull/189 -* fix: handle null runtime context values by @ak684 in https://github.com/OpenHands/enterprise/pull/112 -* fix: use agent server as conversation creation source by @malhotra5 in https://github.com/OpenHands/enterprise/pull/156 -* fix: let managed LLM profiles take the org's current key on rotation by @dylan-openhands in https://github.com/OpenHands/enterprise/pull/178 -* fix(budgets): persist maintenance updates by @saurya in https://github.com/OpenHands/enterprise/pull/204 -* fix: let free-tier (no-credit) teams run $0-cost models by @juanmichelini in https://github.com/OpenHands/enterprise/pull/143 -* fix: protect personal organization billing credits by @saurya in https://github.com/OpenHands/enterprise/pull/167 -* fix(budgets): prevent per-user allowance renewal on sync by @saurya in https://github.com/OpenHands/enterprise/pull/205 -* fix: display usage monitoring timestamps in local time by @saurya in https://github.com/OpenHands/enterprise/pull/208 -* fix: use verified repo provider in Jira Cloud conversation start request by @ak684 in https://github.com/OpenHands/enterprise/pull/216 -* fix(billing): show personal-workspace credits without a member budget row by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/218 -* fix: clarify Jira email-visibility guidance with exact setting and delay by @ak684 in https://github.com/OpenHands/enterprise/pull/222 -* fix(enterprise): match provisioned user on Keycloak sub, not email by @tofarr in https://github.com/OpenHands/enterprise/pull/224 -* fix(enterprise): match on Keycloak sub in TOCTOU idempotent recovery too by @tofarr in https://github.com/OpenHands/enterprise/pull/225 -* fix(enterprise): await session.merge in billing success callback by @tofarr in https://github.com/OpenHands/enterprise/pull/226 -* fix: OHE-3127 : return null credits instead of 503 when budget is None by @tofarr in https://github.com/OpenHands/enterprise/pull/228 -* fix: return 0 credits instead of None for users without a budget by @tofarr in https://github.com/OpenHands/enterprise/pull/238 -* fix(settings): stop a member's settings save writing to the whole org by @jlav in https://github.com/OpenHands/enterprise/pull/254 - -#### Maintenance -* chore: remove dead localStorage feature-flag mechanism by @tofarr in https://github.com/OpenHands/enterprise/pull/230 -* docs: Replace with Polyform License by @jpelletier1 in https://github.com/OpenHands/enterprise/pull/240 - ---- - -### Software Agent SDK - -#### Features -* Feat: structured output by @luciobaiocchi in https://github.com/OpenHands/software-agent-sdk/pull/4207 -* agent-server: make conversation worktree root configurable by @xmrflipflop in https://github.com/OpenHands/software-agent-sdk/pull/4362 -* feat(observability): emit LLM and TOOL spans for ACP turns by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4376 -* feat: derive automation conversation tags in base RemoteWorkspace by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4414 -* feat: emit canonical conversation telemetry from agent server by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4459 -* feat(hooks): implement prompt-based evaluation by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4160 -* feat(security): AST-backed shell command-name resolution (#2721 Phase 2b) by @eeee2345 in https://github.com/OpenHands/software-agent-sdk/pull/3944 -* feat: add public from_persisted() entry point to AgentSettingsBase by @mvanhorn in https://github.com/OpenHands/software-agent-sdk/pull/3503 -* feat(sdk): add cleanup LLM profile for outward agent text by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4344 -* feat(llm): resolve provider-specific runtime metadata for routed models by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4423 -* feat: add pre-flight LLM validation endpoint (POST /api/profiles/{name}/validate) by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4422 -* feat: carry ConversationErrorEvent on ConversationRunError for automation callbacks by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4458 -* feat(plugin): add Agent Plugins manifest loader (root plugin.json, closed schema) by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4474 -* feat(file-router): add POST /file/create_directory by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4482 -* Add read-at-use LLM provider connections by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/4492 -* feat: Add deployment kind to agent-server telemetry by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4522 -* feat(telemetry): identify automation conversations by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4529 -* feat(tools): add structured task outcome preset by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4479 -* feat(prompt): mention local conversation history by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4527 - -#### Bug Fixes -* fix(mcp): close reconciliation gaps left by #4367 by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4369 -* fix(acp): recover credential monitor after transient errors by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4403 -* fix(sdk): make ACP auth failures self-diagnosing by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4404 -* fix(observability): record non-executed tool results by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4415 -* fix(agent-server): compose ConversationInfo off the event loop to avoid GC wedge by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4417 -* fix(agent-server): initialize observability after deferred env by @Shimada666 in https://github.com/OpenHands/software-agent-sdk/pull/4426 -* fix(settings): inherit condenser max_tokens from LLM effective_max_input_tokens by @vnktadithya in https://github.com/OpenHands/software-agent-sdk/pull/4435 -* fix(goal): don't halt the goal loop on a STUCK run by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4381 -* fix(llm): stop serializing calls through global config by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4473 -* fix(security-scan): improve release security scan comment by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4397 -* fix(profiles): repair v1 skills migration by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4320 -* fix(agent-server): base_state.json as single source of truth for the agent (end meta.json duplication) by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4440 -* fix(sdk): cap condenser token limit by agent context by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4461 -* fix(agent-server): move bash event search off event loop and replace glob with scandir by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4481 -* fix: redact API key from validate_profile error responses and logs by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4506 -* fix: make dict-entry secret redaction case-insensitive by @chintan-diwakar in https://github.com/OpenHands/software-agent-sdk/pull/4508 -* fix(agent-server): propagate out-of-band run failures as ConversationErrorEvent (#16686) by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4535 -* fix(sdk): normalize Kimi K3 vision metadata by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4567 -* fix(agent): keep terminal prefix aliases from doubling an existing executable by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4471 -* fix(sdk): resolve workspace default from active LLM profile by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4497 - -#### Maintenance -* chore: drop the OpenHands/OpenHands bump-PR target from version-bump-prs.yml by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4400 -* refactor(plugin): extract PluginFormat strategy (prep for Agent Plugins support) by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/4420 -* chore(ci): collapse the auto-posted Agent Server images PR section by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4442 -* Add ready-for-dev issue and PR gates by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4464 -* test(terminal): stabilize Windows Ctrl-C cleanup assertion by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4290 -* perf(agent-server): cache unchanged conversation summaries by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4483 -* ci: re-run PR description check when new commits are pushed by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4486 -* Weekly test sweep: remove low-value tests + simplify by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4484 -* test(sdk): pin events_to_messages boundaries + fix responses_reasoning_item batch drop by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4526 -* test(sdk): pin send_message skill-activation wiring by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4536 - ---- - -### Runtime API - -#### Bug Fixes -* fix: anchor runtime reaping and DB pruning on last activity, not creation time by @hieptl in https://github.com/OpenHands/runtime-api/pull/707 -* fix: anchor the idle-grace period on last_state_change, not created_at by @hieptl in https://github.com/OpenHands/runtime-api/pull/713 -* fix: OHE-3100 : root-owned working_dir subdirs on PVC via init container by @tofarr in https://github.com/OpenHands/runtime-api/pull/714 -* fix: reorder cleanup phases and resume expired deployment list tokens by @dylan-openhands in https://github.com/OpenHands/runtime-api/pull/712 - ---- - -### Automation - -#### Features -* feat(automation): tag local automation conversations by @neubig in https://github.com/OpenHands/automation/pull/319 -* feat: sync automations to a git repository by @VascoSch92 in https://github.com/OpenHands/automation/pull/327 -* feat: accept catalog bundle automations on the raw create path by @VascoSch92 in https://github.com/OpenHands/automation/pull/346 - -#### Bug Fixes -* fix: stop marking successful automation runs as FAILED by @hieptl in https://github.com/OpenHands/automation/pull/331 - -#### Maintenance -* chore: add success logging for tarball storage writes and deletes by @jpshackelford in https://github.com/OpenHands/automation/pull/335 -* chore: remove QA changes workflow by @neubig in https://github.com/OpenHands/automation/pull/340 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat: e2e: restructure for Keycloak admin + dual GitHub user flows by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1089 -* feat: add configurable daily conversation limit to chart by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/1100 -* feat: wire Jira Cloud email-match integration for Replicated installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1113 -* feat: add org-management e2e suite with super-admin REST provisioning by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1122 -* feat(replicated): declare app and sandbox node roles by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1133 -* feat(chart): add affinity plumbing to all pod specs by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1134 -* feat(replicated): gate dedicated sandbox nodes behind a config option by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1135 -* feat(preflight): warn when dedicated sandbox nodes are enabled with no sandbox node by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1136 -* feat(replicated): PLTF-3461 configure duplicate email checks by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1139 -* feat(azure-devops): wire the resolver webhook secret into the chart and KOTS config by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1160 - -#### Bug Fixes -* fix: Bound Laminar ClickHouse diagnostic log retention by @juanmichelini in https://github.com/OpenHands/OpenHands-Cloud/pull/1031 -* fix: wire installer SMTP config into Keycloak realm email by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1090 -* fix(e2e): handle onboarding-form and 2FA auto-navigate race conditions by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1091 -* fix(e2e): enable role during static discovery by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1099 -* fix(e2e): replace networkidle waits and fix Promise.race short-circuit by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1108 -* fix(automation): keep events service available during node drains by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1112 -* fix: refresh changes panel when empty in VSCode integration test by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1114 -* fix(e2e): order API keys spec after billing so new-user has credits by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1118 -* fix(e2e): PLTF-3461 honor AUTH_BASE_URL for Keycloak admin URL by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1126 -* fix(chart): set the warm pool working dir to /workspace/project by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1140 -* fix(deploy): tolerate a restarting kotsadm in replicated_deploy.sh by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1141 -* fix(e2e): PLTF-3461 move the credit-gated API key check into the billing suite by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1143 -* fix(ci): PLTF-3461 call the E2E trigger from each release workflow by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1144 - -#### Maintenance -* test(e2e): add Playwright release harness by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1048 -* test(e2e): cover organization-scoped member API keys by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1049 -* test(e2e): add optional ReportPortal reporting by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1088 -* test(e2e): make returning/new-user roles opt-in via *_GITHUB_USERNAME by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1092 -* test(e2e): migrate Stripe credit purchase into billing suite by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1094 -* test(e2e): migrate home avatar and user-menu tests by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1095 -* test(e2e): remove example.spec.ts by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1096 -* test(e2e): migrate API key creation and API access test by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1097 -* test(e2e): migrate legacy conversation control tests by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1101 -* ci: auto-deploy Replicated releases to internal instances by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1123 -* ci: PLTF-3461 run E2E after Replicated deploys by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1129 -* ci: name the Replicated release workflows consistently for README badges by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1131 -* ci: fix unparseable expression in deploy-replicated, lint workflows in CI by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1132 - ---- - -## 0.45.0 - -This release introduces **Canvas Extensions**, a major new capability that enables installing, managing, and refreshing extensions with manifest support and persistent storage. The Agent SDK saw significant improvements with conversation error classification, accumulated LLM cost tracking, and observability enhancements including detached traces for delegate conversations. The Automation component was modernized with the retirement of the standalone frontend, enhanced preset metadata, and LLM cost tracking. Critical stability fixes addressed S3/MinIO silent truncation issues, improved CSP compatibility for the Monaco diff viewer, and enhanced secrets handling across the platform. - -### Enterprise Server - -#### Features -* feat: migrate existing managed MiniMax M2.7 settings to the GLM 5.2 default by @juanmichelini in https://github.com/OpenHands/enterprise/pull/140 - -#### Bug Fixes -* fix(sandbox): OHE-3021 : honor OH_SANDBOX_MAX_NUM_SANDBOXES in RemoteSandboxServiceInjector fallback by @tofarr in https://github.com/OpenHands/enterprise/pull/153 -* fix: self-host Monaco so the diff viewer works under CSP by @hieptl in https://github.com/OpenHands/enterprise/pull/155 -* fix: stop silent truncation of archived and shared conversations on S3/MinIO by @hieptl in https://github.com/OpenHands/enterprise/pull/158 -* fix: stop surfacing Git provider token required errors for SSO-only users by @hieptl in https://github.com/OpenHands/enterprise/pull/159 -* fix(s3 file store): OHE-3079 : paginate list_objects_v2 to avoid silent truncation at 1000 keys by @tofarr in https://github.com/OpenHands/enterprise/pull/157 -* fix: redirect Automations sidebar icon to /canvas/automations by @hieptl in https://github.com/OpenHands/enterprise/pull/162 - ---- - -### Software Agent SDK - -#### Features -* feat(llm): verify kimi-for-coding (Kimi Code membership) by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4150 -* feat(sdk): classify conversation errors by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4316 -* feat: report accumulated LLM cost in the automation completion callback by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4311 -* feat(agent-server): Canvas Extensions manifest and containment [1/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4361 -* feat(sdk): track requested_ref alongside resolved_ref in InstallationInfo [2/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4375 -* feat(agent-server): Canvas Extensions installation persistence [3/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4364 -* feat(agent-server): Canvas Extensions staged refresh (check/apply) [4/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4374 - -#### Bug Fixes -* fix(sdk): respect subscription validator composition by @Sehlani042 in https://github.com/OpenHands/software-agent-sdk/pull/3953 -* fix(agent-server): keep secrets out of workspace persistence by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/3990 -* fix(acp): surface Claude Opus 5 in Claude Code model picker by @nicolasdmolina in https://github.com/OpenHands/software-agent-sdk/pull/4326 -* fix: PATCH /api/settings loads the profile's LLM when setting active_profile by @emmanuel-adu in https://github.com/OpenHands/software-agent-sdk/pull/4319 -* fix(git): demote expected command failures to debug by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4341 -* fix(sdk): nudge before hard-terminating on a repeating action-error pattern by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4332 -* fix(mcp): reconcile live agent tool snapshots by @Shimada666 in https://github.com/OpenHands/software-agent-sdk/pull/4367 -* fix(observability): mark utility LLM spans (title generation, ask_agent) by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4359 -* fix(observability): give delegate conversations their own detached Laminar trace by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4378 -* fix(browser): a browser tool that cannot start should not fail the conversation by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4342 -* fix(observability): keep the conversation object out of TOOL span input by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4379 - -#### Maintenance -* chore(ci): remove QA Changes workflows by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4299 -* refactor(llm): add LiteLLM-backed provider abstraction by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/2363 -* chore(sdk): deprecate AgentBase.model_dump_succint by @AzeelSajjad in https://github.com/OpenHands/software-agent-sdk/pull/4328 -* refactor(observability): stop depending on lmnr to propagate trace context into tool workers by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4360 -* test: stop ambient LMNR env vars deciding what the tracing tests measure by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4390 -* chore: remove deprecated features past their 1.41.0 removal deadline by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4394 - ---- - -### Automation - -#### Features -* feat: retire the standalone automation frontend by @hieptl in https://github.com/OpenHands/automation/pull/284 -* feat: report the configured automation timeout cap by @neubig in https://github.com/OpenHands/automation/pull/296 -* feat: record accumulated LLM cost per automation run by @hieptl in https://github.com/OpenHands/automation/pull/280 -* feat: set descriptive titles on automation-born conversations by @hieptl in https://github.com/OpenHands/automation/pull/312 -* feat: add generic preset metadata field to Automation model by @hieptl in https://github.com/OpenHands/automation/pull/313 -* feat: add template provenance, idempotent enablement, and first-run outcome to presets by @hieptl in https://github.com/OpenHands/automation/pull/322 - -#### Bug Fixes -* fix: normalize SQLite telemetry timestamps by @Linxiushen in https://github.com/OpenHands/automation/pull/301 -* fix: default FILE_STORE to local instead of gcs by @neubig in https://github.com/OpenHands/automation/pull/314 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat(chart): OHE-3021 : expose OH_SANDBOX_MAX_NUM_SANDBOXES as a ConfigOption by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1035 - ---- - -## 0.41.0 - -This release advances the **Agent Canvas** rollout with a new homepage banner and an updated Canvas build, and sets GLM 5.2 as the default model for SaaS deployments. The remainder of the release focuses on Codex authentication handling, secrets and settings reliability, and a range of stability fixes across the Enterprise Server and Helm charts. - -### Enterprise Server - -#### Features -* feat: set SaaS default model to GLM 5.2 by @juanmichelini in https://github.com/OpenHands/enterprise/pull/89 -* feat: Add Agent Canvas homepage banner by @malhotra5 in https://github.com/OpenHands/enterprise/pull/124 -* feat: expose observability fields on app conversations by @juanmichelini in https://github.com/OpenHands/enterprise/pull/130 - -#### Bug Fixes -* fix(frontend): wire Export CSV buttons on Usage & Monitoring Overview and Models tabs by @saurya in https://github.com/OpenHands/enterprise/pull/78 -* fix: Pass pod security context from runtime-api warm configs to sandbox start by @tofarr in https://github.com/OpenHands/enterprise/pull/108 -* fix: skip default CSP on FastAPI docs paths (OHE-2815) by @tofarr in https://github.com/OpenHands/enterprise/pull/118 -* fix(settings): keep active LLM profile selected during updates by @saurya in https://github.com/OpenHands/enterprise/pull/107 -* fix(enterprise): Fix 405 error when uploading files before conversation is ready by @jpelletier1 in https://github.com/OpenHands/enterprise/pull/134 -* fix: propagate registered marketplaces to conversations by @tofarr in https://github.com/OpenHands/enterprise/pull/126 -* fix(app-server): serialize secrets writes to fix lost-write race (OHE-3052) by @tofarr in https://github.com/OpenHands/enterprise/pull/133 -* fix: load_settings should show meta for secrets by @tofarr in https://github.com/OpenHands/enterprise/pull/138 -* fix(enterprise): make POST /api/organizations/provision-user idempotent (OHE-2980) by @tofarr in https://github.com/OpenHands/enterprise/pull/117 -* fix: validate Codex auth secrets on save by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/141 -* fix(app-server): pre-flight Codex credentials by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/139 - -#### Maintenance -* chore(enterprise): enforce PostgreSQL-only migrations by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/95 - ---- - -### Runtime API - -#### Features -* feat(helm): add generic-device-plugin DaemonSet for FUSE support by @tofarr in https://github.com/OpenHands/runtime-api/pull/685 - -#### Bug Fixes -* fix: resolve real service-account email for GCS URL signing by @jlav in https://github.com/OpenHands/runtime-api/pull/686 - -#### Maintenance -* chore: PLTF-3242 Emit cleanup backlog/throughput counts as a structured log summary by @aivong-openhands in https://github.com/OpenHands/runtime-api/pull/665 -* build(deps): bump aiohttp from 3.13.4 to 3.14.1 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/680 -* build(deps): bump ddtrace from 3.5.1 to 4.8.2 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/687 -* build(deps): bump awscli from 1.44.38 to 1.44.78 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/689 -* build(deps): bump pyasn1 from 0.6.3 to 0.6.4 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/688 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat(charts): device-plugin subchart for kvm/fuse passthrough by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1006 -* feat(openhands): PLTF-1247 offer Valkey as an opt-in cache backend by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1007 -* feat(agent-canvas): bump chart image tag to 1.10.0 by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1024 - -#### Bug Fixes -* fix(budget-maintenance): disable cronjob until fixed image ships by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/999 -* fix(replicated): preserve Keycloak identity provider timeout by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1001 -* fix: disable email changes for Replicated installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1002 -* fix(rustfs): PLTF-1250 make the bundled store deployable when enabled by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1010 -* fix(charts): pass fuse_s3_mount through warm-runtimes configmap by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1011 -* fix(build): PLTF-1250 stop shipping Chart.yaml.bak in released charts by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1013 -* fix(build): PLTF-1250 restore Chart.lock after packaging by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1014 -* fix(charts)!: OHE-3033 durable automation package storage by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1015 -* fix(charts): restore the nested sandbox hostname default by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1021 -* fix(litellm-helm): bump default image tag to 1.94.1 for memory fix by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1023 -* fix(budget-maintenance): re-enable cronjob with 1.49.1 by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1018 - -#### Maintenance -* chore: bump Agent Canvas chart image to 1.9.0 by @malhotra5 in https://github.com/OpenHands/OpenHands-Cloud/pull/1009 -* chore: add storage-lifetime and naming checks to the code-review skill by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1016 - -## 0.36.1 - -This patch release was focused on stability fixes for the Enterprise Server, including preserving user sessions during transient network failures and giving deployments the ability to disable email changes. - -### Enterprise Server - -#### Bug Fixes -* fix(auth): preserve sessions during transient network failures by @ak684 in https://github.com/OpenHands/enterprise/pull/81 -* fix: allow deployments to disable email changes by @ak684 in https://github.com/OpenHands/enterprise/pull/110 -* fix(enterprise): fix broken import in run_budget_maintenance.py by @saurya in https://github.com/OpenHands/enterprise/pull/80 - -## 0.36.0 - -This release makes the **Agent Canvas** experience available to users at `your-openhands-instance.acmeco.com/canvas`. As mentioned in 0.28.0 release notes, Agent Canvas will coexist with the current OpenHands Enterprise conversation interface for the time being. A future release will announce the deprecation date for the current interface, after which Agent Canvas will become the default UI. - -Additionally, this release improves security and adds support for Bitbucket Data Center as a supported Git provider for Skills marketplace registrations. Improvements to database-pool resiliency, LLM usage-metrics accuracy, and runtime cleanup performance have also made it into this release. - -### Enterprise Server - -#### Features -* feat: Expose app and SDK versions in server info by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15345 -* feat: surface sandbox start-failure reason in conversation start errors by @ak684 in https://github.com/OpenHands/OpenHands/pull/14885 -* feat(settings): support title generation profile preference by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15366 -* feat: Allow disabling redis_rate_limiter via empty RATE_LIMIT_AUTH_WINDOWS by @tofarr in https://github.com/OpenHands/enterprise/pull/97 -* feat: Enforce CSP via middleware (OHE-2815) by @tofarr in https://github.com/OpenHands/enterprise/pull/94 - -#### Bug Fixes -* fix(app-server): support Bitbucket Data Center personal repos as marketplace sources by @ak684 in https://github.com/OpenHands/OpenHands/pull/15334 -* fix(frontend): add jittered rate-limit backoff by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/15236 -* fix: upgraded instances with no superadmin by @tofarr in https://github.com/OpenHands/OpenHands/pull/15349 -* fix: clear member key on managed profile switch by @saurya in https://github.com/OpenHands/OpenHands/pull/15356 -* fix(enterprise): avoid rotating keys on LiteLLM non-auth errors by @saurya in https://github.com/OpenHands/OpenHands/pull/15267 -* fix(app-server): persist combined LLM usage metrics across all usage buckets by @ak684 in https://github.com/OpenHands/OpenHands/pull/15354 -* fix(app-server): prevent webhook callbacks from starving the database pool by @ak684 in https://github.com/OpenHands/OpenHands/pull/15379 -* fix: filter automation event forwarding by requested types by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15388 -* fix: enforce cloud analytics consent from TOS by @malhotra5 in https://github.com/OpenHands/enterprise/pull/79 -* fix(ci): use private bot PAT for pr-artifacts cleanup job by @jlav in https://github.com/OpenHands/enterprise/pull/88 -* fix(enterprise): atomically migrate legacy empty tool settings by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/12 -* fix(settings): accept legacy detached MCP configs by @neubig in https://github.com/OpenHands/enterprise/pull/93 - -#### Maintenance -* test: PLTF-1269 split enterprise test_user_model into focused per-model tests by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/13997 -* chore: Suppress verbose Laminar info logs by @tofarr in https://github.com/OpenHands/OpenHands/pull/15374 -* chore: Unify release-please into a single semver release line by @mamoodi in https://github.com/OpenHands/enterprise/pull/76 - ---- - -### Software Agent SDK - -#### Features -* feat: surface plugin contents in the agent-server plugins API by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4103 -* Lazily hydrate persisted conversations by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4100 -* feat(agent-server): support deployment context on profile launches by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4030 -* feat(agent-server): sanitized product-analytics telemetry with split consent policy by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4172 -* feat: add opt-in persistent memory across sessions by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4178 -* feat(marketplace): auto-load standalone marketplace skills by @ak684 in https://github.com/OpenHands/software-agent-sdk/pull/4176 -* feat(mcp): subscribe to tools/list_changed for progressive-disclosure servers by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/3894 -* feat(agent-server): persist parent/child conversation relationships by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4188 -* feat: expose agent_context.load_memory in the agent-settings schema by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4205 -* feat: publish typed Agent Server OpenAPI contract by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4229 -* feat: automate TypeScript client contract handoff by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4234 -* feat(agent-server): add MCP settings CRUD endpoints by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4294 -* feat: add MCPServer.enabled to switch a server off without removing it by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4307 - -#### Bug Fixes -* fix(sdk): rehydrate persisted subscription LLMs by @lufen in https://github.com/OpenHands/software-agent-sdk/pull/4092 -* fix(observability): stamp tool_call_id onto the TOOL span by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4010 -* Fix REST API contract summary deduplication by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/3918 -* fix(acp): bound ACP server startup with a timeout by @rsd-darshan in https://github.com/OpenHands/software-agent-sdk/pull/4126 -* fix(visualizer): show per-request token usage alongside cumulative by @luciobaiocchi in https://github.com/OpenHands/software-agent-sdk/pull/4146 -* fix(agent): apply filter_tools_regex to runtime tools by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4186 -* fix(sdk): accept boolean JSON Schema nodes in _process_schema_node by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4185 -* fix(sdk): mask all registered secrets, not only exported ones by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4191 -* fix(acp): persist rotated Codex credentials by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4124 -* fix(settings): restore MCP schema migration by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4013 -* fix(terminal): submit multiline PowerShell commands on Windows by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4155 -* fix(agent-server): default bind host to loopback without a session API key by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4180 -* fix: parallel tool metrics by @luciobaiocchi in https://github.com/OpenHands/software-agent-sdk/pull/4193 -* fix(agent-server): /api/vscode/url without base_url advertises the configured VSCode port by @harish-chandramowli in https://github.com/OpenHands/software-agent-sdk/pull/4181 -* fix(agent-server): require credential reactivation before cold load by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4198 -* fix(sdk): reject unknown event parents on append by @hxaxd in https://github.com/OpenHands/software-agent-sdk/pull/4089 -* fix(agent-server): redact LLM & condenser secrets in download-trajectory by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4217 -* fix: honor the stored memory preference on profile launches by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4223 -* fix(agent-server): include server_base_path in the advertised VSCode URL by @harish-chandramowli in https://github.com/OpenHands/software-agent-sdk/pull/4222 -* fix(sdk): mark corrective nudge as environment event by @Sehlani042 in https://github.com/OpenHands/software-agent-sdk/pull/3954 -* fix(security): authenticate WebSockets outside URLs by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4279 -* fix(llm): generalize model capability resolution by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4200 -* fix(security): stop logging runtime command contents by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4280 - -#### Maintenance -* chore(deps): bump starlette from 1.0.1 to 1.3.1 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4140 -* chore(deps): bump pyjwt from 2.12.0 to 2.13.0 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4138 -* chore(deps): bump tornado from 6.5.5 to 6.5.7 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4139 -* chore(deps): bump python-multipart from 0.0.27 to 0.0.31 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4141 -* chore(deps): bump cryptography from 46.0.7 to 48.0.1 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4142 -* bump laminar to latest version, fix compat issues by @dinmukhamedm in https://github.com/OpenHands/software-agent-sdk/pull/4179 -* perf(agent-server): index conversation execution status for search/count by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4201 -* perf(agent-server): evict idle conversations from memory after a configurable TTL by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4202 -* Import SkillInfo from the SDK instead of redefining it in skills_router by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4277 -* Move duplicated LLM option blocks into common.py by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4276 -* Share the Gemini edit/write_file diff rendering by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4278 - ---- - -### Runtime API - -#### Features -* feat(cleanup): paginate cleanup_stuck_pvcs PVC list by @tofarr in https://github.com/OpenHands/runtime-api/pull/658 -* feat: surface pod scheduling/image failure reason in sandbox status by @ak684 in https://github.com/OpenHands/runtime-api/pull/615 - -#### Bug Fixes -* fix(cleanup): archive with actual conversation IDs by @simonrosenberg in https://github.com/OpenHands/runtime-api/pull/654 -* fix: reap runtimes stuck Pending/unschedulable by @ak684 in https://github.com/OpenHands/runtime-api/pull/655 -* fix: Optimize idle runtime cleanup pod listing by @tofarr in https://github.com/OpenHands/runtime-api/pull/662 - -#### Maintenance -* perf(cleanup): page snapshot_and_delete_idle_pvcs over bound PVCs by @tofarr in https://github.com/OpenHands/runtime-api/pull/660 -* build(deps): bump starlette from 0.49.1 to 1.3.1 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/650 - ---- - -### Automation - -#### Features -* feat: add automation server info endpoint by @malhotra5 in https://github.com/OpenHands/automation/pull/248 -* feat: capture automation telemetry events by @malhotra5 in https://github.com/OpenHands/automation/pull/254 -* feat: expose requested automation event types by @malhotra5 in https://github.com/OpenHands/automation/pull/260 -* feat: expose automation capabilities and preflight validation by @hieptl in https://github.com/OpenHands/automation/pull/270 - -#### Bug Fixes -* fix: add server versions to telemetry by @malhotra5 in https://github.com/OpenHands/automation/pull/256 -* fix: normalize MCP config shapes in automation presets by @malhotra5 in https://github.com/OpenHands/automation/pull/257 -* fix: attribute PostHog events to automation actors by @neubig in https://github.com/OpenHands/automation/pull/265 -* fix(security): keep injected secrets out of commands by @simonrosenberg in https://github.com/OpenHands/automation/pull/267 - -#### Maintenance -* chore: Add missing index on automation_runs.automation_id by @aivong-openhands in https://github.com/OpenHands/automation/pull/250 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat: enable the pending-runtime reaper on OHE installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/931 -* feat(charts): add external S3 file store support by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/946 -* feat(openhands): PLTF-3258 re-add fail guard for postgresql disabled without external database by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/948 -* feat: add SMTP and budget maintenance deployment wiring by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/780 -* feat: wire Agent Canvas through Replicated/Helm installs by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/954 -* feat(rustfs): PLTF-1250 optional in-cluster object store by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/983 -* feat(charts): adopt kubernetes recommended labels by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/960 -* feat(dns): add a simple single-wildcard hostname layout by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/985 - -#### Bug Fixes -* fix(openhands): namespace-qualify bundled litellm url for sandboxes by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/937 -* fix(openhands): validate filestore values and test external S3 env by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/947 -* fix(openhands): PLTF-3258 scope render guards to enabled releases by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/950 -* fix: increase Replicated MinIO resource headroom by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/970 -* fix(integrations-hub): default admin.emails to empty by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/976 -* fix(budget-maintenance): disable the budget maintenance cronjob by default by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/978 -* fix(minio): PLTF-1250 stop the bundled bucket job purging data on every upgrade by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/981 -* fix(integrations-hub): derive public base URL by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/963 -* fix(litellm): PLTF-3363 bump pinned litellm image to 1.93.0 by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/987 -* fix(auth): extend Keycloak identity provider timeout by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/975 -* fix(troubleshoot): PLTF-3264 unblock support bundle exec collectors on Helm installs by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/989 -* fix(replicated): PLTF-3264 include app and license info in support bundles by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/992 -* fix(replicated): PLTF-3264 pass the SDK its pull secret in map form by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/996 - -#### Maintenance -* ci: PLTF-3287 sticky comment notify on openhands chart appVersion drift by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/951 -* chore(openhands-secrets): remove no-op config keys by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/871 -* chore(openhands): remove no-op values file keys by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/869 -* chore(openhands): pin redis master resources to effective values by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/868 -* revert: re-enable budget maintenance by default by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/982 - -## 0.28.0 - -This release adds the embedded **Agent Canvas** endpoint (mounted under `your-openhands-instance.acmeco.com/canvas`). Agent Canvas will coexist with the current OpenHands Enterprise conversation interface for the time being. A future release will announce the deprecation date for the current interface, after which Agent Canvas will become the default UI; in the meantime, teams can begin experimenting with the new Agent Canvas experience and share feedback with the OpenHands product teams. - -Additionally, this release brings better Helm chart validation and more configuration options to make installs easier to configure and validate. The rest of the release is focused on stability and maintenance fixes. - -### Enterprise Server - -#### Bug Fixes -* fix: retry idempotent runtime-api reads once on timeout by @ak684 in https://github.com/OpenHands/OpenHands/pull/15266 -* fix(agent-profiles): honor profile settings in cloud launches by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15228 -* fix: Fix CVE-2026-53571: Update vite to 8.0.16, 7.3.5, 6.4.3 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14982 -* fix: restore automations login redirects by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15295 -* fix: Avoid logout on transient provider get_user errors by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15305 -* fix: treat Integrations Hub as a cross-app route by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15324 -* fix: add managed LLM key refresh endpoint by @neubig in https://github.com/OpenHands/OpenHands/pull/15023 -* fix(app-server): restore previous DB pool_size default by @dylan-openhands in https://github.com/OpenHands/OpenHands/pull/15333 -* fix: Debounce last_used_at writes in ApiKeyStore.validate_api_key by @tofarr in https://github.com/OpenHands/OpenHands/pull/15331 -* fix(jira): allow conversations without repositories by @tofarr in https://github.com/OpenHands/OpenHands/pull/15328 - ---- - -### Runtime API - -#### Bug Fixes -* fix: recycle pooled DB connections and bound pg8000 socket reads by @ak684 in https://github.com/OpenHands/runtime-api/pull/640 -* fix(cleanup): paginate deployment listing to stop OOM in cleanup job by @rbren in https://github.com/OpenHands/runtime-api/pull/642 -* fix(cleanup): hold archive concurrency slot until worker finishes (#643) by @aivong-openhands in https://github.com/OpenHands/runtime-api/pull/644 - -#### Maintenance -* perf(cleanup): batch PVC snapshot waits instead of blocking serially by @jlav in https://github.com/OpenHands/runtime-api/pull/648 -* build(deps): bump python-multipart from 0.0.27 to 0.0.31 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/652 -* build(deps): bump cryptography from 46.0.7 to 48.0.1 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/651 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat(openhands): PLTF-3256 add values.schema.json for chart values validation by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/920 -* feat(openhands): PLTF-3257 add NOTES.txt post-install output to the openhands chart by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/922 -* feat: mount Agent Canvas under /canvas by @malhotra5 in https://github.com/OpenHands/OpenHands-Cloud/pull/900 -* feat: Added environment variable for RUNTIME_API_BASE_URL by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/926 -* feat(openhands): PLTF-3258 add fail guard for ingress.enabled without ingress.host by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/923 -* feat: route Integrations Hub on the primary OpenHands host by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/899 -* feat: expose sandbox ephemeral-storage as a configurable field by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/930 - -#### Bug Fixes -* fix(release): make lint pass --app [PLTF-3195] by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/898 -* fix: preserve Integrations Hub API auth responses by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/933 - -#### Maintenance -* chore(postgres): remove obsolete emptyDir-to-PVC migration by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/919 - -## 0.24.0 - -This release introduces a **Usage & Monitoring** dashboard, giving organization administrators visibility into AI spend and adoption across the organization. This dashboard provides high-level reports showing conversation counts, active sessions, and cost-per-conversation metrics, along with detailed conversation, user, and model-level breakdowns to help teams measure efficiency and ROI. - -The new **Budgets** feature -- also enabled for organization admins -- enables org-level spending limits with configurable alert thresholds (e.g., 80%, 90%, 100%) delivered via email or Slack. Default budgets and override budgets allow administrators to manage individual user spending limits. - -The **Settings → Agent** page enables the use of third-party agents -- like Claude Code or Codex -- on OpenHands Enterprise sandboxes through the ACP (Agent Canvas Protocol) framework. - -Several additional Jira Cloud and Data CEnter enhancements have been made to improve overall integration experience. - -### Enterprise Server - -#### Features -* feat: implement semantic file chunking using tree-sitter AST parsing by @ysinghc in https://github.com/OpenHands/OpenHands/pull/14699 -* feat(org): Add organization conversation admin dashboard by @saurya in https://github.com/OpenHands/OpenHands/pull/14846 -* feat(app-server): capture production workspace state — initial snapshot at start + archive before delete (APP-2403) by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/14953 -* feat(device-verify): align warning, button color, and add workspace dropdown by @tofarr in https://github.com/OpenHands/OpenHands/pull/15031 -* feat(enterprise/auth): add super roles via user.role_id with permission fallback by @chuckbutkus in https://github.com/OpenHands/OpenHands/pull/14937 -* feat(org): expose caller permissions on GET /organizations/{id}/me by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/15048 -* feat(api-keys): add optional active window (not_before & expires_at) by @tofarr in https://github.com/OpenHands/OpenHands/pull/15085 -* feat(app-server): add repo/branch to Laminar trace metadata by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15059 -* feat: add parallel tool calls (tool_concurrency_limit) to agent settings by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/14929 -* feat(api-keys): make 'unbound' org scope an explicit, first-class option by @tofarr in https://github.com/OpenHands/OpenHands/pull/15096 -* feat(jira-dc): fix the integration panel so members get guidance, not the admin setup form by @ak684 in https://github.com/OpenHands/OpenHands/pull/15040 -* feat: Add dynamic marketplace support for plugin registration by @HeyItsChloe in https://github.com/OpenHands/OpenHands/pull/14887 -* feat(saas-auth): accept api_key cookie as a fallback credential by @tofarr in https://github.com/OpenHands/OpenHands/pull/15101 -* feat(enterprise/auth): super-admin management endpoint (grant/revoke/list) by @jpshackelford in https://github.com/OpenHands/OpenHands/pull/15006 -* feat: rename admin dashboard to usage & monitoring by @saurya in https://github.com/OpenHands/OpenHands/pull/15146 -* feat: add SMTP email service by @saurya in https://github.com/OpenHands/OpenHands/pull/15144 -* feat: track user login timestamps by @saurya in https://github.com/OpenHands/OpenHands/pull/15148 -* feat: surface email enabled for smtp/resend by @saurya in https://github.com/OpenHands/OpenHands/pull/15185 -* feat: pass repository metadata to observability traces by @neubig in https://github.com/OpenHands/OpenHands/pull/14431 -* feat(enterprise): Agent Profiles on the cloud/SaaS backend (#15044) by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15060 -* feat(backend): Add Budgets dashboard and expand Usage Dashboard by @saurya in https://github.com/OpenHands/OpenHands/pull/15149 -* feat: budgets and usage monitoring UI by @saurya in https://github.com/OpenHands/OpenHands/pull/15186 -* feat: surface email enabled for smtp/resend by @saurya in https://github.com/OpenHands/OpenHands/pull/15214 -* feat(app-server): enrich final archive manifests and remove initial snapshots by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15058 -* feat(enterprise): make BYOR key alias pattern configurable by @tofarr in https://github.com/OpenHands/OpenHands/pull/15232 - -#### Bug Fixes -* fix(jira): make Jira Cloud and Jira DC HTTP timeouts configurable and consistent by @ak684 in https://github.com/OpenHands/OpenHands/pull/15012 -* fix: Fix CVE-2026-44681: Update authlib to >=1.6.12 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14983 -* fix: don't switch LLM profile before the conversation UUID exists (avoids 422) by @ak684 in https://github.com/OpenHands/OpenHands/pull/14900 -* fix(enterprise): log automation HTTP response failures as errors by @wgu9 in https://github.com/OpenHands/OpenHands/pull/15004 -* fix(enterprise): add alembic migration for execution_status column by @tofarr in https://github.com/OpenHands/OpenHands/pull/15030 -* fix(jira-dc): more forgiving repo + mention resolution for Data Center by @ak684 in https://github.com/OpenHands/OpenHands/pull/15034 -* fix(device-verify): rename 'Workspace' dropdown to 'Organization' by @tofarr in https://github.com/OpenHands/OpenHands/pull/15057 -* fix(jira-dc): don't org-gate a personal-workspace Jira DC integration by @ak684 in https://github.com/OpenHands/OpenHands/pull/15036 -* fix: stream LLM tokens for cloud conversations and profile switches by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/15021 -* fix: set email person property in PostHog during onboarding completion by @lilagrc in https://github.com/OpenHands/OpenHands/pull/15070 -* fix: Timezones stored in the db do not have a timezone by @tofarr in https://github.com/OpenHands/OpenHands/pull/15092 -* fix: add test for InMemoryRateLimiter.__init__ to prevent duplicate assignment regression by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/14729 -* fix(frontend): stop streamed deltas rendering twice and fragmenting in V1 chat by @shanemort1982 in https://github.com/OpenHands/OpenHands/pull/15108 -* fix: crash when request.client is None in InMemoryRateLimiter by @rakshith1928 in https://github.com/OpenHands/OpenHands/pull/15119 -* fix(sandbox-spec): fall back to defaults when runtime-api has no warm runtimes by @tofarr in https://github.com/OpenHands/OpenHands/pull/15141 -* fix: settings page scroll layout by @saurya in https://github.com/OpenHands/OpenHands/pull/15147 -* fix(app_server): pass flat mcp_config shape to SDK Agent by @tofarr in https://github.com/OpenHands/OpenHands/pull/15159 -* fix: scroll settings sidebar so Skills is reachable in orgs by @hieptl in https://github.com/OpenHands/OpenHands/pull/15138 -* fix(frontend): read SDK 1.31.x flat mcp_config wire format by @tofarr in https://github.com/OpenHands/OpenHands/pull/15165 -* fix(app_server): derive agent server image from package version by @tofarr in https://github.com/OpenHands/OpenHands/pull/15168 -* fix(app-server): pass index columns as a list in migration 013 by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/15176 -* fix: default ENABLE_ACP on so ACP agent settings show in OH Cloud by @hieptl in https://github.com/OpenHands/OpenHands/pull/15183 -* fix: send authenticated marketplace URLs to agent-server by @hieptl in https://github.com/OpenHands/OpenHands/pull/15187 -* fix: prevent webhook-driven DB connection leaks by @tofarr in https://github.com/OpenHands/OpenHands/pull/15212 -* fix(frontend): mention SMTP env vars for budget alerts by @saurya in https://github.com/OpenHands/OpenHands/pull/15218 -* fix(enterprise): cascade-delete conversation_cost_events on conversation delete by @tofarr in https://github.com/OpenHands/OpenHands/pull/15220 -* fix: Enable LIFO database connection pooling by @tofarr in https://github.com/OpenHands/OpenHands/pull/15225 -* fix(app-server): preserve observability context metadata by @hxaxd in https://github.com/OpenHands/OpenHands/pull/15215 -* fix(app-server): preserve conversation created_at across lifecycle webhooks by @Sujit-1509 in https://github.com/OpenHands/OpenHands/pull/15243 -* fix(mcp): preserve SaaS credentials with encrypted storage by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15257 -* fix(frontend): restore cross-domain PostHog tracking by aligning client/server distinct_id (WIP) by @lilagrc in https://github.com/OpenHands/OpenHands/pull/15100 -* fix(app-server): lower DB pool defaults and make them env-tunable by @dylan-openhands in https://github.com/OpenHands/OpenHands/pull/15270 -* fix(mcp): preserve MCP auth secrets stripped by settings GET round-trip by @jlav in https://github.com/OpenHands/OpenHands/pull/15285 - -#### Maintenance -* build: pin dependency versions exactly by @rbren in https://github.com/OpenHands/OpenHands/pull/14384 -* ci: add release ready gate by @enyst in https://github.com/OpenHands/OpenHands/pull/14987 -* ci: PLTF-2960 open a chart image-tag bump PR on cloud release by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/15166 -* ci: PLTF-2960 sync chart appVersion with cloud image tag by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/15219 -* ci: wait for the docker build before retagging images by @jlav in https://github.com/OpenHands/OpenHands/pull/15213 -* chore: Update README.md by @rbren in https://github.com/OpenHands/OpenHands/pull/15271 - ---- - -### Software Agent SDK - -#### Features -* feat(agent-server): expose repository metadata for workspace archives by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/3932 -* feat: commit-history API — list commits and per-commit diffs by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4075 -* feat(security): add ToolShieldLLMSecurityAnalyzer by @xli04 in https://github.com/OpenHands/software-agent-sdk/pull/2911 - -#### Bug Fixes -* fix(skills): match keyword triggers on whole words only by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4008 -* fix(sdk): reconnect remote conversation websocket by @bozhnyukAlex in https://github.com/OpenHands/software-agent-sdk/pull/3987 -* fix(security): add a secret-disclosure consent rule to the agent security policy by @warmjademe in https://github.com/OpenHands/software-agent-sdk/pull/3823 -* fix(sdk): keep legacy history on resume when the stored tail is a non-tree artifact by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4068 -* fix: support GPT-5.6 across Codex authentication by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4056 -* fix: pick a display base ref that keeps committed work visible by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4065 -* fix(mcp): validate secrets after parsing by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4099 -* fix(skills): make marketplaces additive to public skills by @rsd-darshan in https://github.com/OpenHands/software-agent-sdk/pull/4087 -* fix(mcp): preserve nested object properties in LLM-facing tool schema by @ixchio in https://github.com/OpenHands/software-agent-sdk/pull/4011 -* [codex] fix ACP prompt argument order by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/3996 - -#### Maintenance -* ci(version-bump-prs): make PR-creation steps independent by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4051 -* ci: add release security-scan by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4042 -* chore(deps): bump MishaKav/pytest-coverage-comment from 1.7.2 to 1.10.0 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4046 -* chore(deps): bump docker/setup-buildx-action from 4.0.0 to 4.2.0 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4045 - ---- - -### Runtime API - -#### Features -* feat(logging): emit exc_info and stack_info as JSON arrays by @tofarr in https://github.com/OpenHands/runtime-api/pull/635 -* feat(cleanup): enrich final workspace archive manifests by @simonrosenberg in https://github.com/OpenHands/runtime-api/pull/630 - -#### Bug Fixes -* fix: prevent DetachedInstanceError on Runtime accessed after session close by @tofarr in https://github.com/OpenHands/runtime-api/pull/636 - ---- - -### OpenHands Cloud (Helm Chart) - -#### Features -* feat: upgrade embedded cluster to 2.19.2+k8s-1.34 by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/821 -* feat: upgrade embedded cluster to 2.19.2+k8s-1.35 by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/822 -* feat: upgrade embedded cluster to 2.19.2+k8s-1.36 by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/826 -* feat(sysbox): default sandbox isolation on the embedded cluster by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/770 -* feat: PLTF-3196 Configure global OpenHands resolver label by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/807 -* feat: PLTF-2960 sync metadata with image tag bumps by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/828 -* feat: Add replicated vendor portal links in release workflows by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/833 -* feat: PLTF-3198 enable the Replicated SDK by default for helm installs by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/895 -* feat(replicated): add OEM User Creation Flow advanced option by @jpshackelford in https://github.com/OpenHands/OpenHands-Cloud/pull/914 - -#### Bug Fixes -* fix(postgres): raise embedded postgres memory limit to avoid OOM by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/829 -* fix: improve integrations-hub Datadog and probe configuration by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/862 -* fix(openhands): stop warm-runtimes job pods matching the runtime-api Service selector by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/867 -* fix(openhands): mirror agentServerEnv into warm-runtime env so warm pools stay claimable by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/866 -* fix: set default agent-server tag back to 1.36.0-python by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/908 - -#### Maintenance -* ci: PLTF-2920 dispatch staging chart bumps after publish by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/801 -* refactor(openhands): rename gitlab webhook install cronjob by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/865 -* ci: PLTF-3193 dispatch development chart bumps after publish by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/843 -* test: PLTF-1257 helm-unittest setup by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/894 -* chore: add CODEOWNERS by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/878 diff --git a/enterprise/release-notes/0.24.0.mdx b/enterprise/release-notes/0.24.0.mdx new file mode 100644 index 000000000..87bfd387a --- /dev/null +++ b/enterprise/release-notes/0.24.0.mdx @@ -0,0 +1,165 @@ +--- +title: OpenHands Enterprise 0.24.0 +description: Release notes for OpenHands Enterprise version 0.24.0 +--- + +# OpenHands Enterprise 0.24.0 + +Released September 23, 2026. + +## Highlights + +- **Usage & Monitoring Dashboard** — Organization administrators gain visibility into AI spend and adoption with conversation counts, active sessions, cost-per-conversation metrics, and detailed breakdowns +- **Budgets Feature** — Org-level spending limits with configurable alert thresholds (80%, 90%, 100%) delivered via email or Slack; includes default and override budgets for individual users +- **Third-Party Agent Support** — Settings → Agent page enables Claude Code, Codex, and other third-party agents through the ACP (Agent Canvas Protocol) framework +- **Jira Enhancements** — Improved Cloud and Data Center integration experience + +## Features + +#### Enterprise Server + +* feat: implement semantic file chunking using tree-sitter AST parsing by @ysinghc in https://github.com/OpenHands/OpenHands/pull/14699 +* feat(org): Add organization conversation admin dashboard by @saurya in https://github.com/OpenHands/OpenHands/pull/14846 +* feat(app-server): capture production workspace state — initial snapshot at start + archive before delete (APP-2403) by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/14953 +* feat(device-verify): align warning, button color, and add workspace dropdown by @tofarr in https://github.com/OpenHands/OpenHands/pull/15031 +* feat(enterprise/auth): add super roles via user.role_id with permission fallback by @chuckbutkus in https://github.com/OpenHands/OpenHands/pull/14937 +* feat(org): expose caller permissions on GET /organizations/{id}/me by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/15048 +* feat(api-keys): add optional active window (not_before & expires_at) by @tofarr in https://github.com/OpenHands/OpenHands/pull/15085 +* feat(app-server): add repo/branch to Laminar trace metadata by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15059 +* feat: add parallel tool calls (tool_concurrency_limit) to agent settings by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/14929 +* feat(api-keys): make 'unbound' org scope an explicit, first-class option by @tofarr in https://github.com/OpenHands/OpenHands/pull/15096 +* feat(jira-dc): fix the integration panel so members get guidance, not the admin setup form by @ak684 in https://github.com/OpenHands/OpenHands/pull/15040 +* feat: Add dynamic marketplace support for plugin registration by @HeyItsChloe in https://github.com/OpenHands/OpenHands/pull/14887 +* feat(saas-auth): accept api_key cookie as a fallback credential by @tofarr in https://github.com/OpenHands/OpenHands/pull/15101 +* feat(enterprise/auth): super-admin management endpoint (grant/revoke/list) by @jpshackelford in https://github.com/OpenHands/OpenHands/pull/15006 +* feat: rename admin dashboard to usage & monitoring by @saurya in https://github.com/OpenHands/OpenHands/pull/15146 +* feat: add SMTP email service by @saurya in https://github.com/OpenHands/OpenHands/pull/15144 +* feat: track user login timestamps by @saurya in https://github.com/OpenHands/OpenHands/pull/15148 +* feat: surface email enabled for smtp/resend by @saurya in https://github.com/OpenHands/OpenHands/pull/15185 +* feat: pass repository metadata to observability traces by @neubig in https://github.com/OpenHands/OpenHands/pull/14431 +* feat(enterprise): Agent Profiles on the cloud/SaaS backend (#15044) by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15060 +* feat(backend): Add Budgets dashboard and expand Usage Dashboard by @saurya in https://github.com/OpenHands/OpenHands/pull/15149 +* feat: budgets and usage monitoring UI by @saurya in https://github.com/OpenHands/OpenHands/pull/15186 +* feat: surface email enabled for smtp/resend by @saurya in https://github.com/OpenHands/OpenHands/pull/15214 +* feat(app-server): enrich final archive manifests and remove initial snapshots by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15058 +* feat(enterprise): make BYOR key alias pattern configurable by @tofarr in https://github.com/OpenHands/OpenHands/pull/15232 + +#### Software Agent SDK + +* feat(agent-server): expose repository metadata for workspace archives by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/3932 +* feat: commit-history API — list commits and per-commit diffs by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4075 +* feat(security): add ToolShieldLLMSecurityAnalyzer by @xli04 in https://github.com/OpenHands/software-agent-sdk/pull/2911 + +#### Runtime API + +* feat(logging): emit exc_info and stack_info as JSON arrays by @tofarr in https://github.com/OpenHands/runtime-api/pull/635 +* feat(cleanup): enrich final workspace archive manifests by @simonrosenberg in https://github.com/OpenHands/runtime-api/pull/630 + +#### OpenHands Cloud (Helm Chart) + +* feat: upgrade embedded cluster to 2.19.2+k8s-1.34 by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/821 +* feat: upgrade embedded cluster to 2.19.2+k8s-1.35 by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/822 +* feat: upgrade embedded cluster to 2.19.2+k8s-1.36 by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/826 +* feat(sysbox): default sandbox isolation on the embedded cluster by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/770 +* feat: PLTF-3196 Configure global OpenHands resolver label by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/807 +* feat: PLTF-2960 sync metadata with image tag bumps by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/828 +* feat: Add replicated vendor portal links in release workflows by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/833 +* feat: PLTF-3198 enable the Replicated SDK by default for helm installs by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/895 +* feat(replicated): add OEM User Creation Flow advanced option by @jpshackelford in https://github.com/OpenHands/OpenHands-Cloud/pull/914 + +## Bug Fixes + +#### Enterprise Server + +* fix(jira): make Jira Cloud and Jira DC HTTP timeouts configurable and consistent by @ak684 in https://github.com/OpenHands/OpenHands/pull/15012 +* fix: Fix CVE-2026-44681: Update authlib to >=1.6.12 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14983 +* fix: don't switch LLM profile before the conversation UUID exists (avoids 422) by @ak684 in https://github.com/OpenHands/OpenHands/pull/14900 +* fix(enterprise): log automation HTTP response failures as errors by @wgu9 in https://github.com/OpenHands/OpenHands/pull/15004 +* fix(enterprise): add alembic migration for execution_status column by @tofarr in https://github.com/OpenHands/OpenHands/pull/15030 +* fix(jira-dc): more forgiving repo + mention resolution for Data Center by @ak684 in https://github.com/OpenHands/OpenHands/pull/15034 +* fix(device-verify): rename 'Workspace' dropdown to 'Organization' by @tofarr in https://github.com/OpenHands/OpenHands/pull/15057 +* fix(jira-dc): don't org-gate a personal-workspace Jira DC integration by @ak684 in https://github.com/OpenHands/OpenHands/pull/15036 +* fix: stream LLM tokens for cloud conversations and profile switches by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/15021 +* fix: set email person property in PostHog during onboarding completion by @lilagrc in https://github.com/OpenHands/OpenHands/pull/15070 +* fix: Timezones stored in the db do not have a timezone by @tofarr in https://github.com/OpenHands/OpenHands/pull/15092 +* fix: add test for InMemoryRateLimiter.__init__ to prevent duplicate assignment regression by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/14729 +* fix(frontend): stop streamed deltas rendering twice and fragmenting in V1 chat by @shanemort1982 in https://github.com/OpenHands/OpenHands/pull/15108 +* fix: crash when request.client is None in InMemoryRateLimiter by @rakshith1928 in https://github.com/OpenHands/OpenHands/pull/15119 +* fix(sandbox-spec): fall back to defaults when runtime-api has no warm runtimes by @tofarr in https://github.com/OpenHands/OpenHands/pull/15141 +* fix: settings page scroll layout by @saurya in https://github.com/OpenHands/OpenHands/pull/15147 +* fix(app_server): pass flat mcp_config shape to SDK Agent by @tofarr in https://github.com/OpenHands/OpenHands/pull/15159 +* fix: scroll settings sidebar so Skills is reachable in orgs by @hieptl in https://github.com/OpenHands/OpenHands/pull/15138 +* fix(frontend): read SDK 1.31.x flat mcp_config wire format by @tofarr in https://github.com/OpenHands/OpenHands/pull/15165 +* fix(app_server): derive agent server image from package version by @tofarr in https://github.com/OpenHands/OpenHands/pull/15168 +* fix(app-server): pass index columns as a list in migration 013 by @VascoSch92 in https://github.com/OpenHands/OpenHands/pull/15176 +* fix: default ENABLE_ACP on so ACP agent settings show in OH Cloud by @hieptl in https://github.com/OpenHands/OpenHands/pull/15183 +* fix: send authenticated marketplace URLs to agent-server by @hieptl in https://github.com/OpenHands/OpenHands/pull/15187 +* fix: prevent webhook-driven DB connection leaks by @tofarr in https://github.com/OpenHands/OpenHands/pull/15212 +* fix(frontend): mention SMTP env vars for budget alerts by @saurya in https://github.com/OpenHands/OpenHands/pull/15218 +* fix(enterprise): cascade-delete conversation_cost_events on conversation delete by @tofarr in https://github.com/OpenHands/OpenHands/pull/15220 +* fix: Enable LIFO database connection pooling by @tofarr in https://github.com/OpenHands/OpenHands/pull/15225 +* fix(app-server): preserve observability context metadata by @hxaxd in https://github.com/OpenHands/OpenHands/pull/15215 +* fix(app-server): preserve conversation created_at across lifecycle webhooks by @Sujit-1509 in https://github.com/OpenHands/OpenHands/pull/15243 +* fix(mcp): preserve SaaS credentials with encrypted storage by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15257 +* fix(frontend): restore cross-domain PostHog tracking by aligning client/server distinct_id (WIP) by @lilagrc in https://github.com/OpenHands/OpenHands/pull/15100 +* fix(app-server): lower DB pool defaults and make them env-tunable by @dylan-openhands in https://github.com/OpenHands/OpenHands/pull/15270 +* fix(mcp): preserve MCP auth secrets stripped by settings GET round-trip by @jlav in https://github.com/OpenHands/OpenHands/pull/15285 + +#### Software Agent SDK + +* fix(skills): match keyword triggers on whole words only by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4008 +* fix(sdk): reconnect remote conversation websocket by @bozhnyukAlex in https://github.com/OpenHands/software-agent-sdk/pull/3987 +* fix(security): add a secret-disclosure consent rule to the agent security policy by @warmjademe in https://github.com/OpenHands/software-agent-sdk/pull/3823 +* fix(sdk): keep legacy history on resume when the stored tail is a non-tree artifact by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4068 +* fix: support GPT-5.6 across Codex authentication by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4056 +* fix: pick a display base ref that keeps committed work visible by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4065 +* fix(mcp): validate secrets after parsing by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4099 +* fix(skills): make marketplaces additive to public skills by @rsd-darshan in https://github.com/OpenHands/software-agent-sdk/pull/4087 +* fix(mcp): preserve nested object properties in LLM-facing tool schema by @ixchio in https://github.com/OpenHands/software-agent-sdk/pull/4011 +* [codex] fix ACP prompt argument order by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/3996 + +#### Runtime API + +* fix: prevent DetachedInstanceError on Runtime accessed after session close by @tofarr in https://github.com/OpenHands/runtime-api/pull/636 + +#### OpenHands Cloud (Helm Chart) + +* fix(postgres): raise embedded postgres memory limit to avoid OOM by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/829 +* fix: improve integrations-hub Datadog and probe configuration by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/862 +* fix(openhands): stop warm-runtimes job pods matching the runtime-api Service selector by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/867 +* fix(openhands): mirror agentServerEnv into warm-runtime env so warm pools stay claimable by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/866 +* fix: set default agent-server tag back to 1.36.0-python by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/908 + +## Maintenance + +#### Enterprise Server + +* build: pin dependency versions exactly by @rbren in https://github.com/OpenHands/OpenHands/pull/14384 +* ci: add release ready gate by @enyst in https://github.com/OpenHands/OpenHands/pull/14987 +* ci: PLTF-2960 open a chart image-tag bump PR on cloud release by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/15166 +* ci: PLTF-2960 sync chart appVersion with cloud image tag by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/15219 +* ci: wait for the docker build before retagging images by @jlav in https://github.com/OpenHands/OpenHands/pull/15213 +* chore: Update README.md by @rbren in https://github.com/OpenHands/OpenHands/pull/15271 + +#### Software Agent SDK + +* ci(version-bump-prs): make PR-creation steps independent by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4051 +* ci: add release security-scan by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4042 +* chore(deps): bump MishaKav/pytest-coverage-comment from 1.7.2 to 1.10.0 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4046 +* chore(deps): bump docker/setup-buildx-action from 4.0.0 to 4.2.0 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4045 + +#### OpenHands Cloud (Helm Chart) + +* ci: PLTF-2920 dispatch staging chart bumps after publish by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/801 +* refactor(openhands): rename gitlab webhook install cronjob by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/865 +* ci: PLTF-3193 dispatch development chart bumps after publish by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/843 +* test: PLTF-1257 helm-unittest setup by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/894 +* chore: add CODEOWNERS by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/878 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.28.0.mdx b/enterprise/release-notes/0.28.0.mdx new file mode 100644 index 000000000..dee3c9907 --- /dev/null +++ b/enterprise/release-notes/0.28.0.mdx @@ -0,0 +1,72 @@ +--- +title: OpenHands Enterprise 0.28.0 +description: Release notes for OpenHands Enterprise version 0.28.0 +--- + +# OpenHands Enterprise 0.28.0 + +Released September 23, 2026. + +## Highlights + +- **Agent Canvas Embedded** — New `/canvas` endpoint available; will coexist with current Enterprise interface while teams experiment and provide feedback +- **Helm Chart Improvements** — Better validation and more configuration options for easier installs +- **Stability & Maintenance** — Focus on fixes and improvements across the platform + +## Features + +#### OpenHands Cloud (Helm Chart) + +* feat(openhands): PLTF-3256 add values.schema.json for chart values validation by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/920 +* feat(openhands): PLTF-3257 add NOTES.txt post-install output to the openhands chart by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/922 +* feat: mount Agent Canvas under /canvas by @malhotra5 in https://github.com/OpenHands/OpenHands-Cloud/pull/900 +* feat: Added environment variable for RUNTIME_API_BASE_URL by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/926 +* feat(openhands): PLTF-3258 add fail guard for ingress.enabled without ingress.host by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/923 +* feat: route Integrations Hub on the primary OpenHands host by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/899 +* feat: expose sandbox ephemeral-storage as a configurable field by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/930 + +## Bug Fixes + +#### Enterprise Server + +* fix: retry idempotent runtime-api reads once on timeout by @ak684 in https://github.com/OpenHands/OpenHands/pull/15266 +* fix(agent-profiles): honor profile settings in cloud launches by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15228 +* fix: Fix CVE-2026-53571: Update vite to 8.0.16, 7.3.5, 6.4.3 by @mamoodi in https://github.com/OpenHands/OpenHands/pull/14982 +* fix: restore automations login redirects by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15295 +* fix: Avoid logout on transient provider get_user errors by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15305 +* fix: treat Integrations Hub as a cross-app route by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15324 +* fix: add managed LLM key refresh endpoint by @neubig in https://github.com/OpenHands/OpenHands/pull/15023 +* fix(app-server): restore previous DB pool_size default by @dylan-openhands in https://github.com/OpenHands/OpenHands/pull/15333 +* fix: Debounce last_used_at writes in ApiKeyStore.validate_api_key by @tofarr in https://github.com/OpenHands/OpenHands/pull/15331 +* fix(jira): allow conversations without repositories by @tofarr in https://github.com/OpenHands/OpenHands/pull/15328 + +#### Runtime API + +* fix: recycle pooled DB connections and bound pg8000 socket reads by @ak684 in https://github.com/OpenHands/runtime-api/pull/640 +* fix(cleanup): paginate deployment listing to stop OOM in cleanup job by @rbren in https://github.com/OpenHands/runtime-api/pull/642 +* fix(cleanup): hold archive concurrency slot until worker finishes (#643) by @aivong-openhands in https://github.com/OpenHands/runtime-api/pull/644 + +#### OpenHands Cloud (Helm Chart) + +* fix(release): make lint pass --app [PLTF-3195] by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/898 +* fix: preserve Integrations Hub API auth responses by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/933 + +## Maintenance + +#### Runtime API + +* perf(cleanup): batch PVC snapshot waits instead of blocking serially by @jlav in https://github.com/OpenHands/runtime-api/pull/648 +* build(deps): bump python-multipart from 0.0.27 to 0.0.31 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/652 +* build(deps): bump cryptography from 46.0.7 to 48.0.1 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/651 + +#### OpenHands Cloud (Helm Chart) + +* chore(postgres): remove obsolete emptyDir-to-PVC migration by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/919 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.36.0.mdx b/enterprise/release-notes/0.36.0.mdx new file mode 100644 index 000000000..960d5c982 --- /dev/null +++ b/enterprise/release-notes/0.36.0.mdx @@ -0,0 +1,182 @@ +--- +title: OpenHands Enterprise 0.36.0 +description: Release notes for OpenHands Enterprise version 0.36.0 +--- + +# OpenHands Enterprise 0.36.0 + +Released September 23, 2026. + +## Highlights + +- **Agent Canvas Now Available** — The Agent Canvas experience is now accessible at `/canvas` and will coexist with the current Enterprise conversation interface +- **Bitbucket Data Center Support** — Added as a supported Git provider for Skills marketplace registrations +- **Security & Performance** — Improved database-pool resiliency, LLM usage-metrics accuracy, and runtime cleanup performance + +## Features + +#### Enterprise Server + +* feat: Expose app and SDK versions in server info by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15345 +* feat: surface sandbox start-failure reason in conversation start errors by @ak684 in https://github.com/OpenHands/OpenHands/pull/14885 +* feat(settings): support title generation profile preference by @simonrosenberg in https://github.com/OpenHands/OpenHands/pull/15366 +* feat: Allow disabling redis_rate_limiter via empty RATE_LIMIT_AUTH_WINDOWS by @tofarr in https://github.com/OpenHands/enterprise/pull/97 +* feat: Enforce CSP via middleware (OHE-2815) by @tofarr in https://github.com/OpenHands/enterprise/pull/94 + +#### Software Agent SDK + +* feat: surface plugin contents in the agent-server plugins API by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4103 +* Lazily hydrate persisted conversations by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4100 +* feat(agent-server): support deployment context on profile launches by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4030 +* feat(agent-server): sanitized product-analytics telemetry with split consent policy by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4172 +* feat: add opt-in persistent memory across sessions by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4178 +* feat(marketplace): auto-load standalone marketplace skills by @ak684 in https://github.com/OpenHands/software-agent-sdk/pull/4176 +* feat(mcp): subscribe to tools/list_changed for progressive-disclosure servers by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/3894 +* feat(agent-server): persist parent/child conversation relationships by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4188 +* feat: expose agent_context.load_memory in the agent-settings schema by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4205 +* feat: publish typed Agent Server OpenAPI contract by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4229 +* feat: automate TypeScript client contract handoff by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4234 +* feat(agent-server): add MCP settings CRUD endpoints by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4294 +* feat: add MCPServer.enabled to switch a server off without removing it by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4307 + +#### Runtime API + +* feat(cleanup): paginate cleanup_stuck_pvcs PVC list by @tofarr in https://github.com/OpenHands/runtime-api/pull/658 +* feat: surface pod scheduling/image failure reason in sandbox status by @ak684 in https://github.com/OpenHands/runtime-api/pull/615 + +#### Automation + +* feat: add automation server info endpoint by @malhotra5 in https://github.com/OpenHands/automation/pull/248 +* feat: capture automation telemetry events by @malhotra5 in https://github.com/OpenHands/automation/pull/254 +* feat: expose requested automation event types by @malhotra5 in https://github.com/OpenHands/automation/pull/260 +* feat: expose automation capabilities and preflight validation by @hieptl in https://github.com/OpenHands/automation/pull/270 + +#### OpenHands Cloud (Helm Chart) + +* feat: enable the pending-runtime reaper on OHE installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/931 +* feat(charts): add external S3 file store support by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/946 +* feat(openhands): PLTF-3258 re-add fail guard for postgresql disabled without external database by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/948 +* feat: add SMTP and budget maintenance deployment wiring by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/780 +* feat: wire Agent Canvas through Replicated/Helm installs by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/954 +* feat(rustfs): PLTF-1250 optional in-cluster object store by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/983 +* feat(charts): adopt kubernetes recommended labels by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/960 +* feat(dns): add a simple single-wildcard hostname layout by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/985 + +## Bug Fixes + +#### Enterprise Server + +* fix(app-server): support Bitbucket Data Center personal repos as marketplace sources by @ak684 in https://github.com/OpenHands/OpenHands/pull/15334 +* fix(frontend): add jittered rate-limit backoff by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/15236 +* fix: upgraded instances with no superadmin by @tofarr in https://github.com/OpenHands/OpenHands/pull/15349 +* fix: clear member key on managed profile switch by @saurya in https://github.com/OpenHands/OpenHands/pull/15356 +* fix(enterprise): avoid rotating keys on LiteLLM non-auth errors by @saurya in https://github.com/OpenHands/OpenHands/pull/15267 +* fix(app-server): persist combined LLM usage metrics across all usage buckets by @ak684 in https://github.com/OpenHands/OpenHands/pull/15354 +* fix(app-server): prevent webhook callbacks from starving the database pool by @ak684 in https://github.com/OpenHands/OpenHands/pull/15379 +* fix: filter automation event forwarding by requested types by @malhotra5 in https://github.com/OpenHands/OpenHands/pull/15388 +* fix: enforce cloud analytics consent from TOS by @malhotra5 in https://github.com/OpenHands/enterprise/pull/79 +* fix(ci): use private bot PAT for pr-artifacts cleanup job by @jlav in https://github.com/OpenHands/enterprise/pull/88 +* fix(enterprise): atomically migrate legacy empty tool settings by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/12 +* fix(settings): accept legacy detached MCP configs by @neubig in https://github.com/OpenHands/enterprise/pull/93 + +#### Software Agent SDK + +* fix(sdk): rehydrate persisted subscription LLMs by @lufen in https://github.com/OpenHands/software-agent-sdk/pull/4092 +* fix(observability): stamp tool_call_id onto the TOOL span by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4010 +* Fix REST API contract summary deduplication by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/3918 +* fix(acp): bound ACP server startup with a timeout by @rsd-darshan in https://github.com/OpenHands/software-agent-sdk/pull/4126 +* fix(visualizer): show per-request token usage alongside cumulative by @luciobaiocchi in https://github.com/OpenHands/software-agent-sdk/pull/4146 +* fix(agent): apply filter_tools_regex to runtime tools by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4186 +* fix(sdk): accept boolean JSON Schema nodes in _process_schema_node by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4185 +* fix(sdk): mask all registered secrets, not only exported ones by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4191 +* fix(acp): persist rotated Codex credentials by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4124 +* fix(settings): restore MCP schema migration by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4013 +* fix(terminal): submit multiline PowerShell commands on Windows by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4155 +* fix(agent-server): default bind host to loopback without a session API key by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4180 +* fix: parallel tool metrics by @luciobaiocchi in https://github.com/OpenHands/software-agent-sdk/pull/4193 +* fix(agent-server): /api/vscode/url without base_url advertises the configured VSCode port by @harish-chandramowli in https://github.com/OpenHands/software-agent-sdk/pull/4181 +* fix(agent-server): require credential reactivation before cold load by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4198 +* fix(sdk): reject unknown event parents on append by @hxaxd in https://github.com/OpenHands/software-agent-sdk/pull/4089 +* fix(agent-server): redact LLM & condenser secrets in download-trajectory by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4217 +* fix: honor the stored memory preference on profile launches by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4223 +* fix(agent-server): include server_base_path in the advertised VSCode URL by @harish-chandramowli in https://github.com/OpenHands/software-agent-sdk/pull/4222 +* fix(sdk): mark corrective nudge as environment event by @Sehlani042 in https://github.com/OpenHands/software-agent-sdk/pull/3954 +* fix(security): authenticate WebSockets outside URLs by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4279 +* fix(llm): generalize model capability resolution by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4200 +* fix(security): stop logging runtime command contents by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4280 + +#### Runtime API + +* fix(cleanup): archive with actual conversation IDs by @simonrosenberg in https://github.com/OpenHands/runtime-api/pull/654 +* fix: reap runtimes stuck Pending/unschedulable by @ak684 in https://github.com/OpenHands/runtime-api/pull/655 +* fix: Optimize idle runtime cleanup pod listing by @tofarr in https://github.com/OpenHands/runtime-api/pull/662 + +#### Automation + +* fix: add server versions to telemetry by @malhotra5 in https://github.com/OpenHands/automation/pull/256 +* fix: normalize MCP config shapes in automation presets by @malhotra5 in https://github.com/OpenHands/automation/pull/257 +* fix: attribute PostHog events to automation actors by @neubig in https://github.com/OpenHands/automation/pull/265 +* fix(security): keep injected secrets out of commands by @simonrosenberg in https://github.com/OpenHands/automation/pull/267 + +#### OpenHands Cloud (Helm Chart) + +* fix(openhands): namespace-qualify bundled litellm url for sandboxes by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/937 +* fix(openhands): validate filestore values and test external S3 env by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/947 +* fix(openhands): PLTF-3258 scope render guards to enabled releases by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/950 +* fix: increase Replicated MinIO resource headroom by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/970 +* fix(integrations-hub): default admin.emails to empty by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/976 +* fix(budget-maintenance): disable the budget maintenance cronjob by default by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/978 +* fix(minio): PLTF-1250 stop the bundled bucket job purging data on every upgrade by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/981 +* fix(integrations-hub): derive public base URL by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/963 +* fix(litellm): PLTF-3363 bump pinned litellm image to 1.93.0 by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/987 +* fix(auth): extend Keycloak identity provider timeout by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/975 +* fix(troubleshoot): PLTF-3264 unblock support bundle exec collectors on Helm installs by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/989 +* fix(replicated): PLTF-3264 include app and license info in support bundles by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/992 +* fix(replicated): PLTF-3264 pass the SDK its pull secret in map form by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/996 + +## Maintenance + +#### Enterprise Server + +* test: PLTF-1269 split enterprise test_user_model into focused per-model tests by @aivong-openhands in https://github.com/OpenHands/OpenHands/pull/13997 +* chore: Suppress verbose Laminar info logs by @tofarr in https://github.com/OpenHands/OpenHands/pull/15374 +* chore: Unify release-please into a single semver release line by @mamoodi in https://github.com/OpenHands/enterprise/pull/76 + +#### Software Agent SDK + +* chore(deps): bump starlette from 1.0.1 to 1.3.1 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4140 +* chore(deps): bump pyjwt from 2.12.0 to 2.13.0 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4138 +* chore(deps): bump tornado from 6.5.5 to 6.5.7 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4139 +* chore(deps): bump python-multipart from 0.0.27 to 0.0.31 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4141 +* chore(deps): bump cryptography from 46.0.7 to 48.0.1 by @dependabot[bot] in https://github.com/OpenHands/software-agent-sdk/pull/4142 +* bump laminar to latest version, fix compat issues by @dinmukhamedm in https://github.com/OpenHands/software-agent-sdk/pull/4179 +* perf(agent-server): index conversation execution status for search/count by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4201 +* perf(agent-server): evict idle conversations from memory after a configurable TTL by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4202 +* Import SkillInfo from the SDK instead of redefining it in skills_router by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4277 +* Move duplicated LLM option blocks into common.py by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4276 +* Share the Gemini edit/write_file diff rendering by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4278 + +#### Runtime API + +* perf(cleanup): page snapshot_and_delete_idle_pvcs over bound PVCs by @tofarr in https://github.com/OpenHands/runtime-api/pull/660 +* build(deps): bump starlette from 0.49.1 to 1.3.1 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/650 + +#### Automation + +* chore: Add missing index on automation_runs.automation_id by @aivong-openhands in https://github.com/OpenHands/automation/pull/250 + +#### OpenHands Cloud (Helm Chart) + +* ci: PLTF-3287 sticky comment notify on openhands chart appVersion drift by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/951 +* chore(openhands-secrets): remove no-op config keys by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/871 +* chore(openhands): remove no-op values file keys by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/869 +* chore(openhands): pin redis master resources to effective values by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/868 +* revert: re-enable budget maintenance by default by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/982 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.36.1.mdx b/enterprise/release-notes/0.36.1.mdx new file mode 100644 index 000000000..e9b25656b --- /dev/null +++ b/enterprise/release-notes/0.36.1.mdx @@ -0,0 +1,30 @@ +--- +title: OpenHands Enterprise 0.36.1 +description: Release notes for OpenHands Enterprise version 0.36.1 +--- + +# OpenHands Enterprise 0.36.1 + +Released September 23, 2026. + +## Highlights + +- **Session Preservation** — Fixed user session handling during transient network failures +- **Email Configuration** — Deployments can now disable email changes +- **Stability Focus** — Patch release concentrated on Enterprise Server fixes + +## Bug Fixes + +#### Enterprise Server + +* fix(auth): preserve sessions during transient network failures by @ak684 in https://github.com/OpenHands/enterprise/pull/81 +* fix: allow deployments to disable email changes by @ak684 in https://github.com/OpenHands/enterprise/pull/110 +* fix(enterprise): fix broken import in run_budget_maintenance.py by @saurya in https://github.com/OpenHands/enterprise/pull/80 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.41.0.mdx b/enterprise/release-notes/0.41.0.mdx new file mode 100644 index 000000000..51ef54d27 --- /dev/null +++ b/enterprise/release-notes/0.41.0.mdx @@ -0,0 +1,94 @@ +--- +title: OpenHands Enterprise 0.41.0 +description: Release notes for OpenHands Enterprise version 0.41.0 +--- + +# OpenHands Enterprise 0.41.0 + +Released September 23, 2026. + +## Highlights + +- **Agent Canvas Rollout** — New homepage banner and updated Canvas build +- **GLM 5.2 Default** — Set as the default model for SaaS deployments +- **Authentication & Secrets** — Improved Codex authentication handling and secrets/settings reliability +- **Stability Fixes** — Range of fixes across Enterprise Server and Helm charts + +## Features + +#### Enterprise Server + +* feat: set SaaS default model to GLM 5.2 by @juanmichelini in https://github.com/OpenHands/enterprise/pull/89 +* feat: Add Agent Canvas homepage banner by @malhotra5 in https://github.com/OpenHands/enterprise/pull/124 +* feat: expose observability fields on app conversations by @juanmichelini in https://github.com/OpenHands/enterprise/pull/130 + +#### Runtime API + +* feat(helm): add generic-device-plugin DaemonSet for FUSE support by @tofarr in https://github.com/OpenHands/runtime-api/pull/685 + +#### OpenHands Cloud (Helm Chart) + +* feat(charts): device-plugin subchart for kvm/fuse passthrough by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1006 +* feat(openhands): PLTF-1247 offer Valkey as an opt-in cache backend by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1007 +* feat(agent-canvas): bump chart image tag to 1.10.0 by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1024 + +## Bug Fixes + +#### Enterprise Server + +* fix(frontend): wire Export CSV buttons on Usage & Monitoring Overview and Models tabs by @saurya in https://github.com/OpenHands/enterprise/pull/78 +* fix: Pass pod security context from runtime-api warm configs to sandbox start by @tofarr in https://github.com/OpenHands/enterprise/pull/108 +* fix: skip default CSP on FastAPI docs paths (OHE-2815) by @tofarr in https://github.com/OpenHands/enterprise/pull/118 +* fix(settings): keep active LLM profile selected during updates by @saurya in https://github.com/OpenHands/enterprise/pull/107 +* fix(enterprise): Fix 405 error when uploading files before conversation is ready by @jpelletier1 in https://github.com/OpenHands/enterprise/pull/134 +* fix: propagate registered marketplaces to conversations by @tofarr in https://github.com/OpenHands/enterprise/pull/126 +* fix(app-server): serialize secrets writes to fix lost-write race (OHE-3052) by @tofarr in https://github.com/OpenHands/enterprise/pull/133 +* fix: load_settings should show meta for secrets by @tofarr in https://github.com/OpenHands/enterprise/pull/138 +* fix(enterprise): make POST /api/organizations/provision-user idempotent (OHE-2980) by @tofarr in https://github.com/OpenHands/enterprise/pull/117 +* fix: validate Codex auth secrets on save by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/141 +* fix(app-server): pre-flight Codex credentials by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/139 + +#### Runtime API + +* fix: resolve real service-account email for GCS URL signing by @jlav in https://github.com/OpenHands/runtime-api/pull/686 + +#### OpenHands Cloud (Helm Chart) + +* fix(budget-maintenance): disable cronjob until fixed image ships by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/999 +* fix(replicated): preserve Keycloak identity provider timeout by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1001 +* fix: disable email changes for Replicated installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1002 +* fix(rustfs): PLTF-1250 make the bundled store deployable when enabled by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1010 +* fix(charts): pass fuse_s3_mount through warm-runtimes configmap by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1011 +* fix(build): PLTF-1250 stop shipping Chart.yaml.bak in released charts by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1013 +* fix(build): PLTF-1250 restore Chart.lock after packaging by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1014 +* fix(charts)!: OHE-3033 durable automation package storage by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1015 +* fix(charts): restore the nested sandbox hostname default by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1021 +* fix(litellm-helm): bump default image tag to 1.94.1 for memory fix by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1023 +* fix(budget-maintenance): re-enable cronjob with 1.49.1 by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1018 + +## Maintenance + +#### Enterprise Server + +* chore(enterprise): enforce PostgreSQL-only migrations by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/95 + +#### Runtime API + +* chore: PLTF-3242 Emit cleanup backlog/throughput counts as a structured log summary by @aivong-openhands in https://github.com/OpenHands/runtime-api/pull/665 +* build(deps): bump aiohttp from 3.13.4 to 3.14.1 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/680 +* build(deps): bump ddtrace from 3.5.1 to 4.8.2 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/687 +* build(deps): bump awscli from 1.44.38 to 1.44.78 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/689 +* build(deps): bump pyasn1 from 0.6.3 to 0.6.4 by @dependabot[bot] in https://github.com/OpenHands/runtime-api/pull/688 + +#### OpenHands Cloud (Helm Chart) + +* chore: bump Agent Canvas chart image to 1.9.0 by @malhotra5 in https://github.com/OpenHands/OpenHands-Cloud/pull/1009 +* chore: add storage-lifetime and naming checks to the code-review skill by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1016 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.45.0.mdx b/enterprise/release-notes/0.45.0.mdx new file mode 100644 index 000000000..267c4d70f --- /dev/null +++ b/enterprise/release-notes/0.45.0.mdx @@ -0,0 +1,93 @@ +--- +title: OpenHands Enterprise 0.45.0 +description: Release notes for OpenHands Enterprise version 0.45.0 +--- + +# OpenHands Enterprise 0.45.0 + +Released September 23, 2026. + +## Highlights + +- **Canvas Extensions** — Major new capability for installing, managing, and refreshing extensions with manifest support and persistent storage +- **Agent SDK Improvements** — Conversation error classification, accumulated LLM cost tracking, and observability enhancements including detached traces for delegate conversations +- **Automation Modernization** — Standalone frontend retired, enhanced preset metadata, and LLM cost tracking +- **Critical Stability Fixes** — Addressed S3/MinIO silent truncation, improved CSP compatibility for Monaco diff viewer, and enhanced secrets handling + +## Features + +#### Enterprise Server + +* feat: migrate existing managed MiniMax M2.7 settings to the GLM 5.2 default by @juanmichelini in https://github.com/OpenHands/enterprise/pull/140 + +#### Software Agent SDK + +* feat(llm): verify kimi-for-coding (Kimi Code membership) by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4150 +* feat(sdk): classify conversation errors by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4316 +* feat: report accumulated LLM cost in the automation completion callback by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4311 +* feat(agent-server): Canvas Extensions manifest and containment [1/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4361 +* feat(sdk): track requested_ref alongside resolved_ref in InstallationInfo [2/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4375 +* feat(agent-server): Canvas Extensions installation persistence [3/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4364 +* feat(agent-server): Canvas Extensions staged refresh (check/apply) [4/4] by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4374 + +#### Automation + +* feat: retire the standalone automation frontend by @hieptl in https://github.com/OpenHands/automation/pull/284 +* feat: report the configured automation timeout cap by @neubig in https://github.com/OpenHands/automation/pull/296 +* feat: record accumulated LLM cost per automation run by @hieptl in https://github.com/OpenHands/automation/pull/280 +* feat: set descriptive titles on automation-born conversations by @hieptl in https://github.com/OpenHands/automation/pull/312 +* feat: add generic preset metadata field to Automation model by @hieptl in https://github.com/OpenHands/automation/pull/313 +* feat: add template provenance, idempotent enablement, and first-run outcome to presets by @hieptl in https://github.com/OpenHands/automation/pull/322 + +#### OpenHands Cloud (Helm Chart) + +* feat(chart): OHE-3021 : expose OH_SANDBOX_MAX_NUM_SANDBOXES as a ConfigOption by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1035 + +## Bug Fixes + +#### Enterprise Server + +* fix(sandbox): OHE-3021 : honor OH_SANDBOX_MAX_NUM_SANDBOXES in RemoteSandboxServiceInjector fallback by @tofarr in https://github.com/OpenHands/enterprise/pull/153 +* fix: self-host Monaco so the diff viewer works under CSP by @hieptl in https://github.com/OpenHands/enterprise/pull/155 +* fix: stop silent truncation of archived and shared conversations on S3/MinIO by @hieptl in https://github.com/OpenHands/enterprise/pull/158 +* fix: stop surfacing Git provider token required errors for SSO-only users by @hieptl in https://github.com/OpenHands/enterprise/pull/159 +* fix(s3 file store): OHE-3079 : paginate list_objects_v2 to avoid silent truncation at 1000 keys by @tofarr in https://github.com/OpenHands/enterprise/pull/157 +* fix: redirect Automations sidebar icon to /canvas/automations by @hieptl in https://github.com/OpenHands/enterprise/pull/162 + +#### Software Agent SDK + +* fix(sdk): respect subscription validator composition by @Sehlani042 in https://github.com/OpenHands/software-agent-sdk/pull/3953 +* fix(agent-server): keep secrets out of workspace persistence by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/3990 +* fix(acp): surface Claude Opus 5 in Claude Code model picker by @nicolasdmolina in https://github.com/OpenHands/software-agent-sdk/pull/4326 +* fix: PATCH /api/settings loads the profile's LLM when setting active_profile by @emmanuel-adu in https://github.com/OpenHands/software-agent-sdk/pull/4319 +* fix(git): demote expected command failures to debug by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4341 +* fix(sdk): nudge before hard-terminating on a repeating action-error pattern by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4332 +* fix(mcp): reconcile live agent tool snapshots by @Shimada666 in https://github.com/OpenHands/software-agent-sdk/pull/4367 +* fix(observability): mark utility LLM spans (title generation, ask_agent) by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4359 +* fix(observability): give delegate conversations their own detached Laminar trace by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4378 +* fix(browser): a browser tool that cannot start should not fail the conversation by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4342 +* fix(observability): keep the conversation object out of TOOL span input by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4379 + +#### Automation + +* fix: normalize SQLite telemetry timestamps by @Linxiushen in https://github.com/OpenHands/automation/pull/301 +* fix: default FILE_STORE to local instead of gcs by @neubig in https://github.com/OpenHands/automation/pull/314 + +## Maintenance + +#### Software Agent SDK + +* chore(ci): remove QA Changes workflows by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4299 +* refactor(llm): add LiteLLM-backed provider abstraction by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/2363 +* chore(sdk): deprecate AgentBase.model_dump_succint by @AzeelSajjad in https://github.com/OpenHands/software-agent-sdk/pull/4328 +* refactor(observability): stop depending on lmnr to propagate trace context into tool workers by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4360 +* test: stop ambient LMNR env vars deciding what the tracing tests measure by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4390 +* chore: remove deprecated features past their 1.41.0 removal deadline by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4394 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.55.0.mdx b/enterprise/release-notes/0.55.0.mdx new file mode 100644 index 000000000..ccefc8681 --- /dev/null +++ b/enterprise/release-notes/0.55.0.mdx @@ -0,0 +1,206 @@ +--- +title: OpenHands Enterprise 0.55.0 +description: Release notes for OpenHands Enterprise version 0.55.0 +--- + +# OpenHands Enterprise 0.55.0 + +Released September 23, 2026. + +## Highlights + +- **Daily Conversation Quotas** — Enterprise Server now includes read-only usage pages with reset countdown, org-level exemptions, and self-service quota increase requests +- **Dedicated Sandbox Node Scheduling** — Enterprise installs can configure app and sandbox node roles with affinity across all pod specs and preflight validation +- **Expanded Issue Tracker Support** — Org-scoped Jira Cloud resolver with email-match mode and Azure DevOps webhook configuration +- **Agent SDK Enhancements** — Agent Plugins manifest loader, structured output, pre-flight LLM validation, and read-at-use provider connections +- **Runtime Activity-Based Anchoring** — Runtime reaping, database pruning, and idle-grace periods now anchor on last activity instead of creation time +- **Identity & Billing Improvements** — Hardened Keycloak identity matching using subject instead of email, plus extensive billing and credit-handling fixes + +## Features + +#### Enterprise Server + +* feat(settings): increase LLM profile limit to 50 and make it configurable by @jpelletier1 in https://github.com/OpenHands/enterprise/pull/114 +* feat: add cloud workspace file-listing endpoint (OHE-3053) by @lilagrc in https://github.com/OpenHands/enterprise/pull/135 +* feat: Expose organization creation teaser UX by @malhotra5 in https://github.com/OpenHands/enterprise/pull/151 +* feat: set SaaS default model to Kimi K3 and migrate GLM 5.2 settings by @juanmichelini in https://github.com/OpenHands/enterprise/pull/190 +* feat: org-scope the Jira Cloud resolver and add email-match mode for OHE by @hieptl in https://github.com/OpenHands/enterprise/pull/192 +* feat(frontend): add data-testid to changes refresh button by @tofarr in https://github.com/OpenHands/enterprise/pull/203 +* feat: add daily conversation quota schema foundation by @neubig in https://github.com/OpenHands/enterprise/pull/180 +* feat: add read-only quota usage page with reset countdown by @neubig in https://github.com/OpenHands/enterprise/pull/199 +* feat: add work-email quota increase requests with self-service verification by @neubig in https://github.com/OpenHands/enterprise/pull/200 +* feat: add org-level daily conversation quota exemptions by @neubig in https://github.com/OpenHands/enterprise/pull/212 +* feat: accept Jira Cloud picker mentions of the service account by @ak684 in https://github.com/OpenHands/enterprise/pull/223 +* feat(settings): auto-rotate invalid managed LLM keys on settings writes by @tofarr in https://github.com/OpenHands/enterprise/pull/231 +* feat: migrate Kimi K3 settings to DeepSeek V4 Flash by @neubig in https://github.com/OpenHands/enterprise/pull/253 + +#### Software Agent SDK + +* Feat: structured output by @luciobaiocchi in https://github.com/OpenHands/software-agent-sdk/pull/4207 +* agent-server: make conversation worktree root configurable by @xmrflipflop in https://github.com/OpenHands/software-agent-sdk/pull/4362 +* feat(observability): emit LLM and TOOL spans for ACP turns by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4376 +* feat: derive automation conversation tags in base RemoteWorkspace by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4414 +* feat: emit canonical conversation telemetry from agent server by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4459 +* feat(hooks): implement prompt-based evaluation by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4160 +* feat(security): AST-backed shell command-name resolution (#2721 Phase 2b) by @eeee2345 in https://github.com/OpenHands/software-agent-sdk/pull/3944 +* feat: add public from_persisted() entry point to AgentSettingsBase by @mvanhorn in https://github.com/OpenHands/software-agent-sdk/pull/3503 +* feat(sdk): add cleanup LLM profile for outward agent text by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4344 +* feat(llm): resolve provider-specific runtime metadata for routed models by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4423 +* feat: add pre-flight LLM validation endpoint (POST /api/profiles/{name}/validate) by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4422 +* feat: carry ConversationErrorEvent on ConversationRunError for automation callbacks by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4458 +* feat(plugin): add Agent Plugins manifest loader (root plugin.json, closed schema) by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4474 +* feat(file-router): add POST /file/create_directory by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4482 +* Add read-at-use LLM provider connections by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/4492 +* feat: Add deployment kind to agent-server telemetry by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4522 +* feat(telemetry): identify automation conversations by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4529 +* feat(tools): add structured task outcome preset by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4479 +* feat(prompt): mention local conversation history by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4527 + +#### Automation + +* feat(automation): tag local automation conversations by @neubig in https://github.com/OpenHands/automation/pull/319 +* feat: sync automations to a git repository by @VascoSch92 in https://github.com/OpenHands/automation/pull/327 +* feat: accept catalog bundle automations on the raw create path by @VascoSch92 in https://github.com/OpenHands/automation/pull/346 + +#### OpenHands Cloud (Helm Chart) + +* feat: e2e: restructure for Keycloak admin + dual GitHub user flows by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1089 +* feat: add configurable daily conversation limit to chart by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/1100 +* feat: wire Jira Cloud email-match integration for Replicated installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1113 +* feat: add org-management e2e suite with super-admin REST provisioning by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1122 +* feat(replicated): declare app and sandbox node roles by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1133 +* feat(chart): add affinity plumbing to all pod specs by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1134 +* feat(replicated): gate dedicated sandbox nodes behind a config option by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1135 +* feat(preflight): warn when dedicated sandbox nodes are enabled with no sandbox node by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1136 +* feat(replicated): PLTF-3461 configure duplicate email checks by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1139 +* feat(azure-devops): wire the resolver webhook secret into the chart and KOTS config by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1160 + +## Bug Fixes + +#### Enterprise Server + +* fix: resolve LLM profile keys in /users/me expose-secrets response by @hieptl in https://github.com/OpenHands/enterprise/pull/168 +* fix: handle null identity_provider for direct Keycloak logins by @tofarr in https://github.com/OpenHands/enterprise/pull/169 +* fix: URL-encode Redis password in authed URL for coredis/limits by @tofarr in https://github.com/OpenHands/enterprise/pull/177 +* fix: close dropdown menu after selection when wrapped in a label by @hieptl in https://github.com/OpenHands/enterprise/pull/176 +* fix: stop redacting the Jira DC base URL in agent output by @hieptl in https://github.com/OpenHands/enterprise/pull/182 +* fix: inject Bitbucket DC server URL, repo URL, and token context into agent prompt by @hieptl in https://github.com/OpenHands/enterprise/pull/183 +* fix(auth): make Keycloak HTTP retries configurable by @neubig in https://github.com/OpenHands/enterprise/pull/186 +* fix: OHE-3100 : use sandbox_spec.working_dir instead of hardcoded /workspace by @tofarr in https://github.com/OpenHands/enterprise/pull/188 +* fix(auth): make LiteLLM management timeout configurable by @neubig in https://github.com/OpenHands/enterprise/pull/189 +* fix: handle null runtime context values by @ak684 in https://github.com/OpenHands/enterprise/pull/112 +* fix: use agent server as conversation creation source by @malhotra5 in https://github.com/OpenHands/enterprise/pull/156 +* fix: let managed LLM profiles take the org's current key on rotation by @dylan-openhands in https://github.com/OpenHands/enterprise/pull/178 +* fix(budgets): persist maintenance updates by @saurya in https://github.com/OpenHands/enterprise/pull/204 +* fix: let free-tier (no-credit) teams run $0-cost models by @juanmichelini in https://github.com/OpenHands/enterprise/pull/143 +* fix: protect personal organization billing credits by @saurya in https://github.com/OpenHands/enterprise/pull/167 +* fix(budgets): prevent per-user allowance renewal on sync by @saurya in https://github.com/OpenHands/enterprise/pull/205 +* fix: display usage monitoring timestamps in local time by @saurya in https://github.com/OpenHands/enterprise/pull/208 +* fix: use verified repo provider in Jira Cloud conversation start request by @ak684 in https://github.com/OpenHands/enterprise/pull/216 +* fix(billing): show personal-workspace credits without a member budget row by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/218 +* fix: clarify Jira email-visibility guidance with exact setting and delay by @ak684 in https://github.com/OpenHands/enterprise/pull/222 +* fix(enterprise): match provisioned user on Keycloak sub, not email by @tofarr in https://github.com/OpenHands/enterprise/pull/224 +* fix(enterprise): match on Keycloak sub in TOCTOU idempotent recovery too by @tofarr in https://github.com/OpenHands/enterprise/pull/225 +* fix(enterprise): await session.merge in billing success callback by @tofarr in https://github.com/OpenHands/enterprise/pull/226 +* fix: OHE-3127 : return null credits instead of 503 when budget is None by @tofarr in https://github.com/OpenHands/enterprise/pull/228 +* fix: return 0 credits instead of None for users without a budget by @tofarr in https://github.com/OpenHands/enterprise/pull/238 +* fix(settings): stop a member's settings save writing to the whole org by @jlav in https://github.com/OpenHands/enterprise/pull/254 + +#### Software Agent SDK + +* fix(mcp): close reconciliation gaps left by #4367 by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4369 +* fix(acp): recover credential monitor after transient errors by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4403 +* fix(sdk): make ACP auth failures self-diagnosing by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4404 +* fix(observability): record non-executed tool results by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4415 +* fix(agent-server): compose ConversationInfo off the event loop to avoid GC wedge by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4417 +* fix(agent-server): initialize observability after deferred env by @Shimada666 in https://github.com/OpenHands/software-agent-sdk/pull/4426 +* fix(settings): inherit condenser max_tokens from LLM effective_max_input_tokens by @vnktadithya in https://github.com/OpenHands/software-agent-sdk/pull/4435 +* fix(goal): don't halt the goal loop on a STUCK run by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4381 +* fix(llm): stop serializing calls through global config by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4473 +* fix(security-scan): improve release security scan comment by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4397 +* fix(profiles): repair v1 skills migration by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4320 +* fix(agent-server): base_state.json as single source of truth for the agent (end meta.json duplication) by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4440 +* fix(sdk): cap condenser token limit by agent context by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4461 +* fix(agent-server): move bash event search off event loop and replace glob with scandir by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4481 +* fix: redact API key from validate_profile error responses and logs by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4506 +* fix: make dict-entry secret redaction case-insensitive by @chintan-diwakar in https://github.com/OpenHands/software-agent-sdk/pull/4508 +* fix(agent-server): propagate out-of-band run failures as ConversationErrorEvent (#16686) by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4535 +* fix(sdk): normalize Kimi K3 vision metadata by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4567 +* fix(agent): keep terminal prefix aliases from doubling an existing executable by @onatozmenn in https://github.com/OpenHands/software-agent-sdk/pull/4471 +* fix(sdk): resolve workspace default from active LLM profile by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4497 + +#### Runtime API + +* fix: anchor runtime reaping and DB pruning on last activity, not creation time by @hieptl in https://github.com/OpenHands/runtime-api/pull/707 +* fix: anchor the idle-grace period on last_state_change, not created_at by @hieptl in https://github.com/OpenHands/runtime-api/pull/713 +* fix: OHE-3100 : root-owned working_dir subdirs on PVC via init container by @tofarr in https://github.com/OpenHands/runtime-api/pull/714 +* fix: reorder cleanup phases and resume expired deployment list tokens by @dylan-openhands in https://github.com/OpenHands/runtime-api/pull/712 + +#### Automation + +* fix: stop marking successful automation runs as FAILED by @hieptl in https://github.com/OpenHands/automation/pull/331 + +#### OpenHands Cloud (Helm Chart) + +* fix: Bound Laminar ClickHouse diagnostic log retention by @juanmichelini in https://github.com/OpenHands/OpenHands-Cloud/pull/1031 +* fix: wire installer SMTP config into Keycloak realm email by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1090 +* fix(e2e): handle onboarding-form and 2FA auto-navigate race conditions by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1091 +* fix(e2e): enable role during static discovery by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1099 +* fix(e2e): replace networkidle waits and fix Promise.race short-circuit by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1108 +* fix(automation): keep events service available during node drains by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1112 +* fix: refresh changes panel when empty in VSCode integration test by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1114 +* fix(e2e): order API keys spec after billing so new-user has credits by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1118 +* fix(e2e): PLTF-3461 honor AUTH_BASE_URL for Keycloak admin URL by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1126 +* fix(chart): set the warm pool working dir to /workspace/project by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1140 +* fix(deploy): tolerate a restarting kotsadm in replicated_deploy.sh by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1141 +* fix(e2e): PLTF-3461 move the credit-gated API key check into the billing suite by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1143 +* fix(ci): PLTF-3461 call the E2E trigger from each release workflow by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1144 + +## Maintenance + +#### Enterprise Server + +* chore: remove dead localStorage feature-flag mechanism by @tofarr in https://github.com/OpenHands/enterprise/pull/230 +* docs: Replace with Polyform License by @jpelletier1 in https://github.com/OpenHands/enterprise/pull/240 + +#### Software Agent SDK + +* chore: drop the OpenHands/OpenHands bump-PR target from version-bump-prs.yml by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4400 +* refactor(plugin): extract PluginFormat strategy (prep for Agent Plugins support) by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/4420 +* chore(ci): collapse the auto-posted Agent Server images PR section by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4442 +* Add ready-for-dev issue and PR gates by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4464 +* test(terminal): stabilize Windows Ctrl-C cleanup assertion by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4290 +* perf(agent-server): cache unchanged conversation summaries by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4483 +* ci: re-run PR description check when new commits are pushed by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4486 +* Weekly test sweep: remove low-value tests + simplify by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4484 +* test(sdk): pin events_to_messages boundaries + fix responses_reasoning_item batch drop by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4526 +* test(sdk): pin send_message skill-activation wiring by @georgeglarson in https://github.com/OpenHands/software-agent-sdk/pull/4536 + +#### Automation + +* chore: add success logging for tarball storage writes and deletes by @jpshackelford in https://github.com/OpenHands/automation/pull/335 +* chore: remove QA changes workflow by @neubig in https://github.com/OpenHands/automation/pull/340 + +#### OpenHands Cloud (Helm Chart) + +* test(e2e): add Playwright release harness by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1048 +* test(e2e): cover organization-scoped member API keys by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1049 +* test(e2e): add optional ReportPortal reporting by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1088 +* test(e2e): make returning/new-user roles opt-in via *_GITHUB_USERNAME by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1092 +* test(e2e): migrate Stripe credit purchase into billing suite by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1094 +* test(e2e): migrate home avatar and user-menu tests by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1095 +* test(e2e): remove example.spec.ts by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1096 +* test(e2e): migrate API key creation and API access test by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1097 +* test(e2e): migrate legacy conversation control tests by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1101 +* ci: auto-deploy Replicated releases to internal instances by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1123 +* ci: PLTF-3461 run E2E after Replicated deploys by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1129 +* ci: name the Replicated release workflows consistently for README badges by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1131 +* ci: fix unparseable expression in deploy-replicated, lint workflows in CI by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1132 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.64.0.mdx b/enterprise/release-notes/0.64.0.mdx new file mode 100644 index 000000000..5a5d190a0 --- /dev/null +++ b/enterprise/release-notes/0.64.0.mdx @@ -0,0 +1,215 @@ +--- +title: OpenHands Enterprise 0.64.0 +description: Release notes for OpenHands Enterprise version 0.64.0 +--- + +# OpenHands Enterprise 0.64.0 + +Released September 23, 2026. + +## Highlights + +- **Shared LLM Provider Connections** — Organization-level provider connections can now back multiple members' managed profiles +- **GPG Commit Signing** — Users can configure GPG commit signing with a Set GPG Key button in settings +- **Organization Lifecycle Tools** — Superadmins can seed new orgs via invitations; Git providers can be connected/disconnected post-auth from Settings → Integrations +- **Automation Permissions** — Split into separate view and manage roles + +## Features + +#### Enterprise Server + +* feat: add ENABLE_BYOR_EXPORT env var and frontend feature flag by @tofarr in https://github.com/OpenHands/enterprise/pull/232 +* feat: configurable GPG commit signing at user level (OHE-3115) by @tofarr in https://github.com/OpenHands/enterprise/pull/264 +* feat: add Set GPG Key button to app settings by @tofarr in https://github.com/OpenHands/enterprise/pull/274 +* feat: add database-driven feature flag library (OHE-3101) by @tofarr in https://github.com/OpenHands/enterprise/pull/217 +* feat(org): shared LLM provider connections (cloud) by @juanmichelini in https://github.com/OpenHands/enterprise/pull/219 +* feat: link daily quota increase requests by @neubig in https://github.com/OpenHands/enterprise/pull/283 +* feat: add cron script to clean stale app_conversation_start_task rows by @tofarr in https://github.com/OpenHands/enterprise/pull/290 +* feat: OHE-3197 : Unify ENABLE_BILLING resolution through the feature flag env fallback by @tofarr in https://github.com/OpenHands/enterprise/pull/301 +* feat: split automations permission into view and manage by @tofarr in https://github.com/OpenHands/enterprise/pull/304 +* feat: add GET /organizations/{org_id}/members/{user_id} by @hieptl in https://github.com/OpenHands/enterprise/pull/313 +* feat: connect and disconnect Git providers post-auth from Settings > Integrations by @hieptl in https://github.com/OpenHands/enterprise/pull/309 +* feat(enterprise): allow superadmin to seed a new org via a normal invitation by @lilagrc in https://github.com/OpenHands/enterprise/pull/292 +* feat(enterprise): instance-level admin user lifecycle API (disable/enable/delete) by @neubig in https://github.com/OpenHands/enterprise/pull/181 +* feat: OHE-3178 : add per-conversation event index for efficient search by @tofarr in https://github.com/OpenHands/enterprise/pull/327 + +#### Software Agent SDK + +* feat: add manifest to installed canvas extension responses by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/4611 +* feat(sdk): add ask_oracle tool by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/3673 +* feat(agent-server): add INSTALL_ACP_PROVIDERS build arg by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4687 +* feat: move TypeScript client into monorepo by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4702 +* feat(agent-server): add INSTALL_CAPABILITIES build arg by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4698 +* feat: add ACP-less agent-server image fallback by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4805 +* feat(observability): allow selecting Laminar instruments by @Shimada666 in https://github.com/OpenHands/software-agent-sdk/pull/4434 +* feat(acp): centralize ACP npm installation metadata by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4832 +* feat(agent-server): add /sockets/session/{id} with a non-Event envelope by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4807 +* feat(acp): add Kimi Code, plus the hardening the other provider PRs share by @ysntony in https://github.com/OpenHands/software-agent-sdk/pull/4714 +* feat(sdk): register Pi as a built-in ACP provider by @Deep070203 in https://github.com/OpenHands/software-agent-sdk/pull/4419 +* feat(acp): add OpenCode as a built-in ACP provider by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4827 +* feat: add GPT-6 Astra model support by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4861 +* Add claude-sonnet-5 to PROMPT_CACHE_MODELS by @swabeinvader in https://github.com/OpenHands/software-agent-sdk/pull/4043 +* feat(plugin): map client extensions under the dev.openhands namespace by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4496 + +#### Runtime API + +* feat: OHE-3139 : Split cleanup CronJob into per-phase jobs by @tofarr in https://github.com/OpenHands/runtime-api/pull/729 +* feat: overlay database warm-runtime configs onto ConfigMap entries by name by @ak684 in https://github.com/OpenHands/runtime-api/pull/731 +* feat: Add coverage gate to unit test workflow by @tofarr in https://github.com/OpenHands/runtime-api/pull/737 + +#### Automation + +* feat: add structured task outcomes to preset finish tool by @malhotra5 in https://github.com/OpenHands/automation/pull/334 +* feat: replace the parse-only source registry with a provider descriptor and verifier registry by @VascoSch92 in https://github.com/OpenHands/automation/pull/378 +* feat: persist accepted events to deduplicate redeliveries and expose events that matched nothing by @VascoSch92 in https://github.com/OpenHands/automation/pull/381 +* feat: report lifetime per-status run counts on the runs list by @hieptl in https://github.com/OpenHands/automation/pull/383 +* feat: report live run phases for dashboard visibility by @hieptl in https://github.com/OpenHands/automation/pull/388 +* feat: add in-service Slack Socket Mode via a supervised stream transport by @VascoSch92 in https://github.com/OpenHands/automation/pull/384 +* feat: split automation permissions into view and manage by @tofarr in https://github.com/OpenHands/automation/pull/415 +* feat: auto-disable for consecutively failing automations [PLTF-3374] by @dylan-openhands in https://github.com/OpenHands/automation/pull/397 +* feat: route events to an existing conversation via a derived conversation id by @VascoSch92 in https://github.com/OpenHands/automation/pull/385 +* feat: add ready-for-dev issue and PR readiness gates by @neubig in https://github.com/OpenHands/automation/pull/380 +* feat: restrict automation edits to the creator by @hieptl in https://github.com/OpenHands/automation/pull/427 + +#### OpenHands Cloud (Helm Chart) + +* feat(local-kind): PLTF-3527 enable Agent Canvas at /canvas by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1168 +* feat(replicated): PLTF-3456 enable automations by default for new installs by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1158 +* feat(runtime-api): sync split cleanup CronJob from runtime-api#729 by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1178 +* feat(e2e): PLTF-3514 dispatch e2e test revision bumps to saas-deploy by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1148 +* feat: enable warm-runtime config overlay mode for Replicated by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1183 +* feat: configure Enterprise SSO for Replicated VM deployments by @jpelletier1 in https://github.com/OpenHands/OpenHands-Cloud/pull/1116 +* feat: add CronJob to clean stale app_conversation_start_task rows by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1196 +* feat: enable appConversationStartTaskClean CronJob by default by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1197 +* feat(skills): PLTF-3531 add upgrade-rollback-runbook skill by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1204 +* feat(skills): PLTF-3531 add gke-install cluster-install skill by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1205 +* feat(skills): PLTF-3531 add eks-install cluster-install skill by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1203 +* feat: diagnose runtime ingress failures in support bundles by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1208 + +## Bug Fixes + +#### Enterprise Server + +* fix: delete MCP servers from a null mcp_config entry by @hieptl in https://github.com/OpenHands/enterprise/pull/270 +* fix: remove --forked from test commands to fix coverage measurement by @tofarr in https://github.com/OpenHands/enterprise/pull/277 +* fix: include registered marketplaces in the conversation skills listing by @hieptl in https://github.com/OpenHands/enterprise/pull/286 +* fix: stop polling behind the re-auth modal once the session expires by @hieptl in https://github.com/OpenHands/enterprise/pull/298 +* fix: stop title updates clobbering conversation metadata by @hieptl in https://github.com/OpenHands/enterprise/pull/299 +* fix(budgets): make LiteLLM spend reporting resilient by @ak684 in https://github.com/OpenHands/enterprise/pull/242 +* fix: prevent invalid proxy tokens after managed profile changes by @saurya in https://github.com/OpenHands/enterprise/pull/209 +* fix(analytics): use detected automation trigger by @neubig in https://github.com/OpenHands/enterprise/pull/147 +* fix: Updated release please config to include uv.lock by @tofarr in https://github.com/OpenHands/enterprise/pull/330 +* fix: prevent cross-user managed LLM key attribution by @ak684 in https://github.com/OpenHands/enterprise/pull/317 +* fix(ui): disable telemetry UI in self-hosted enterprise by @ak684 in https://github.com/OpenHands/enterprise/pull/326 + +#### Software Agent SDK + +* fix(agent-server): keep crash recovery result on interrupted action branch by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4488 +* fix(workspace): honor explicit provider host when injecting git clone tokens by @rsd-darshan in https://github.com/OpenHands/software-agent-sdk/pull/4571 +* fix(agent-server): replace global _lifecycle_lock with per-conversation locks by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4570 +* fix(tools): unique user_data_dir per conversation to prevent SingletonLock collisions by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4602 +* fix(sdk): bound AsyncExecutor.close() so it cannot hang forever by @AaronAbuUsama in https://github.com/OpenHands/software-agent-sdk/pull/4548 +* fix(agent-server): detect all secret-bearing fields for the plaintext-save warning, not just llm.api_key by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4618 +* fix: enable condenser for subscription LLMs via existing completion dispatch by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4517 +* fix(sdk): resolve structured builtin tool specs remotely by @malhotra5 in https://github.com/OpenHands/software-agent-sdk/pull/4691 +* fix(agent-server): stop fanning streaming deltas out to every subscriber by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4689 +* fix(acp): never inject workspace project skills into an ACP agent (#4019) by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4699 +* fix(sdk): mask model output in the durable MessageEvent by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4783 +* fix(sdk): match nested repo paths by ancestry, not string prefix by @alanhuangyoo in https://github.com/OpenHands/software-agent-sdk/pull/4767 +* fix(tools): mask secrets in every tool's observation at the shared chokepoint by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4788 +* fix(agent-server): keep the idle timer alive during streamed completions by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4790 +* fix(sdk): remove secrets from subprocess env by @smolpaws in https://github.com/OpenHands/software-agent-sdk/pull/4801 +* fix(sdk): persist events before publishing them, return the assigned seq by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4806 +* fix(llm): allow security_risk param on read-only tools like finish by @sideeffffect in https://github.com/OpenHands/software-agent-sdk/pull/4153 +* fix(sdk): require fastmcp>=3.2.0 so expired MCP OAuth tokens refresh by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4857 +* fix(sdk): pick up a user message that arrives during an async step by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4194 +* fix(agent-server): propagate load_memory preference to all launch paths by @vnktadithya in https://github.com/OpenHands/software-agent-sdk/pull/4566 +* fix: respect OH_PERSISTENCE_DIR for all ~/.openhands paths by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/4476 +* fix(ci): align ready-for-dev gates with OpenHands pipefail-safe approach by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4607 +* fix(tests): stop pinning LLM capability tests to upstream metadata by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4879 +* fix(ci): centralize release publication dispatches by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4886 +* fix(agent-server): restore subscription credentials in pre-flight validation by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4898 +* fix(llm): register litellm_proxy alias pricing so spans aren't silently $0 by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/4836 +* fix(extensions): compose local source with repo_path by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4839 + +#### Runtime API + +* fix: redact sensitive URL query parameters in pod crash logs by @all-hands-bot in https://github.com/OpenHands/runtime-api/pull/706 +* fix: treat empty ADMIN_PASSWORD as unset so admin routes stay disabled by @ak684 in https://github.com/OpenHands/runtime-api/pull/730 +* fix: OHE-3187 : clean up warm runtimes orphaned by split-brain claim by @tofarr in https://github.com/OpenHands/runtime-api/pull/735 + +#### Automation + +* fix: capture automation failure modes as status states by @malhotra5 in https://github.com/OpenHands/automation/pull/345 +* fix: treat missing tarball objects as permanent and defer superseded deletes until commit by @hieptl in https://github.com/OpenHands/automation/pull/356 +* fix: auto-disable unhealthy automations by @malhotra5 in https://github.com/OpenHands/automation/pull/352 +* fix: scope automation management to the org instead of the owner by @VascoSch92 in https://github.com/OpenHands/automation/pull/399 +* fix: require preset automations to use finish tool by @malhotra5 in https://github.com/OpenHands/automation/pull/405 +* fix: Forward X-Org-Id during automation auth by @malhotra5 in https://github.com/OpenHands/automation/pull/403 +* fix(automation): purge expired local-mode run workspaces by @trungminhdo4-glitch in https://github.com/OpenHands/automation/pull/277 + +#### OpenHands Cloud (Helm Chart) + +* fix(local-kind): PLTF-3527 use bundled MinIO for conversation/event storage by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1163 +* fix(replicated): drop the KOTS update check that ruins the target cursor by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1175 +* fix: Disable agent-canvas telemetry by default for self-hosted by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1156 +* fix(e2e): PLTF-3515 give the Tavily test its own conversation by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1146 +* fix: rename warm-runtime default config to v1_current to match the app default spec lookup by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1181 +* fix: give the Runtime API admin password a real KOTS field with a generated default by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1182 +* fix: advertise the runtime API ingress to fuse mounts by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1184 +* fix(chart): render reaper archive volume under a volumes: key (staging reaper outage) by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1185 +* fix(ci): bypass broken deploy-gate check temporarily by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1186 +* fix: make E2E repo-test prompt explicitly instruct file edit by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1189 + +## Maintenance + +#### Enterprise Server + +* refactor(frontend): remove legacy max-budget settings control by @saurya in https://github.com/OpenHands/enterprise/pull/213 +* chore: remove dead code by @tofarr in https://github.com/OpenHands/enterprise/pull/271 +* chore: remove redundant comments across enterprise codebase by @tofarr in https://github.com/OpenHands/enterprise/pull/272 +* chore: remove comments referencing previous functionality by @tofarr in https://github.com/OpenHands/enterprise/pull/273 +* test: replace mocked sessions with SQLite fixtures in org invitation store by @tofarr in https://github.com/OpenHands/enterprise/pull/276 +* docs: fix stale, wrong, and inapplicable documentation references by @tofarr in https://github.com/OpenHands/enterprise/pull/275 +* chore: remove Reo tracking integration by @neubig in https://github.com/OpenHands/enterprise/pull/227 +* refactor: PLTF-3545 PLTF-3546 flatten enterprise/ into the repo root and move to uv by @jlav in https://github.com/OpenHands/enterprise/pull/312 + +#### Software Agent SDK + +* docs: document SDK repository boundaries by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4587 +* chore(ci): clarify issue readiness bot comment and reference templates by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/4625 +* Relax ready-for-dev heading check to accept h2 headings by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4632 +* docs(examples): align Ask Oracle conventions by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4655 +* refactor(agent-server): share ACP provider payload as a parent-independent Docker layer by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4651 +* test(agent-server): cover conversation reads not serializing behind an unrelated start by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4685 +* ci: enforce SDK and TypeScript client version parity by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4779 +* refactor(agent-server): remove the VNC/desktop stack entirely by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4792 +* refactor(agent-server,ci): remove overdue org_config field and catch this class of gap in check_deprecations.py by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4795 +* ci: remove the endpoint-audit PR comment, report via the job summary by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4825 +* test(acp): live conformance + model-acceptance probes for built-in providers (#4830 P0) by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4834 +* ci(typescript-client): run integration tests against the branch's agent-server by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4844 +* perf(sdk): make EventLog.append cost flat against conversation length by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4697 + +#### Automation + +* perf: remove redundant readiness query by @Linxiushen in https://github.com/OpenHands/automation/pull/303 +* refactor: extract a transport-neutral accept_event() from the webhook handler by @VascoSch92 in https://github.com/OpenHands/automation/pull/367 +* chore: add Dependabot configuration by @neubig in https://github.com/OpenHands/automation/pull/372 +* docs: document automation repository boundaries by @neubig in https://github.com/OpenHands/automation/pull/369 +* ci: enforce minimum 76% coverage on unit tests by @tofarr in https://github.com/OpenHands/automation/pull/419 + +#### OpenHands Cloud (Helm Chart) + +* ci: check the agent-server tag against the enterprise SDK pin by @jlav in https://github.com/OpenHands/OpenHands-Cloud/pull/1167 +* ci: make the Replicated deploy check blocking, with a break-glass label [PLTF-3535] by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1187 +* test: harden 003 legacy conversations spec (from #1176, without 005 canvas spec) by @tofarr in https://github.com/OpenHands/OpenHands-Cloud/pull/1200 +* docs(skills): PLTF-3531 use --context=0 for helm diff in upgrade-rollback runbook by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1206 +* test(e2e): verify managed LLM key ownership by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1207 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases) diff --git a/enterprise/release-notes/0.70.0.mdx b/enterprise/release-notes/0.70.0.mdx new file mode 100644 index 000000000..899abb0c7 --- /dev/null +++ b/enterprise/release-notes/0.70.0.mdx @@ -0,0 +1,196 @@ +--- +title: OpenHands Enterprise 0.70.0 +description: Release notes for OpenHands Enterprise version 0.70.0 +--- + +# OpenHands Enterprise 0.70.0 + +Released September 23, 2026. + +## Highlights + +- **Refreshed UI** — Updated conversation and Settings experiences now align with OpenHands Agent Canvas for a more intuitive developer and admin experience. +- **Organization-Scoped Secrets** — Admins can create shared secrets for use across the Organization, reducing duplicate credential setup and centralizing access. +- **User Budget Dashboard** — Users can view their usage and monthly budget consumption under **Settings > Your Budget** for better spend visibility. +- **OAuth MCP Support** — Users can authenticate to MCP servers with OAuth, including supported services like GitLab and Atlassian Rovo, using their own identity. +- **Organization-Visible Automations** — Users can see Automations across their Organization, including who created them and which identity they run as; Admins can disable or delete them. +- **Automation Git Sync** — Admins can sync Automations with a Git repository for version history, backup, and pull request-based review workflows. + +## Features + +#### Enterprise Server + +* feat: DB-driven free/default/verified model flags by @juanmichelini in https://github.com/OpenHands/enterprise/pull/191 +* feat: surface runtime ingress startup failures by @ak684 in https://github.com/OpenHands/enterprise/pull/332 +* feat: PLTF-3553 Add org condenser max_tokens rollout configuration by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/337 +* feat: enforce daily quota and surface structured 429 with settings link by @neubig in https://github.com/OpenHands/enterprise/pull/201 +* feat(budgets): add upgrade preflight and post-upgrade reconciliation gate by @hieptl in https://github.com/OpenHands/enterprise/pull/362 +* feat: add system_prompt and disabled_skills to conversation start API by @hieptl in https://github.com/OpenHands/enterprise/pull/335 +* feat(super-admins): flag-gate super-admin list discovery (OHE-3196) by @tofarr in https://github.com/OpenHands/enterprise/pull/390 +* feat(budgets): normalize per-member cycle baselines with provenance by @hieptl in https://github.com/OpenHands/enterprise/pull/365 +* feat: org-scoped secrets — backend Phase 1 (OHE-2568) by @tofarr in https://github.com/OpenHands/enterprise/pull/391 +* feat(analytics): emit PostHog events for HubSpot contact sync by @malhotra5 in https://github.com/OpenHands/enterprise/pull/392 +* feat(frontend): OpenHands-Neo settings theme aligned with agent-canvas by @FraterCCCLXIII in https://github.com/OpenHands/enterprise/pull/174 +* feat(secrets): org-scoped secrets UI — share checkbox and permission-gated actions [OHE-2568] by @tofarr in https://github.com/OpenHands/enterprise/pull/449 +* feat(mcp): run OAuth MCP installs from the app server by @hieptl in https://github.com/OpenHands/enterprise/pull/404 +* feat(conversations): add tags to start/update requests and a tags__contains search filter by @hieptl in https://github.com/OpenHands/enterprise/pull/432 +* feat: add exact name filter to GET /api/organizations by @hieptl in https://github.com/OpenHands/enterprise/pull/447 +* feat(budgets): show each user their own budget and usage by @hieptl in https://github.com/OpenHands/enterprise/pull/448 +* feat(orgs) : OHE-3303 : expose is_visible on organization listings by @tofarr in https://github.com/OpenHands/enterprise/pull/461 + +#### Software Agent SDK + +* feat(agent-server): add OpenAI Responses gateway by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4694 +* feat(sdk): StreamContext mints the stream identity and closes every stream by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4822 +* feat(profiles): scope which secrets an agent profile receives by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4931 +* feat(agent-server): conversation-scoped runtime APIs and clients by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4966 +* feat(sdk): extend existing conversation and workspace APIs for automation by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5010 +* feat(workspace): add AgentSandboxWorkspace (Kubernetes, kubernetes-sigs/agent-sandbox) by @aleks-stefanovic in https://github.com/OpenHands/software-agent-sdk/pull/4516 +* feat(agent-server): publish python-minimal image by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5088 +* feat(profiles): scope saved secrets at lookup by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5017 +* feat(agent-server): add docker runtime mode for per-conversation containers by @rbren in https://github.com/OpenHands/software-agent-sdk/pull/3403 +* feat(plugin): add the Agent Plugins mcp.json loader by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5093 + +#### Automation + +* feat: add user-authenticated KV access by @tofarr in https://github.com/OpenHands/automation/pull/445 +* feat: scope git sync to organizations so cloud deployments can sync by @hieptl in https://github.com/OpenHands/automation/pull/429 +* feat: make automation sandbox cleanup delay configurable by @hieptl in https://github.com/OpenHands/automation/pull/459 +* feat: select an agent profile for delegated automation work by @neubig in https://github.com/OpenHands/automation/pull/479 +* feat: allow raw automations to start disabled by @XiaoFeiCode in https://github.com/OpenHands/automation/pull/387 + +#### OpenHands Cloud (Helm Chart) + +* feat: PLTF-3553 Add Helm values for org condenser defaults by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1214 +* feat: wire the git sync wrapping secret and a /workspace volume by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1213 +* feat(openhands): add budget preflight and reconciliation gate hook jobs by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1251 +* feat(replicated): OHE-3231 expose the automation conversation archive delay as a ConfigOption by @hieptl in https://github.com/OpenHands/OpenHands-Cloud/pull/1244 +* feat: configure Keycloak admin login through Replicated by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1269 + +## Bug Fixes + +#### Enterprise Server + +* fix: OHE-3155 : lazily repair free-tier LiteLLM allowlists on org upgrade by @tofarr in https://github.com/OpenHands/enterprise/pull/338 +* fix: refresh Bitbucket Data Center tokens for automation sandboxes by @ak684 in https://github.com/OpenHands/enterprise/pull/334 +* fix(budgets): recover missing member cycle baselines after upgrade by @hieptl in https://github.com/OpenHands/enterprise/pull/347 +* fix: restore Git identity after sandbox resume by @ak684 in https://github.com/OpenHands/enterprise/pull/333 +* fix(metrics): OHE-3110 : omit misleading "No budget limit" line in conversation metrics modal by @tofarr in https://github.com/OpenHands/enterprise/pull/349 +* fix: bulk-repair cross-user managed LLM key ownership by @ak684 in https://github.com/OpenHands/enterprise/pull/353 +* fix: expose desired and applied budget state by @ak684 in https://github.com/OpenHands/enterprise/pull/357 +* fix: fail budget maintenance on reconciliation errors by @ak684 in https://github.com/OpenHands/enterprise/pull/356 +* fix: gate Cloud on an explicit ACP provider allowlist by @simonrosenberg in https://github.com/OpenHands/enterprise/pull/336 +* fix(sandbox): allow max_num_sandboxes=1 by accepting 0 in pause_old_sandboxes by @hieptl in https://github.com/OpenHands/enterprise/pull/386 +* fix: upgrade postcss to 8.5.18+ to fix path traversal vulnerability by @mamoodi in https://github.com/OpenHands/enterprise/pull/396 +* fix: Update js-yaml for CVE remediation by @mamoodi in https://github.com/OpenHands/enterprise/pull/401 +* fix: resolve duplicate migration revision 162 (rename to 164, make idempotent) by @tofarr in https://github.com/OpenHands/enterprise/pull/445 +* fix(bitbucket-dc): validate tokens against /projects so scoped PATs pass by @hieptl in https://github.com/OpenHands/enterprise/pull/423 +* fix: Tag Enterprise telemetry by deployment kind by @malhotra5 in https://github.com/OpenHands/enterprise/pull/441 +* fix: replace stale custom LLM key when switching back to the managed default profile by @juanmichelini in https://github.com/OpenHands/enterprise/pull/425 +* fix: heal stale org-level BYOR LLM key on conversation start (#421) by @juanmichelini in https://github.com/OpenHands/enterprise/pull/437 +* fix(sandbox): make resume state-aware and preserve conflict semantics by @hieptl in https://github.com/OpenHands/enterprise/pull/422 + +#### Software Agent SDK + +* fix(tools): add logging filter to redact secrets from libtmux log output by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4871 +* fix(sdk): add sk-oh-* OpenHands API key pattern to redact_api_key_literals by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4947 +* Fail over to fallback LLM immediately on hard quota exhaustion by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/4917 +* fix(llm): remove LLM.modify_params past its v1.47.0 removal deadline by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4954 +* fix(acp): materialise only the running provider's file secrets by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/4927 +* fix(sdk): generate titles with Responses and subscription streaming by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4968 +* fix(ts-client): reject browser-only downloads early in Node.js by @BORAN002 in https://github.com/OpenHands/software-agent-sdk/pull/4982 +* fix(sdk): strip inline reasoning from LLM-generated titles by @aniketwaghh in https://github.com/OpenHands/software-agent-sdk/pull/4703 +* fix(agent-server): enforce the paginated search limit by @mkuri in https://github.com/OpenHands/software-agent-sdk/pull/4991 +* fix(agent-server): use a minimal Debian Python/Node runtime by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5077 +* fix(sdk): don't deep-copy the agent LLM in ask_agent by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5085 +* fix(agent-server): delegate MCP OAuth callback to FastMCP instead of forking it by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/4821 +* fix(agent-server): preserve Docker conversation metadata route by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5112 +* fix(agent-server): preserve legacy conversations in Docker catalogs by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5128 +* fix(agent-server): stop rescanning Docker conversations by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5137 +* fix(agent-server): preserve Docker proxy root paths by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5140 +* fix(deps): hold fastmcp below 4 so browser tools keep working in unlocked installs by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/5153 +* fix(plugin): enforce package path containment in plugin formats by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5101 +* fix(agent-server): create Docker conversation workspaces by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5130 +* fix(agent-server): block Docker restarts during deletion by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5132 +* fix(agent-server): expose Docker host gateway by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5164 +* fix(tests): track upstream reasoning_effort support for kimi-k2.5 by @simonrosenberg in https://github.com/OpenHands/software-agent-sdk/pull/5183 +* fix(workspace): preserve caller's AgentContext in load_skills_from_agent_server() by @vnktadithya in https://github.com/OpenHands/software-agent-sdk/pull/4876 +* fix(sdk): stamp the output item id on Responses stream deltas by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5204 +* fix(agent-server): use MCP OAuth credentials passed inline on the agent by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/5078 +* fix(secret): resolve this server's own LookupSecret URLs in-process by @lkshrk in https://github.com/OpenHands/software-agent-sdk/pull/5026 +* Fix #5205: Reset agent_settings when deleting active ACP profile by @jpshackelford in https://github.com/OpenHands/software-agent-sdk/pull/5206 + +#### Automation + +* fix(presets): install SDK into the run virtualenv by @palrohitg in https://github.com/OpenHands/automation/pull/460 +* fix: tolerate transient SQLite write contention by @neubig in https://github.com/OpenHands/automation/pull/462 +* fix: route automation commands through SDK workspaces by @neubig in https://github.com/OpenHands/automation/pull/481 +* fix: release request sessions before route telemetry by @neubig in https://github.com/OpenHands/automation/pull/458 +* fix: cut redundant/noisy PostHog telemetry events by @malhotra5 in https://github.com/OpenHands/automation/pull/486 +* fix(git-sync): preserve selected agent profiles by @neubig in https://github.com/OpenHands/automation/pull/501 +* fix: Add deployment kind to automation telemetry by @malhotra5 in https://github.com/OpenHands/automation/pull/497 +* fix: let org members create automations by @hieptl in https://github.com/OpenHands/automation/pull/496 + +#### OpenHands Cloud (Helm Chart) + +* fix: validate embedded storage capacity for bundled MinIO by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1220 +* fix: stop cert-manager from claiming uploaded LiteLLM TLS secrets by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1221 +* fix(replicated): PLTF-3561 drop dead laminar-query-engine status informers by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1255 +* fix(replicated): PLTF-3561 drop dead laminar-quickwit status informers by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1256 +* fix(replicated): PLTF-3560 cover all LiteLLM credentials in restart checksum by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1258 + +## Maintenance + +#### Enterprise Server + +* test: add a postgres test-database harness by @jlav in https://github.com/OpenHands/enterprise/pull/321 +* test: point the shared database fixtures at postgres by @jlav in https://github.com/OpenHands/enterprise/pull/322 +* test: drop the per-file sqlite engine fixtures by @jlav in https://github.com/OpenHands/enterprise/pull/323 +* chore: Add quint-specs folder with quint lockfile by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/293 +* test(budgets): add the org-budgets Quint spec and oracle instrumentation by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/370 +* revert: remove instance-level admin user lifecycle API by @neubig in https://github.com/OpenHands/enterprise/pull/325 +* docs: clarify DEPLOYMENT_MODE vs app_mode for cloud/self-hosted detection by @juanmichelini in https://github.com/OpenHands/enterprise/pull/454 +* refactor: remove vestigial /api/refresh-tokens endpoint and dead token-fetch code by @tofarr in https://github.com/OpenHands/enterprise/pull/435 + +#### Software Agent SDK + +* ci: enable API compliance and condenser test labels by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4204 +* fix(ci): open PR for merged artifact cleanup by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/4933 +* chore: forbid getattr and setattr in SDK by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4906 +* ci: check Python API breakage on release PRs by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/4971 +* chore: remove merged PR artifacts by @all-hands-bot in https://github.com/OpenHands/software-agent-sdk/pull/5020 +* chore: enable Dependabot uv ecosystem by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5050 +* chore: isolate Dependabot uv updates by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5060 +* ci: accept the existing search limit schema repair by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/5032 +* test(ts-client): migrate from Jest to Vitest by @neubig in https://github.com/OpenHands/software-agent-sdk/pull/5075 +* test(examples): exclude agent-sandbox example from example tests by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5083 +* ci(version-bump-prs): push the TypeScript client bump with the bot PAT by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5089 +* chore(agent-server): remove deprecated desktop URL endpoint past its 1.49.0 deadline by @enyst in https://github.com/OpenHands/software-agent-sdk/pull/5105 +* refactor(sdk): delegate plugin skills discovery to load_skills_from_dir by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5086 +* test(plugin): end-to-end tests for the Agent Plugins package format by @VascoSch92 in https://github.com/OpenHands/software-agent-sdk/pull/5160 + +#### Automation + +* ci: bring .pr/ artifact workflow to parity with software-agent-sdk by @all-hands-bot in https://github.com/OpenHands/automation/pull/435 +* fix(ci): pull MinIO test image from Quay by @palrohitg in https://github.com/OpenHands/automation/pull/447 +* fix(ci): let triage and repository writers own readiness by @neubig in https://github.com/OpenHands/automation/pull/507 + +#### OpenHands Cloud (Helm Chart) + +* fix(ci): send the run identifiers the E2E binding selects on [ref PLTF-3540] by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1228 +* ci: block the openhands release PR on a red unstable E2E [ref PLTF-3540] by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1149 +* fix(e2e): complete new-user login past the 2FA-settings reminder by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1242 +* fix(replicated-deploy): Make the Replicated deploy job re-runnable and its failures more legible by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1243 +* chore: PLTF-3548 raise preflight memory recommendation to 32Gi by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1249 +* test(e2e): cover budget maintenance incidents by @saurya in https://github.com/OpenHands/OpenHands-Cloud/pull/1117 +* chore: PLTF-3561 Add laminar app-server and consumer pod logs to support bundle by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1253 +* test: rename end-to-end test for budgets by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1263 +* build: retry helm package to tolerate transient chart-dependency download failures by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1264 + +## Full Changelog + +- [Enterprise Server releases](https://github.com/OpenHands/enterprise/releases) +- [Software Agent SDK releases](https://github.com/OpenHands/software-agent-sdk/releases) +- [Runtime API releases](https://github.com/OpenHands/runtime-api/releases) +- [Automation releases](https://github.com/OpenHands/automation/releases) +- [OpenHands Cloud releases](https://github.com/OpenHands/OpenHands-Cloud/releases)